.sgp-post{font-family:-apple-system,BlinkMacSystemFont,“Segoe UI”,Roboto,Helvetica,Arial,sans-serif;line-height:1.7;color:#1a1a1a;max-width:800px;margin:0 auto;}
.sgp-post h1{font-size:28px;font-weight:700;line-height:1.3;margin:0 0 24px;}
.sgp-post h2{font-size:22px;font-weight:700;margin:40px 0 16px;}
.sgp-post h3{font-size:18px;font-weight:700;margin:28px 0 12px;}
.sgp-post p{margin:0 0 18px;font-size:16px;}
.sgp-post ul{margin:0 0 18px;padding-left:22px;}
.sgp-post li{margin-bottom:8px;font-size:16px;}
.sgp-post .sgp-table-wrap{overflow-x:auto;margin:24px 0;}
.sgp-post table{width:100%;border-collapse:collapse;font-size:14px;min-width:640px;}
.sgp-post th{background:#0c2a4d;color:#ffffff;text-align:left;padding:10px 12px;font-weight:600;}
.sgp-post td{padding:10px 12px;border-bottom:1px solid #e2e2e2;vertical-align:top;}
.sgp-post tr:nth-child(even) td{background:#f7f8fa;}
.sgp-post strong{font-weight:700;}
SafeGuard Privacy’s New Multi-State Data Broker Assessment
Data broker enforcement actions are a rapidly growing area of focus for privacy enforcers so, today, SafeGuard Privacy is releasing a new Multistate Data Broker Assessment for companies to use to ensure they and their vendors are complying with the many new data broker laws. SafeGuard’s new Data Broker Assessment provides questions and commentary to guide you through the requirements of the California Delete Act/DROP requirements, Texas and Vermont information security program implementations and other nuances in Oregon and Nevada data broker requirements, providing an efficient means to conduct due diligence on vendors that qualify as data brokers.
The Data Broker Assessment Covers All State Data Broker Laws Currently In Effect
The Data Broker Assessment includes questions on all state data broker laws currently in effect:
- California Data Broker Registration Law, Cal. Civ. Code Title 1.81.48, § 1798.99.80 et seq., as amended by the Delete Act, SB 362 (2023)
- Texas Data Broker Law, Tex. Bus. & Com. Code §§ 509.001 et seq., as amended by SB 1834 (2019) and SB 2105 (2023)
- Vermont Data Broker Law, § 2. 9 V.S.A. chapter 62, §§ 2430, 2433, 2446–2447
- Oregon Data Broker Law, ORS 646A.593 et seq.
- Nevada Privacy Law, NRS 603A.300–603A.36, as amended by SB 260 (2021)
The Data Broker Assessment begins with preliminary questions to determine whether your company – or your vendors – are considered to be data brokers under the various state laws, as the jurisdictional requirement of each law is different. The Data Broker Assessment then focuses on ensuring that companies qualifying as data brokers have properly completed the data broker registration in each state in which they qualify. Because every state with a data broker law requires completion of an online registration form, we do not needlessly repeat each question from the online registration, but instead focus on providing links to the forms, guidance on completing the forms, and – especially for vendors – confirmation that the company has properly completed the forms.
The Data Broker Assessment also provides questions and commentary guidance on the other requirements in the state data brokers laws – of which there are many. In fact, because there are few commonalities between any of the state data broker laws, the Data Broker Assessment provides you with the broad scope of coverage of all of the unique requirements.
California
Since California is the most active regulator in Privacy, Delete Act obligations are front and center in the Data Broker Assessment. This starts with California Privacy Protection Agency’s (CalPrivacy) Delete Request and Opt-Out Platform (DROP) requirements. DROP gives California consumers the power to submit a single verifiable request directing every registered data broker to delete their personal information.
Beginning August 1, 2026, data brokers that fail to handle DROP deletion requests properly and in a timely manner will face daily penalties for each mishandled request.
The Data Broker Assessment also covers unique Delete Act privacy notice disclosure requirements and independent third party auditing requirements that take effect in 2028.
Texas
The Texas Data Broker Law (TDBL) has a disclosure requirement for companies unlike the California Delete Act. The TDBL notice must be on a data broker’s main website, not just the linked privacy notice. This Data Broker Assessment also covers the unique TDBA requirement that any changes to a data broker’s submission must be accompanied by a formal statement of correction.
By far the most important TDBL requirement is its extensive and detailed information security program demands. The Data Broker Assessment covers all of these TDBL infosec requirements in the exacting detail necessary to make sure that your company – and your vendors – are in compliance.
Vermont
Like the TDBL, Vermont’s Data Broker Law (VTBDL) contains an extensive list of infosec program requirements. Some of the VTDBL’s infosec requirements overlap with the TBDL’s, but not all do – we cover them all so you don’t have to worry about gaps.
Oregon
Oregon’s Data Broker Law has some unique disclosure requirements to notify the Oregon Department of Consumer and Business Services within 45 days of any data breach or any material changes to the data broker registration or corporate status.
Nevada
Nevada is the only state that does not specifically require data broker registration, but sets out requirements for both data brokers and certain in-state website owners, which the Nevada Privacy Law calls “operators.” SafeGuard’s Data Broker Assessment covers both the Nevada Privacy Law notice requirements for operators and the right to opt out requirements for both operators and data brokers.
Why Do You Need SafeGuard’s Data Broker Assessment? Enforcement Risk.
As noted above, data broker enforcement actions are proliferating with California first conducting an audit, then deploying a full-fledged strike force.
The Data Broker Registration Compliance Sweep
In October 2024, California’s privacy regulator decided that a registry no one polices isn’t a registry at all. The CalPrivacy data broker investigative sweep launched a methodical audit of who was actually registered to buy and sell Californians’ personal information – and who wasn’t. The results were blunt: nine enforcement actions, hundreds of thousands of dollars in fines, and the public unmasking of brokers who thought registration was optional. From sales-prospecting tools to a marketing firm with a multibillion-record breach in its rearview mirror, the Sweep proved that “I didn’t know I was a data broker” is not a defense California’s regulators are interested in hearing.
Data Broker Enforcement Strike Force
If the Sweep was the audit, the Strike Force is the standing task force. Launched in November 2025, CalPrivacy’s Data Broker Enforcement Strike Force signaled a permanent shift from periodic compliance checks to sustained, intensive investigation — explicitly modeled on the strike-force playbook long used by U.S. Attorneys and state AGs. The Strike Force’s mandate goes beyond simple registration: it scrutinizes data brokers for full CCPA compliance, not just paperwork. CalPrivacy’s press release for the Strike Force’s first victim, ROR Partners, delivered the line that now defines California’s enforcement posture: “a sale is a sale.” Convert personal data to profiles, call it marketing services or anything else really; if you’re in the business of selling Californians’ personal information, the Strike Force says you’re a data broker. If you haven’t registered, the risk is real that the Strike Force will find you – and fine you.
| Company | Date | Reason | Fine | Enforcement Action |
|---|---|---|---|---|
| Growbots, Inc. | Nov. 8, 2024 | Failed to register (177 days) | $35,400 | 2024 Data Broker Registration Compliance Sweep |
| UpLead LLC | Nov. 8, 2024 | Failed to register (172 days) | $34,400 | Sweep |
| PayDae, Inc. d/b/a Infillion | Dec. 19, 2024 | Failed to register (278 days) | $54,200 | Sweep |
| The Data Group, LLC | Dec. 19, 2024 | Failed to register (233 days) | $46,600 | Sweep |
| Key Marketing Advantage, LLC (KMA) | Jan. 27, 2025 | Failed to register (279 days) | $55,800 | Sweep |
| Jerico Pictures, Inc. d/b/a National Public Data | May 8, 2025 | Registered 230 days late, only after CPPA contact; 2.9 billion-record breach | $46,000 | Sweep |
| Background Alert, Inc. | Feb. 26, 2025 | Created and sold consumer profiles from inferences on public records; failed to register (251 days) | Must cease operations through 2028 or pay $50,000 | Sweep |
| Accurate Append, Inc. | July 29, 2025 | Registered only after CalPrivacy demand | $55,400 | Sweep |
| ROR Partners, LLC | Nov. 26, 2025 | Built consumer profiles/custom audience segments sold for targeted advertising, failed to register | $56,600 | Data Broker Enforcement Strike Force |
| Rickenbacher Data LLC d/b/a Datamasters | Dec. 30, 2025 | Sold lists based on sensitive data; failed to register | $45,000, plus order to stop selling CA consumer data | Strike Force |
| S&P Global, Inc. | Jan. 8, 2026 | Failed to register, claimed administrative error (313 days) | $62,600 | Strike Force |
Fines – to date – are based upon the Delete Act’s $200/day penalty for failing to register. So far, 575 data brokers have registered for 2026. CalPrivacy believes that there are thousands who have not registered. That means we are very likely to see the number of enforcement actions increase. Even bigger fines, in the six and seven figures, are likely given CalPrivacy’s new DROP site.
Beginning August 1, 2026, data brokers must retrieve DROP deletion requests at least every 45 days, evaluate and match requests using standardized identifiers, delete personal information unless a statutory exception applies, and complete determinations within 90 days of retrieval. Failing to comply with the DROP requirements carries its own $200/day penalty – which means that the meter will be running for every deletion request that’s late.
As of May 1, 2026, there were over 285,000 registrations for DROP, representing more than 1 million California residents. CalPrivacy is running a $2.5 million paid media campaign to raise consumer awareness which will bring those numbers even higher. Considering that even one missed DROP request can cost you $200/day, the potential multi-million dollar threat of missing thousands of them is reason enough to focus on Delete Act/DROP requirements.
Texas Takes Action Too
California is not the only state to have taken action against unregistered data brokers. In June 2024, Texas Attorney General Ken Paxton issued letters notifying over 100 companies of their apparent failure to register as data brokers. The Texas Attorney General followed up with a January 13, 2025 lawsuit against Allstate and its subsidiary Arity, alleging among other things, that the companies processed the personal data of over 50,000 individuals but failed to register under the Texas Data Broker Law. The action is pending.
We’ll Update the Data Broker Assessment For Changes in This Fast-Growing Area
More states are passing data broker laws. We will be updating the Data Broker Assessment soon to incorporate coming obligations, including:
Connecticut
Connecticut SB-4/Public Act No. 26-64 (along with two companion bills) added a data broker registration framework to the Connecticut Data Privacy Act. The data broker amendments to the CTDPA will become effective on October 1, 2026.
Vermont
Vermont H.211 amended the VTDBRA to increase registration fees and impose a legitimate-purpose certification, a surety bond requirement, and strengthen the data breach notification rules. While it did not enact the equivalent of the California Delete Act, did fund a study of the feasibility of doing so. The Vermont data broker amendments become generally effective on January 1, 2027.
New Jersey
On June 30, 2026, the New Jersey governor signed NJ A3538, making the New Jersey Data Broker Act effective immediately, though the registration and enforcement provisions do not take effect until 270 days after, on March 27, 2027. The NJDBA is similar to other data broker laws, but also requires covered data brokers to complete Data Protection Assessments. The NJDBA goes above and beyond other laws in terms of its costs, with filing fees of up to $1.5 million dollars for the largest data brokers and penalties of $2,500 per day for late registration filings. There have been a couple of notable developments since this law was enacted. NJ Division of Consumer Affairs issued an alert clarifying that registration and fees are not required until 2027 and that it will offer guidance on the prohibition against selling sensitive personal information. There are also suggestions that the law may be subject to quick amendment by the legislature to remedy what are seen as deficits.
Additional State Laws
There has been much talk in state legislative circles about the need for more control over data brokers, particularly in light of a continued lack of federal action in this area. We will continue to track developments – and add new questions and guidance to the new Multistate Data Broker Assessment as events warrant.
