Product Updates

New: US Multi-State Data Broker Assessment

Efficiently conduct due diligence on vendors that qualify as data brokers. Includes requirements of the California Delete Act/DROP requirements, Texas and Vermont information security program implementations, and Oregon and Nevada data broker requirements.

.sgp-post{font-family:-apple-system,BlinkMacSystemFont,“Segoe UI”,Roboto,Helvetica,Arial,sans-serif;line-height:1.7;color:#1a1a1a;max-width:800px;margin:0 auto;}
.sgp-post h1{font-size:28px;font-weight:700;line-height:1.3;margin:0 0 24px;}
.sgp-post h2{font-size:22px;font-weight:700;margin:40px 0 16px;}
.sgp-post h3{font-size:18px;font-weight:700;margin:28px 0 12px;}
.sgp-post p{margin:0 0 18px;font-size:16px;}
.sgp-post ul{margin:0 0 18px;padding-left:22px;}
.sgp-post li{margin-bottom:8px;font-size:16px;}
.sgp-post .sgp-table-wrap{overflow-x:auto;margin:24px 0;}
.sgp-post table{width:100%;border-collapse:collapse;font-size:14px;min-width:640px;}
.sgp-post th{background:#0c2a4d;color:#ffffff;text-align:left;padding:10px 12px;font-weight:600;}
.sgp-post td{padding:10px 12px;border-bottom:1px solid #e2e2e2;vertical-align:top;}
.sgp-post tr:nth-child(even) td{background:#f7f8fa;}
.sgp-post strong{font-weight:700;}

SafeGuard Privacy’s New Multi-State Data Broker Assessment

Data broker enforcement actions are a rapidly growing area of focus for privacy enforcers so, today, SafeGuard Privacy is releasing a new Multistate Data Broker Assessment for companies to use to ensure they and their vendors are complying with the many new data broker laws. SafeGuard’s new Data Broker Assessment provides questions and commentary to guide you through the requirements of the California Delete Act/DROP requirements, Texas and Vermont information security program implementations and other nuances in Oregon and Nevada data broker requirements, providing an efficient means to conduct due diligence on vendors that qualify as data brokers.

The Data Broker Assessment Covers All State Data Broker Laws Currently In Effect

The Data Broker Assessment includes questions on all state data broker laws currently in effect:

  • California Data Broker Registration Law, Cal. Civ. Code Title 1.81.48, § 1798.99.80 et seq., as amended by the Delete Act, SB 362 (2023)
  • Texas Data Broker Law, Tex. Bus. & Com. Code §§ 509.001 et seq., as amended by SB 1834 (2019) and SB 2105 (2023)
  • Vermont Data Broker Law, § 2. 9 V.S.A. chapter 62, §§ 2430, 2433, 2446–2447
  • Oregon Data Broker Law, ORS 646A.593 et seq.
  • Nevada Privacy Law, NRS 603A.300–603A.36, as amended by SB 260 (2021)

The Data Broker Assessment begins with preliminary questions to determine whether your company – or your vendors – are considered to be data brokers under the various state laws, as the jurisdictional requirement of each law is different. The Data Broker Assessment then focuses on ensuring that companies qualifying as data brokers have properly completed the data broker registration in each state in which they qualify. Because every state with a data broker law requires completion of an online registration form, we do not needlessly repeat each question from the online registration, but instead focus on providing links to the forms, guidance on completing the forms, and – especially for vendors – confirmation that the company has properly completed the forms.

The Data Broker Assessment also provides questions and commentary guidance on the other requirements in the state data brokers laws – of which there are many. In fact, because there are few commonalities between any of the state data broker laws, the Data Broker Assessment provides you with the broad scope of coverage of all of the unique requirements.

California

Since California is the most active regulator in Privacy, Delete Act obligations are front and center in the Data Broker Assessment. This starts with California Privacy Protection Agency’s (CalPrivacy) Delete Request and Opt-Out Platform (DROP) requirements. DROP gives California consumers the power to submit a single verifiable request directing every registered data broker to delete their personal information.

Beginning August 1, 2026, data brokers that fail to handle DROP deletion requests properly and in a timely manner will face daily penalties for each mishandled request.

The Data Broker Assessment also covers unique Delete Act privacy notice disclosure requirements and independent third party auditing requirements that take effect in 2028.

Texas

The Texas Data Broker Law (TDBL) has a disclosure requirement for companies unlike the California Delete Act. The TDBL notice must be on a data broker’s main website, not just the linked privacy notice. This Data Broker Assessment also covers the unique TDBA requirement that any changes to a data broker’s submission must be accompanied by a formal statement of correction.

By far the most important TDBL requirement is its extensive and detailed information security program demands. The Data Broker Assessment covers all of these TDBL infosec requirements in the exacting detail necessary to make sure that your company – and your vendors – are in compliance.

Vermont

Like the TDBL, Vermont’s Data Broker Law (VTBDL) contains an extensive list of infosec program requirements. Some of the VTDBL’s infosec requirements overlap with the TBDL’s, but not all do – we cover them all so you don’t have to worry about gaps.

Oregon

Oregon’s Data Broker Law has some unique disclosure requirements to notify the Oregon Department of Consumer and Business Services within 45 days of any data breach or any material changes to the data broker registration or corporate status.

Nevada

Nevada is the only state that does not specifically require data broker registration, but sets out requirements for both data brokers and certain in-state website owners, which the Nevada Privacy Law calls “operators.” SafeGuard’s Data Broker Assessment covers both the Nevada Privacy Law notice requirements for operators and the right to opt out requirements for both operators and data brokers.

Why Do You Need SafeGuard’s Data Broker Assessment? Enforcement Risk.

As noted above, data broker enforcement actions are proliferating with California first conducting an audit, then deploying a full-fledged strike force.

The Data Broker Registration Compliance Sweep

In October 2024, California’s privacy regulator decided that a registry no one polices isn’t a registry at all. The CalPrivacy data broker investigative sweep launched a methodical audit of who was actually registered to buy and sell Californians’ personal information – and who wasn’t. The results were blunt: nine enforcement actions, hundreds of thousands of dollars in fines, and the public unmasking of brokers who thought registration was optional. From sales-prospecting tools to a marketing firm with a multibillion-record breach in its rearview mirror, the Sweep proved that “I didn’t know I was a data broker” is not a defense California’s regulators are interested in hearing.

Data Broker Enforcement Strike Force

If the Sweep was the audit, the Strike Force is the standing task force. Launched in November 2025, CalPrivacy’s Data Broker Enforcement Strike Force signaled a permanent shift from periodic compliance checks to sustained, intensive investigation — explicitly modeled on the strike-force playbook long used by U.S. Attorneys and state AGs. The Strike Force’s mandate goes beyond simple registration: it scrutinizes data brokers for full CCPA compliance, not just paperwork. CalPrivacy’s press release for the Strike Force’s first victim, ROR Partners, delivered the line that now defines California’s enforcement posture: “a sale is a sale.” Convert personal data to profiles, call it marketing services or anything else really; if you’re in the business of selling Californians’ personal information, the Strike Force says you’re a data broker. If you haven’t registered, the risk is real that the Strike Force will find you – and fine you.

Company Date Reason Fine Enforcement Action
Growbots, Inc. Nov. 8, 2024 Failed to register (177 days) $35,400 2024 Data Broker Registration Compliance Sweep
UpLead LLC Nov. 8, 2024 Failed to register (172 days) $34,400 Sweep
PayDae, Inc. d/b/a Infillion Dec. 19, 2024 Failed to register (278 days) $54,200 Sweep
The Data Group, LLC Dec. 19, 2024 Failed to register (233 days) $46,600 Sweep
Key Marketing Advantage, LLC (KMA) Jan. 27, 2025 Failed to register (279 days) $55,800 Sweep
Jerico Pictures, Inc. d/b/a National Public Data May 8, 2025 Registered 230 days late, only after CPPA contact; 2.9 billion-record breach $46,000 Sweep
Background Alert, Inc. Feb. 26, 2025 Created and sold consumer profiles from inferences on public records; failed to register (251 days) Must cease operations through 2028 or pay $50,000 Sweep
Accurate Append, Inc. July 29, 2025 Registered only after CalPrivacy demand $55,400 Sweep
ROR Partners, LLC Nov. 26, 2025 Built consumer profiles/custom audience segments sold for targeted advertising, failed to register $56,600 Data Broker Enforcement Strike Force
Rickenbacher Data LLC d/b/a Datamasters Dec. 30, 2025 Sold lists based on sensitive data; failed to register $45,000, plus order to stop selling CA consumer data Strike Force
S&P Global, Inc. Jan. 8, 2026 Failed to register, claimed administrative error (313 days) $62,600 Strike Force

Fines – to date – are based upon the Delete Act’s $200/day penalty for failing to register. So far, 575 data brokers have registered for 2026. CalPrivacy believes that there are thousands who have not registered. That means we are very likely to see the number of enforcement actions increase. Even bigger fines, in the six and seven figures, are likely given CalPrivacy’s new DROP site.

Beginning August 1, 2026, data brokers must retrieve DROP deletion requests at least every 45 days, evaluate and match requests using standardized identifiers, delete personal information unless a statutory exception applies, and complete determinations within 90 days of retrieval. Failing to comply with the DROP requirements carries its own $200/day penalty – which means that the meter will be running for every deletion request that’s late.

As of May 1, 2026, there were over 285,000 registrations for DROP, representing more than 1 million California residents. CalPrivacy is running a $2.5 million paid media campaign to raise consumer awareness which will bring those numbers even higher. Considering that even one missed DROP request can cost you $200/day, the potential multi-million dollar threat of missing thousands of them is reason enough to focus on Delete Act/DROP requirements.

Texas Takes Action Too

California is not the only state to have taken action against unregistered data brokers. In June 2024, Texas Attorney General Ken Paxton issued letters notifying over 100 companies of their apparent failure to register as data brokers. The Texas Attorney General followed up with a January 13, 2025 lawsuit against Allstate and its subsidiary Arity, alleging among other things, that the companies processed the personal data of over 50,000 individuals but failed to register under the Texas Data Broker Law. The action is pending.

We’ll Update the Data Broker Assessment For Changes in This Fast-Growing Area

More states are passing data broker laws. We will be updating the Data Broker Assessment soon to incorporate coming obligations, including:

Connecticut

Connecticut SB-4/Public Act No. 26-64 (along with two companion bills) added a data broker registration framework to the Connecticut Data Privacy Act. The data broker amendments to the CTDPA will become effective on October 1, 2026.

Vermont

Vermont H.211 amended the VTDBRA to increase registration fees and impose a legitimate-purpose certification, a surety bond requirement, and strengthen the data breach notification rules. While it did not enact the equivalent of the California Delete Act, did fund a study of the feasibility of doing so. The Vermont data broker amendments become generally effective on January 1, 2027.

New Jersey

On June 30, 2026, the New Jersey governor signed NJ A3538, making the New Jersey Data Broker Act effective immediately, though the registration and enforcement provisions do not take effect until 270 days after, on March 27, 2027. The NJDBA is similar to other data broker laws, but also requires covered data brokers to complete Data Protection Assessments. The NJDBA goes above and beyond other laws in terms of its costs, with filing fees of up to $1.5 million dollars for the largest data brokers and penalties of $2,500 per day for late registration filings. There have been a couple of notable developments since this law was enacted. NJ Division of Consumer Affairs issued an alert clarifying that registration and fees are not required until 2027 and that it will offer guidance on the prohibition against selling sensitive personal information. There are also suggestions that the law may be subject to quick amendment by the legislature to remedy what are seen as deficits.

Additional State Laws

There has been much talk in state legislative circles about the need for more control over data brokers, particularly in light of a continued lack of federal action in this area. We will continue to track developments – and add new questions and guidance to the new Multistate Data Broker Assessment as events warrant.

SafeGuard Privacy

Ready to close the gap between trust centers and actual due diligence?

Give us 20 minutes to show you how we can help.

Schedule a DemoExplore the Platform