Compliance Intelligence for Online Businesses.
What Changed. Why It Matters. What to Do Next.
California Data Broker Compliance Is Becoming an Operations Test.
Operational Compliance Intelligence for Internet Businesses.
Welcome to the CLICBrain Weekly Briefing – operational compliance intelligence for internet businesses from CLIClaw.com.
Each week, we identify significant privacy, AI, advertising, data governance, email marketing, and regulatory developments and focus on what they mean operationally: what systems, workflows, governance controls, and evidence organizations should examine in response.
This week, our attention turns to California’s evolving data broker framework – and an important shift from registration compliance to operational execution.
California’s Data Broker Rules Are Moving From Registration to Execution.
For years, a central California data broker compliance question was relatively straightforward:
Did the business determine whether it qualified as a data broker and, if required, register?
That is no longer enough.
California’s Delete Request and Opt-out Platform (“DROP”) became available to consumers on January 1, 2026. Beginning August 1, 2026, registered data brokers must access DROP at least once every 45 days and process consumer deletion requests in accordance with the law.
That changes the operational challenge.
A business may need to determine whether it can identify the consumer’s personal information, delete information that must be deleted, direct applicable service providers and contractors to take required action, handle information that may be retained under a statutory exception, and maintain the processes necessary to support ongoing compliance.
The question is no longer simply:
“Did we register?”
It is becoming:
“Can our organization actually execute the obligations that follow?”
If a DROP Request Arrived Today, What Would Happen?
Ask three questions:
-
Could we locate the consumer’s personal information across the systems where it is maintained?
-
Could we identify the service providers or contractors that may also hold information covered by the request?
-
Could we document what was deleted, what was retained under an applicable exception, and how the request was handled?
If answering those questions requires reconstructing data flows, searching old spreadsheets, contacting multiple employees to determine what happened, or figuring out vendor responsibilities for the first time, the organization may have a workflow problem, not merely a legal interpretation problem.
From Registration to Deletion Governance.
California’s DROP system allows California consumers to submit a single request directing registered data brokers to delete personal information associated with them.
Beginning August 1, 2026, data brokers must access DROP at least once every 45 days. Under the Delete Act framework, they generally must process applicable deletion requests within 45 days after receiving them through the system.
The obligations can extend beyond information sitting in the data broker’s own database.
For applicable deletion requests, the law requires data brokers to direct associated service providers or contractors to delete personal information in their possession related to the requesting consumer. Where a deletion request cannot be verified, the law provides for processing the request as an opt-out of sale or sharing, subject to applicable statutory limitations.
Certain information may also qualify for statutory exceptions. Information retained under those provisions is subject to restrictions on its subsequent use.
For businesses, that means DROP readiness can involve much more than periodically downloading a file.
An effective process may require coordination among:
-
consumer identity and matching processes;
-
internal databases and customer systems;
-
marketing and advertising systems;
-
data enrichment and audience tools;
-
service providers and contractors;
-
exception-handling procedures;
-
suppression or opt-out controls; and
-
documentation showing how the request was resolved.
California’s regulations also contemplate both manual and automated access to DROP. Even businesses developing automated integrations need procedures addressing what happens if those automated connections fail.
That makes deletion governance a business process, not simply a privacy-policy requirement.
-
California Is Already Enforcing Data Broker Registration.
The California Privacy Protection Agency’s Data Broker Enforcement Strike Force continued its enforcement activity in January.
On January 8, 2026, the Agency announced decisions involving Rickenbacher Data LLC, doing business as Datamasters, and S&P Global.
Datamasters agreed to pay a $45,000 fine for failing to register as a data broker and was ordered to stop selling Californians’ personal information.
The enforcement action is particularly notable because the Agency said the company bought and resold information associated with individuals with serious health conditions for targeted advertising.
S&P Global agreed to pay $62,600 for failing to register as required.
✔ CLIClaw Compliance Tip: Data broker applicability needs an owner, a documented determination, and a process for making sure required registrations actually occur.
-
Registration Is Becoming a More Meaningful Governance Record.
California’s data broker registration regime is increasingly requiring businesses to know more about their own data practices.
That makes the annual registration process more than an administrative filing exercise.
Organizations should be able to reconcile what is reported through registration with the information reflected in their data inventories, consumer-rights metrics, contracts, privacy disclosures, and internal governance records.
✔ CLIClaw Compliance Tip: A filing that cannot be supported by the organization’s underlying records can expose a larger operational problem: The organization may not have reliable visibility into its own data practices.
-
Federal Scrutiny Adds Another Data-Flow Question.
California is not the only reason businesses should understand where personal information goes.
On February 9, 2026, the Federal Trade Commission announced that it had sent warning letters to 13 data brokers concerning their obligations under the Protecting Americans’ Data from Foreign Adversaries Act of 2024 (“PADFAA”).
PADFAA restricts data brokers from selling, releasing, disclosing, or providing access to certain personally identifiable sensitive data about U.S. individuals to foreign adversaries or entities controlled by them.
✔ CLIClaw Compliance Tip: DROP requires organizations to understand where consumer data resides. PADFAA can require organizations to understand where sensitive data goes.
Both depend on reliable data-flow visibility and downstream-party governance.
The Enforcement Lesson: Governance Failures Count.
The S&P Global enforcement action demonstrates a compliance problem that businesses sometimes underestimate.
Not every violation begins with someone consciously deciding to ignore the law.
According to the CPPA, S&P Global’s registration failure resulted from an administrative error. The resulting decision nevertheless required payment of a $62,600 fine and implementation of procedures addressing registration and compliance auditing.
That matters for businesses far beyond the data broker industry.
An organization can understand a legal requirement and still fail because:
-
responsibility was unclear;
-
a deadline was not assigned;
-
a recurring obligation was not tracked;
-
an internal handoff failed; or
-
no one verified that the required action actually occurred.
✔ CLIClaw Compliance Tip: Knowing the requirement and operationalizing the requirement are two different controls.
Your Deletion Process Depends on Someone Manually Figuring Out Where the Data Went.
A deletion request should not require employees to reconstruct the organization’s data ecosystem from memory.
If the process depends heavily on spreadsheets, individual employees remembering which vendors receive data, manually emailing third parties, or figuring out system ownership after a request arrives, the organization may not have a scalable deletion-governance process.
That weakness becomes increasingly important when a single consumer request can require coordinated action across multiple systems and outside parties.
✔ CLIClaw Compliance Tip: If the organization cannot reliably trace where the data went, it may struggle to prove where deletion needed to go.
Trace One Deletion Request From Start to Finish.
Don’t wait until August to discover where the workflow breaks.
Select one test consumer record and simulate what would happen if a DROP deletion request involving that record reached the organization.
Start with the identifier you would receive.
Then trace the record through the systems and processes that would actually be involved:
-
Where is the consumer’s information located?
-
What other identifiers are associated with that person?
-
Which service providers or contractors may possess related information?
-
Who is responsible for initiating deletion?
-
How would an applicable exception be identified and documented?
-
How would required opt-out treatment be handled if the deletion request could not be verified?
-
What evidence would demonstrate that the process was completed?
You do not need to redesign the entire privacy program during the exercise.
✔ CLIClaw Compliance Tip: Find the point where the request stops moving smoothly. That is the workflow to address before August 1.
Q: We license aggregated behavioral data to analytics companies. Could we be a data broker?
CLICBrain: Potentially. The analysis depends on the underlying information, how it was collected, the relationship with the consumer, what downstream recipients receive, and whether information described as aggregated or deidentified actually meets applicable legal standards.
Do not rely on the label attached to the dataset or the company’s business model alone.
The more useful compliance question is:
“Can we document why we concluded that we are, or are not, a data broker?”
Have another compliance question? Ask CLICBrain on CLIClaw.com.
Related CLIClaw Solutions.
This week’s CLICBrain Takeaway highlights two connected compliance needs: determining whether an organization falls within California’s data broker requirements and preparing operational systems to carry out the obligations that follow.
California Data Broker Applicability & Readiness Playbook. Use it to evaluate whether business activities may trigger California data broker requirements and document the organization’s applicability determination.
California Data Broker Compliance Toolkit. Use it to move from applicability and registration into the technical, operational, and governance controls needed to support ongoing compliance.
One Question to Take With You.
If a California consumer’s DROP request reached your organization tomorrow, could you trace that consumer’s data through your systems, service providers, deletion decisions, exceptions, and evidence without reconstructing the process from scratch?
That may be the difference between having a privacy requirement on paper and having a compliance process that actually works.
CLICBrain Weekly Briefings provide operational compliance intelligence and commentary for internet businesses. Regulatory developments, enforcement activity, and legal requirements discussed herein should be evaluated in the context of your organization’s specific operations, systems, data practices, and risk profile. This briefing is for informational and educational purposes only and does not constitute legal advice.





