US State Law California, USA

California Data Broker Registration: CPPA Registry Rules

Who must register as a data broker in California, annual disclosure requirements, CPPA sweep enforcement at $200 per day, and how the registry feeds the Delete Act.

Regulation

Civ. Code 1798.99.80 et seq. (data broker registration, as amended by the Delete Act)

Max Penalty

$200 per day of unregistered operation, plus unpaid fees and enforcement costs

Enforcing Authority

California Privacy Protection Agency (CPPA)

Official Source

cppa.ca.gov

Executive Summary

  • California requires annual registration by data brokers: businesses that knowingly collect and sell personal information about consumers with whom they have no direct relationship.
  • The Delete Act moved the registry from the AG to the CPPA (from 2024), raised the disclosure requirements, and attached the registry to the DROP deletion mechanism.
  • Registration discloses data practices publicly: whether the broker handles minors' data, precise geolocation, or reproductive health data, plus request metrics and deletion instructions.
  • The CPPA runs active non-registration sweeps and has issued public orders against late registrants at $200 per day of non-compliance, its earliest enforcement program.
  • Registration is jurisdiction-stacking: Vermont, Texas, and Oregon operate their own registries, so national brokers typically file in four states with differing definitions and deadlines.

California’s broker registry began as a transparency measure and became an enforcement funnel. Since the Delete Act handed it to the CPPA, registration is the agency’s easiest case type: the obligation is binary, the evidence is public, and the penalty accrues daily. The registry also now defines who must obey the DROP, so the classification question, are we a broker?, has stopped being academic.

ProvisionCiv. Code 1798.99.80 et seq.
DeadlineAnnual registration by January 31
Penalty$200/day unregistered + fees
RegulatorCPPA (registry public)
Statute1798.99.80 et seq.

The classification analysis

Work through the elements against each revenue stream, not the company as a whole. A SaaS business with a direct customer base is not a broker for its core product, but becomes one for a side business selling enriched firmographic-plus-contact datasets. The no-direct-relationship element is the pivot: data about your own users is out; data about people who never interacted with you is in. Document the analysis, the CPPA asks for it when marketing copy (“400M consumer profiles”) contradicts a non-registration position.

Multistate stacking

Vermont’s registry (2018) started the model; Texas (SB 2105, 2023) and Oregon (HB 2052, 2023) followed with their own definitions and portals. Differences worth noting: Texas requires a comprehensive security program and posts its registry through the Secretary of State; Oregon’s definition sweeps in licensing arrangements explicitly; Vermont’s disclosures focus on opt-out practices and breaches. A national filing calendar with per-state definition mapping is standard practice; California’s Delete Act architecture is the engineering superset that satisfies the rest.

Beyond the filing

Registered brokers remain fully subject to the CCPA (notices, DSARs, opt-outs), face the CPPA’s stated priority on broker practices, and should treat the 2026 DROP deadline as a systems project with a year of lead time. Companies unsure whether their data-sharing patterns edge into brokering can start with the factual record: a free scan maps what flows out of your properties and to whom.

Frequently Asked Questions

What makes a company a 'data broker' in California?

Three elements: knowing collection, sale to third parties, and no direct relationship with the consumers described. 'Sale' carries the CCPA's broad definition (any disclosure for valuable consideration), so licensing enriched profiles, selling audience segments, or monetizing scraped data all qualify. Entities regulated under FCRA, GLBA, or the Insurance Information and Privacy Protection Act are exempt for that regulated activity only, a partial exemption often misread as total.

When and how do we register?

Annually by January 31, through the CPPA's registry portal, with the statutory fee and required disclosures. New brokers register before or upon beginning brokering activity. Filings are public and machine-readable, and privacy researchers, plaintiffs' firms, and the CPPA itself mine the registry for inconsistencies with company marketing claims.

What has enforcement looked like?

The CPPA's Enforcement Division opened its public docket with registration sweeps: investigations of unregistered brokers identified through industry lists and marketing materials, resolved through orders imposing the $200/day penalty plus fees. Published resolutions include penalties against location and people-search brokers, and the division has said sweeps continue as a standing program, low-effort, high-visibility enforcement.

What do we have to disclose about our data?

Beyond identity and contact details: whether you collect or sell minors' data, precise geolocation, or reproductive healthcare data; consumer request metrics (requests received, complied with, denied, response times) from the prior year; and a link to a page explaining how consumers exercise rights. These flags matter: minors', location, and reproductive-health brokering attract the sharpest regulatory and legislative attention.

Does registration change our substantive obligations?

Registration itself is disclosure, but it puts you inside the Delete Act machinery: registered brokers must poll the DROP list every 45 days from August 2026, honor bulk deletion with continuous suppression, and undergo third-party compliance audits every three years from 2028. Registration is the on-ramp; the deletion architecture is the real compliance cost.

Regulatory Crosswalk

Delete ActVermont broker registryTexas SB 2105Oregon HB 2052

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.