Enforcement Has Already Started
If your company sells or shares data and hasn’t registered as a data broker, you may already be non-compliant. Regulators are actively enforcing data broker laws:
Companies are being penalized not for misuse, but simply for failing to register or meet baseline requirements. And these are just early enforcement actions.
The Real Risk Isn’t the Fine, It’s How It Scales
- Failure to register can trigger $200 per day in fines
- Failure to process deletion requests can trigger $200 per request, per day
That means:
- 6 months unregistered → ~$36,000 exposure
- 12 months unregistered → ~$73,000+ exposure
- Mishandling deletion requests at scale → six- to seven-figure risk
California is not alone, as other states already require data broker registration:
- Vermont — one of the earliest data broker laws (since 2018)
- Texas — active registration and disclosure requirements
- Oregon — newer law with expanding scope
Redefining Who is a “Data Broker”
Enforcement is not limited to obvious players. Even companies that don’t identify as data brokers are being pulled into scope. Regulators care about what your product does with data, not how you label your company.
If you use third-party data, this may fall into scope if your product:
- Sells leads or contact data (lead gen tools)
- Enriches profiles with external data (CRMs, enrichment platforms)
- Builds or sells audience (marketing tools)
- Returns personal data via API (data products)
In each case, you’re distributing data about people you don’t have a direct relationship with; this is a core trigger for data broker classification.
Are You Acting Like a Data Broker?
Answer a few quick questions:
- Do you use or acquire data about individuals from third-party sources?
- Do you provide that data to customers by selling it, licensing it, or exposing it via API or product features?
- Do you NOT have a direct relationship with most of the individuals in that data?
If you answered Yes to multiple questions, you should assume potential obligations under laws like the California Delete Act and similar frameworks in Texas, Vermont, and Oregon.
Final Takeaway and Next Steps
Data broker laws aren’t targeting a specific type of company, rather than a behavior: Acquiring data about people you don’t know and providing it to others. If that describes any part of your product, this isn’t a theoretical issue. It’s a current compliance risk that can cost your business thousands of dollars.
If you answered “Yes” to multiple questions above, don’t wait for enforcement to find you. Start with:
- Mapping your data flows: Where data comes from, how it’s enriched, and where it’s exposed
- Identifying where you lack a direct relationship with individuals: This is the trigger most teams overlook
- Checking registration requirements across states: Especially California, Texas, Vermont, and Oregon
At
People Data Labs, we believe that data is one of the most powerful growth levers available to any business. As regulations and market landscapes continue to evolve, businesses that prioritize compliance and transparency will outperform those that don’t.
If you’re looking for a partner to help build your data strategy or are just unsure about how these new regulations might impact your business,
let’s talk!