CalPrivacy issued Enforcement Advisory No. 2025-01 to remind data brokers of their annual registration obligations under California's Delete Act, including disclosing all trade names and websites and registering independently rather than through a parent company. The advisory warns that failures to comply may result in administrative fines of $200 per day, plus fees and recovery costs. It also highlights the upcoming Delete Request and Opt-Out Platform (DROP) launching January 1, 2026.
In-house legal teams should review all vendor, data processing, and customer agreements where the company may be classified as a 'data broker' under the California Delete Act. Specifically, scrutinize clauses requiring disclosure of all trade names and websites, ensuring the agreement does not rely on a parent or affiliate entity's registration. Update contracts to reflect the upcoming Delete Request and Opt-Out Platform (DROP) compliance obligations, including mechanisms for honoring consumer deletion requests effective January 1, 2026. Verify that any data brokering activities are covered by an independent, current registration with CalPrivacy and that annual fee responsibilities are clearly allocated.
Entity
Data Brokers
Industry
Data BrokerOfficial Press Release
https://privacy.ca.gov/2025/12/calprivacy-issues-enforcement-advisory-highlighting-data-broker-registration/
enfadvisory202501
https://privacy.ca.gov/wp-content/uploads/sites/357/2026/01/enfadvisory202501.pdf
California Attorney General Enforcement Page
https://oag.ca.gov/privacy/privacy-enforcement-actions
The Federal Trade Commission (FTC) sent warning letters to 13 data brokers reminding them of their obligations under the Protecting Americans’ Data from Foreign Adversaries Act (PADFAA). PADFAA prohibits data brokers from selling or providing sensitive personal data about Americans to foreign adversaries such as China, Russia, Iran, and North Korea. The letters warn that violations could result in civil penalties of up to $53,088 per violation and urge companies to review their business practices for compliance.
The California Privacy Protection Agency (CalPrivacy) announced the creation of a Data Broker Enforcement Strike Force to investigate privacy violations by data brokers. The strike force will focus on compliance with the Delete Act's registration requirement and the CCPA, building on previous enforcement actions. This initiative aims to hold data brokers accountable and protect Californians' personal information.
The California Privacy Protection Agency (CalPrivacy) announced the creation of a Data Broker Enforcement Strike Force to investigate privacy violations by data brokers under the CCPA and Delete Act. The strike force will focus on compliance with registration requirements and other obligations, building on previous enforcement actions to increase accountability.
Governor Newsom signed the Expanding Privacy Rights Act (SB 923), expanding CCPA deletion rights to cover personal information obtained from third parties and requiring online-only businesses to offer an online method for submitting privacy requests. The law takes effect January 1, 2027, and allows businesses to maintain suppression lists to help keep deleted information from being reacquired.
The California Privacy Protection Agency announced that the California State Legislature approved the Expanding Privacy Rights Act (SB 923), which expands the CCPA's right to delete to cover all non-exempt personal information a business holds about a consumer, including data originally collected from third parties. The bill also requires online-only businesses with a direct relationship to consumers to provide online methods, such as webforms, for submitting access, deletion, and correction requests, and expressly permits businesses to retain suppression lists so deleted information stays deleted. The bill, authored by Senator Becker and sponsored by CalPrivacy, now goes to the Governor for consideration.
A bipartisan coalition of 33 state attorneys general, led by Minnesota AG Keith Ellison, began trial against Meta Platforms, Inc., alleging the company knowingly designed and deployed harmful features on Facebook and Instagram that drive children and teens to use the platforms compulsively, while falsely assuring parents and the public that its platforms were safe for young users. The states also allege Meta illegally collected personal information from children under 13 without parental consent, violating COPPA. The trial opened before Judge Yvonne Gonzalez Rogers in the U.S. District Court for the Northern District of California, with the states seeking monetary penalties and injunctive relief.