Is My Startup a Data Broker Under California Law?
“We don’t sell data, so this doesn’t apply to us.” That sentence just got a lot more expensive to be wrong about.
On August 11, 2026, California’s Privacy Protection Agency (CalPrivacy) fined Iowa-based LocateSmarter LLC $116,490. It was the first enforcement action ever to combine CCPA and Delete Act violations in a single case.
Two days later, on August 13, 2026, CalPrivacy fined Boston-based Cybba, Inc. $52,400 for missing the Delete Act’s data broker registration deadline of January 31, 2025.
Both fines landed right as a new requirement kicked in. As of August 1, 2026, every registered data broker must check California’s deletion platform, called DROP, at least every 45 days. Miss it, and the penalty runs $200 a day.
What Actually Makes You a “Data Broker”
Founders hear “data broker” and picture a company that sells consumer profiles for a living. The legal definition is much wider, and it covers sharing, not just selling for cash.
- You qualify if you knowingly sell or share personal information with a third party that has no direct relationship with your customer.
- Ad networks, analytics platforms, and AI vendors all count as that third party.
- One integration is enough to trigger the definition. You do not need a data-selling business model.
Where the Exposure Usually Hides
Most founders never sat down and mapped their vendors. That is exactly where this catches them.
- Ad tech pixels, analytics SDKs, and AI training partnerships are the most common ways startups trip this without meaning to.
- The integration may have been added years ago by someone no longer on the team.
- Investors and enterprise buyers now ask about this directly in diligence. A gap here is a red flag they are trained to catch.
Registration Is Not a One-Time Filing
Founders who register once assume the obligation is done. It is not.
- Registered data brokers must check the DROP deletion platform at least every 45 days.
- Missing that check carries a $200 per day penalty, on top of any underlying violation.
- Annual re-registration is required for as long as your company meets the definition.
- CalPrivacy has shown in the last week alone that it will combine violations into one enforcement action, not treat them separately.
Common Founder Mistakes
- Assuming the Label Doesn’t Apply. Founders assume “data broker” means someone else’s business model. The statute only requires sharing data with a third party you have no direct relationship with, which one integration can trigger.
- Never Mapping Which Vendors Touch User Data. Founders add ad networks, analytics tools, and AI partners over time without tracking what data each one receives. Without that map, there is no way to know whether one integration created exposure.
- Treating Registration as a One-Time Task. Founders file once and move on, missing the annual renewal or the 45-day DROP check. Both gaps now carry per-day fines plus six-figure settlements, as CalPrivacy just proved twice in one week.
10-Minute Self-Check
Before you assume this regulation doesn’t apply to you, work through this:
- Do I know every third-party vendor that receives user data from my product?
- Does any of those vendors have no direct relationship with my customers?
- Have I confirmed whether my company meets California’s data broker definition?
- If registered, have I checked the DROP platform in the last 45 days?
- Is my data broker registration current for this year?
- Would my answers here hold up if an investor asked in diligence?
If you cannot answer yes to all of these, you are not ready to assume this law doesn’t apply to you.
Bottom Line
The data broker definition was written broadly on purpose, and California just proved it will enforce that breadth with real fines. Finding out where you stand costs an afternoon of mapping. Finding out from a regulator costs six figures and a diligence flag investors won’t unsee.
Do I Know Where My Company’s Data Actually Goes?
Download our free Data Mapping Worksheet to identify where personal information is collected, stored, and transferred throughout your business. Mapping your data before updating your privacy documentation helps ensure your policies accurately reflect how your product actually works.
Get the free worksheet: https://primumlaw.com/data-mapping-worksheet/?post_type=page