California Privacy Agency Warns Data Brokers Over Inaccurate Registration Disclosures

The California Privacy Protection Agency is warning data brokers that inaccurate information in their annual registrations can carry daily financial penalties, even when the error was not intentional.

In Enforcement Advisory 2026-01, issued September 3, CalPrivacy’s Enforcement Division said data brokers may face a $200 administrative fine for each day incorrect information remains in the state’s data broker registry. The agency emphasized that the Delete Act requires registration information to be true and correct, and that the law does not distinguish between an accidental reporting mistake and an intentional misrepresentation.

The advisory signals a broader enforcement focus for CalPrivacy. The agency has already pursued more than a dozen actions involving data brokers that failed to register. It is now making clear that simply registering is not enough. The information submitted must also accurately reflect a broker’s data collection and sharing practices.

What Data Brokers Must Disclose

Under California’s Delete Act, businesses that operated as data brokers during the prior year must register with CalPrivacy by January 31, pay the required registration fee, and provide information about their activities.

Those disclosures include certain metrics, the types of personal information collected, and whether that information was shared or sold to specific categories of recipients. The law identifies recipients including federal and state governments, law enforcement, certain foreign actors, and developers of generative AI systems or models.

The categories of personal information covered by the reporting requirements can be extensive. They include information involving minors, citizenship and immigration status, union membership, sexual orientation, gender identity and expression, biometric data, precise geolocation, reproductive health information, and other identifying details.

CalPrivacy said the accuracy of these disclosures is important because the state registry is intended to give consumers visibility into how data brokers collect and distribute personal information.

Mistakes Can Still Lead to Enforcement

One of the strongest points in the advisory is that intent does not determine whether registration information is considered incorrect.

According to the Enforcement Division, it has observed data brokers submitting information that was not true or accurate. The Delete Act does not provide a separate standard for inadvertent mistakes. Incorrect information can create the same compliance problem regardless of how the error occurred.

CalPrivacy also noted that it has already brought multiple enforcement actions involving reporting errors. That history gives the advisory greater weight than a general compliance reminder. It indicates that inaccurate disclosures are already part of the agency’s enforcement activity.

Advisory Provides Examples for Reviewing Registrations

The agency included several hypothetical scenarios designed to show how data brokers should evaluate their registration responses.

In one example, a business selling consumer leads is encouraged to consider whether new categories of information added to its database must also be reported. Another scenario asks businesses to determine whether certain customers may qualify as foreign actors under the law.

The advisory also addresses companies selling information to businesses developing AI-powered products. Data brokers are encouraged to consider whether those customers meet the statutory definition of a developer of a generative AI system or model, which may trigger additional disclosure requirements.

These examples reinforce the need for businesses to review their data practices and customer relationships each year rather than relying on prior registration responses.

DROP Adds Another Compliance Requirement

The advisory comes as data brokers are also adjusting to requirements tied to California’s Delete Request and Opt-Out Platform, known as DROP.

As of January 2026, covered data brokers must establish a DROP account. Beginning August 1, 2026, they must access the platform at least once every 45 days and process applicable consumer deletion requests submitted through the state’s centralized mechanism. CalPrivacy has said the system depends on accurate data broker registration information to function effectively.

For data brokers, the message is increasingly clear. Registration is no longer a once-a-year administrative exercise. Businesses need to verify what information they collect, who receives it, how their activities changed during the prior year, and whether those changes affect their disclosures.

With daily penalties attached to inaccurate reporting and enforcement already underway, accuracy in the registry is becoming a more visible part of California privacy compliance.

Published On: September 15th, 2026|By |Categories: Industry News & Announcements|Tags: |

Related Posts