California’s data broker registry is supposed to answer a basic privacy question: who has information about me, what kind of information do they have, and where might it be going? That promise depends on the answers in the registry being true. On September 3, 2026, the California Privacy Protection Agency’s Enforcement Division issued Enforcement Advisory 2026-01, warning data brokers that incorrect registration information can violate the Delete Act and lead to a $200 administrative fine for each day the error remains in the registry.
This is not a newly enacted statute, a court ruling, or a final enforcement order against a particular company. It is an enforcement advisory explaining how the agency views an existing obligation. The advisory also says that the Enforcement Division has already brought multiple actions involving reporting errors. For privacy teams, product leaders, and developers, the message is practical: annual registration cannot be treated as a clerical form that gets copied forward without checking the underlying data practices.
Why registry accuracy matters
Data brokers usually do not have the direct relationship with consumers that a bank, retailer, or streaming service has. A person may never recognize the name of a company that holds or sells information about them. California’s registry is designed to reduce that visibility gap. The agency’s September 3 announcement explains that registration disclosures cover subjects such as the types of data collected, request metrics, and whether information was shared with certain categories of recipients.
Those details are not abstract. The advisory identifies categories including precise geolocation, biometrics, reproductive-health information, citizenship or immigration data, union membership, sexual orientation, gender identity, and common identifiers such as names, dates of birth, email addresses, phone numbers, and home addresses. It also discusses disclosures about sharing or selling information to government entities, law enforcement, certain foreign actors, and developers of generative-AI systems or models.
When a registry entry is wrong, a consumer may make a privacy decision using an incomplete picture. They may not understand that a broker handles sensitive data or that information may have reached a category of recipient they care about. Accuracy therefore supports more than regulatory paperwork. It supports informed use of privacy rights.
That connection is especially important now that California’s Delete Request and Opt-out Platform, known as DROP, is operating. According to CalPrivacy’s official DROP guidance, California residents have been able to submit a single request to active data brokers since January 2026, and brokers were required to begin processing those requests on August 1, 2026. The same guidance says brokers must access and process DROP requests at least once every 45 days. Reliable registration information helps make that centralized system meaningful.
The obligation is annual—and factual
Under the Delete Act framework described by the agency, a business that operated as a data broker in the prior year must register by January 31, pay the required fee, and make required disclosures. The advisory points to Civil Code section 1798.99.82 and the implementing regulations. It emphasizes that the rules require “only true and correct responses” in the registration.
The agency also makes an important point about intent: the law does not distinguish between an unintentional mistake and an intentional misrepresentation when the result is incorrect information. That does not mean every error will produce the same enforcement outcome; the advisory says enforcement decisions are made case by case. But it does mean that “we did not mean to” is not a substitute for maintaining an accurate reporting process.
The hypothetical examples in the advisory are useful because they show where mistakes can begin. A lead-generation business may add new data fields or new customers during the year. A company operating tracking cookies or mobile software development kits may start collecting location data and associating it with nearby stores. A data buyer may use purchased information in connection with a generative-AI product. Each change can alter what must be disclosed during the next registration cycle.
What developers and product teams should do
Registration accuracy should be supported by the same systems used to understand the product’s data flows. A once-a-year questionnaire is fragile if no one can trace what production systems actually collect, derive, receive, sell, or share. Engineering, privacy, security, legal, sales, and vendor-management teams need a common inventory that reflects reality rather than assumptions.
Developers can help by documenting the data categories created by new features, the third-party SDKs and tracking tools in use, the purpose and destination of outbound data, retention behavior, and whether a recipient’s role has changed. Product change reviews should ask whether a new data source, model-training use, government customer, or location feature will affect future registry disclosures. Versioned records are valuable because registration concerns activity during the prior year, not simply the configuration visible on the day the form is submitted.
Companies should also build an owner-and-review process around registration. Someone should be accountable for gathering evidence, another person should verify the answers against data maps and contracts, and changes made after submission should be evaluated promptly. CalPrivacy’s registry page provides public access to submitted information and a way for brokers to request updates, so discovering an error should trigger correction—not a wait-until-next-year approach.
For consumers, the practical takeaway is to treat the registry and DROP as useful tools while remembering that their value depends on accurate company reporting and active enforcement. If an entry appears inconsistent with a broker’s public practices, CalPrivacy’s announcement directs consumers to the agency’s complaint process. A transparent system works best when businesses maintain accurate records, regulators test them, and consumers can flag problems.
California’s advisory turns a simple concept into an operational privacy requirement: transparency has to be true to be useful. A registry filled with stale or incomplete answers creates the appearance of accountability without the substance. For developers and organizations, the durable response is not better wording alone. It is better knowledge of the data moving through the product—and a process that converts that knowledge into accurate public disclosures.
About Joseph Sides
Joseph Sides is a South Florida-based data privacy advocate, consultant, and entrepreneur whose work focuses on consumer rights, digital transparency, website tracking, meaningful privacy choices, and responsible technology. His public DEV introduction describes a bachelor’s degree in criminology, a minor in business, and training in data analytics. These interests connect questions about how technology operates with questions about what people understand and how organizations remain accountable for their decisions.
The educational purpose of these articles is to make privacy developments easier to follow and their practical implications easier to examine. That means connecting the language of laws and regulatory actions with familiar experiences: visiting a website, choosing an app, responding to a consent request, or trying to delete information. For developers, the discussion also considers how interface choices and data practices shape the choices available to consumers. The aim is informed understanding and thoughtful questions, with attention to both individual rights and responsible product decisions.
Educational Information — Not Legal Advice
This article provides general education and commentary, not legal advice. Joseph writes as a privacy advocate and consultant, not as an attorney. Reading this article does not create an attorney-client relationship, and the discussion is not a substitute for advice from a qualified attorney about your particular circumstances.
Laws, interpretations, applicability, exemptions, and deadlines vary by jurisdiction and can change. A requirement that applies to one organization or activity may apply differently to another. Readers should consult current primary sources and a qualified attorney when evaluating obligations, available rights, or a specific course of action. This article does not promise complete coverage, guaranteed outcomes, or personal legal guidance.
AI Disclosure
Prepared with AI assistance.
Top comments (0)