What happened
California's privacy regulator has warned data brokers that an incorrect registration filing carries the same $200 per day penalty as failing to register at all, whether or not the error was deliberate. The warning came in Enforcement Advisory No. 2026-01, published on September 3 and titled Accuracy of Data Broker Registration Information.
In the advisory, the enforcement division said it had observed data brokers failing to provide true and correct information in their registrations, and that the Delete Act does not distinguish unintentional mistakes from intentional misrepresentation because both result in incorrect information. The implementing regulations require only true and correct responses.
The registration duty itself comes from California's Delete Act, which requires any business that operated as a data broker in the prior calendar year to register by January 31, pay a fee, and disclose specifics about its data collection and sharing practices. The definition of data broker is broader than it sounds. It covers a business that knowingly collects and sells to third parties the personal information of consumers with whom it has no direct relationship, where sell includes disclosure for monetary or other valuable consideration. Regulations that took effect in 2025 define a direct relationship as a consumer intentionally interacting with the business in the past three years.
Two operational obligations sit alongside registration. Since January 2026, registered brokers must hold an account on the Delete Request and Opt-out Platform, known as DROP. Since August 1, 2026, they must check it at least once every 45 days and process the deletion requests they find.
Why this is a GRC story
Registration is a control with a deadline attached, and the regulator has just removed intent as a defence. That changes the risk profile of a task most organisations file under legal administration and touch once a year.
The reasoning is not unusual. Many enforcement regimes work this way, because proving intent is expensive and the accuracy of a public register is the point of the register. What makes this worth noting is the arithmetic: a filing error that goes uncorrected for months accumulates a penalty that can dwarf the cost of the compliance work itself.
The scope question is the harder one. The data broker definition reaches a business that never set out to sell data at all. Buying a marketing list, or disclosing information about your own customers to a third party for value, can be enough. Plenty of organisations believe they are outside scope because they do not think of themselves as data brokers, and that belief has never been tested in their own files.
What to watch
Watch whether enforcement action follows the advisory, since the California agency has already been active against brokers this year. An advisory that is not followed by penalties teaches the market that accuracy is aspirational.
Watch the 45 day DROP cycle as well. It is a recurring obligation with a timestamp attached, exactly the kind of control an auditor can test from logs.
The practical step for a business that might be in scope: read your own registration entry as a stranger would, confirm every answer is still true after any change in ownership, vendors or data flows, and put a named owner and a calendar reminder on both the annual filing and the 45 day check.
Attribution: Analysis based on JD Supra and related public reporting. This article is original commentary, not a repost of the source material.
