Is my company a data broker under California's Delete Act?
The definition is one sentence long and covers more companies than many expect. A way to work through it for your business.
- A data broker collects and sells personal information about consumers it doesn't have a direct relationship with.
- There's no size threshold.
- Some businesses regulated under FCRA, GLBA, California's insurance privacy law, and HIPAA are excluded.
The legal definition
Under Civil Code § 1798.99.80, a data broker is:
"a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship."
Three parts have to be true at once:
- You collect personal information. The CCPA's broad definition applies, so this includes identifiers like emails and device IDs as well as names and addresses.
- You sell it to third parties. "Sell" follows the CCPA meaning: disclosing personal information for money or other valuable consideration. Data swaps and co-ops can count.
- You don't have a direct relationship with the consumer. The statute doesn't define "direct relationship." In practice it usually means the person isn't your customer, user or subscriber and didn't knowingly give you their data.
Who's excluded?
The definition doesn't cover entities to the extent they're covered by:
- the federal Fair Credit Reporting Act (consumer reporting agencies and similar);
- the Gramm-Leach-Bliley Act and its regulations (financial institutions);
- California's Insurance Information and Privacy Protection Act;
- HIPAA, for covered entities and business associates, to the extent exempt under the CCPA.
The carve-outs apply only to the extent a law covers you. A company covered by one of them for part of its data may still be a data broker for the rest.
Questions to work through
- Do we receive personal information from sources other than the consumer: data vendors, public records, partners, scraped sources?
- Do we pass any of it to other companies for something of value, including data exchanges, enrichment partnerships or revenue shares?
- For the people whose data we pass on, would they recognize us as a company they deal with?
- Is any of this data covered by FCRA, GLBA, insurance privacy law or HIPAA?
If the honest answers are yes, yes, no and no, you're likely a data broker for that data. Talk to counsel to confirm.
Why it matters now
CalPrivacy has been enforcing against businesses that should have registered and didn't, and has set up a dedicated data broker enforcement team. Unregistered brokers face $200 per day plus back fees. Registered brokers have to process DROP deletion requests every 45 days, with fines of $200 per request per day for misses.
If you are a broker, next read registration requirements and fees and the 45-day DROP checklist.
Check every record against DROP with one API call
Purgepath keeps your DROP list current daily and tells you exactly what to delete. Unlimited scrubs by API or CSV upload, $500/month.
Sources
This article is general information as of October 5, 2026, not legal advice. Rules and fees can change; check the sources above and talk to counsel about your situation.