If your organization buys, sells, or shares consumer data, you're likely subject to data broker registration requirements. California's privacy agency recently warned data brokers about facing daily fines for not only failing to register but also for submitting inaccurate information about their data practices. This second risk often catches organizations off guard.
This checklist guides you through the registration process and the ongoing accuracy requirements to keep you compliant. It's designed for organizations that collect and share consumer information, whether or not you consider yourself a traditional "data broker."
Prerequisites
Before you start this checklist, confirm:
You've determined whether you meet the definition of a data broker under applicable state laws. Many organizations assume they're exempt because they don't sell mailing lists, but the definition is broader. If you collect consumer information and make it available to third parties for consideration, you likely qualify.
You have access to your data flow documentation. You'll need to describe what data you collect, from what sources, and who receives it. If you can't map that flow accurately, pause and document it first.
You've assigned ownership for ongoing registration accuracy. Registration isn't a one-time task. Someone needs to monitor changes in your data practices and update your registration accordingly.
Registration and Reporting Checklist
1. Complete initial registration within required timeframes
Check your jurisdiction's deadline. In California, data brokers must register annually. Missing the registration window triggers daily penalties that accumulate quickly.
Good looks like: You've marked the registration deadline on your compliance calendar with a 30-day advance reminder and completed and submitted your registration at least two weeks before the deadline.
2. Accurately describe all categories of personal information you collect
List every category: names, addresses, purchase history, browsing behavior, device identifiers, geolocation data, biometric information. Don't generalize or leave categories out because they seem minor.
Good looks like: Your registration matches your data inventory. If an auditor compared your registration to your actual data holdings, they'd find no discrepancies.
3. Identify all sources from which you obtain personal information
Document whether you collect directly from consumers, purchase from other data brokers, scrape from public records, obtain from partners, or use any other acquisition method. Be specific about each source type.
Good looks like: You've listed each distinct source category and can provide examples of specific sources within each category if asked.
4. Disclose all purposes for which you collect and use the data
Don't just write "marketing." Specify: targeted advertising, credit decisioning, employment screening, fraud prevention, or whatever your actual purposes are. Each distinct purpose should be listed.
Good looks like: Your purposes align with your privacy policy and your actual business practices. There are no purposes in your registration that you don't actually use the data for, and no actual uses missing from your registration.
5. List all categories of third parties who receive the data
Identify who you share with or sell to: advertisers, marketing platforms, analytics providers, other data brokers, credit agencies, background check services, or any other recipient category.
Good looks like: You've reviewed your contracts and data sharing agreements to ensure every third-party recipient category is captured in your registration.
6. Verify the accuracy of deletion and opt-out statistics
If your registration requires you to report how many consumer requests you received and fulfilled, audit those numbers before submitting. Inaccurate metrics are a red flag for regulators.
Good looks like: Your reported statistics come directly from your request tracking system, and you can produce supporting documentation if questioned.
7. Establish a review trigger for material changes
Set up a process to flag when your data practices change in ways that affect your registration: new data categories collected, new third-party relationships, new collection sources, or new purposes.
Good looks like: Your legal, privacy, and business development teams know to notify compliance when they're launching initiatives that involve new data flows, and you've built a quarterly registration accuracy review into your compliance calendar.
8. Document your registration submission and confirmation
Keep proof that you submitted your registration on time and that it was accepted. Save confirmation emails, submission receipts, and copies of what you submitted.
Good looks like: You maintain a compliance file with timestamped records of each year's registration, including the date submitted and any correspondence with the regulatory agency.
9. Pay required fees on time
Some jurisdictions charge registration fees. Late payment can invalidate your registration even if you submitted the paperwork on time.
Good looks like: You've confirmed the current fee amount, budgeted for it, and submitted payment with your registration rather than waiting for an invoice.
10. Train relevant staff on registration requirements
Your data management, privacy, legal, and business development teams need to understand what triggers a registration update. They can't flag changes they don't know matter.
Good looks like: You've held a training session explaining what data broker registration covers and who needs to alert compliance about potential changes. You've provided examples of the types of business decisions that affect registration accuracy.
Common Mistakes
Treating registration as a legal task rather than an operational one. Your lawyers can help interpret requirements, but your operations teams hold the information needed for accurate registration. This is a cross-functional project.
Assuming your privacy policy covers registration requirements. Privacy policies and data broker registrations serve different purposes and have different audiences. Don't copy-paste your policy language into your registration and assume you're done.
Failing to update registration when you add new data sources or partners. Your initial registration might be accurate, but if you launch a new product that collects different data or partner with a new vendor who receives consumer information, your registration is now incomplete.
Underestimating what counts as "personal information." Device identifiers, IP addresses, and cookie data often qualify. If you're collecting it and it relates to an identified or identifiable person, include it.
Next Steps
Set a recurring calendar reminder for 60 days before your next registration deadline. Use that time to review your current registration against your actual practices.
If you discover inaccuracies in your current registration, file an amendment promptly. Regulators distinguish between organizations that self-correct when they discover errors and those that wait until an audit forces the issue.
Consider whether you need to adjust your vendor due diligence process. If you're receiving data from third parties, you need assurance that they're also complying with data broker requirements. Their non-compliance can create problems for you.
Finally, if your organization is expanding into new states or new lines of business, check whether additional registration requirements apply. Data broker laws vary by jurisdiction, and what's required in one state may differ significantly from another.



