The Challenge
A Virginia-based data broker was fined $36,400 by the California Privacy Protection Agency for not registering as required by state law. Beyond the fine, the company must now honor consumer deletion requests through California's new data deletion tool.
This incident highlights a broader issue for those managing third-party vendor risk. Your organization likely partners with numerous data brokers, marketing platforms, and analytics providers. How many of them are aware of the state-specific registration requirements that apply to them? How many track their obligations across different jurisdictions?
If they don't know, your organization is still at risk.
Understanding the Regulatory Landscape
California's data broker registration requirement is part of a rapidly evolving regulatory framework. The California Privacy Protection Agency actively enforces these rules, targeting not just major platforms but also smaller operators who may lack robust compliance systems.
For those managing third-party risks, this means you can't assume your vendors understand their obligations. A data broker in Virginia might not keep up with California's regulatory updates or have legal counsel to track state registration deadlines. They might process data from California residents without realizing they've triggered registration requirements.
While your vendor contracts likely include compliance assurances, verifying these promises is challenging when state requirements are constantly changing. You're navigating a landscape where the rules are expanding, and your vendors might not even know what applies to them.
The Agency's Approach
The California Privacy Protection Agency's enforcement strategy is telling. The penalty wasn't just for missed registration. The resolution also required the company to honor deletion requests through California's consumer data deletion tool, which allows residents to submit requests to multiple data brokers simultaneously.
This dual requirement highlights the agency's priorities. Registration provides visibility, helping regulators identify who handles California resident data. The deletion tool requirement supports consumer protection, ensuring residents can exercise their privacy rights without tracking down each data broker individually.
For the Virginia company, compliance now involves two components: administrative registration and operational capability to process deletion requests. The latter requires technical integration with California's deletion tool, internal workflows to manage requests, and documentation to prove compliance.
The Impact
The $36,400 penalty may seem modest, but it significantly impacts smaller operators. More importantly, the company now has a public enforcement record, affecting its ability to secure new business, especially with enterprise clients conducting vendor due diligence.
The deletion tool requirement also imposes ongoing compliance costs. Each deletion request demands staff time for verification, processing, and documentation. If the company handles data for many California residents, this operational burden can quickly escalate.
For your vendor portfolio, this case sets a benchmark. If a data broker you work with hasn't registered in California, they're exposed to the same risks as the Virginia company. The question isn't if they'll get caught, but whether you want to find out through an enforcement notice.
Learning from Mistakes
The obvious lesson is to register on time, but there's more to learn.
Start by mapping your regulatory footprint. Identify which states you process resident data from and which have data broker registration requirements. Understand what triggers these requirements and whether you're over the threshold.
Integrate monitoring into your operations. When onboarding a new client or data source, check if it expands your geographic footprint. When states pass new privacy laws, assess if they create registration obligations. Don't wait for enforcement to reveal you've crossed a line.
Finally, build operational capabilities in advance. If you anticipate deletion requests, establish the intake and processing workflow now. Don't wait until you're under a consent decree to figure out how to honor consumer rights at scale.
Takeaways for Your Team
If you manage third-party risk, consider these actions:
Inventory your data broker relationships. Include marketing platforms, analytics providers, lead generation services, and anyone collecting or providing consumer data on your behalf. Ask each vendor if they've registered as a data broker in states that require it.
Map the deletion request workflow. California's deletion tool isn't the only mechanism consumers use. Some states require businesses to provide their own deletion request forms. Others allow consumers to email requests directly. Your vendors need to handle requests from multiple channels. Ask them how they receive deletion requests, how long processing takes, and how they document completion.
Don't rely solely on contractual compliance clauses. While your vendor agreement likely states the vendor will comply with applicable laws, that's not enough. With changing state requirements and small vendor compliance teams, you need verification. Incorporate vendor compliance checks into your annual review process. Request evidence like registration confirmations, deletion request logs, and privacy policy updates.
The Virginia data broker likely thought they were too small or too far from California to be noticed. They were wrong. If your vendors are making the same assumption, you're carrying their risk.



