Skip to main content
California's Data Broker Strike Force: What the Enforcement Team Signals for Multi-State ComplianceLaws and Regulations
3 min readFor Enterprise IT and Security Teams

California's Data Broker Strike Force: What the Enforcement Team Signals for Multi-State Compliance

Overview of the New Enforcement Initiative

CalPrivacy has launched a Data Broker Enforcement Strike Force, a team dedicated to investigating violations of data broker registration and consumer privacy protection. This move aligns with recent actions under California's Delete Act and the expansion of the Consortium of Privacy Regulators, now including Minnesota and New Hampshire alongside Colorado, Connecticut, Delaware, Indiana, New Jersey, Oregon, and California.

In September, the consortium demonstrated its coordinated approach when California, Colorado, and Connecticut jointly investigated companies for failing to honor sale opt-out requests and Global Privacy Control (GPC) signals.

Key Developments Timeline

Early 2024: Consortium of Privacy Regulators established with initial member states.

September 2024: Joint investigation by California, Colorado, and Connecticut into companies' failure to honor opt-out requests and GPC signals.

Late 2024: Minnesota and New Hampshire join the consortium. CalPrivacy announces the Data Broker Enforcement Strike Force.

Identifying Systemic Control Gaps

The strike force and consortium expansion target systemic control gaps in the data broker ecosystem:

  • Missing registration controls: Data brokers operating without proper state registration.
  • Inadequate opt-out mechanisms: Companies not honoring consumer sale opt-out requests, especially those via GPC.
  • Weak cross-jurisdictional coordination: Treating each state law as isolated rather than building unified controls.
  • Insufficient audit trails: Lack of records proving opt-out request processing or accurate data broker registrations.

The September investigation revealed that companies often complied with individual state laws but failed when practices were compared across jurisdictions. Discrepancies in interpretations of "sale" between states like California and Colorado became enforcement targets.

Compliance Standards to Meet

  • California Delete Act: Requires data brokers to register with CalPrivacy and allows consumers to request deletion of personal information.
  • California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA): Broadly define "sale" and "sharing" of personal information, requiring businesses to honor opt-out requests. CCPA § 1798.135 requires a "Do Not Sell or Share My Personal Information" link on homepages.
  • Global Privacy Control specification: Recognized by California regulations as a valid opt-out signal under CCPA § 999.315(d).
  • Multi-state alignment: Laws like the Colorado Privacy Act (CPA) and Connecticut Data Privacy Act (CTDPA) establish parallel opt-out rights. Your controls must satisfy the strictest interpretation across all applicable states.

The strike force's structure indicates CalPrivacy's proactive approach, moving beyond complaints to conduct audits and identify non-registrants systematically.

Actionable Steps for Your Team

  • Map Data Broker Activities: Document your analysis of data broker activities across consortium states with specific citations to each state's statutory definition.
  • Implement GPC as Binding: Configure systems to treat GPC headers as manual opt-out requests and test regularly.
  • Build a Unified Opt-Out Registry: Create a single opt-out list that applies the most protective standard across your operations.
  • Audit Data Broker Registrations Quarterly: Expect scrutiny if you're registered in California but not in other states where you operate similarly.
  • Document Definitional Analysis: Record your reasoning when concluding an activity doesn't constitute a "sale" under CCPA or "targeted advertising" under CPA.
  • Pressure-Test Controls: Run exercises to ensure your team can respond consistently to simultaneous inquiries from multiple states.
  • Adopt Principles-Based Compliance: Build controls around consumer privacy principles rather than narrow statutory compliance.

The strike force announcement signals a shift towards coordinated state-level privacy enforcement. Your compliance architecture must reflect this coordination to avoid defending the same practice to multiple regulators with varying standards.

You Might Also Like