Skip to main content
Five States, Five Data Broker Laws: What Your Team Must TrackLaws and Regulations
4 min readFor Data Governance Teams

Five States, Five Data Broker Laws: What Your Team Must Track

Scope - What This Guide Covers

This guide addresses the emerging patchwork of US state data broker laws enacted as of early 2025. It's designed for data governance teams managing compliance across jurisdictions with limited resources. You'll find requirement breakdowns, implementation guidance, and a quick-reference table to help you determine which obligations apply to your organization.

This guide doesn't cover general state privacy laws (CCPA, CPA, etc.) except where they intersect with broker-specific requirements. It assumes your organization either operates as a data broker or contracts with entities that do.

Key Concepts and Definitions

Before assessing your obligations, you need clear terminology:

Data Broker: An entity that aggregates, buys, sells, or discloses consumer data to create detailed profiles for commercial purposes. The critical distinction: data brokers typically lack a direct relationship with the consumers whose data they process.

Entity-Level Exemption: Applies to your entire organization. If you qualify, the whole business is exempt from certain privacy law requirements. Financial institutions regulated by GLBA or healthcare providers under HIPAA often benefit from these.

Data-Level Exemption: Applies only to specific data types within your organization. You still comply with the privacy law for all other personal data you process.

Pseudonymous Data: Data processed so it can't be attributed to a specific individual without additional information. Most US privacy laws recognize pseudonymization as a protective measure, but don't automatically exempt it from regulation. New Jersey's law, for instance, exempts "de-identified" data but not pseudonymous data.

Requirements Breakdown

As of this writing, five states have passed data broker laws:

  • CA SB362 (California)
  • TX SB2105 (Texas)
  • OR HB2052 (Oregon)
  • VT HB764 (Vermont)
  • NV SB260 (Nevada)

Each law takes a different approach to registration, disclosure, and consumer rights. California's framework, for example, builds on the CCPA's existing controller-processor model. Vermont's law predates most comprehensive state privacy laws and focuses heavily on registration and transparency.

The common thread: these laws close a regulatory gap. Data brokers weren't adequately covered under existing privacy regulations, despite processing billions of consumer records. Consumers often have no awareness their data is being aggregated, profiled, and sold.

Implementation Guidance

Step 1: Determine if You're a Data Broker

Don't rely on your business model label. Ask: Do you aggregate consumer data from sources other than direct consumer relationships? Do you sell, license, or disclose that data to third parties for value? If yes to both, you likely meet the definition under at least one state law.

Step 2: Map Your Data Flows

You can't comply with broker-specific laws without understanding what data you collect, from whom, and where it goes. Most laws don't explicitly mandate data mapping, but they require activities (data inventories, assessments, records of processing, subject rights requests) that are nearly impossible to execute without it.

Start with high-risk data flows: Behavioural Advertising pipelines, third-party cookie implementations, and any processing that involves sensitive personal information.

Step 3: Implement Universal Opt-Out Mechanisms

Universal Opt-Out Mechanisms (UOOMs) allow consumers to signal their privacy preferences across multiple platforms. To comply:

  • Update your privacy policy to clearly explain how you handle UOOM signals and what rights consumers have regarding their data.
  • Integrate a Consent Management Platform that can recognize and honor opt-out signals automatically.
  • Train your team on handling data subject requests and respecting consumer privacy preferences.
  • Conduct regular audits to ensure your UOOM implementation remains compliant as regulations evolve.

Step 4: Assess Controller vs. Processor Status

Many US privacy laws use controller and processor terminology. A controller determines the purposes and means of processing. A processor follows the controller's instructions.

Your status determines your contractual obligations. All of 2025's data privacy laws include requirements around data processing agreements between controllers and processors. If you're acting as a processor, you'll need contracts that specify processing instructions, data security measures, and breach notification procedures.

Step 5: Evaluate Employee Data Separately

Only the CCPA applies to employee data. US privacy laws generally exclude data collected by employers from their scope. This means your compliance obligations for workforce data differ significantly from consumer data obligations.

Common Pitfalls

Assuming ISO Certification Equals Compliance: ISO certifications demonstrate good data governance practices, but they're distinct from legal compliance. Each state privacy law has specific requirements that certifications don't address.

Treating Third-Party Cookies as Low-Risk: Some laws treat third-party cookies as a "sale" of personal information because data transfer to third parties constitutes valuable consideration, even without money changing hands. If you're using third-party cookies for targeted advertising, you're likely triggering sale provisions.

Overlooking Nonprofit Status: Many laws exempt nonprofits, but not all. The Colorado Privacy Act, New Jersey Data Privacy Act, Minnesota Consumer Data Privacy Act, Maryland Online Data Privacy Act, Oregon Consumer Privacy Act, and Delaware Personal Data Privacy Act do not exempt nonprofits.

Confusing Pseudonymization with De-identification: Pseudonymous data still requires compliance in most jurisdictions. Maryland's law, for instance, provides no exemption for pseudonymous data.

Quick Reference Table

State Law Key Requirement Exemption Type Employee Data
CA SB362 Registration + CCPA rights Entity & data-level Covered under CCPA
TX SB2105 Registration + disclosure Entity & data-level Not covered
OR HB2052 Registration + consumer rights Entity & data-level Not covered
VT HB764 Registration + security Entity-level Not covered
NV SB260 Registration + opt-out Entity & data-level Not covered

Strategic Recommendation: Rather than attempting perfect compliance with each law individually, identify the strictest requirements across all five and build your baseline program to meet those standards. Then document jurisdiction-specific variations in a compliance matrix you can reference during audits or vendor reviews.

The trend is clear: more states will pass data broker laws. Your compliance architecture should be flexible enough to absorb new requirements without requiring a complete redesign.

You Might Also Like