California’s privacy regulator has a new warning for data brokers: filing a registration is not enough if the information in it is wrong.
The California Privacy Protection Agency, now operating publicly as CalPrivacy, issued Enforcement Advisory 2026-01 on September 3, putting the industry on notice that inaccurate information in California’s Data Broker Registry can itself create enforcement exposure.
The advisory is significant because CalPrivacy is not treating registration errors as harmless paperwork problems.
Its Enforcement Division says a data broker can face a $200 fine for each day it fails to register “as required by” the Delete Act’s reporting provisions, including when required registration information is incorrect. The agency specifically noted that it has already brought multiple enforcement actions involving reporting errors.
That can add up quickly.
An inaccurate registration left untouched for 100 days could theoretically create $20,000 in exposure under the agency’s interpretation, before accounting for registration fees or costs associated with an enforcement action.
And in 2026, the accuracy of those registrations matters considerably more than it did a year ago.
California’s Delete Request and Opt-Out Platform, better known as DROP, is now live and actively sending consumer deletion requests to data brokers.
The registry is no longer just a public directory.
It is becoming part of the infrastructure California uses to make privacy rights actually work.
California Says the Information in the Registry Has to Be Correct
Businesses that meet California’s definition of a data broker generally must register annually with CalPrivacy after a year in which they operated as a data broker.
That registration is not limited to telling the state that the company exists.
Data brokers have to provide information about their operations, including disclosures concerning the types of personal information they collect, their data practices, applicable metrics and certain recipients of that information.
The registry gives Californians a way to see who is operating in an industry that, by definition, often involves companies consumers have never directly interacted with.
CalPrivacy’s latest advisory makes clear that those disclosures cannot be treated casually.
“The Enforcement Division will continue using all the tools at its disposal to protect Californians’ privacy, including publishing advisories to help stop violations from happening in the first place,” Michael Macko, CalPrivacy’s head of enforcement, said when announcing the advisory.
The agency’s position is straightforward: a data broker that files inaccurate information has not necessarily satisfied its registration obligation merely because it submitted a form.
This Builds on an Earlier Warning
This is not CalPrivacy’s first attempt to tighten up the Data Broker Registry.
In December 2025, the agency issued another enforcement advisory addressing data brokers that used trade names, operated multiple websites or had complicated parent-subsidiary structures.
CalPrivacy warned then that businesses must disclose all required trade names and website addresses and that separate legal entities generally cannot simply point to an affiliated company’s registration.
The agency specifically said some registration practices could make it difficult for consumers to identify the business actually handling their information.
The September 2026 advisory goes a step further.
The issue is no longer only whether a company registered or properly identified itself.
CalPrivacy is now focusing on whether the substance of the information provided in that registration is accurate.
For compliance teams, those are very different obligations.
The first asks whether the form was filed.
The second requires someone inside the company to verify that the answers still match the business.
DROP Makes Accuracy Much More Important
The timing is not accidental.
California launched DROP on January 1, 2026. The system allows a California resident to submit one centralized request directing registered data brokers to delete and stop selling applicable personal information.
More than 600 registered data brokers can be reached through the system. By July, CalPrivacy said more than 325,000 consumers had already signed up and submitted deletion requests.
Then another major deadline arrived.
Beginning August 1, 2026, data brokers became obligated to access DROP at least once every 45 days, retrieve applicable consumer deletion requests, attempt to match them against their records, process those requests and report the results back through the system.
That changes the practical role of registration information.
A registry containing incorrect information can interfere with more than transparency. It can affect the machinery California is now using to connect consumers with the companies possessing their data.
CalPrivacy Executive Director Tom Kemp made that connection directly when the agency announced the new advisory.
“DROP works because the law requires data brokers to report correct information about their activities,” Kemp said.
That may be the most important sentence in the announcement.
California is increasingly treating data broker registration, deletion processing and consumer transparency as parts of one compliance system rather than separate regulatory exercises.
The $200-Per-Day Problem
The potential penalty structure deserves attention.
The Delete Act authorizes a $200-per-day administrative fine for data brokers that fail to register as required.
CalPrivacy’s new advisory takes the position that “as required” includes providing correct information under the law’s reporting requirements. The agency therefore warns that liability can continue for each day incorrect information remains in the registry.
That means a mistake should not be handled like an error in an old corporate filing that can simply be fixed at the next annual renewal.
If a company discovers that its registration materially misstates its business, CalPrivacy’s position creates an incentive to correct it quickly.
There is also an important distinction in how the potential penalty should be described.
The advisory does not say every incorrect field automatically creates a separate $200-per-day penalty. Rather, the agency is warning that failing to register in the manner required by the Delete Act, including satisfying the reporting requirements accurately, can trigger daily liability.
That distinction may become important if the agency eventually litigates the issue in a contested proceeding.
For now, however, the message to the industry is not particularly ambiguous: accuracy is an enforcement priority.
Data Brokers Should Not Assume Someone Else Owns the Registration
The practical compliance problem is that data broker registration frequently cuts across several departments.
Legal may file the registration.
Marketing knows which brands and domains the company operates.
Engineering understands the data actually collected.
Sales knows which products package or distribute the information.
Privacy teams know how consumer requests are handled.
Corporate counsel knows which subsidiaries and affiliates conduct which operations.
If the registration process becomes an annual legal exercise based on last year’s answers, inaccurate information can remain in the registry even though nobody intentionally submitted a false statement.
That is precisely why companies should treat the registration as something closer to an annual data-governance certification.
The business needs to know whether its answers are still true.
A merger, new website, product launch, acquisition, change in data sources, change in categories of information sold or a restructuring of corporate entities may alter the registration analysis.
Data broker compliance cannot be delegated entirely to whoever happens to have the login credentials for the CalPrivacy portal.
The Agency Is Already Aggressively Enforcing the Delete Act
CalPrivacy’s warning is more credible because it comes during a sustained enforcement campaign.
The agency says it has brought more than a dozen actions involving unregistered data brokers. Just two days before issuing the new advisory, it announced an action against Virginia-based SalesIntel Research.
The Enforcement Division has also pursued considerably more aggressive remedies where it believed the underlying data practices warranted them.
In January 2026, CalPrivacy announced a settlement with Datamasters, a Texas data broker that the agency said purchased and resold information concerning millions of people with conditions including Alzheimer’s disease, drug addiction and bladder incontinence.
Datamasters agreed to pay $45,000 for failing to register and was ordered to stop selling Californians’ personal information.
Another case involved Background Alert, a company that promoted its ability to uncover what it called a “scary” amount of information about people.
Rather than simply paying a late registration penalty, Background Alert agreed to stop operating as a data broker for three years.
These cases help explain why the newest advisory should not be dismissed as routine guidance.
CalPrivacy has repeatedly followed enforcement advisories with actual investigations and cases.
Data Brokers Now Have Two Separate $200-a-Day Risks to Watch
DROP adds another financial issue.
CalPrivacy currently identifies two major Delete Act penalty categories for data brokers.
The first is the $200-per-day exposure associated with registration failures.
The second can be much larger: a data broker that fails to process a required DROP deletion can face $200 per day for each deletion request for which it remains noncompliant, plus the agency’s investigation and administrative costs.
That second calculation can scale differently.
A registration violation is generally tied to days of noncompliance.
DROP violations can potentially multiply across consumer requests.
For data brokers managing large datasets, the operational part of Delete Act compliance may therefore become as important as the original registration requirement.
The process now involves retrieving requests, standardizing and hashing company records, matching those records against requests, performing required deletions and transmitting status information back through DROP. CalPrivacy requires brokers to repeat the cycle at least every 45 days.
This is no longer a law that can be handled once a year by filling out a form.
What Data Brokers Should Be Checking Now
Companies that qualify as data brokers should consider reviewing their current California registration rather than waiting for the next filing cycle.
That review should confirm basic corporate information, trade names, websites and affiliated entities, but it should also go deeper.
The people responsible for the registration should compare the disclosures against the company’s actual data inventory and business operations.
Are the categories of personal information correct?
Have data sources changed?
Are descriptions of selling or sharing still accurate?
Are the company’s websites and trade names complete?
Have new products or business lines been launched?
Has an acquisition or corporate restructuring changed which legal entity actually operates the data brokerage activity?
Does the information submitted to CalPrivacy match what the company says in its privacy notice and other public disclosures?
And separately, is the company actually processing DROP requests on the required 45-day cycle?
Those questions are increasingly connected.
A company should be concerned if its privacy policy says one thing, its data broker registration says another and its technical systems reveal something else.
That inconsistency is exactly the type of issue modern privacy enforcement can expose.
California Is Moving From Privacy Policies to Privacy Operations
For years, a large portion of U.S. privacy compliance centered on disclosures: publish the correct privacy policy, provide the required notice and include the appropriate opt-out mechanism.
California’s current enforcement program is moving beyond that model.
CalPrivacy has brought cases involving opt-out friction, failures to honor consumer rights, missing registrations, sensitive-data sales and now inaccurate data broker reporting.
At the same time, DROP requires hundreds of companies to participate in a continuing technical process for honoring deletion requests.
The direction is clear.
California privacy compliance increasingly requires companies to prove that the operational reality matches the statements they make to consumers and regulators.
For data brokers, September’s enforcement advisory makes that especially concrete.
Submitting a registration is no longer the finish line.
The information in it has to be right.