State privacy enforcement is moving beyond general consumer rights and into the business models, technical systems and contractual relationships that determine how personal information is actually collected and monetized.
Data brokers and companies processing sensitive information are receiving particular attention.
Recent enforcement actions in California, Oregon, Texas, Utah and Connecticut show that regulators are examining more than whether a company has published a privacy policy or added an opt-out link.
They are asking whether a business should have registered as a data broker, whether consumers received meaningful notice, whether consent was obtained before sensitive data was collected, whether privacy choices were easy to exercise and whether third-party contracts actually restrict downstream uses of personal information.
The broader message is clear: businesses that collect, enrich, analyze, resell or share consumer information must be able to explain the full lifecycle of that data.
Data Broker Registration Has Become an Enforcement Entry Point
Several states now require qualifying data brokers to register with a state agency.
These requirements are no longer being treated as minor administrative obligations.
Failure to register can lead to an investigation that exposes much broader questions about the company’s data collection, profiling, disclosure and sales practices.
California has been especially active through enforcement of the Delete Act and its data broker registration requirements.
A business that meets California’s definition of a data broker generally must register with the California Privacy Protection Agency by Jan. 31 of each applicable year.
CalPrivacy has already conducted investigative sweeps and reached settlements with businesses that allegedly failed to register.
Those actions have involved companies such as Key Marketing Advantage, Jerico Pictures and S&P Global.
The enforcement pattern suggests that registration records are becoming a practical screening tool.
Regulators can compare publicly available business activities, websites, marketing materials and data products against the official registry. A company that appears to buy, sell or license personal information but is absent from the registry may become an easy target for an inquiry.
Oregon Complaints Show Growing Concern About People-Search Services
Oregon has also identified data brokers as a major source of consumer concern.
According to an enforcement report from the Oregon attorney general, 62 of the 214 complaints received under the Oregon Consumer Privacy Act involved data brokers.
People-search websites are receiving particular scrutiny because they collect information from multiple sources and assemble detailed profiles about individuals.
Those profiles may contain:
- Names and aliases
- Current and former addresses
- Telephone numbers
- Email addresses
- Family relationships
- Property records
- Court records
- Employment information
- Estimated income or financial indicators
- Possible associates
The information may be obtained from public records, commercial databases, online activity and other third-party sources.
The risk is not limited to disclosure.
When data from several sources is combined, outdated or inaccurate information can be presented as a current and authoritative profile. A minor error can be repeated, amplified and sold to additional parties.
Regulators are therefore examining not only what information is collected but also how companies verify accuracy, respond to correction requests and disclose the sources and purposes of their data processing.
Public Records Do Not Automatically Eliminate Privacy Obligations
Some data businesses assume that information obtained from public records can be collected, combined and sold without significant privacy restrictions.
Recent enforcement activity challenges that assumption.
CalPrivacy’s action involving Background Alert focused on the company’s alleged use of public records to create individual profiles.
The agency also emphasized the use of pattern recognition to generate inferences about people.
Under the California Consumer Privacy Act, inferences drawn from personal information can themselves constitute personal information when they are used to create a profile reflecting a person’s characteristics, behavior, preferences or abilities.
This means a company may create new regulated information even when the underlying sources were publicly available.
Examples could include inferred:
- Income levels
- Political interests
- Religious affiliations
- Health concerns
- Purchasing preferences
- Relationship status
- Creditworthiness
- Likelihood of moving
- Interest in particular products
The more information a company combines, the greater the chance that seemingly ordinary data points can be used to identify, reidentify or classify a consumer.
Businesses should therefore review both the source data they acquire and the new information created through analytics, scoring and profiling.
National Data Sales Can Trigger California Registration Requirements
A company does not need to operate exclusively in California to create California data broker obligations.
CalPrivacy’s settlement involving Rickenbacher Data illustrates this point.
The company allegedly purchased and resold personal information, including information used to create targeted marketing lists.
Some of the information came from national databases containing records about consumers across the United States.
According to the agency’s allegations, some nationwide data orders included information about California residents that had not been removed before the lists were sold or transferred.
That was sufficient, in CalPrivacy’s view, to trigger the state’s registration requirement.
The enforcement lesson is significant for businesses that purchase or sell national datasets.
A company cannot assume that a nationwide list falls outside California law merely because the product is not marketed specifically to Californians.
Businesses should determine:
- Whether the dataset contains California residents
- Whether the company can identify or remove California records
- Whether the information is being sold or shared
- Whether the business has a direct relationship with the individuals
- Whether any statutory exemptions apply
- Whether the company meets the definition of a data broker
Failure to answer these questions can turn an ordinary data sale into a registration and enforcement issue.
Sensitive Data Is Becoming a Central Enforcement Priority
State regulators are also targeting the collection and use of sensitive personal information.
Sensitive data generally receives heightened protection because misuse can create a greater risk of discrimination, physical harm, surveillance, identity theft or other serious consequences.
Depending on the state law, sensitive information may include:
- Precise geolocation
- Biometric identifiers
- Genetic information
- Health information
- Sexual orientation
- Religious beliefs
- Citizenship or immigration status
- Children’s information
- Account credentials
- Government identification numbers
Recent cases show that regulators are concentrating on three recurring questions:
- Did the company clearly disclose that the information would be collected?
- Did the company obtain legally valid consent?
- Did the company use or sell the information in ways the consumer would not reasonably expect?
Texas Challenges the Collection and Sale of Driving Data
Texas brought its first lawsuit under the Texas Data Privacy and Security Act against Allstate and its data analytics subsidiary, Arity.
The state alleged that Arity collected precise geolocation and driving-related information through mobile applications.
The information allegedly included:
- GPS location
- Vehicle speed
- Travel timing
- Driving behavior
- Movement patterns
The state further alleged that the information was analyzed and sold, including to automobile insurers.
Texas argued that consumers were not clearly informed that their location and driving information would be collected, analyzed and commercialized.
The case focuses attention on whether a company can rely on consent obtained through another application, partner or software development kit.
Consent must generally be informed, affirmative and freely given.
A business may face difficulty defending consent when:
- The disclosure is buried in a long privacy notice
- The consumer is not told that data will be sold
- The collection occurs through a third-party application
- The information is used for a purpose unrelated to the service requested
- The consumer cannot decline without losing access to unrelated functionality
Companies using mobile software development kits should understand exactly what those tools collect, where the information is sent and how it is later used.
Google Settlements Highlight Geolocation and Biometric Risks
Texas also reached a $1.375 billion settlement with Google involving three lawsuits, including cases centered on precise geolocation and biometric information.
One lawsuit alleged that Google collected location information through its operating system, applications and services.
The state claimed that location collection could remain active through several settings and technologies even after a consumer believed location services had been disabled.
Texas also alleged that users were repeatedly prompted to turn location functions back on after declining.
These allegations illustrate a growing enforcement concern: a privacy control must work across the entire product ecosystem.
A consumer may disable one setting while another service, permission or connected device continues collecting similar information.
Regulators may examine whether:
- The consumer was told about every relevant collection method
- The opt-out applied across devices
- Background collection continued
- Settings were presented clearly
- The consumer was pressured to reverse the choice
- Data was retained after the feature was disabled
The second Texas case involved alleged collection of facial geometry and voiceprints.
The state argued that Google used facial recognition, artificial intelligence and machine learning within Google Photos to identify and store facial information relating to users and non-users.
The lawsuit also alleged that voice information was collected through Google Assistant products without appropriate prior consent.
Biometric information creates unusual compliance risks because it cannot be replaced in the same way as a password.
A person can reset a compromised password. A face, fingerprint or voice pattern may remain identifiable for life.
Utah Targets Sensitive Information Collected Through AI
Utah’s enforcement action against Snap shows how state privacy laws are being applied to artificial intelligence features.
The Utah attorney general alleged that Snap’s My AI feature collected sensitive information without providing adequate notice or a meaningful opportunity to opt out.
The information allegedly included geolocation and biometric indicators such as speech patterns and voiceprints.
The state also raised concerns about the collection of sensitive information from known children without tools allowing parents to provide or withhold consent.
The case demonstrates that companies cannot separate AI governance from privacy compliance.
An AI feature may process more information than the company’s traditional product.
It may analyze conversations, infer interests, collect location context, process voice input or generate profiles from repeated interactions.
Before deploying an AI feature, businesses should identify:
- What information the system receives
- What information it generates
- Whether any information is sensitive
- Whether children are likely to use the feature
- Whether consent is required
- Whether the user can decline the processing
- How long the information is retained
- Whether the information is used to train models
- Which third parties receive the information
Privacy Notices Are Becoming Easy Enforcement Targets
Privacy notice deficiencies remain one of the most visible forms of noncompliance.
Connecticut has conducted several privacy notice sweeps designed to identify businesses whose disclosures do not satisfy the Connecticut Data Privacy Act.
Common concerns include:
- Failure to describe consumer rights
- Missing instructions for exercising those rights
- Unreadable or inaccessible notices
- Incomplete descriptions of data sales
- Failure to disclose targeted advertising
- Request mechanisms that do not work
Connecticut’s action against TicketNetwork followed a cure notice identifying alleged deficiencies in the company’s privacy notice and consumer rights mechanisms.
The state alleged that the company failed to correct the problems within the statutory 60-day period, misrepresented its compliance efforts and did not communicate with regulators in a timely manner.
The case illustrates that a cure period is not an invitation to delay.
When a regulator provides an opportunity to correct a violation, the business should:
- Respond promptly
- Identify the responsible internal owner
- Document the corrective steps
- Test the revised process
- Provide accurate information to the regulator
- Maintain open communication
A company’s response to the inquiry may affect the severity of the final outcome.
Privacy Notices Must Match Actual Data Practices
A privacy notice is not compliant merely because it contains legally required terminology.
It must accurately describe what the business does.
Texas alleged that Arity’s privacy policy did not adequately disclose that personal information would be sold or used for targeted advertising.
The state also claimed consumers were not told how to opt out of targeted advertising, data sales or profiling.
Businesses should compare their privacy notice against:
- Website tracking technologies
- Mobile application permissions
- Software development kits
- Advertising platforms
- Data broker relationships
- Analytics tools
- Artificial intelligence systems
- Vendor contracts
- Internal data inventories
If the notice and the technology tell different stories, regulators will rely on what the systems actually do.
California Requires Symmetrical Privacy Choices
California enforcement has also focused on whether privacy-protective choices are as easy to exercise as less protective options.
This principle is commonly described as symmetry of choice.
In its action involving Honda, CalPrivacy alleged that the company’s cookie banner allowed users to accept cookies with one click while requiring additional steps to opt out.
The agency also alleged that users could reverse the opt-out and opt back in more easily than they could make the original privacy-protective choice.
California treats certain cookie banner interactions as methods for submitting requests to opt out of the sale or sharing of personal information.
That means banner design is not merely a user experience decision.
It can determine whether the business is honoring a statutory privacy right.
Businesses should test whether:
- Accept and reject options require the same number of steps
- Buttons are equally visible
- Privacy-protective choices use clear language
- A user can change a choice without unnecessary friction
- The banner correctly communicates the decision to tracking technologies
- The preference remains effective on future visits
The fact that a banner was supplied by a compliance vendor does not eliminate the business’s responsibility.
Vendor Contracts Are Becoming Part of Privacy Enforcement
Regulators are examining whether companies have appropriate contracts with service providers, contractors and third parties.
California’s settlement with Tractor Supply addressed alleged failures to ensure that contracts prohibited downstream parties from selling or sharing personal information collected on the company’s behalf.
The settlement required contractual terms designed to ensure CCPA compliance, comparable levels of protection and support for consumer rights requests.
A separate California action involving Healthline focused on advertising partner agreements.
Some contracts allegedly allowed partners to use personal information for broad internal or business purposes that benefited the partner.
Language allowing unrestricted “internal use” can be problematic when the party is expected to operate only as a service provider or contractor.
Compliant agreements should clearly address:
- The permitted business purpose
- Prohibited uses
- Restrictions on selling or sharing information
- Consumer request assistance
- Security requirements
- Retention and deletion
- Subcontractor obligations
- Audit rights
- Notice of unauthorized processing
A contract should reflect the actual relationship.
Calling a company a service provider does not make it one if it uses personal information for its own advertising, analytics or commercial purposes.
Tracking Technologies Require Continuing Vendor Review
Website and mobile application vendors can change their technologies, data uses and contractual terms over time.
That makes one-time vendor review inadequate.
As part of the Healthline settlement, the company was required to conduct annual reviews of its websites and mobile applications to determine which partners received consumer information through tracking technologies.
The company was also required to maintain audit records and address contracts with those partners.
This reflects a broader regulatory expectation that companies continuously monitor their digital environments.
A business should be able to identify:
- Which cookies and trackers are active
- Which companies receive information
- What information is transmitted
- Whether the transmission constitutes a sale or sharing
- Whether the vendor honors opt-out signals
- Whether the contractual classification remains accurate
A website can change without the privacy team’s knowledge when marketing, development or analytics teams add new technologies.
Continuous or recurring scanning is therefore becoming an important part of operational compliance.
Registration Failures Can Lead to Broader Investigations
Several recent data broker investigations began with a relatively simple question: did the business register?
Once the regulator began reviewing the company, the inquiry expanded into how information was acquired, analyzed, sold and disclosed.
This creates a significant risk for businesses that treat registration as a low-priority filing issue.
A missing registration can invite examination of:
- Data sources
- National consumer databases
- Sensitive data
- Consumer profiling
- Data accuracy
- Deletion procedures
- Opt-out mechanisms
- Vendor relationships
- Privacy notices
The initial administrative violation may therefore become the doorway to a much broader enforcement matter.
Businesses Should Review Whether They Function Like Data Brokers
Some companies do not describe themselves as data brokers but may still meet a statutory definition.
Potential indicators include:
- Purchasing personal information from third parties
- Combining information from several sources
- Creating consumer profiles
- Selling marketing lists
- Licensing audiences for targeted advertising
- Providing identity or background information
- Enriching customer databases
- Generating behavioral inferences
- Reselling location, demographic or financial information
A company’s branding or industry label is not decisive.
Regulators will examine what the business actually does with information and whether it has a direct relationship with the individuals involved.
A Practical Enforcement Checklist
Businesses that buy, sell, share or analyze consumer information should take several immediate steps.
Evaluate Data Broker Status
Review the company’s activities under every applicable state definition. Do not assume one state’s exemption or interpretation applies nationally.
Confirm Registration Deadlines
Identify annual registration requirements and assign responsibility for timely filing, renewal and updating of disclosures.
Map Sensitive Information
Document where precise geolocation, biometric, health, genetic, children’s and other sensitive information is collected, stored and transferred.
Review Consent
Determine whether consent is affirmative, informed, specific and freely given before sensitive information is collected or used.
Test Opt-Out Mechanisms
Verify that opt-outs work across websites, applications, devices, accounts and downstream vendors.
Review Privacy Notices
Confirm that disclosures are readable, current and consistent with actual business practices.
Assess Contractual Relationships
Ensure that service provider, contractor and third-party agreements contain the restrictions required by applicable privacy laws.
Scan Tracking Technologies
Identify cookies, pixels, software development kits and other technologies transmitting personal information to outside parties.
Prepare for Regulatory Inquiries
Maintain records showing registrations, consent, consumer requests, vendor assessments, privacy notices and corrective actions.
Captain Compliance Helps Businesses Address Data Broker and Sensitive Data Risk
Captain Compliance helps organizations determine whether their activities trigger data broker obligations, assess state privacy law requirements, map sensitive data, scan tracking technologies, manage consumer requests and maintain evidence supporting compliance.
As state regulators expand investigative sweeps, businesses need more than written policies.
They need operational controls showing that data broker registrations are current, consent is valid, opt-outs work, vendor contracts contain the required restrictions and sensitive information is handled according to applicable law.
The enforcement trend is moving in one direction.
Regulators are looking beyond what companies call themselves and examining what they actually do with personal information.
Frequently Asked Questions
What is a data broker?
A data broker is generally a business that knowingly collects and sells personal information about consumers with whom it does not have a direct relationship. The exact definition varies by state.
Do data brokers have to register?
Several states require qualifying data brokers to register with a state regulator. California requires registration with CalPrivacy by Jan. 31 of each applicable year.
Can a company become a data broker by selling national lists?
Yes. A national dataset may include residents of states with data broker laws. A company should determine whether the information contains covered residents and whether its activities trigger registration.
Does public-record information count as personal information?
Some public information may be exempt in certain circumstances, but companies can still create regulated personal information by combining records, generating profiles or drawing inferences about individuals.
What is considered sensitive data?
Sensitive data may include precise geolocation, biometric identifiers, genetic information, health data, children’s information, account credentials and information revealing protected personal characteristics. Definitions vary by state.
Is a privacy notice enough to establish consent?
Not necessarily. Consent may need to be affirmative, informed, specific and freely given. A disclosure buried in a privacy policy may not satisfy state requirements for sensitive data processing.
What is symmetry of choice?
Symmetry of choice means that a privacy-protective option should not require more effort than a less protective option. For example, rejecting tracking should generally be as easy as accepting it.
Can a company rely on its compliance vendor?
A vendor can support compliance, but the regulated business remains responsible for ensuring that its privacy notices, cookie banners, contracts and request mechanisms satisfy applicable law.
Why are vendor contracts important?
State privacy laws may require contracts to restrict how service providers and contractors use personal information, prohibit unauthorized sales or sharing and require assistance with consumer privacy requests.
How can Captain Compliance help?
Captain Compliance can assist with DROP Act automation and DSAR to stay compliant with the ramped up enforcement of data broker requirements.