What’s the Deal With Data Broker Law?

LinkedIn
X
WhatsApp
Facebook
Email
Print

Data broker law: one data hub sending personal information out through hundreds of channels, Aber Law Firm

A data broker law makes you register with the state, pay an annual fee, disclose how your data business works, and honor consumer deletion requests, if you sell or license personal information about people you have no direct relationship with. California, Vermont, Oregon, Texas, Connecticut, and now New Jersey all have one, and the fines run per day and sometimes per consumer.

Yea I know, “data broker” sounds like somebody else’s problem. The phrase conjures up the sketchy outfits that sell lists of people sorted by medical condition. But after doing 100’s…maybe 1,000’s…of deals representing SaaS and software companies, I can tell you the legal definition is a lot wider than the reputation, and plenty of ordinary software vendors are sitting inside it without knowing.

What These Laws Are Actually Aimed At.

The target is the third party data trade. The theory is simple. If a company collects your information directly, you at least know it exists and you can go complain to it. If a company bought your information from somebody else, you have no idea it exists, so you cannot exercise any right against it. Registration fixes the visibility problem. Deletion platforms fix the “now what” problem.

So these laws generally do four things. They define a covered entity by the absence of a direct consumer relationship. They require annual registration and a fee. They require disclosures about opt out and deletion rights. And, increasingly, they plug you into a centralized deletion mechanism so one consumer request hits every registered broker at once. California’s Delete Request and Opt-out Platform (DROP) went live for consumers in January 2026, and registered brokers have to start processing DROP requests on August 1, 2026.

Why You Might Be Covered Without Realizing It.

Here is the part that surprises software vendors. Nothing in these statutes cares what you call yourself. The test is whether you sell or license personal data about people who never dealt with you directly, and “license” is doing a lot of work in the newer laws.

Connecticut’s SB 4 defines license to mean granting access to, or distributing, brokered personal data in exchange for consideration. That reaches ongoing API access and data platform models, not just a one time file transfer. If you enrich a customer dataset with third party records and expose the result through your API, you should at least run the analysis. New Jersey went further and invented a second category called a “data collector,” which captures a business that collects personal data directly from consumers and then sells or licenses it to a data broker. That one is aimed squarely at first party companies feeding the ecosystem.

This is the same definitional creep we saw with location data, which I covered in the post on mobile apps and precise geolocation data. If you are working through whether any of this reaches your product, that is exactly the analysis we run as a data privacy lawyer for SaaS and software vendors.

Three Ways Companies Get Around It.

Now the interesting part. Because these laws turn on definitions rather than on conduct, the compliance game gets played on the definitions. Three moves come up over and over.

  • Manufacture a direct relationship. Most of these statutes exempt data about consumers who are in a contractual or similar relationship with you. Connecticut’s carve out expressly covers a consumer who is or was a customer, an investor, a donor, or in “a similar relationship.” So bolt a free account or a newsletter signup onto the front of the product and the same records arguably stop being brokered data. Sometimes that is a real relationship. Sometimes it is a costume.
  • Change the verb. “We do not sell data, we license it.” Or “we just provide access.” That argument worked better before Connecticut wrote licensing into the statute and before several states aligned “sale” with the California definition. If your position depends entirely on which verb appears in your order form, it is a weak position.
  • Stay hard to find. This is the one regulators are openly annoyed about. CalPrivacy issued Enforcement Advisory No. 2025-01 in December 2025 because some brokers register under one name while operating through undisclosed trade names and websites, or point at a parent company’s registration instead of registering themselves. The advisory says the quiet part out loud: disclose every trade name and every website, and register the entity, not the family tree.

Then there is the passive version, which is just not registering at all. The EFF and Privacy Rights Clearinghouse compared the state registries in April 2025 and found 750 companies registered in at least one state, but 291 of them were not registered in California, 524 not in Texas, 475 not in Oregon, and 309 not in Vermont. Some of that gap is genuine definitional variation between states. Some of it is not.

The Latest Update.

Enforcement stopped being theoretical. CalPrivacy stood up a Data Broker Enforcement Strike Force in November 2025, and on January 8, 2026 its Board issued two decisions. The first hit a Texas reseller doing business as Datamasters with a $45,000 fine plus an order to stop selling Californians’ personal information altogether. The second was a $62,600 fine against S&P Global.

Read that second one twice. S&P Global is a data and technology company, not a shady list broker, and the agency’s own announcement attributes the failure to register to an administrative error. It still cost $62,600 plus a mandated registration and compliance auditing program.

The base penalty in California is $200 per day for failing to register, with no cap. New Jersey’s new law, signed June 30, 2026, runs $2,500 per day for registration failures and up to $50,000 per record for certain sensitive data violations, with registration fees scaled by volume from $5,000 up to $1.5 million. Connecticut runs up to $200 per day per consumer.

Where This Is Heading.

Three trends worth planning around.

  • The definitions are closing. Every dodge above is getting legislated shut. Vermont’s Act 138 added a duty to vet downstream data recipients, which is basically know your customer for data. New Jersey created the “data collector” category. Connecticut wrote licensing and ongoing access into the definition.
  • Volume thresholds are stopping being a shield. New Jersey bans the sale of sensitive data regardless of processing volume. If your data includes precise geolocation, biometrics used for identification, or financial account information, being small will not save you.
  • Registration is becoming continuous. An annual form is turning into a standing operational duty. California brokers start processing DROP requests August 1, 2026. Connecticut brokers must check its deletion platform at least every 45 days starting October 1, 2028, post annual request metrics starting July 1, 2029, and engage an independent auditor every three years starting July 1, 2031.

What I Tell Clients to Do Now.

Two things, and neither is expensive. First, run the definition against your actual data flows instead of against your self image, state by state, and write down both the conclusion and the reasoning. If somebody asks later, a documented analysis is a much better answer than a shrug. The same discipline applies to how long you hold what you collect, which I covered in the post on building a data retention policy.

Second, look at your vendor and reseller agreements. If you buy third party records, you want representations about the source and the consent chain. If you license data out, you want to know whether your buyer is registered, because Vermont style vetting duties make your counterparty’s compliance your problem. For the broader picture of what belongs in your privacy documentation, start with our outline of privacy issues for app developers.

Data Broker Law FAQ.

What is a data broker law? It is a state statute that regulates companies which sell or license personal information about consumers they have no direct relationship with. The core obligations are annual registration with the state, a fee, public disclosures about the business and its opt out and deletion mechanics, and in the newer laws participation in a centralized deletion platform.

Which states have a data broker law? California, Vermont, Oregon, Texas, Connecticut, and New Jersey have enacted registration regimes, and the list keeps growing. The definitions differ enough that you can be covered in one state and not another, so the analysis has to be run state by state rather than once.

Am I a data broker if I am a SaaS company? Possibly, and the label you use for yourself does not decide it. If you sell or license personal data about people who never had a direct relationship with you, or if you collect data directly and then sell it to a broker, you should run the analysis. Connecticut’s definition of “license” reaches ongoing API and data platform access, not just file transfers.

What is the penalty for failing to register as a data broker? California charges $200 per day with no cap, and has now issued fines including $45,000 against Datamasters and $62,600 against S&P Global. New Jersey runs $2,500 per day for registration failures and up to $50,000 per record for certain sensitive data violations. Connecticut runs up to $200 per day per consumer.

Does the first party customer exemption solve this? Only if the relationship is real. Most of these statutes exempt data about your own customers, investors, and donors, but bolting a token free account onto a third party dataset to manufacture that relationship is a thin position, and regulators are already policing structural workarounds.

I hope this helps. Trust me on this one, it is far cheaper to document why you are not a data broker than to explain an administrative error to a regulator after the fact.

Last updated: July 25, 2026.

Resources:

Disclaimer:

This post is for informational and educational purposes only, and is not legal advice. You should hire an attorney if you need legal advice, which should be provided only after review of all relevant facts and applicable law.


Discover more from Aber Law Firm

Subscribe to get the latest posts sent to your email.

Free initial Consultaion

Get started with a free initial consultation. Fill out the form below to connect with our experts today!