Home Data Privacy Roundup Pay Attention To The Delete Act (Even If You Don’t Think You’re A Data Broker)

Pay Attention To The Delete Act (Even If You Don’t Think You’re A Data Broker)

SHARE:
Selling private information and social media personal data market concept as a finger holding a fingerprint with a price tag as an internet business with 3D illustration elements.

Attention, data brokers: If you operated in California last year, you need to register with the California Privacy Protection Agency (CPPA) by the end of this month.

Otherwise, you might get a nastygram from the CPPA and possibly hit with a $200 fine for each day you fail to register, as per California’s Delete Act, which went into effect on Jan. 1, 2024.

Going forward, data brokers are required to reregister annually on or before January 31.

(The law also gives California consumers the right to delete all of their personal data from a broker’s database with a single request, but that’s a subject for a future newsletter.)

If you’re thinking, “That sounds intense, but I’m all good, since I’m not a data broker” – well, I’d take a beat. Because you may well be one, according to the CPPA.

Recognize yourself?

The term “data broker” is usually associated with credit-reporting agencies (e.g., Experian, TransUnion and Equifax) and data providers (e.g., Acxiom or Dun & Bradstreet) that aggregate and sell consumer data.

But the Delete Act “casts a much wider net,” says Daniel Goldberg, a partner at Frankfurt Kurnit Klein & Selz and chair of the firm’s data strategy, privacy and security group.

The law defines a data broker as any company that collects and sells personal data about consumers without having a direct relationship with them.

And the CPPA goes even further in its regulations, Goldberg says, by broadly interpreting the word “sell” to include activities such as using data for targeted advertising. According to the CPPA, a “direct relationship” only applies to first-party data.

This means companies using third-party data for targeted advertising may qualify as data brokers under California law, Goldberg says, “even if they do not view themselves in that light.”

Subscribe

AdExchanger Daily

Get our editors’ roundup delivered to your inbox every weekday.

And California isn’t the only state with a comprehensive data broker law. Texas and Oregon each have their own – both went into effect on Jan. 1, 2024 – and Vermont has had a data broker law since 2019.

Meanwhile, numerous other states have passed state privacy laws that include obligations for data brokers. And just because a company doesn’t self-identity as a data broker doesn’t mean a regulator will see it that way.

“Buying and selling personal data in any capacity could bring companies into the scope of data broker registry requirements,” says Cobun Zweifel-Keegan, managing director of the International Association of Privacy Professionals.

Expect more enforcement

Problem is, Zweifel-Keegan says, “many companies are not paying enough attention to this,” despite scrutiny of data brokers being “one of the biggest recent policy trends in privacy.”

Which is no bueno, because regulators are paying attention.

The CPPA already announced financial settlements with four companies at the end of last year for failing to register as data brokers: sales tech startup Growbots, B2B lead gen platform UpLead, ad tech company Infillion and data solutions provider The Data Group.

A comic showing lab techs as stand-ins for legislators experimenting with provisions for US state privacy laws.Meanwhile, the Texas attorney general’s office has sent more than 100 notices of violations to alleged unregistered data brokers, and Goldberg says he’s also aware of warning letters sent by regulators in other jurisdictions, as well as ongoing nonpublic investigations.

“Expect more enforcement in 2025,” he says.

So why aren’t businesses rushing to register? It’s not like they aren’t aware regulators are cracking down.

The issue is, many simply still “don’t realize they may fall under the definition,” Goldberg says.

Spirit vs. letter

And “we didn’t realize” isn’t a defense.

The smart move is to consult a privacy attorney, of course, and review your obligations. But it’s also worth acknowledging the spirit of the law and not just the letter.

“The point of this regulation is transparency,” said Dimitri Sirota, CEO and co-founder of privacy tech company BigID.

Beyond registering as a data broker, the Delete Act also requires that covered companies make disclosures to the CPPA about the types of personal data they collect, how they use it and who they share it with. Data brokers also must inform consumers about why they want to collect data and which third parties are involved.

“By enhancing transparency,” Sirota said, “the Delete Act aims to build trust between consumers and organizations while ensuring that data practices are fair and accountable.”

🙏 Thanks for reading! And am I crazy (don’t answer that) or does this incredible sea creature kinda look like a cat?? Anyway, as always, feel free to drop me a line at allison@adexchanger.com with any comments or feedback.

Must Read

The Arena Group's Stephanie Mazzamaro (left) chats with ad tech consultant Addy Atienza at AdMonsters' Sell Side Summit Austin.

For Publishers, AI Gives Monetizable Data Insight But Takes Away Traffic

Traffic-starved publishers are hopeful that their long-undervalued audience data will fuel advertising’s automated future – if only they can finally wrest control of the industry narrative away from ad tech middlemen.

Q3: The Trade Desk Delivers On Financials, But Is Its Vision Fact Or Fantasy?

The Trade Desk posted solid Q3 results on Thursday, with $739 million in revenue, up 18% year over year. But the main narrative for TTD this year is less about the numbers and more about optics and competitive dynamics.

Comic: He Sees You When You're Streaming

IP Address Match Rates Are a Joke – And It’s No Laughing Matter

According to a new report, IP-to-email matches are accurate just 16% of the time on average, while IP-to-postal matches are accurate only 13% of the time. (Oof.)

Privacy! Commerce! Connected TV! Read all about it. Subscribe to AdExchanger Newsletters
Comic: Gamechanger (Google lost the DOJ's search antitrust case)

The DOJ And Google Sharpen Their Remedy Proposals As The Two Sides Prepare For Closing Arguments

The phrase “caution is key” has become a totem of the new age in US antitrust regulation. It was cited this week by both the DOJ and Google in support of opposing views on a possible divestiture of Google’s sell-side ad exchange.

create a network of points with nodes and connections, plain white background; use variations of green and grey for the dots and the connctions; 85% empty space

Alt Identity Provider ID5 Buys TrueData, Marking Its First-Ever Acquisition

ID5 bought TrueData mainly to tackle what ID5 CEO Mathieu Roche calls the “massive fragmentation” of digital identity, which is a problem on the user side and the provider side.

CTV Manufacturers Have A New Tool For Catching Spoofed Devices

The IAB Tech Lab’s new device attestation feature for its Open Measurement SDK provides a scaled way for original device manufacturers to confirm that ad impressions are associated with real devices.