top of page

AUTHORSHIP

13 August 2026

Data brokers' noncompliance with California's Delete Act undermines landmark privacy law

Brokers' obstruction of law giving Californians control of their personal data reflects an exploitative business model

CFTC building

Attribution: Glenn Carstens-Peters' (Unsplash)

ISSUE AREAS

CONSUMER PROTECTION

TECH REGULATION


I. Introduction


For decades, the federal government has failed to modernize privacy protections for the digital age. In this vacuum, commercial data brokers have become a multi-billion dollar industry through monetizing users’ online activity without their consent. Estimates suggest major data brokers have managed to compile around 1,000 data points on every person with a digital presence. Many consumers are under the impression this data collection model primarily serves to power targeted advertising. However, the implications of this surveillance model extend far beyond unwelcome advertisements. The sale of broker-collected data has material implications for everyday consumers, particularly in the era of personalized pricing. These systemic privacy violations have also led to Americans being targeted by online scammers or even real life violence. Research suggests that data brokers’ mishandling of sensitive data has caused U.S. consumers some $20 billion in identity theft.


California, long a trendsetter on national policy, has taken measures to advance privacy protections in recent years. In 2020, the state would establish the California Privacy Protection Agency (CPPA), an agency tasked with enforcing state privacy regulations. Legislators in 2023 would pass the Delete Act, heralded at the time as a model for privacy legislation nationwide. The law was written to empower consumers to take back control of their data from data brokers. Under the law, all businesses who have collected data from at least ten million state residents give users the option to delete their data. As an enforcement mechanism, all data brokers were required to register with the state government. Additionally, the law also gives consumers the opportunity to request corrections on inaccurate personal data. Three years after the legislation’s passage, the CPPA launched the DROP (Delete Request and Opt-out Platform) in August 2026, giving consumers an accessible way to request the deletion of their data. 


The launch of DROP is a welcome one, and the Delete Act has already inspired other states to consider data broker legislation of their own. In recognition of the promise of the Delete Act, policy-makers across the country should take heed of data brokers’ apparent obstruction in the face of these rules. Research suggests that, in response to the law’s rollout, data brokers have used dark patterns tactics to complicate the removal request process at users’ expense. Akin to companies that deliberately make subscription cancellations difficult, research suggests that brokers are using similar obstructive tactics. This includes the use of confusing user interfaces and requirements that users navigate multiple forms to request removal. Brokers' illegal use of dark patterns tactics shows their willingness to defy both the spirit of the law and the principle of individuals’ owning their own data. 



II. Promises and Limitations of the Delete Act


INDUSTRY’S CULTURE OF NON-COMPLIANCE


The data broker industry has long resisted regulations to protect individuals’ rights to their own data. During the legislative process surrounding the Delete Act, data broker groups mounted strenuous opposition in Sacramento. This included the launch of a dedicated campaign website known as “NO to SB 362”, which claimed the proposal would destroy the state’s ‘data-driven economy.’ In a state home to the global tech industry, this argument, along with other baseless claims that the bill would undermine the ability of “cybersecurity firms to fight fraud,” was clearly tailored to win support from tech industry-aligned lawmakers. Despite the industry's campaign against the bill, polling in 2023 affirmed that the proposal was overwhelmingly popular, with one survey finding 81% among Californians polled


The bill would ultimately be signed into law in the face of industry opposition, and would inspire efforts to enact a similar federal model. Despite the law’s enactment, data brokers would continue to undermine the spirit of the law, including through unlawfully failing to register with the CPPA. In January, the CPPA penalized Datamasters, a Texas-based data broker, for failing to register with the state in defiance of the Delete Act. In addition to its unlawful non-registration, Datamasters was fined for selling the data of millions of Alzheimer’s patients, including their “names, addresses, phone numbers, and email addresses.” Data brokers’ willingness to sell the personal data of millions of people suffering from a degenerative disease, one that impairs both memory and basic cognitive function, illustrates the exploitative nature of their business model. 


ENFORCEMENT CONSTRAINTS


A recent Stanford University study suggests that a majority of data brokers are defying the Delete Act. Though data brokers’ willingness to obstruct the law is unsurprising, the study illustrates the sheer scale of the industry’s noncompliance. The research determined that only 9% of covered brokers are acting in full accordance with the Delete Act’s requirements. The law’s requirement that the CPPA be given access to DSR (data subject request) metrics, a simple transparency measure to ensure compliance, has only been upheld by 45% of brokers. The study also found that an outright majority of brokers have employed unlawful dark patterns tactics to undermine consumers’ ability to control their data. CPPA regulations expressly prohibit adding "unnecessary burden or friction to the process by which the consumer submits a CCPA request or provides or withdraws consent." 


Since the creation of the CPPA, observers have noted that the agency’s structural limitations, namely resource and staffing constraints, could prevent its ability to police violators. Earlier observers raised concerns that the agency’s $10 million budget would undermine its ability to combat privacy violations, particularly by Big Tech companies. Independent research found that major tech firms such as Google and Meta have systematically violated the CPPA’s opt-out rules, ignoring users’ requests 86% and 69% of the time, respectively. Though data brokers do not possess trillion-dollar market caps, the global data brokerage industry is estimated to be worth hundreds of billions of dollars.


Additionally, the self-registration process under the Delete Act has been identified as a structural limitation that undermines compliance. As noted by Stanford researchers, the self-registry system "limit[s] monitoring and penalties for brokers that do not register.” As we noted in past analysis, consumer protection laws reliant on corporate self-reporting, particularly when accompanied by few mechanisms to punish violators, are unlikely to deter noncompliance.



III. Conclusion


It’s clear that the CPPA has taken meaningful steps towards ensuring compliance with both the Delete Act and the California Consumer Privacy Act. On August 11, the agency issued a $116,490 fine against data broker LocateSmarter, the first penalty over a broker’s failure to self-register. The fine also targeted the company’s added friction to the data removal request process. To complicate users’ ability to prevent the monetization of their data, LocateSmarter required consumers to provide the firm with the last four digits of their Social Security numbers. Earlier this year, the CPPA’s work helped secure a $12.75 million settlement with General Motors over the sale of driving data to brokers. These actions align with the state government’s broader efforts to bolster its consumer protection apparatus. In July 2026, the state launched the cabinet-level Business and Consumer Services Agency (BCSA). The new “super-agency” consolidates several consumer protection and corporate oversight functions within the state government. Consumer advocates welcomed the selection of Rohit Chopra, the former director of the Consumer Financial Protection Bureau (CFPB) and a past FTC commissioner, to lead the agency. Chopra’s selection follows the appointments of several Biden-era consumer protection officials to state or local offices amid the federal government’s retreat from enforcement.​

​While the Delete Act is worth celebrating, data brokers’ non-compliance shows the importance of pairing strong legislation with necessary resources for enforcement. In June, Connecticut passed equivalent legislation to allow users to request deletion of their data with a single click. The legislation also contains important provisions that prohibit brokers collecting users’ precise geolocation data. This measure is a necessary one given that brokers’ sale of physical address data has likely led to real-world violence. Following the assassination of Minnesota Democratic lawmaker Melissa Hortman, an affidavit stated that the killer helped prepare for the crime by “identifying several websites that allow users to search for the personal information of others like home addresses and family member names.” 

In 2000, the Federal Trade Commission (FTC) released a report on the state of online privacy in the emerging digital age. The document, which found that 97% of studied websites included personally identifiable information (PII) such as email addresses, underscored the need for federal privacy rules. The commission noted that “the limited success of self-regulatory efforts” heightened the importance of implementing measures to protect consumer privacy. Congress’ failure to pass strong privacy legislation in the decades that followed has put Americans’ personal data in the hands of unaccountable companies. While state-level measures are important to fill a federal policy vacuum, comprehensive federal rules are needed to prevent the systematic abuse of consumers’ data.


Founder, Labyrinth Insights

Aidan Smith
bottom of page