Key takeaway
The word “brokerage” on a website does not decide regulatory status. The actual collection, sale, relationships and legal scope matter.
Begin with the statutory definition.
CPPA describes a data broker as a qualifying business that knowingly collects and sells personal information to third parties about a consumer with whom it lacks a direct relationship. Applicability, exemptions and the meaning of those terms need review against the actual operation. A referral service and a seller of consumer personal information are different factual models.
Review the records as well as the business model.
Operational records can contain personal information even when sold for a business purpose. Names are only one signal; notes, location, contact details and combinations of fields may identify or relate to people. Have the reviewer distinguish company-created operational context from identifiable customer or workforce information.
Treat DROP as a current obligation where applicable.
As of this guide’s October 6, 2026 review, applicable data brokers have begun the duties that took effect August 1, 2026. CalPrivacy’s instructions require accessing DROP at least once every 45 calendar days to download and process deletion requests. Exceptions and ongoing requirements need careful application; do not treat this as a future launch.
Check the official registration and DROP instructions for your entity and start date. This guide does not determine that VOID, your business or a proposed receiving program is a registered data broker.
Ask operational questions before a commercial launch.
A compliance review should produce an implementable plan, not only a classification. If obligations apply, identify an accountable owner and how they interact with delivery, downstream use and retention.
- Which entity collects and sells which categories?
- What direct relationships exist and what evidence supports them?
- Do registration, privacy disclosures and fees apply?
- How are deletion requests matched, processed and recorded?
- How do contracts handle removed records and downstream recipients?
Keep wider US issues on the agenda.
California is one jurisdiction. Other state privacy and data-broker rules, sector-specific requirements, confidentiality and federal consumer-protection issues may also matter. Ask advisers to define the actual jurisdictional scope rather than using a California-only checklist as nationwide clearance. This is educational context, not a compliance certification.
Use this review agenda with your legal and privacy advisers. Requirements depend on the records, jurisdictions and intended use.