Skip to content

Regulatory Pulse

CalPrivacy warns data brokers: incorrect registration data can trigger daily fines

CalPrivacy’s 3 September 2026 advisory says annual data-broker registrations must be true and correct, with daily fines possible while errors remain.

California, United States
Data brokers, registration accuracy and privacy operations
Guidance
Official source reviewed

PrivacyBuilt Editorial · Source published Enforcement Advisory 2026-01 — existing registration duties · Reviewed 4 September 2026 · 7 min read

The 60-second summary

On 3 September 2026, CalPrivacy’s Enforcement Division issued Advisory 2026-01 on the accuracy of annual data-broker registrations. The advisory says data brokers must provide only true and correct responses, including disclosures about data categories, recipients, rights-request metrics and whether data went to specified recipient types such as government bodies, foreign actors or developers of generative-AI systems or models. It states that intentional and unintentional errors both produce incorrect information and that a $200 administrative fine can accrue for each day inaccurate information remains in the registry. The advisory does not create a new law or safe harbour; the statute and regulations control.

Timeline that matters

  1. By 31 January each year

    Annual registration

    A business that operated as a data broker in the prior year must register and provide required disclosures.

  2. January 2026

    DROP accounts required

    The advisory notes that registered data brokers must establish a DROP account for deletion-request processing.

  3. 3 September 2026

    Advisory issued

    The Enforcement Division published Advisory 2026-01 on true and correct registration information.

  4. 4 September 2026

    PrivacyBuilt review

    Official newsroom notice, advisory, regulations and statute checked.

  5. 18 September 2026

    Next editorial review

    Check for related enforcement actions, corrections or additional registration guidance.

What changed

The advisory puts registration accuracy squarely into CalPrivacy’s enforcement programme. It identifies recurring reporting errors and uses practical scenarios involving lead databases, identification data, tracking cookies, SDK-derived location information, generative-AI customers and rights-request metrics. Covered businesses should treat the annual filing as an evidence-based attestation built from verified operational data, not a form completed from assumptions or last year’s answers.

Who should pay attention?

Data-broker registration owners

Validate every response against current evidence and retain the approval trail supporting the filing.

Data governance and discovery teams

Identify data categories, sources, recipients and historical changes that feed the annual registration.

Sales, partnerships and procurement teams

Classify recipient relationships accurately, including public-sector, foreign-actor and generative-AI use cases where the law requires disclosure.

Privacy operations teams

Reconcile registry metrics with rights-request systems, privacy-policy reporting and DROP operations.

What the guidance clarifies

The advisory does not create a new duty
It explains the Enforcement Division’s observations about existing statutory and regulatory registration requirements. The statute and regulations control if there is a conflict.
Accuracy covers more than contact details
The filing can require verified information about data categories, recipients, annual metrics and business practices, including sensitive categories and specified recipient types.
Unintentional mistakes are not exempt
The advisory states that the Delete Act does not distinguish an accidental error from an intentional misrepresentation when the submitted information is incorrect.
The agency links errors to daily exposure
CalPrivacy states that data brokers can face a $200 administrative fine for each day incorrect information appears in the registry.
No safe harbour is offered
The advisory expressly says it does not provide alternative relief or a safe harbour and that enforcement decisions remain case-specific.

Regulatory filings need traceable operational evidence

Why this matters for global organisations

Registry declarations often depend on information spread across privacy, sales, data engineering, legal and customer-support systems. A defensible filing process identifies the responsible source for every answer, reconciles metrics and recipients, records changes during the reporting period and preserves approvals.

  • Treat regulatory registrations as controlled data products with named owners.
  • Reconcile submitted categories and recipients with inventories and contracts.
  • Validate request metrics against source systems before attestation.
  • Create a correction and escalation process for newly discovered errors.

12 actions to start now

  1. Confirm whether each business entity met the applicable data-broker definition during the prior year.
  2. Assign a named filing owner and accountable approver for the annual registration.
  3. Build a field-by-field evidence matrix showing the source, owner and review date for every registration response.
  4. Run data discovery and inventory reconciliation for personal-information categories collected during the reporting year.
  5. Review customer, buyer and recipient records for disclosures required by the registration form.
  6. Identify sales or sharing involving specified recipient types, including generative-AI system or model developers where applicable.
  7. Reconcile registry rights-request metrics with case-management systems and figures published in the privacy policy.
  8. Compare the proposed filing with the prior year and investigate unexplained changes or unchanged answers.
  9. Require legal and operational review of ambiguous categories, recipient classifications and entity scope.
  10. Submit through controlled credentials and retain the completed form, confirmations and payment evidence.
  11. Perform a post-filing verification against the public registry and correct discrepancies promptly.
  12. Add change triggers so acquisitions, new datasets, new recipient types or measurement defects prompt a registration review.

Suggested next steps

  • Review current registry information against verified operational evidence and correct identified errors promptly. Validate scope and filing decisions with qualified specialists. PrivacyBuilt’s checklist is original operational analysis, not an official safe harbour.

Evidence worth retaining

  • Entity-scope analysis and approved data-broker determination.
  • Field-level registration evidence matrix and named data owners.
  • Current data inventory, discovery results and category mapping.
  • Customer and recipient register with classification rationale.
  • Contracts, statements of work and documented downstream use cases.
  • Rights-request and DROP metrics reconciled to source systems.
  • Prior-year comparison, exception log and remediation tickets.
  • Legal review notes for ambiguous disclosure questions.
  • Submitted registration, payment receipt and confirmation record.
  • Post-filing registry screenshots and correction history.
  • Approvals, training records and annual process calendar.

Questions to take to counsel or your conformity team

These are discussion prompts, not legal advice or conclusions.

  • Which legal entity operated as a data broker during the prior reporting year?
  • What evidence supports every data category selected or omitted from the filing?
  • Which customers or recipients fall within categories that must be disclosed?
  • Could a buyer qualify as a developer of a generative-AI system or model?
  • Do cookie, SDK, enrichment and lead-generation activities change the registration answers?
  • Are rights-request metrics complete, deduplicated and consistent with public reporting?
  • What process detects a filing error after submission and how quickly can it be corrected?
  • Do service providers preparing the filing have access to authoritative operational data?
  • Which changes during the year require renewed scope or disclosure analysis?

Official sources

PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.

PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.