Data Broker Registration Requirements by State (2026)

A US map graphic featuring data broker network icons and a 2026 compliance badge in purple on a white background.

Key Takeaways

  • Five states require data broker registration in 2026: California, Texas, Oregon, Vermont, and Connecticut (starting 2027), with New Jersey, Delaware, Michigan, and Alaska drafting their own rules.
  • California’s registry lists more than 600 brokers and enforces a $200-per-day penalty starting August 2026; a 2025 database found over 750 registered across all five active state registries combined.
  • Registration is a disclosure requirement. It does not guarantee a broker actually removes or stops re-collecting personal data.
  • A 2026 investigation found registered California brokers hiding opt-out pages from search engines, and one broker’s opt-out link was broken entirely.
  • Each state’s registry defines “data broker” differently, so removal coverage built for one state can miss brokers accountable in another.

Five states now enforce data broker registration requirements by state law, and the list is not finished growing. California, Texas, Oregon, and Vermont already require it. Connecticut joins on January 1, 2027. For any cybersecurity vendor bundling identity or exposure protection into a product line, that number matters more than it looks. A registry is not a removal guarantee, and the gap between the two is where most compliance content stops short.

This guide maps what each state actually requires, what registration does and does not accomplish for the people whose data is listed, and why treating “registered” as “protected” leaves a real gap for any security vendor serving customers across state lines.

Which States Require Data Broker Registration in 2026

Data broker registration requirements by state currently apply in five jurisdictions, each with its own agency, fee, and enforcement mechanism.

StateRegistering AgencyAnnual FeeRenewal TimingPenalty for Non-Compliance
CaliforniaCalifornia Privacy Protection Agency (CPPA)$6,000January 31Up to $200 per day
TexasSecretary of State$300Registration anniversaryUp to $100 per day, capped at $10,000 per year
OregonDepartment of Consumer and Business ServicesSet by ruleDecember 31Up to $500 per day
VermontSecretary of State$100January 31Statutory penalty per violation
ConnecticutTo be designated (Public Act 26-64)Not yet publishedRegistration required starting January 1, 2027Not yet published

California runs the most active enforcement program of the five. As of May 2026, more than 600 data brokers are listed on the state registry, and the CPPA has already brought settlements against unregistered brokers, including two companies fined a combined $69,800 for going unregistered into mid-2025. Texas defines a data broker more narrowly, limiting the requirement to businesses whose principal revenue source is licensing third-party data. Oregon and Vermont extend coverage to brokers that license personal data, not just those that sell it outright, which pulls in business models California’s narrower “sell” definition can miss.

States Still Drafting Registration Rules

California, Texas, Oregon, Vermont, and Connecticut are not the end of the list. New Jersey, Delaware, Michigan, and Alaska are each developing their own data broker registration frameworks as of 2026, though none has enacted a binding requirement yet. A removal product built only against the five active registries needs a process for absorbing new states as they finalize rules, not a one-time integration treated as finished once these five are covered.

The Detail Generic Compliance Guides Skip: Registration Does Not Mean Removal

Image explaining that deletion is temporary because brokers immediately collect new data.

Most coverage of data broker registration requirements by state treats registration as the finish line. It is not. California’s DROP platform lets residents submit one deletion request across every registered broker, and brokers must begin processing those requests every 45 days starting August 1, 2026. That sounds like resolution. It is disclosure, not resolution.

A commentary in Route Fifty put the distinction directly: DROP is a tool for disclosure rather than for removal. Brokers keep collecting new data after a deletion request clears. A record removed today can reappear from a different source thirty days later, and the registry has no mechanism to stop that cycle.

The registry’s own reliability has been tested and found thin. A 2026 investigation by The Markup and CalMatters found that several registered California brokers had hidden their opt-out pages from search engines using no-index code, making the legally required removal path functionally invisible. One broker named in that investigation had a broken opt-out link and had already dropped off the registry entirely by the time reporters checked back. Registered does not mean reachable, and reachable does not mean the removal actually holds.

For a cybersecurity vendor deciding whether to build or buy a broker-removal capability, this is the real differentiator to build a pitch around. Five state registries are a compliance checkbox for the brokers on them. For a security product, they are closer to a live target list: an operational map of which brokers definitely exist, definitely collect personal data, and definitely require repeat action to actually stay clear of.

What Registration Actually Requires

Every state on this list asks for the same baseline: legal business name, contact details, a physical address, and a description of the categories of personal data collected. From there, the requirements diverge in ways that matter for a compliance review.

California’s Delete Act, expanded by SB 361 in 2025, now requires brokers to disclose whether they collect sensitive categories such as government ID numbers, precise geolocation, or account login credentials, and whether that data has been shared with foreign entities, law enforcement, or generative AI developers. Texas requires a website notice explicitly identifying the business as a data broker, a requirement none of the other four states impose in the same form. Vermont’s law, the oldest of the group at 2018, additionally mandates a written information security program, a requirement Oregon shares but narrows to a specific personal-information category.

None of the five states currently requires a security audit of the broker’s own removal process, only of its registration paperwork. That distinction sits at the center of why registration compliance and actual data exposure are two separate problems.

Why the Patchwork Is a Cybersecurity Product Problem, Not Just a Legal One

Minimal visualization of how localized data broker registries are shifting cybersecurity requirements.

Cybersecurity vendors already compete on breadth: threat intelligence, phishing protection, endpoint coverage. Data broker registration requirements by state are creating a parallel form of coverage competition, except the customer question is not “do you detect this,” it is “do you actually get my data off this specific broker’s list, in this specific state, this month.”

A customer whose data sits with a Texas-registered broker and a California-registered broker is not protected by a single generic monitoring dashboard. Each state’s registry represents a distinct list of legally accountable targets, and a white label data broker removal product only earns credibility once it can point to which of those specific, named registries it actually works against. This is where partnering to add data broker removal outperforms simply recommending a third-party consumer removal service: pointing a customer to an outside brand hands away the renewal relationship, the billing history, and the retention lift a bundled feature would have created instead.

A managed service provider client bundled antivirus and VPN protection into one branded suite and reported 20% enterprise client growth and a 32% reduction in operational cost within two months of the bundled launch. That case study is VPN and antivirus bundling specifically, not data broker removal, and is cited here as adjacent evidence for the retention effect of bundling security add-ons generally, not as proof of broker-removal outcomes specifically.

Building Toward State Coverage, Not Just California Coverage

Diagram comparing generic cybersecurity coverage against multi-state data broker removal integration, showing retention benefits and a 20% growth case study.

A registration map is useful operationally only if it maps to actual removal coverage. A 2025 unified database identified more than 750 registered data brokers across five state registries, a broader total than California’s registry alone, and confirmed that many brokers register in one state while skipping registration in others entirely.

The practical takeaway for a cybersecurity vendor is sequencing. California’s 600-plus registered brokers and its January 31 renewal deadline make it the highest-volume target list today. Texas and Oregon add brokers whose “license” or “transfer” activity would not trigger California’s narrower “sell” definition, meaning a removal product built only against California’s list will miss brokers that are legally accountable elsewhere. Connecticut’s 2027 start date gives a runway to build that fifth state into coverage before enforcement begins, rather than reacting to it after the fact.

PureVPN White Label Data Broker Removal

Building broker-removal coverage against five separate, actively changing state registries is not a side project. PureVPN White Label Data Broker Removal gives partners a branded removal capability built to track registered broker activity across all five jurisdictions, so a security vendor can add the feature under its own name instead of sending customers to a third-party consumer removal service.

The practical advantage is control. A partner keeps the billing relationship, the support relationship, and the renewal data instead of handing that value to an outside brand every time a customer asks how to get removed from a broker list. Before committing to any provider, it helps to know what to look for in a white label data broker removal solution, since coverage claims on a sales page can look identical while the actual backend performance differs sharply.

Request API sandbox access for a 20-minute integration walkthrough.

Frequently Asked Questions
Which states require data broker registration in 2026? +
California, Texas, Oregon, and Vermont currently require it, with Connecticut’s requirement starting January 1, 2027.
Does registering with a state make a data broker compliant with removal requests? +
No, registration is a disclosure requirement and does not verify that a broker actually processes or honors removal requests.
What is California’s DROP platform? +
DROP lets California residents submit one deletion request across all state-registered data brokers, who must process it every 45 days starting August 1, 2026.
What happens if a data broker does not register? +
Penalties range from $100 per day in Texas (capped at $10,000 annually) up to $500 per day in Oregon and $200 per day in California.
Is Connecticut’s data broker law already in effect? +
No, Connecticut’s registration requirement under Public Act 26-64 takes effect January 1, 2027.

Leave a Reply

Your email address will not be published. Required fields are marked *

Comment Form

Leave a Reply

Your email address will not be published. Required fields are marked *