California’s Delete Request and Opt-Out Platform (DROP) mandates are prompting companies across the data ecosystem to reassess their privacy compliance obligations.
In Cybersecurity and AI Law Report, Davis+Gilbert Partner Gary Kibel shared insights on recent data broker enforcement regulations and the challenges organizations face as California expands the scope of its privacy regulations.
The article explores how the state’s evolving definition of a data broker is affecting adtech, media and other data-driven businesses, including companies that may have previously assumed they fell outside the Delete Act’s scope because of their direct relationships with consumers. As Gary observed, “before the amendments introduced by the Regulations, the common view was that a business could fall entirely outside the scope of the Delete Act as long as it had any first-party relationships.”
While recent enforcement actions signal increased regulatory scrutiny, Gary noted that the industry is still waiting to see how regulators will approach alleged failures to comply with DROP itself. “We are sitting on the edge of our seats waiting for a real enforcement action post-August 1 that would be for a failure to comply properly with DROP,” he said.
Looking ahead, businesses that collect data directly from consumers while also processing third-party data should assess whether their contracts and data-sharing relationships align with CCPA requirements and evaluate whether they may now fall within California’s expanded definition of a data broker.