Artifact GuideUSData Broker Crossover

US CCPA Data Broker Crossover

Test data-broker status separately from general CCPA scope: the statutory definition turns on knowingly collecting and selling personal information about consumers with whom the business lacks a direct relationship.

A data broker keeps its CCPA duties and may also have registration, DROP, deletion, metrics, and audit obligations under California's Data Broker Registration and Delete Act framework.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 27, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 27, 2026
Overview

A California is a CCPA business that knowingly collects and sells to third parties personal information about a consumer with whom it lacks a direct relationship, subject to statutory exclusions. Test this definition separately from general CCPA coverage, then assign registration, metrics, , deletion, downstream, and audit work.

Section 1

Start with origin, relationship, recipient, and sale

Map where personal information originates, whether the consumer has a direct relationship with the entity, every recipient, and whether the disclosure is a statutory sale. Then apply the data-broker definition and exclusions independently from the entity's general CCPA business analysis.

If the entity is a , connect its CCPA sale and sharing opt-outs to the separate registration and workflow. Beginning August 1, 2026, covered data brokers must access the deletion mechanism at least once every 45 days and process requests subject to the statutory exceptions.

  • Identify the legal entity and confirm it is a CCPA business.
  • Trace each dataset to its source and record what interaction, if any, created a direct consumer relationship.
  • Identify every third-party recipient and the monetary or other valuable consideration for the disclosure.
  • Apply each data-broker exclusion to the specific entity and activity; do not assume a CCPA exemption answers the Delete Act test.
Section 2

Apply the definition and exclusions transaction by transaction

The definition requires all elements: the entity is a CCPA business, knowingly collects personal information, sells it to third parties, and lacks a direct relationship with the consumer. A disclosure that is only sharing for cross-context behavioral advertising does not satisfy the word 'sells' unless it also fits the statutory sale definition.

The statute excludes an entity only to the extent it is covered by the federal Fair Credit Reporting Act, the Gramm-Leach-Bliley Act and its implementing regulations, or the California Insurance Information and Privacy Protection Act. It also excludes a covered entity or business associate to the extent its processing is exempt under Civil Code section 1798.146. A first-party transaction is not a separate statutory exclusion; it matters because the data-broker definition requires the business to lack a direct relationship with the consumer. Apply each condition to the exact entity and activity.

  • Record how each dataset was obtained and what interaction, if any, created a direct relationship.
  • Identify every third-party disclosure and the monetary or other valuable consideration supporting sale classification.
  • Test each statutory exclusion and preserve the facts that satisfy every condition.
  • Reassess when the business adds purchased data, enrichment, lead generation, audience sales, or a new consumer-facing service.
Section 3

Separate CCPA rights from Delete Act duties

A remains subject to the CCPA duties that apply to its business activity, including sale-or-sharing opt-outs and consumer requests. The Delete Act adds a separate registration and centralized deletion layer; registering does not replace the CCPA privacy policy or request channels.

Annual registration and the fee are due by January 31 following each year in which a business meets the data-broker definition. By July 1 following each calendar year in which it meets the definition, the broker must compile and disclose specified prior-year request metrics. Beginning August 1, 2026, it must access at least once every 45 days and process requests subject to statutory exceptions.

  • Map a request to the broker's identifiers and associated service-provider or contractor records.
  • Record each match, deletion, exception, downstream instruction, and scheduled 45-day refresh.
  • After deletion, do not sell or share newly acquired information about that consumer unless the consumer requests otherwise or a statutory exception permits it.
  • Do not treat a failed identity match as permission to ignore later cycles.
Section 4

Calendar, evidence, and audit trail

Keep the classification, direct-relationship evidence, annual registration, fee, public disclosures, access logs, identity matching, deletion results, exceptions, downstream instructions, and metrics together.

Track the separate dates: registration by January 31, metrics disclosure by July 1, processing from August 1, 2026, and an independent third-party audit beginning January 1, 2028 and every three years thereafter.

  • Privacy or legal owns classification; data operations owns matching and deletion; engineering owns recurring suppression; finance owns registration fees; audit owns the independent-audit calendar.
  • Reconcile processing against internal deletion and opt-out logs.
  • Test service-provider and contractor propagation rather than relying only on sent instructions.
  • Retain exception reasons and the provision supporting each non-deletion.
Primary sources

References and citations

leginfo.legislature.ca.gov
Referenced sections
  • Boundary source for CCPA exemptions such as legal compliance, deidentified data, and California-only conduct.
"Collect, use, retain, sell, share, or disclose consumers’ personal information that is deidentified"
leginfo.legislature.ca.gov
Referenced sections
  • Operational source for opt-out and signal fields in the data-broker crossover workflow.
"refrain from selling or sharing the consumer’s personal information"
leginfo.legislature.ca.gov
Referenced sections
  • Operational source for checking data-broker status before assigning CCPA workflow actions.
"The definitions in Section 1798.140 shall apply unless otherwise specified"
cppa.ca.gov
Referenced sections
  • Official CPPA rulemaking page documenting the status and effective date of the March 2023 regulations; the current 2026 sources are cited separately.
"The regulations became effective on March 29, 2023."
cppa.ca.gov
Referenced sections
  • Current official registration, DROP processing, penalty, and independent-audit information.
cppa.ca.gov
Referenced sections
  • Official CPPA page confirming the Agency's authority to adopt and amend CCPA and Delete Act regulations.
"To fulfill its duties, the Agency is authorized to adopt and amend regulations through the Administrative Procedures Act"
privacy.ca.gov
Referenced sections
  • Official operational guidance for the download, match, delete, status, and recurring 45-day cycle beginning August 1, 2026; the page states that the statute and regulations control.
Related guides

Explore more topics

California Data Brokers: CCPA, Registration, and DROP Duties
Decide whether a CCPA business is also a California data broker and track registration, privacy metrics, DROP deletion, vendor, and audit duties.
CCPA Consumer Rights Workflow: Requests, Clocks, and Evidence
Route CCPA requests by right, apply the correct verification and response rule, coordinate downstream action, and retain a clear decision record.
CCPA Contract Classification: Service Provider or Third Party?
Classify CCPA recipients from their actual processing and contracts, then document the clauses, restrictions, monitoring, and opt-out consequences.
CCPA Dark Patterns: Rules, Examples, and Review Checklist
Check a CCPA privacy interface for clear language, symmetrical choices, unnecessary steps, and other designs that can invalidate consent.
CCPA Deadlines and Compliance Calendar
Track CCPA request clocks, annual duties, DROP dates, and phased 2026-2030 deadlines for risk assessments, ADMT, and cybersecurity audits.
CCPA Do Not Sell or Share Guide
Classify CCPA sales and sharing, provide valid opt-out methods, honor preference signals, stop disclosures within 15 business days, and notify recipients.
CCPA Do Not Sell or Share: Implementation and Testing
Implement CCPA sale-or-sharing opt-outs across links, GPC, consent state, ad tech, recipients, confirmation, privacy disclosures, and evidence.
CCPA Do Not Sell or Share: Scope and Implementation
Determine whether a transfer is a CCPA sale or sharing, provide the required opt-out path, honor preference signals, and propagate the choice.
CCPA DSAR Workflow: Intake, Verification, and Response
Run CCPA data-subject requests from intake through verification, search, exception review, downstream action, response, and retained evidence.
CCPA Financial Incentives: Notice, Consent, and Data Value
Assess a loyalty, discount, payment, or service program under the CCPA and document notice, opt-in, withdrawal, and data-value requirements.
CCPA Global Privacy Control (GPC): team obligations and technical implementation
Implement Global Privacy Control as a CCPA sale and sharing opt-out across browsers, devices, known accounts, and relevant downstream systems.
CCPA Minors: Opt-In Rules for Consumers Under 16
Apply the CCPA's under-13 parent authorization and age-13-to-15 consumer opt-in rules for sale or sharing of personal information.
CCPA Notice at Collection: Timing, Content, and Examples
Place a CCPA notice where consumers encounter it before collection and disclose categories, purposes, retention, sale or sharing, and required links.
CCPA Opt-Out Signal Workflow: Detect, Apply, and Test GPC
Process CCPA opt-out preference signals across browsers, devices, profiles, accounts, offline data, conflicts, recipients, and confirmation controls.
CCPA Penalties and Fines: Current Amounts
See current CCPA fines, civil penalties, security-breach damages, adjustment rules, and the facts needed before estimating exposure.
CCPA Personal and Sensitive Information Categories
Classify personal and sensitive personal information under the current CCPA, including exclusions and the duties each category can trigger.
CCPA Privacy Policy Template: Required Content and Review
Draft and maintain a CCPA privacy policy covering data practices, rights, request methods, GPC handling, minors, contacts, and the last-updated date.
CCPA Risk Assessments, Cybersecurity Audits, and ADMT
Apply California's regulations effective January 1, 2026 for risk-assessment triggers, phased cybersecurity audits, ADMT rights, evidence, reviews, and CPPA submissions.
CCPA vs CPRA: What Changed and Which Rules Apply
Compare the original CCPA with the CPRA amendments and learn why current California privacy work must use the CCPA as amended, not two separate laws.
CCPA vs GDPR: Scope, Rights, Duties, and Evidence
Compare the California CCPA and EU GDPR by scope, roles, legal basis, rights, advertising transfers, contracts, security, deadlines, and enforcement.
Does the CCPA apply to my business? Threshold guide
Apply the CCPA revenue, data-volume, and sale-or-sharing revenue thresholds, then check California nexus, control, joint ventures, roles, and exemptions.
US CCPA Applicability Test Guide
Apply the CCPA entity-by-entity: test California nexus, for-profit control, current thresholds, related-entity routes, exemptions, and processing roles.
US CCPA Compliance Checklist
A verifiable CCPA checklist for scope, data mapping, notices, rights, opt-outs, contracts, retention, security, risk assessments, audits, ADMT, and evidence.
US CCPA Compliance Guide
Build a CCPA operating model for entity scope, data mapping, notices, rights, opt-outs, contracts, retention, security, assessments, audits, ADMT, and evidence.
US CCPA Dark Patterns Guide
Review CCPA privacy interfaces for plain language, symmetry, minimal steps, neutral presentation, valid consent, and reliable opt-out operation.
US CCPA DSAR Verification Guide
Verify CCPA know, delete, correct, and ADMT-access requests with request-specific, secure, minimized methods without adding friction to opt-outs.
US CCPA Enforcement and Penalties Guide
Understand CPPA investigations, Attorney General civil actions, CCPA administrative orders, current penalties, and the limited security-breach private action.
US CCPA Financial Incentives Guide
Decide whether a CCPA financial-incentive rule applies, then document the notice, data-value method, opt-in, withdrawal, and nondiscrimination checks.
US CCPA GPC Signal Guide
Implement Global Privacy Control under the CCPA across browsers, devices, accounts, ad technology, downstream recipients, and consumer notices.
US CCPA Minors Guide
Apply the CCPA opt-in rules for selling or sharing personal information of consumers under 16, including age bands, authorization, notices, and evidence.
US CCPA Notice at collection Guide
Build a CCPA Notice at Collection for online and offline collection points, including categories, purposes, sale or sharing, retention, links, and change control.
US CCPA Personal and Sensitive PI Categories Guide
Classify CCPA personal information and sensitive personal information, apply exclusions, and map each category to notices, rights, retention, security, sale, and sharing.
US CCPA Privacy Law FAQ
Direct answers on CCPA scope, rights, notices, opt-outs, GPC, minors, sensitive information, financial incentives, and data brokers.
US CCPA Privacy Notices and Disclosures Guide
Choose and maintain each CCPA consumer notice: privacy policy, collection, sale or sharing, sensitive-information limits, financial incentives, and ADMT.
US CCPA Privacy Policy Guide
Build and maintain a CCPA privacy policy covering online and offline practices, 12-month disclosures, consumer rights, request methods, and annual updates.
US CCPA Requirements Guide
Plain-language CCPA requirements covering scope, minimization, notices, rights, opt-outs, contracts, security, records, risk assessments, audits, and ADMT.
US CCPA Scope and Thresholds Guide
CCPA scope and threshold reference covering the current $26,625,000 revenue threshold, the 100,000-consumer-or-household test, related entities, and exemptions.
US CCPA Service Provider Contractor and Third Party Contracts Guide
Classify CCPA recipients and check the distinct contract terms for service providers, contractors, and third parties before disclosing personal information.
US CCPA Service Provider Contractor Contracts Guide
Check CCPA service-provider and contractor agreements for specific purposes, use restrictions, consumer-request support, subcontractors, and remediation.
US CCPA Thresholds Guide
Apply the CCPA business thresholds per legal entity, including the 2025 CPI-adjusted revenue amount, volume and sale-or-sharing tests, and control routes.
What must a CCPA privacy policy include?
A practical guide to CCPA privacy-policy content, placement, annual updates, consumer rights, request methods, and supporting evidence.
What must CCPA service-provider contracts include?
Required CCPA contract terms, role checks, subcontractor flow-downs, oversight rights, and evidence for service providers and contractors.
What should teams do about consumer request verification under the CCPA?
Choose a proportionate CCPA verification method for know, delete, and correct requests without collecting unnecessary identity data.
When does the CCPA require risk assessments or cyber audits?
CCPA triggers, deadlines, evidence, retention, and submission duties for risk assessments and annual cybersecurity audits.