What should teams do about Data Broker Crossover under the US CCPA?
Apply the definition to the entity, not to a product label. Confirm that the entity is a CCPA business, knowingly collects personal information, sells that information to third parties, and lacks a direct relationship with the affected consumers. Then check the statute's exclusions, including specified consumer-reporting, financial, insurance, and health-data activities.
A direct relationship exists when the consumer intentionally interacts with the business, but the exact facts matter. Buying data indirectly, collecting it from public sources, or operating a consumer-facing site does not by itself resolve whether the business has a direct relationship with each affected consumer.
- Register with CalPrivacy between January 1 and January 31 after each year in which the entity met the data-broker definition.
- Publish the required prior-year request metrics by July 1 and report them during annual registration.
- Beginning August 1, 2026, access at least once every 45 days and process each matched deletion or fallback opt-out request within 45 days after receiving it through the platform, subject to statutory exceptions. The two periods can result in up to 90 days from the consumer's submission.
- Direct associated service providers and contractors to delete covered information or process the required opt-out.
- Prepare for independent audits beginning January 1, 2028 and every three years thereafter; keep the audit report and related materials for at least six years.
Official registration guidance and the operative data-broker definition.
Binding source for the definition, exclusions, registration, metrics, DROP processing, vendor directions, exceptions, penalties, and audit schedule.