The Data Broker Rulebook Splintered — What Counsel Must Do Now

The Data Broker Rulebook Splintered — What Counsel Must Do Now
August 7, 2026

The Federal Floor Fell Out — And the States Filled the Gap

The federal data broker regime you may have planned around no longer exists in the form regulators floated eighteen months ago. The CFPB published its Regulation V data broker NPRM on December 13, 2024 and then formally withdrew it on May 15, 2025, stating that 'legislative rulemaking is not necessary or appropriate at this time.' Read the Federal Register withdrawal notice — the agency killed its own proposal in under five months.

Do not mistake that withdrawal for deregulation. The enforcement energy simply migrated to the states and to the FTC's existing statutory hooks. The Future of Privacy Forum's new issue brief on the U.S. data broker landscape documents the fragmentation: no consensus on who counts as a 'data broker,' and a patchwork of state registration, deletion, and foreign-transfer rules layered on top of one another.

This quarter, counsel must do two things. First, confirm whether your company or your vendors meet any state 'data broker' definition — because those definitions do not match. Second, confirm that your intake systems are already processing against the August 1, 2026 California deletion deadline, which is now in effect. The federal ceiling came down; the state floors keep rising.

Why the FPF Brief Matters: Definitions Do Not Line Up

The core problem the FPF brief surfaces is definitional. There is little consensus as to who is a 'data broker,' what risks and benefits attach to the business model, and which entities regulators actually intend to reach. That ambiguity is not academic — it decides whether you must register, publish disclosures, and honor deletion requests.

As of July 2026, seven states have enacted data broker laws: California, Oregon, Texas, Vermont, Montana, Connecticut (effective October 1, 2026), and New Jersey, whose registration requirements take effect March 27, 2027. Each statute draws the definitional line differently, particularly around whether a company that collects data from consumers with whom it has a direct relationship is exempt.

The practical failure mode: teams assume the CCPA or CPRA definition governs everywhere. It does not. A company exempt in California because of a direct consumer relationship may still be an in-scope 'data broker' under a sister-state statute that draws the line around data sales rather than collection source. Build a definitional matrix per state before you assume you are out of scope. That will not fly with a regulator who reads its own statute literally.

Reading the Enforcement Signal: FTC, PADFAA, and Location Data

The signal is location data and foreign transfer

While the CFPB retreated, the FTC advanced. On December 3, 2024, the FTC announced enforcement actions against Mobilewalla, Inc. and Gravy Analytics Inc. (and its subsidiary Venntel Inc.) for alleged misuse of sensitive consumer location data. The Mobilewalla action included the FTC's first-ever prohibition on collecting consumer data from real-time bidding (RTB) exchanges — a structural remedy, not a fine, and a direct hit on the adtech supply chain.

Then the foreign-transfer regime activated. The Protecting Americans' Data from Foreign Adversaries Act of 2024 (PADFAA) took effect June 23, 2024, prohibiting data brokers from selling or transferring personally identifiable sensitive data of U.S. individuals to foreign adversaries. On February 9, 2026, the FTC sent warning letters to 13 data brokers, warning that noncompliance could carry civil penalties of up to $53,088 per violation.

What the signal tells you:

  • Regulators are targeting sensitive-category data — geolocation above all — not brokerage generically.
  • Structural remedies (RTB collection bans) are now on the table, which changes product design, not just paperwork.
  • Per-violation math under PADFAA scales fast; a single dataset with millions of records is not one violation.

Map your sensitive-data flows and your downstream recipients before the next letter goes out.

The State Machinery Is Live: California DROP and Texas TDPSA

California's Delete Act is now operational

California's Delete Act (SB 362), signed in October 2023, required CalPrivacy to build the Delete Request and Opt-Out Platform (DROP). DROP launched January 1, 2026 for consumer submissions, and data brokers are required to begin processing deletion requests starting August 1, 2026, per the agency's DROP implementation notice. Noncompliance carries penalties of $200 per request per day. That is a per-request, per-day meter — the exposure compounds daily against your intake backlog.

Texas made the first move under a comprehensive privacy law

On January 13, 2025, Texas Attorney General Ken Paxton filed the first-ever enforcement action under the Texas Data Privacy and Security Act (TDPSA) against Allstate and its subsidiary Arity. The suit alleges they unlawfully collected, used, and sold geolocation data from over 45 million third-party app users' cellphones, and that Arity violated the Texas Data Broker Law by failing to register.

The throughline across both states is registration plus operational capability. A registration filing without a working deletion pipeline is a liability, not a defense. The federal DELETE Act companion bills — H.R. 2612 and S. 1287, introduced April 2–3, 2025 in the 119th Congress — remain in committee with no floor votes, so the operative deadlines are state ones.

Action Items for This Quarter

Work through these in order. Sequence matters, because a notice drafted before a data map is a guess.

1. Run a state-by-state definitional scoping. Test your entity and each material vendor against all seven enacted state definitions — California, Oregon, Texas, Vermont, Montana, Connecticut, and New Jersey. Do not assume the CCPA definition governs elsewhere.

2. Calendar the hard deadlines. August 1, 2026 for California DROP processing; October 1, 2026 for Connecticut; March 27, 2027 for New Jersey registration. Assign an owner to each.

3. Build the DROP deletion pipeline before it meters. The $200-per-request-per-day penalty runs against unprocessed requests. Test intake, identity verification, and downstream deletion propagation to vendors now.

4. Map sensitive-data flows for PADFAA. Identify every recipient and every transfer path for geolocation and other sensitive categories. Confirm no recipient is controlled by China, Russia, Iran, or North Korea. Document the analysis — the FTC's warning letters presume you have done it.

5. Reassess RTB and adtech dependencies. The Mobilewalla remedy signals that RTB-sourced data collection is a structural target. If your model depends on it, price in the possibility that the practice becomes prohibited, not merely disclosed.

Key Takeaways and How FinTech Law Helps

The regulatory center of gravity moved from Washington to the states and to the FTC's existing authorities. Plan against operational deadlines, not a defunct federal rule.

  • The federal rule is dead; the state rules are not. The CFPB withdrew its Regulation V NPRM on May 15, 2025, but seven states now regulate data brokers with divergent definitions.
  • California's DROP is a compounding-penalty machine. Processing obligations begin August 1, 2026 with $200-per-request-per-day exposure — a working deletion pipeline is the only defense.
  • PADFAA is now enforced, not theoretical. The FTC's February 9, 2026 letters to 13 data brokers put the $53,088-per-violation figure on the table.
  • Location data is the enforcement target. Both the FTC's Mobilewalla and Gravy Analytics actions and the Texas Allstate/Arity suit turned on geolocation and registration failures.
  • Definitions decide scope. A matrix built before notices and DPAs beats a copy-paste privacy policy every time.

FinTech Law helps companies operationalize data broker compliance — from state-by-state scoping matrices and DROP deletion pipelines to PADFAA transfer analysis and vendor diligence. The firm works where product, legal, and security teams actually meet: data maps, registration calendars, and the audit trails regulators expect on day one of an inquiry.

Start at fintechlaw.ai or contact the team to pressure-test your exposure before the next deadline lands.

This post is for general informational purposes only and does not constitute legal advice. Consult qualified counsel regarding your specific circumstances.