Data Broker Registration Requirements: California, Texas, Oregon, and Vermont
Last updated July 2026 · Obtainer
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
Four US states require data brokers to register: California, Vermont, Texas, and Oregon. California is the strictest and the most expensive, at $6,000 a year filed with the California Privacy Protection Agency between January 1 and January 31. Vermont charges $100 on the same January 31 deadline. Texas charges $300 through the Secretary of State, and Oregon charges a fee set by agency rule through the Department of Consumer and Business Services. In every one of them the trigger is the same idea: you sell or license personal information about people you have no direct relationship with.
The reason this matters more in 2026 than it did in 2024 is that registration is no longer the end of the obligation. California's Delete Act turned the registry into an operating system. From August 1, 2026, registered brokers have to pull deletion requests out of a state-run platform every 45 days and act on them. Registering is now the moment you volunteer for a recurring workload, which is exactly why so many companies want to be sure the definition really catches them before they file.
Which states require data broker registration in 2026
The table below is the current picture. Confirm the statutory text and the agency's own guidance before you rely on any single row, because three of these four laws have been amended since they passed.
| State | Law | Register with | Who has to register | Deadline and fee |
|---|---|---|---|---|
| California | Delete Act (SB 362) | California Privacy Protection Agency | Sells personal information about consumers it has no direct relationship with. No revenue or volume threshold. | January 1 to 31 annually. $6,000 plus a payment processing fee. |
| Vermont | Act 171 of 2018, 9 V.S.A. 2446 | Vermont Secretary of State | Sells or licenses brokered personal information about consumers it has no direct relationship with. | By January 31 annually. $100. |
| Texas | Senate Bill 2105, Bus. and Com. Code ch. 509 | Texas Secretary of State | Over 50 percent of revenue from data it did not collect directly, or revenue from data on over 50,000 individuals it did not collect directly. | Before operating, then annually. $300. |
| Oregon | House Bill 2052 (2023) | Oregon Dept. of Consumer and Business Services | Sells or licenses brokered personal data about consumers it has no direct relationship with. No threshold at all. | Before collecting Oregon data, then annual renewal. Fee set by rule. |
Two of those rows deserve a second look. Texas is the only one of the four with a real threshold, so a company can sell some third-party data and stay under the line. Oregon is the opposite: it has no threshold whatsoever, which makes it the state most likely to catch a business that assumed it was too small to be regulated.
What is a data broker?
A data broker is a business that sells or licenses personal information about people who are not its customers. The legal test in California, Vermont, and Oregon turns on the phrase "direct relationship," and it is deliberately unforgiving. If a person never signed up with you, never bought from you, and has no idea you exist, then the data you hold about them is brokered data, and selling it makes you a broker. Your industry label is irrelevant. So is the fact that you would never describe yourself that way to a customer.
Texas takes a different route to a similar place. Instead of asking about the relationship, it asks about the money and the volume: more than half your revenue from processing or transferring personal data you did not collect directly, or revenue from handling such data about more than 50,000 individuals. That is a measurable test, which makes it easier to answer and easier to fail without noticing, because the 50,000 count includes data you merely process and transfer.
Am I a data broker if I only enrich or resell data I bought?
Usually yes. Buying a file and reselling it is the paradigm case, and adding fields to it does not create a direct relationship with the people in it. The businesses that most often discover they qualify are not the ones that call themselves data companies. They are B2B contact and enrichment vendors, lead-generation platforms selling scored prospect lists, people-search and background-check sites, identity and fraud-signal providers, audience and location data suppliers on the adtech side, and marketplaces that monetize data about the counterparties they never contracted with.
Exemptions exist, but they are narrower than people hope. To the extent your activity is already regulated as a consumer reporting agency under the Fair Credit Reporting Act, as a financial institution under the Gramm-Leach-Bliley Act, or as a covered entity or business associate under HIPAA and its California analogues, that data sits outside the broker regime. What trips companies up is that these carve-outs are scoped to the covered data, not to the whole company. A lender with a marketing data side business does not get to point at the GLBA and stop reading.
What happens if you do not register as a data broker?
California charges $200 for each day you are unregistered, plus the agency's costs in the investigation and administrative action. That per-day structure is the whole story, because it means enforcement does not require anyone to have been harmed. On January 8, 2026 the California Privacy Protection Agency announced two settlements on the same day: Rickenbacher Data LLC, doing business as Datamasters, paid $42,000 for failing to register, and S&P Global, Inc. paid $62,000 after 313 days off the registry. Oregon authorizes civil penalties up to $500 per violation and $500 for each day a violation continues. Vermont and Texas both enforce through their attorneys general.
Registration lapses are also the easiest violation to commit, because nothing visibly breaks when a filing expires. It is the same failure mode finance and operations teams already know from tracking vendor certificates that quietly expire: the document sits in a folder looking perfectly valid until someone checks the date on it. Three of the four states run on an annual cycle, and two of them share a January 31 deadline, so the calendar is at least easy to build.
What registration actually commits you to
Filing is the cheap part. California's registration form asks for far more than contact details. You disclose whether you collect the personal information of minors, precise geolocation, or reproductive healthcare data, your status under the FCRA, GLBA, HIPAA and state insurance and medical privacy laws, a link to the page where consumers exercise their rights, and metrics on how many consumer requests you received, complied with in whole or in part, and denied. The 2026 cycle added disclosures about whether personal information was shared with foreign actors, law enforcement, or developers of generative AI systems.
Then comes the operational tail. From August 1, 2026, every registered California broker has to access the state's Delete Request and Opt-out Platform at least once every 45 days, delete all personal information related to matching consumers, direct its service providers and contractors to delete their copies, and complete determinations within 90 days of retrieval. The duty repeats: once a consumer has come through the platform, you have to delete their data again at least once every 45 days and you may not sell or share new information about them. Beginning January 1, 2028, an independent third party has to audit your compliance every three years.
Those metrics you file each January and those audits in 2028 are both retrospective. They report on how your process behaved when nobody was watching, which is a good argument for running deletion requests through one system of record from the first cycle rather than assembling the evidence later. The full requirements are on our California Delete Act compliance guide.
Does registering as a data broker mean the CCPA applies to me?
The two regimes are separate but they overlap in practice. Registration is required by the Delete Act regardless of your size. The CCPA applies on its own thresholds, and a business meets the revenue test at more than $26,625,000 in annual gross revenue as adjusted for inflation, or by buying, selling, or sharing the personal information of 100,000 or more California consumers or households, or by deriving 50 percent or more of annual revenue from selling or sharing personal information. Most data brokers clear at least one of those, so the practical answer for a broker is usually yes, and the CCPA obligations sit on top of the registry ones rather than replacing them.
It is worth separating the registration question from the wider one about which state privacy laws reach your business. Registration is a narrow four-state duty aimed at a specific business model. The comprehensive consumer privacy laws now in force in twenty states apply to a much broader set of companies on volume and revenue thresholds, and they carry their own request deadlines and penalty schedules. We cover those in which state privacy laws apply to my business and the per-state penalty table in CCPA penalties for non-compliance.
What to do before your first DROP batch
If you are registered in California, the useful work between now and your first retrieval is not legal. It is inventory. Three questions decide whether the first cycle is routine or chaotic. Which systems hold records about people you have no relationship with, including the warehouse tables and vendor exports nobody maintains? Which service providers and contractors have copies you would have to instruct, and can you name them today? And when a request matches, what proof will exist in six months that you deleted what you say you deleted?
The last one decides how the 2028 audit goes. A deletion nobody logged is, for evidentiary purposes, a deletion that did not happen. That is the gap Obtainer fills: it discovers where a person's data actually lives across your source systems, shows the source behind every record it finds so the downstream instruction list is real rather than assumed, tracks the 45-day and 90-day clocks, and keeps a timestamped record of what was searched, found, deleted, and declined, with a human approving before anything is erased.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.