Data Broker Registration: The Four State Registries and What They Require
Key Takeaways
- Four states operate a data broker registry today: California, Vermont, Texas and Oregon. Each statute writes its own definition, and the four definitions do not describe the same set of companies.
- California and Vermont set an annual January 31 filing date tied to the prior calendar year; Texas and Oregon instead condition doing business on registering first, with Texas charging $300 and expiring the certificate on its anniversary.
- California's registration form is a disclosure instrument, not a name-and-address filing: Civil Code section 1798.99.82 requires a broker to state whether it collects reproductive health care data, precise geolocation, immigration status, union membership and sexual orientation, among others.
- The California Privacy Protection Agency has ordered fines for non-registration by default judgment, including a $46,000 order against National Public Data and $56,600 against a marketing firm that had never registered.
- The Justice Department's 28 CFR part 202 regulates data brokerage on a wholly separate axis — national security rather than consumer transparency — and prohibits some transfers outright regardless of registration.
Registration Is a Different Kind of Privacy Obligation
Most privacy duties are triggered by something a consumer does. Someone submits a deletion request, or opts out of a sale, and a clock starts. Data broker registration works the other way around: the obligation attaches to what a company is, it is discharged by filing a form with a state office on a fixed calendar date, and the result is a public list that anyone can read.
That structural difference is why the registries matter out of proportion to their filing fees. A registry converts a category of business that operates by not being visible into a published roster, and it gives an enforcement agency a cheap first question to ask: is this company on the list or not. Every California enforcement action described further down this guide began with that question rather than with a consumer complaint.
Four states operate a registry a broker can file in today: California, Vermont, Texas and Oregon. This guide covers those four. It does not chart all fifty states, because forty-six of them have no registry to chart — and where a state has enacted a registry that has not yet opened, this guide says so rather than describing a filing that cannot yet be made.
The Definitions Do Not Describe the Same Companies
The four statutes each write their own definition, and the differences are not cosmetic. A company can sit squarely inside one and outside another.
California's is the narrowest in one respect and the broadest in another. Civil Code section 1798.99.80(c) defines a data broker as "a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship," and then carves out entities to the extent they are covered by the Fair Credit Reporting Act, the Gramm-Leach-Bliley Act, California's Insurance Information and Privacy Protection Act, or the HIPAA-related exemption in section 1798.146. The carve-outs are written "to the extent" — they exempt an activity, not a company.
Texas turns on revenue. Chapter 509 of the Business and Commerce Code, added by Senate Bill 2105, defines a data broker as a business entity "whose principal source of revenue is derived from the collecting, processing, or transferring of personal data that the entity did not collect directly from the individual." Section 509.003 then supplies the arithmetic: the chapter applies only where, in a 12-month period, the entity derives more than 50 percent of its revenue from that activity, or derives revenue from processing or transferring the personal data of more than 50,000 individuals it did not collect from directly.
Oregon defines the regulated conduct by reference to a list of data elements. Under ORS 646A.593, a data broker is a business entity that collects and sells or licenses "brokered personal data" — a defined set that includes a resident's name, address, date or place of birth, mother's maiden name, biometric information, Social Security or other government identification number, and a catch-all for other information that can reasonably be associated with the individual when sold in combination.
Vermont's definition, as the Secretary of State's data broker filing page states it, is a business "that knowingly collects and sells or licenses to third parties the brokered personal information of a consumer with whom the business does not have a direct relationship." It is the definition California's later statute most closely echoes.
The practical consequence of four definitions is that the four registries are not four copies of one list. A firm whose brokering is a minority of its revenue but touches more than 50,000 Texans is inside Chapter 509 and may sit outside a revenue-principal test elsewhere. A firm selling only business contact data may fall outside Oregon's enumerated elements while meeting California's "personal information" standard.
What Each Registry Actually Asks For
The filings diverge as much as the definitions. Two of the four are essentially identity-and-contact filings; California's is a substantive disclosure questionnaire.
| State | Files with | Timing | Fee stated in the source read |
|---|---|---|---|
| California | California Privacy Protection Agency | On or before January 31 following each year the business met the definition | Set by the agency, capped at the reasonable costs of the registry website and the deletion mechanism |
| Vermont | Secretary of State | Annually, between January 1 and January 31 following each calendar year the business met the definition | Not stated on the Secretary of State page read for this guide |
| Texas | Secretary of State | Before conducting business in the state; certificate expires on its first anniversary | $300 to register, $300 to renew |
| Oregon | Department of Consumer and Business Services | Before collecting, selling or licensing brokered personal data; registration valid until December 31 of the year approved | Set by department rule at an amount sufficient in aggregate to administer the program |
Texas asks a registrant, under section 509.005(b), for its legal name and contact details, a description of the categories of data it processes and transfers, a statement of whether it operates a purchaser credentialing process, and — where it has actual knowledge it holds the personal data of a known child — a statement detailing its collection practices, databases, sales activities and opt-out policies for that data. It also requires the number of security breaches the broker experienced in the preceding year and, if known, the number of consumers affected by each.
Oregon's filing under ORS 646A.593(3) is shorter but pointed at one thing: opt-out rights. The registrant files name, address, telephone, website and email, and a declaration stating whether residents may opt out of all or part of its collection, sale or licensing; identifying which activities or which data an opt-out reaches; describing the method for exercising it; and stating whether an authorized agent may exercise it on the resident's behalf.
California's is the outlier. Section 1798.99.82(b) requires the registrant to answer a series of yes-or-no questions that together sketch the broker's book of business: whether it collects the personal information of minors; whether it collects government identification numbers, mobile advertising identifiers, connected television identifiers or vehicle identification numbers; and whether it collects citizenship or immigration status, union membership, sexual orientation, gender identity and expression, biometric data, precise geolocation, or reproductive health care data. It further asks whether the broker has sold or shared data in the past year to a foreign actor, to the federal government, to other state governments, to law enforcement outside a subpoena or court order, or to a developer of a generative AI system or model.
Those answers are published. The statute turns a registration form into a standing, machine-readable disclosure about who is trading in the categories of data that draw the most regulatory attention.
California Attached a Deletion Mechanism to the Registry
The registry fee in California funds something the other three states do not have. Section 1798.99.86 directed the California Privacy Protection Agency to establish, by January 1, 2026, an "accessible deletion mechanism" — the Delete Request and Opt-Out Platform — that lets a consumer ask, through a single verifiable request, that every registered data broker delete the personal information it holds about them.
The statute specifies the mechanism in detail: it must let a consumer selectively exclude particular brokers from a request, permit a change to a prior request after 45 days have passed, cost the consumer nothing, operate in any language spoken by a consumer whose information brokers have collected, be usable by consumers with disabilities, support authorized agents, and let a consumer check the status of a request.
The obligation it creates on the other side runs on a 45-day cycle. Beginning August 1, 2026, section 1798.99.86(c) requires a registered data broker to access the mechanism at least once every 45 days and process the deletion requests it finds there. That is the provision that converts registration from a disclosure duty into an operational one, and it is why the California registry is structurally different from a roster.
The Enforcement Record Is California's, and It Is Recent
Registration statutes are only as real as the consequence of ignoring them, and on that question the record is lopsided: essentially all of the published enforcement to date comes from one agency.
In May 2025 the California Privacy Protection Agency's Board ordered Jerico Pictures, Inc., doing business as National Public Data, to pay a $46,000 fine for failing to register and pay the annual fee. The agency described the amount as the maximum penalty available under the law for that failure. The Enforcement Division alleged the company registered on September 18, 2024 — 230 days late — and did so only after being contacted during an investigation. The Board issued the order by default after the company did not challenge the allegations. The agency was explicit that the case was separate from the breach the company had been reported to suffer.
In December 2025 the Board issued a decision requiring ROR Partners LLC, a Nevada marketing firm serving fitness and wellness brands, to pay $56,600 in fines and past-due fees for operating in 2024 without registering. The decision recites that the firm used "billions of data points" to build custom audience segments covering more than 262 million Americans and then sold access to those segments for targeted advertising. On the argument that bundling personal information into a larger product changes its character, the decision states: "A sale is a sale. A business cannot bypass the CCPA's and the Delete Act's requirements by selling personal information as part of a larger suite of products and services it offers."
A month before that decision, the agency announced a Data Broker Enforcement Strike Force inside its Enforcement Division, describing it as an expansion of a 2024 investigative sweep into registration compliance that the agency said had produced a record number of enforcement actions and remained ongoing.
Texas and Oregon both wrote penalties into their statutes. Section 509.008 sets a Texas civil penalty of not less than $100 for each day of violation plus unpaid registration fees, capped at $10,000 against the same broker in a 12-month period, recoverable by the Attorney General with fees and costs. ORS 646A.593(7) allows the Oregon department to impose up to $500 per violation or $500 for each day a violation continues, capped at $10,000 in a calendar year. Research for this guide found no published enforcement decision under either provision, and records none rather than inferring activity from the existence of the penalty.
A Federal Rule Regulates Brokerage on an Unrelated Axis
State registration is about visibility to consumers and regulators. A Justice Department regulation, 28 CFR part 202, regulates the same commercial activity for a different reason: keeping bulk data about Americans away from specified foreign governments. It implements Executive Order 14117 of February 28, 2024.
The rule defines "data brokerage" at section 202.214 as the sale of data, licensing of access to data, or similar commercial transactions transferring data from a provider to a recipient "where the recipient did not collect or process the data directly from the individuals linked or linkable to" it. That is recognisably the same concept the state registries use, arrived at independently.
What differs is the trigger and the remedy. Section 202.205 sets volume thresholds measured over the preceding 12 months — more than 100 U.S. persons for human genomic data, 1,000 for other human omic data, 1,000 for biometric identifiers, 1,000 U.S. devices for precise geolocation, 10,000 U.S. persons for personal health data, 10,000 for personal financial data, and 100,000 for covered personal identifiers. Section 202.206 states that the thresholds apply regardless of whether the data is anonymized, pseudonymized, de-identified or encrypted.
Above those lines, section 202.301 prohibits a U.S. person from knowingly engaging in a covered data transaction involving data brokerage with a country of concern or covered person. Section 202.302 reaches one step further down the chain: a transfer to a foreign person who is not a covered person is prohibited unless the U.S. person contractually requires the recipient to refrain from onward brokerage of the same data to a country of concern or covered person, and reports known or suspected violations of that term within 14 days.
No registration cures a part 202 problem, and no part 202 compliance satisfies a state registry. The two regimes share a vocabulary and nothing else.
Where This Guide Stops
Four registries are charted here because four are what the research for this guide could read in the operative source. Legislative activity reported elsewhere suggests additional states have enacted registration schemes with later effective dates, including Connecticut and New Jersey. Those are not described in this guide: the session that researched it could not retrieve the enacted text from the Connecticut General Assembly's server, and rule of the house is that a citation that was not fetched and read does not ship.
The Vermont fee and the Vermont non-registration penalty are likewise absent from the table above. The Secretary of State's filing page was retrieved and supports the definition and the January 1–31 filing window; the statutory fee and penalty figures sit in 9 V.S.A. § 2446, which the Vermont legislature's server would not return. Two blank cells are a smaller cost to a reader than two plausible numbers.
Background
For the underlying law rather than this development: California privacy law, Texas privacy law, Oregon privacy law, Vermont privacy law, Technology & SaaS privacy law.
Frequently Asked Questions
Which states have a data broker registry a company can actually file in?
Does registering in one state satisfy another state's requirement?
What does California's Delete Act require a registered broker to do after it registers?
Has any state actually fined a company for failing to register?
Is an advertising or marketing firm a data broker?
Sources
Everything above is reported from these documents. Follow them to verify.
- Cal. Civ. Code § 1798.99.80 — data broker definition and exclusions (January 1, 2024) statute
- Cal. Civ. Code § 1798.99.82 — registration and required disclosures (January 1, 2026) statute
- Cal. Civ. Code § 1798.99.86 — accessible deletion mechanism (DROP) (January 1, 2026) statute
- Texas S.B. 2105 (88R), enacting Bus. & Com. Code ch. 509 (June 18, 2023) statute
- ORS 646A.593 — registration to operate as data broker in Oregon (January 1, 2023) statute
- Vermont Secretary of State — Data Broker filing requirements (August 24, 2026) agency guidance
- CPPA orders Florida data broker National Public Data to pay $46,000 fine (May 8, 2025) agency release
- CalPrivacy fines ROR Partners LLC $56,600 for unregistered data brokering (December 3, 2025) agency release
- CalPrivacy launches Data Broker Enforcement Strike Force (November 19, 2025) agency release
- 28 CFR part 202 — bulk U.S. sensitive personal data and countries of concern (April 8, 2025) regulation
Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.