AdTech and Lead-Gen Firms Are the New Data-Broker Enforcement Target

If your site runs ad pixels or feeds a lead-generation pipeline, California may already count you as a data broker. You just haven't been told yet. Two moves from the state's privacy regulator in early September make that risk concrete, and neither one targets the companies most people picture when they hear "data broker."

What Happened

On September 1, 2026, the California Privacy Protection Agency (CalPrivacy) ordered SalesIntel Research, Inc., a Virginia B2B contact-data company, to pay $36,400 for operating as a data broker in California without registering by the 2025 deadline the Delete Act requires. SalesIntel also has to publish privacy-rights metrics on its site and start honoring deletion requests through the state's DROP platform. The case is the latest in a rapid run of data-broker actions this summer, and Head of Enforcement Michael Macko aimed the takeaway squarely at the ad industry: "If you're operating in the AdTech ecosystem, these recent enforcement actions are reminders to review whether you engaged in data broker activity and properly registered."

Two days later, on September 3, the Enforcement Division published Enforcement Advisory 2026-01. Its point: registering isn't the finish line. A broker that files inaccurate information, whether wrong metrics or an incomplete list of the data types it collects and the recipients it shares with, is liable for $200 a day for as long as the registry stays wrong. Executive Director Tom Kemp set the standard plainly: "DROP works because the law requires data brokers to report correct information about their activities. Californians are entitled to nothing less."

Why This Reaches Past the Obvious Brokers

Under the Delete Act, a data broker is any business that knowingly collects and sells personal information about consumers it has no direct relationship with. A company selling B2B contact records fits that test cleanly. So can an adtech vendor, a lead aggregator, or an analytics firm that resells the data it gathers, and plenty of them have never filed because they don't think of themselves as brokers at all.

Two questions decide your exposure. Does your data flow meet the broker definition? If you sell or license information about people who aren't your own customers, confirm your registration status before the next annual deadline. And if you have registered, is the filing actually accurate? Advisory 2026-01 turns registry accuracy into an enforceable obligation with a daily meter running, not a form you submit once and forget. See the CCPA enforcement tracker for the running record of CalPrivacy and California AG actions.

Where Privisy Fits

You can't fix a data flow you can't see. Privisy scans your live site and maps where personal information actually goes: which trackers fire, which third parties receive the data, and whether any of that traffic crosses into selling or sharing under the CCPA. That's the same picture a regulator assembles when it checks your real behavior against what the registry says. Seeing it before an enforcement letter does is the whole point.

Do You Owe a Data-Broker Registration?

Privisy shows you where your site sells or shares personal information, so you can answer the question before CalPrivacy does.

Get Your Audit