The Data-Broker Registration Scope Read, State by State
Reach a defensible in-scope or out-of-scope data-broker verdict for your sourcing operation in each registering state, with deadline, fee, and duty attached.
Key takeaways
- Four states require data-broker registration: California, Vermont, Texas, and Oregon, each with its own deadline, fee, and penalty formula.
- The California direct-relationship exemption is a three-year intent test, not a data-source test - the consumer must have intended to interact with you to access, buy, use, or request your products within the preceding three years.
- Texas abandons the direct-relationship standard entirely and can treat you as a broker with respect to your own customers or employees when their data was sourced from a third party.
- B2B and lead-gen tooling is the enforcement archetype: Growbots paid $35,400 for 177 days late and UpLead paid $34,400 for 172 days, both at a flat $200 per day.
- On August 1, 2026 California exposure inverts from a single $200-per-day clock to $200 per deletion request per day, so a broker sitting on matchable records for 5,000 consumers could face $45 million in statutory exposure.
- Texas has two independent quantitative prongs - over 50% of revenue from indirectly collected data, or revenue from processing such data on over 50,000 individuals - and you can fail either one.
This guide is for recruiting operations, revenue operations, and whoever signs off on how your contact data was gathered. It gives you a scoring matrix to apply to your own data flows so you can reach a defensible in-scope or out-of-scope verdict in each registering state, with the deadline, fee, and post-registration duty attached to every state where you land in scope. It is a read on the "direct relationship" and "sale or share" tests as they actually bite on a sourcing operation, not a parallel survey of statutes.
Most ranking pages list each state's rules side by side and stop at the exact fork that matters: whether you are in scope. That fork lives in two tests - whether you have a direct relationship with the people in your database, and whether your outbound flows count as a sale, share, or license. Both tests read differently against a sourcing pipeline than against a consumer app, and that is where the surveys hand the question back to you.
Which states require data-broker registration, and what does each cost
Four states currently require data-broker registration: California, Vermont, Texas, and Oregon. Each sets its own deadline, fee, penalty formula, and enforcer, so a single calendar entry produces late filings that accrue per-day penalties.
Connecticut has enacted a regime, but its start date is reported inconsistently across secondary sources - one places the registration requirement under Public Act 26-64 at January 1, 2027, another describes a Department of Consumer Protection regime effective October 1, 2026. Treat Connecticut as pending and verify the effective date against the primary statute before you calendar anything there.
| State | Deadline | Annual fee | Max/rate penalty | Enforcer |
|---|---|---|---|---|
| California | Jan 31 | $6,000 (2026) | $200/day | CalPrivacy |
| Texas | March 1 | $300 | $100/day, cap $10,000/yr | Secretary of State / AG |
| Oregon | Before activity; renew Dec 31 | $600 | up to $500/day, cap $10,000/yr | DCBS / DFR |
| Vermont | Jan 31 (verify) | $100-$200 (conflict) | up to $10,000 | Secretary of State |
Two cells above carry known conflicts. The Vermont fee is reported as $100 for 2026 rising to $900 in 2027 by one source and as $200 with a February 15 deadline by another; the Vermont deadline is similarly unsettled. Do not file Vermont off this table alone - reconcile the fee and deadline against the Vermont Secretary of State's own registry page. California's fee also carries an associated third-party processing fee for electronic payments on top of the $6,000.
What "direct relationship" actually means, and why it is the fork
The direct-relationship exemption is a three-year intent test, not a data-source test. California defines a data broker as a business that knowingly collects and sells or shares the personal information of consumers with whom it does not have a direct relationship, and the California Privacy Protection Agency has narrowed what counts.
The agency's language is precise: a business does not have a direct relationship with a consumer simply because it collects personal information directly from the consumer; the consumer must intend to interact with the business. A direct relationship exists only when consumers intentionally interact to obtain information about accessing, purchasing, using, or requesting the business's products or services within the preceding three years.
Read that against a sourcing pipeline and the exemption shrinks fast. A person whose email you appended from a third-party supplier never intended to interact with you. A contact who filled in a form four years ago has aged out of the three-year window. A profile you scraped and then verified was never a direct relationship, because collection method alone does not create one. Each of those record classes is brokered data even though your team might describe all of them as "our contacts."
Direct relationship is a three-year intent test, not a data-source test, and stale or appended contacts fall right out of it.
Oregon and Vermont capture businesses that collect and sell or license brokered data, using the same rough shape as California. Texas is the outlier and it matters more than the survey pages admit.
Texas abandons the direct-relationship standard
Texas defines a data broker as a business entity whose principal source of revenue is derived from collecting, processing, or transferring personal data that the entity did not collect directly from the individual. There is no direct-relationship carve-out. That means Texas can treat you as a broker with respect to information about your own customers or employees when that data was sourced from a third party.
For a recruiting team, this is the trap. Buying enriched profiles about your own applicants - data you did not collect from the applicant directly - can pull that data into the Texas definition even though the applicant is, in every ordinary sense, your own candidate. The direct relationship you clearly have does not save you, because Texas is not asking about the relationship. It is asking where the data came from.
The scoring matrix: how to score each data flow
Score every data flow on two axes and the verdict falls out of the quadrant. The first axis is whether you have a direct, in-window relationship with the people in the flow. The second is whether the flow leaves your organization as a sale, share, or license for value.
The scope quadrant for a single data flow
The matrix reads left to right, top to bottom. A flow in the top-left - no direct relationship and sold onward - is the archetypal broker activity and puts you in scope in California, Oregon, and Vermont. A flow in the bottom-right - a genuine in-window customer whose data you never sell - is out of scope everywhere. The two off-diagonal quadrants are where judgement lives, and where Texas keeps pulling flows back into scope that the other three states would release.
Score one flow at a time, not the whole database at once. A pipeline that mixes true first-party form fills with appended third-party emails has flows in more than one quadrant, and the appended flow is enough to make you a broker even if the form flow is clean.
The step-by-step scope read
Run these eight steps in order. The first five reach a verdict; the last three keep you compliant once you are in.
Reaching a per-state verdict
- Inventory every data flowMap every source feeding your contact database - public records, third-party suppliers, SDKs, pixels, purchased lists, forms. Done means a documented data map naming each source and whether it is first-party.
- Apply the direct-relationship test per record classFor each class ask whether the consumer intended to interact with you within the last three years. Records failing that test are brokered data. Done means each class tagged direct or indirect.
- Separate true sales from exempt disclosuresSplit genuine sales or licenses from service-provider, processor, affiliate, fraud-prevention, or consumer-directed disclosures a state may exclude. Done means a sale-or-share-for-value determination per outbound flow.
- Run the Texas revenue and volume testCompute whether more than half your trailing-12-month revenue came from indirectly collected data, or whether you processed such data on more than 50,000 individuals. Done means a yes or no on each Texas prong.
- Score residency exposure state by stateVermont and Oregon require registration only where you broker a resident's data; California and Texas turn on doing business and the definition. Done means an in or out verdict per state.
- Register where in scope on each state's calendarFile and pay in every in-scope state, noting deadlines diverge - California Jan 31, Texas March 1, Oregon before activity. Done means a filed registration and a paid fee per state.
- Stand up post-registration operationsFor California build a DROP retrieval pipeline running at least every 45 days from Aug 1, 2026; for Texas maintain a written information security program. Done means a tested deletion pipeline and a documented WISP.
- Calendar renewals and auditsSet recurring renewals in all four states and the California triennial audit from Jan 1, 2028. Done means a recurring calendar with a named owner per obligation.
The inventory step is the one people skip and the one enforcement guidance actually names. Conduct a data-flow analysis mapping how consumer data moves through your organization, identify whether you collect directly, purchase from third parties, or both, and ensure consent language is clear, specific, and documented. That data-flow map is the artefact you will point to when an enforcer asks how you reached your verdict.
The Texas quantitative test, both prongs
Texas is the only one of the four states with a numeric threshold, and it has two prongs you must test separately. California and Oregon have no numeric revenue or consumer threshold at all - status turns purely on the definition.
The law applies if, in the past 12 months, more than half a data broker's revenue came from processing or transferring personal data it did not collect directly, OR if the broker earned revenue from processing or transferring personal data of over 50,000 individuals not collected directly. Either prong is sufficient.
The volume prong is where the revenue prong lulls people into a miss. A company that reasons "data broking is only a tenth of our revenue, so we are safe" can still be caught if it processes indirectly-collected data on more than 50,000 individuals. The Texas Attorney General filed a January 13, 2025 lawsuit against Allstate and its subsidiary Arity alleging they processed the personal data of over 50,000 individuals but failed to register - the volume prong, not the revenue prong.
What the enforcement record proves about your assumptions
The clearest signal in the enforcement record is that the exact tooling recruiting and revenue operations rely on has already been penalized as broker activity. The first California fines hit an outbound sales platform and a B2B lead generator, which tells you regulators read "data broker" to include sales-intelligence and contact-enrichment tools.
| Company | Fine | Days late | Fine ÷ days (derived) |
|---|---|---|---|
| Growbots | $35,400 | 177 | $200.00 |
| UpLead | $34,400 | 172 | $200.00 |
| Jerico Pictures (proposed) | $46,000 | 230 | $200.00 |
The derived column confirms the pre-DROP formula is a flat $200 per day per entity. According to the CPPA, a direct relationship only applies to first-party data, so companies using third-party data may qualify as brokers even if they do not consider themselves one. Growbots was an outbound sales platform and UpLead was a B2B lead generator - neither thought of itself as a data broker, and both paid.
If your operation buys, enriches, or resells contact data, the honest starting assumption is that you are in the Growbots and UpLead category until your scope read proves otherwise. The read below is how you find out before an enforcer does.
Reaching the verdict is a data-flow question before it is a legal one, and the friction is almost always in the inventory: nobody has written down where each field in the contact record came from. Refolk is built to answer the "find me the people who own this" half of that problem in plain English, so you can pull the operators and privacy owners who have already worked the registration question rather than starting cold.
How this goes wrong: the false positives that cost the fine
The expensive mistakes here are false negatives - reasons a team convinces itself it is out of scope when it is in. Each one below has a specific test that breaks the assumption.
- "We collect it directly, so we're exempt." This treats web-form or scraped-then-verified contacts as first-party. Test it against the rule that the consumer must intend to interact with the business within three years. Collection method alone does not create a direct relationship.
- "It's B2B work-contact data, not consumer data." Growbots and UpLead were B2B tools and were still fined. Test it by asking whether any single record is about a person you have no intended interaction with. If yes, that record is in scope regardless of how professional the contact is.
- "It's public-record data, so we're out." Oregon exempts some publicly available business and government-record data, but California does not blanket-exempt it. Check each state's specific carve-out rather than assuming one generous rule applies everywhere.
- "The 50% revenue prong doesn't apply to us." This misses the Texas volume prong. A company below the revenue threshold can still be caught by processing indirectly-collected data on more than 50,000 individuals. Test both prongs.
- "One deadline covers all our states." California January 31, Texas March 1, and Oregon before activity are three different triggers. A single calendar entry accrues per-day penalties in whichever state it missed.
- "We registered, so we're done." From August 1, 2026 the risk shifts from a flat $200 per day to $200 per deletion request per day. A registration certificate with no 45-day DROP retrieval pipeline behind it is the more dangerous state, not the safe one.
- "Our registration is accurate enough." Enforcement Advisory No. 2025-01, issued December 2025, warned that some brokers may be evading registration by using trade names or websites not disclosed in their registrations. Verify that your registry entries match your live operating entities and every trade name you use.
Why the penalty geometry inverts on August 1, 2026
Before August 1, 2026, California non-registration exposure is a single daily clock: $200 per day per entity, which is why Growbots' 177 late days produced exactly $35,400. After that date, the geometry changes shape, and the change is the single most important thing on your calendar.
Beginning August 1, 2026, data brokers must access the accessible deletion mechanism - DROP - at least once every 45 days and process consumer deletion requests, subject to limited exceptions. The penalty for missing a deletion request is $200 per request per day. That is per record, not per entity.
The scale is not hypothetical. The DROP queue already exceeded 300,000 consumer requests before the August 1 processing deadline. A broker holding matchable records on 5,000 consumers for a full 45-day period could face $45 million in potential statutory exposure. The mechanism is simple and unforgiving: the fine multiplies across every record you fail to delete.
| Date | Event |
|---|---|
| Jan 1, 2026 | DROP opens to consumers |
| Aug 1, 2026 | Brokers must retrieve requests every 45 days; $200/request/day penalty begins |
| Jan 1, 2028 | Triennial independent audits begin |
| Jan 1, 2029 | First audit results due |
Note one source tension on the deletion clock worth resolving locally: the statute frames it as access every 45 days and process within 45 days of receipt, while some summaries describe a 90-day determination window after retrieval. Build to the tighter reading and verify the exact window against the CPPA regulation page before you rely on the looser one.
How California exposure escalates
- Fail to register$200 per day, one clock per entity, as in the Growbots and UpLead settlements
- Register but ignore DROPFrom Aug 1, 2026, $200 per request per day begins to accrue
- Hold matchable recordsEvery un-deleted matched record multiplies the daily fine
- Miss a triennial auditFrom Jan 1, 2028, independent audits become a separate obligation
The artefacts to have before you call the job done
No published enforcement action specifies a mandated day-one artefact list beyond the registration disclosures themselves and, for Texas, a written information security program - so a formal regulator checklist is not publicly established. What enforcement guidance does emphasize is a data-flow map and documented consent language, and those are the artefacts that let you defend your verdict.
The template below is the scoring record to keep per flow. It is what turns "we think we're out of scope" into a dated, sourced determination you can hand to counsel or an enforcer.
Flow name: Source (public record / supplier / SDK / pixel / purchased list / form): First-party? (Y/N) - consumer intended to interact within last 3 years? (Y/N): Outbound use: sold / shared / licensed / internal-only / exempt disclosure type: Sale-or-share-for-value determination: (yes / no + reasoning): Texas revenue prong contribution (% of trailing-12-mo revenue): Texas volume prong contribution (# of individuals): Resident states implicated (CA / TX / OR / VT): Per-state verdict: CA ___ TX ___ OR ___ VT ___ Determined by / date:
Fill one per data flow, not one per company. Re-date whenever a source or outbound use changes.
Before you call the scope read done
- A data-flow map names every source and tags each as first-party or brokered
- Each record class is scored against the three-year intent test, not the collection method
- Every outbound flow has a sale-share-or-license determination with reasoning
- Both Texas prongs are computed separately with numbers, not assumed
- A per-state in-or-out verdict exists for California, Texas, Oregon, and Vermont
- Registration deadlines are calendared individually - CA Jan 31, TX March 1, OR before activity
- A DROP retrieval pipeline is designed to run at least every 45 days from Aug 1, 2026
- A Texas written information security program exists and is documented
- Registry entries match every live operating entity, trade name, and domain
- Renewals and the Jan 1, 2028 California audit have named owners on a recurring calendar
Keeping the verdict current
A scope read is not a one-time document. Your verdict can flip when a new supplier feed enters the pipeline, when a customer relationship ages past the three-year window, or when your Texas revenue mix crosses either prong. Re-run the per-flow record whenever a source or an outbound use changes, and re-check the Texas thresholds each fiscal quarter rather than once a year.
Three moving parts need active monitoring. The Connecticut effective date is genuinely unsettled - one source says January 1, 2027 under Public Act 26-64, another says October 1, 2026 - so track it against the primary statute rather than trusting a survey. The Vermont fee and deadline are reported inconsistently and must be reconciled against the Vermont Secretary of State's own page before each filing. And the California DROP determination window carries a statute-versus-summary tension that you should resolve to the tighter 45-day reading until the regulation text says otherwise. Where the evidence is thin, that is the honest position: hold the conservative reading and re-verify at the primary source before you rely on the looser one.
Questions practitioners ask
Am I a data broker if I only sell to businesses and only handle work contacts?
Probably yes, if any record concerns a person you have no intended relationship with. B2B lead-gen tooling is the enforcement archetype, not an exception. Growbots, an outbound sales platform, paid $35,400 and UpLead, a B2B lead generator, paid $34,400 for failing to register. The definitions turn on whether the data was collected outside a direct relationship, not on whether the person is a consumer or a professional.
Does collecting data from a public web form make it first-party and exempt?
No. The California Privacy Protection Agency has ruled that a business does not have a direct relationship simply because it collects personal information directly from the consumer; the consumer must intend to interact with the business to access, purchase, use, or request its products within the preceding three years. Collection method alone does not create the exemption, so scraped-then-verified or passively acquired contacts still count as brokered.
Do I need to register as a data broker in every state, or just where I am based?
Just where you are in scope, and the trigger differs by state. Vermont and Oregon require registration only where you broker data about a resident of that state. California and Texas turn on doing business and meeting the definition. Score residency exposure state by state and produce a separate in-scope or out-of-scope verdict for each of the four registering states.
What is the Texas 50,000-individual threshold and can I fail it even if data broking is a small part of my revenue?
Yes. Texas applies two independent prongs: more than half your revenue in the past 12 months from processing or transferring data you did not collect directly, OR revenue from processing such data on over 50,000 individuals. You can pass the revenue prong and still fail the volume prong. Test both separately. The Texas Attorney General sued Allstate and Arity over data on more than 50,000 individuals.
What happens after I register in California under the Delete Act?
From August 1, 2026 you must access the accessible deletion mechanism, DROP, at least once every 45 days and process consumer deletion requests. Penalties become $200 per request per day, so exposure multiplies per record rather than accruing as a single daily fine. From January 1, 2028 you become subject to independent privacy audits every three years, with first results due January 1, 2029.
Try it on the search you came here for
Stop building boolean strings. Just describe the person.
Type one sentence. I plan the search, read GitHub, public LinkedIn and Crunchbase records, and the open web as it is right now, and hand back a ranked list with the reason next to every name.
01Describe them
One plain sentence. Role, city, stack, stage, whatever matters to you.
02I read the web live
GitHub, public LinkedIn and Crunchbase records, the open web. Not a database that went stale last quarter.
03You read the shortlist
Ranked, with the reasoning under every name. Open a profile, ask a follow-up, narrow it down.
- Staff backend engineers in NYC who shipped Rust in production
- Series A fintechs in SF under 50 people, growing headcount this year
- Maintainers of fast-growing Rust web frameworks on GitHub
- No boolean, no filters, no seat to buy. One box.
- Read at search time, so a profile updated yesterday counts today.
- Every step visible as it runs, every name with its reason.
500 free credits on sign-up. No card, no demo call. See real searches.