California’s Delete Act: Strengthening Privacy Protections and Impacting Data Brokers

Recently, California introduced a significant legislation that further reinforces the state’s commitment to citizen privacy rights. The Delete Act, officially known as Senate Bill 362, aims to build stronger privacy protections on top of the state’s existing legal framework concerning personal data usage. The introduction of this new regulation ensues the milestone enforcement of the California Consumer Privacy Act (CCPA) and it is expected to profoundly impact data brokers.

For businesses unclear about the term ‘data broker’, the new legislation describes it as: “a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship.” More or less 500 data brokers are currently registered on the California Data Broker Registry. The definition is essentially unchanged from the previous incarnation of the law, yet the obligations on data brokers are now greatly amplified.

Data brokers will soon encounter new obligations to be enforced at different stages. Beginning from January 2024, data brokers will see an expansion in their disclosure responsibilities and fines for administrative breaches. Come July 2024, they will be obligated to reveal more detailed metrics with regards to CCPA requests handling.

By August 2026, the law mandates the California Privacy Protection Agency (CPPA) to establish a mechanism for consumers to request the deletion of their personal data from the records of any single or all data broker(s). From this period onwards, data brokers will also be tasked with regularly accessing this deletion medium, processing all deletion requests, and further managing the retention, sale, or sharing of any new personal information that they may receive about that individual in the future.

This law empowers the CPPA to penalize data brokers that do not comply with the deletion requests as required. The fine can extend up to $200 per deletion request with each day of non-compliance considered as a separate violation.

Finally, as of January 2028, a data broker will have to undertake an independent third-party audit every three years to ensure compliance with the law and notify the CPPA about their audit schedule, results, and maintain these documents for a minimum period of six years. This era of increased scrutiny of data brokers under the new law signifies the state’s continual effort in defining the expansive landscape of data privacy.

The Delete Act can be described as a crucial initiative in regulating the data sharing economy. The essence of the law lies in its capacity to illuminate the sensitive privacy-related practices of data brokers, requiring them to present how effectively they abide by CCPA requests. The information collected will directly aid the CPPA in its enforcement efforts for both the CCPA and the Delete Act, consequently raising the stakes for companies that fall within the broad expanse of data brokers under the new law.

For the complete details about the Delete Act, you can read the full text of the law here.

For an in-depth analysis of the law, refer to the following Bloomberg article, that includes insights from Christine Lyon and Jackson Myers, legal experts at Freshfields Bruckhaus Deringer.