Introduction
By mid-2026, at least five U.S. states (California, Vermont, Oregon, Texas, New Jersey) have data broker laws in effect, with Connecticut’s new law active and others in development. State-level data broker compliance involves complex registration and licensing systems, and frameworks differ across states like California, Connecticut, and New Jersey. Data brokers face increased regulatory oversight involving reporting and transparency requirements at every level.
The term “data broker” has no single federal definition. California and Vermont define it as a business that intentionally gathers and sells a consumer’s personal information without having a direct relationship with that consumer. New Jersey splits the concept into two categories: a “data broker” (no direct relationship, sells or licenses data) and a “data collector” (has a direct relationship but sells or licenses personal data to a data broker). Many marketing, analytics, list-rental, and lead-generation operations qualify under one or both categories.
Data broker compliance generally rests on three pillars:
- Registration: filing with a state agency, paying fees, disclosing data practices
- Centralized deletion or opt-out mechanisms: responding to consumer requests via state-run platforms
- Enhanced transparency and security: audit requirements, breach notification, and detailed disclosures
These obligations are layered on top of comprehensive state privacy laws and consumer protection rules. For e-commerce and Shopify merchants, the risk is indirect but real: your ad tech vendors, email enrichment providers, and affiliate tracking platforms may be data brokers. If they fail to register or honor deletion requests, you inherit reputational and contractual risk.
California: CCPA, the Delete Act, and the DROP System
California operates the most mature data broker regime in the country. The California Delete Act (SB 362) became effective on January 1, 2024, expanding on CCPA/CPRA protections and creating new obligations enforced by the California Privacy Protection Agency (CPPA). California enforces the Delete Act, which regulates data brokers with standards that go beyond general privacy law.
California’s data broker law requires registration with the Attorney General (now transferred to CPPA). The annual registration fee rose to $6,000 in 2026. Every business meeting the definition must register annually between January 1 and January 31 for the prior calendar year. The DROP (Delete Request and Opt-out Platform) is the centerpiece of the Delete Act. California’s DROP platform lets consumers delete data from all registered data brokers with a single verifiable request. As of May 1, 2026, over 285,000 registrations for DROP exist, and more than 600 data brokers are listed in the registry.
Consumers can submit deletion requests through California’s Drop Request Platform using identifiers such as name, email, phone, and date of birth. California’s DROP platform requires brokers to delete data every 45 days starting August 1, 2026. Data brokers must handle deletion requests within 90 days, and failure to comply incurs a $200 daily penalty. Data brokers in California must report consumer deletion metrics annually by July 1.
California’s enforcement actions resulted in nine penalties for unregistered brokers. The CPPA has conducted registration sweeps and levied administrative fines against covered data brokers that failed to register or process deletion requests. Mandatory third-party audits begin January 1, 2028, requiring brokers to verify compliance with DROP, deletion obligations, registration, and security.
California compliance checklist:
- Confirm whether your business or vendors qualify as data brokers under California law
- Register with CPPA by January 31 each year; budget $6,000+ in registration fees
- Prepare technical workflows to match hashed deletion lists from DROP
- Align with CCPA requirements and honor Global Privacy Control signals
- Plan for independent audits starting 2028

Connecticut’s Data Broker Framework under the Connecticut Data Privacy Act
Connecticut’s Public Act No. 26-64 introduces data broker registration and a deletion mechanism, making it one of the first states to emulate California’s centralized approach. Connecticut’s data broker law took effect on May 27, 2026, with data broker registration provisions active as of October 1, 2026. Starting January 1, 2027, data brokers cannot sell or license brokered personal data in Connecticut without active registration.
The scope is broad. Connecticut considers a “data broker” as any entity that sells or licenses personal data to another party. Unlike California’s model, Connecticut does not require the broker to have collected the data itself; a business that only licenses third-party data qualifies. This makes the Connecticut Data Privacy Act amendments broader in reach than those in several peer states.
Connecticut’s law requires data brokers to register annually with the Department of Consumer Protection. Connecticut requires data brokers to pay a $2,500 annual registration fee. Registration disclosures include categories of brokered personal data, sources, opt-out mechanisms, breach history, and practices involving minors. Connecticut requires data brokers to register by May 27, 2026, and independent audits begin July 1, 2031.
Connecticut must launch its centralized deletion mechanism by July 1, 2028. Once operational, registered data brokers must query the system at least every 45 days and promptly process deletion requests. Connecticut prohibits selling precise geolocation data outright, and the law expands the definition of sensitive data to include financial account information, government IDs, neural data, and biometric data. Connecticut’s law enhances consumer rights regarding automated decision-making technology, including the right to access inferences about consumers and to know which third parties receive their data.
A notable consumer protection provision: Connecticut bans surveillance pricing. Retailers that adjust prices using personal data collected through tracking technologies must display the disclosure “THIS PRICE WAS INCREASED BY A PRICE SETTING DEVICE USING YOUR PERSONAL DATA.” This is directly relevant for online services using dynamic personalization tied to behavioral tracking.
Preparation steps for 2026 through 2028:
- Inventory all brokered personal data involving Connecticut residents
- Map vendors that might qualify as data brokers under CT’s broader definition
- Adapt deletion workflows to accommodate the upcoming centralized mechanism
- Review CCPA 2026 updates for parallel compliance strategies
New Jersey: The Data Broker Act vs. the New Jersey Data Privacy Act
New Jersey’s data broker law (Assembly Bill A3538) was signed June 30, 2026. The law took effect immediately, but registration and enforcement provisions become operative on March 27, 2027. It operates alongside the broader Jersey Data Privacy Act, which covers controllers and processors more generally.
New Jersey’s law defines “data collector” to expand regulatory reach beyond traditional data brokers. Two categories of businesses subject to the law are regulated:
Category | Definition | Key Distinction |
|---|---|---|
Data Broker | Knowingly collects or purchases personal data from consumers without a direct relationship, then sells or licenses it | No direct consumer relationship required |
Data Collector | Has a direct relationship with consumers but sells or licenses personal information to data brokers | Direct relationship exists; still regulated |
New Jersey data brokers must register annually with the Division of Consumer Affairs. New Jersey’s registration fees range from $5,000 to $1.5 million, tiered by the number of New Jersey residents whose data is sold or licensed:
- 100,000 or fewer consumers: $5,000
- 100,001 to 500,000: $10,000
- 500,001 to 1,000,000: $100,000
- 1,000,001 to 1,500,000: $500,000
- 1,500,001 to 2,500,000: $750,000
- 2,500,001 to 4,500,000: $1,000,000
- More than 4,500,000: $1,500,000
New Jersey’s data broker law imposes fees up to $1.5 million annually for the largest operators. The law bans the sale of sensitive personal data categories, including financial information, precise geolocation, health, and biometric data. Businesses must also perform data protection assessments for covered processing activities.
The Data Broker Act differs from the Jersey Data Privacy Act in scope: the Jersey Data Privacy Act focuses on collection, use, consumer rights, and broad processing of personal data, while the Data Broker Act specifically targets commercial sale and data-licensing arrangements with separate registration, fee, and transaction-level restrictions. The New Jersey Attorney General enforces both, with civil penalties of up to $2,500 per day for late registration.
For e-commerce operators, review loyalty programs, co-marketing arrangements, and lead generation in New Jersey. Ensure any vendors acting as data brokers or data collectors are registered and contractually obligated to maintain compliance obligations.
Other State Data Broker Laws: Vermont, Oregon, Texas, Nevada and Emerging States
A complete 2026 through 2027 strategy must look beyond the three headline states. Vermont mandates annual registration and rigorous data security programs for data brokers. Recent amendments in H.211 (effective January 1, 2027) raised registration fees, added a legitimate-purpose certification, required a surety bond, and tightened breach notification laws. Vermont does not yet operate a centralized deletion platform but has funded a feasibility study.
Texas and Oregon require data brokers to register with state authorities and disclose practices. Texas issued over 100 notifications for unregistered data brokers in 2024, using a distinct approach that includes clear privacy disclosures on the broker’s main website, formal statements of correction when updating submissions, and detailed information security program requirements that overlap with the state’s security act.
Oregon’s data broker obligations include registration, notifying the Department of Consumer and Business Services within 45 days of a data breach, and reporting material changes to registration or corporate status. Oregon’s definition is narrower and typically requires both collection and sale or licensing of brokered personal data.
Nevada does not operate a standalone data broker registration system. However, under its privacy law, operators and de facto data brokers face duties around notice and opt-out rights, particularly regarding sale of covered consumer information.
Additional states (Colorado, Virginia-style jurisdictions) are experimenting with narrower “data broker” or “data seller” concepts. Analysts expect more legislation by 2028. Businesses should maintain a multistate matrix tracking which states require data broker registration, centralized deletion compliance, information security programs, or special disclosures.

Where Pandectes Fits: Consent, Cookies, and Retail Data Broker Risk
Pandectes does not replace legal advice or state data broker registration. It provides a foundational layer of data privacy and consent management that supports multistate compliance for Shopify merchants.
Pandectes’ cookie banner and consent management capabilities help merchants comply with CCPA/CPRA, GDPR, LGPD, and other data privacy laws by recording explicit consent, respecting opt-out choices, and integrating with Google Consent Mode. Better consent controls reduce accidental “sale” or “sharing” of personal information through online tracking and ad tech, lowering the risk that a merchant’s data flows trigger data broker obligations.
Cross-border capabilities matter. Pandectes offers multilingual banners, region-specific rulesets, and scanning tools that detect tracking technologies. These features are directly useful for Shopify stores serving consumers in California, Connecticut, New Jersey, the EU/UK, and Brazil.
Where Pandectes GDPR Compliance app helps most:
- Implementing “Do Not Sell/Share” and GPC handling under CCPA
- Supporting DSAR workflows by identifying cookies and trackers that sell personal information
- Documenting consent for sensitive data categories where state laws require opt-in
- Detecting vendor-side risk through store scanning features
For vendors and platforms that may themselves be data brokers, Pandectes supports a defensible privacy posture when combined with appropriate registration, contracts, and security programs.
- No coding required
- Works with all Shopify themes
- Blocks tracking before consent
- Google Consent Mode v2 ready
- Trusted by 185k+ stores
- 3,000+ 5-star reviews
- Google CMP Partner
Practical Roadmap for 2026 through 2028: Key Dates and Next Steps
Companies that buy, sell, license, or rely on consumer data in multiple states need a phased plan tied to known enforcement dates.
Date | Event |
|---|---|
May 27, 2026 | Connecticut data broker registration requirement effective |
June 30, 2026 | New Jersey Data Broker Act signed into law |
August 1, 2026 | California DROP deletion obligations begin; brokers must process requests every 45 days |
October 1, 2026 | Connecticut data broker and CTDPA amendments fully effective |
January 1, 2027 | Connecticut: no sale/licensing of brokered personal data without registration; Vermont H.211 amendments effective |
March 27, 2027 | New Jersey registration and enforcement start |
July 1, 2028 | Connecticut centralized deletion mechanism operational |
January 1, 2028 | California mandatory third-party audits begin |
Conclusion
Data broker compliance in 2026 and beyond is a rapidly evolving landscape shaped by comprehensive privacy laws across key states such as California, Connecticut, and New Jersey. The emergence of centralized deletion platforms like California’s DROP, stringent registration and fee requirements, and expanded consumer rights underscore the increasing regulatory scrutiny data brokers face. Businesses, especially e-commerce and Shopify merchants, must carefully evaluate relationships with vendors and data processors to ensure compliance with these complex frameworks.
With enforcement activity intensifying and penalties for non-compliance rising, understanding the nuances of each state’s law, including sensitive personal information protections, opt-out platforms, and annual fee obligations, is critical. Federal laws and the Federal Trade Commission’s oversight also continue to shape the broader compliance environment.
Proactive preparation, including mapping data flows, implementing robust deletion request processes, and aligning with evolving regulations, will be key to managing risk and maintaining consumer trust. Tools like Pandectes provide valuable support in consent management and privacy compliance, helping businesses navigate this multifaceted regulatory landscape effectively. Staying informed and agile will empower organizations to meet their obligations and thrive amid the growing demands of data broker compliance in 2026 and beyond.


