The California Data Broker Registry is a public, state-run directory built from annual filings by businesses that report qualifying as data brokers. It helps people identify brokers and review disclosures; it does not itself delete personal information.
What the registry is designed to do
The registry is an informational publication maintained by the California Privacy Protection Agency (CPPA), which operates publicly as CalPrivacy. Under Civil Code sections 1798.99.80–1798.99.89, a business that meets the statutory data-broker definition during a calendar year must register with the Agency by January 31 of the following year, pay the registration fee set by the Agency, and provide the required information.
This is a legal classification, not a label for every company that handles data. The statute generally defines a data broker as a business that knowingly collects and sells to third parties personal information about a consumer with whom it does not have a direct relationship, and it states several exclusions. The exact definition and exclusions control. The broader explanation of what a data broker is is useful background but cannot resolve whether a particular legal entity must register.
The annual cycle matters when reading the directory. A registry for a given filing year reports activity from the preceding calendar year; the Agency’s registry page identifies the operating year represented by the displayed records and provides prior registry downloads. A listing is therefore an annual filing record, not a live map of every data transaction occurring on the day of a search.
Registration, publication, and administration
The CPPA has maintained and implemented the registry since January 1, 2024, according to the Agency’s registration rulemaking page. Earlier registries remain available as historical downloads on the current registry page. Readers should use the current Agency page rather than assuming an older Department of Justice dataset is the active registry.
Registration is more than entering a business name. The approved registration regulations define registration as submission of all required information plus payment of the annual fee. They also require an authorized employee or agent with sufficient knowledge of the broker’s practices to certify that the submitted information is true and correct to the best of that person’s knowledge.
After the registration period, CalPrivacy publishes information supplied by registered brokers. The current registry interface describes the visible table as information provided by each broker and offers a downloadable dataset containing the submitted public responses. That wording is important: the entries are regulated company filings, not an Agency finding that every statement has been independently verified.
What information a registry entry can contain
The current statute requires filings to cover business identity, request metrics, specified data practices, selected recipient categories, a consumer-rights link, the extent of coverage by certain sectoral laws, and any optional explanation the broker chooses to provide. The complete list appears in Civil Code section 1798.99.82, and the public interface may summarize some fields while the downloadable file exposes the complete set of public responses.
Commonly useful parts of a record include:
- Business identity. The filing identifies the data broker and gives primary contact and website information. Applicable trade names are also required by the registration regulations.
- Data-practice indicators. Required responses address specified categories, including minors’ data, account credentials, government identifiers, biometric data, precise geolocation, and reproductive health care data, as set out in the effective statutory text.
- Recipient indicators. The filing includes past-year yes-or-no disclosures concerning specified recipients, including government bodies, law enforcement in the circumstance described by the statute, foreign actors, and developers of generative AI systems or models under the current filing requirements.
- Consumer request metrics. Brokers report aggregate counts and response-time measures for listed privacy requests under section 1798.99.85. These metrics describe prior request handling; they are not the status of an individual request.
- Rights page. A broker must link to a page explaining how consumers may exercise listed California privacy rights, and that page must not use dark patterns under section 1798.99.82.
- Other regulatory coverage. A filing states whether and to what extent the broker or a subsidiary is regulated by specified federal or state privacy regimes, as required by section 1798.99.82. That disclosure should not be read as a blanket exemption for every activity or record.
Not every field submitted to the Agency becomes public. Civil Code section 1798.99.84 withholds the specific registration responses identified there, and the registration regulations also state that the broker’s internal point-of-contact information is not posted. The statutory publication rule should control over assumptions based on a missing column.
Registry, DELETE Act, and DROP are separate components
The DELETE Act is the law enacted as SB 362. DROP is the Data broker Requests and Opt-out Platform created to carry out the centralized request function. The public registry and DROP are connected, but they are not interchangeable.
| Component | Primary function | What a consumer can do | Important limit |
|---|---|---|---|
| California Data Broker Registry | Publishes annual registration information | Search names and disclosures, open an entry, and download public filing data | A listing does not prove the broker has a record about a particular person |
| DROP | Sends a centralized deletion request to active registered data brokers | Submit and later review broker-reported outcomes through the official platform | Matching, statutory exceptions, and broker-reported results still affect the outcome |
| Direct California privacy request | Exercises an applicable right with a particular business | Request access, correction, deletion, or an opt-out through the business’s official channel | Coverage, verification, exceptions, and the requested right vary by situation |
The California DELETE Act overview explains the relationship in more detail. As of January 1, 2026, California residents may use DROP, and registered brokers have been required to begin accessing and processing its requests since August 1, 2026, under the operative statutory schedule. The Agency’s DROP instructions state that consumers can view the active broker list within DROP and choose brokers to exclude from a request.
A DROP submission is a specialized consumer request. It is not created merely by viewing a registry record. Conversely, the registry can support a direct request because an entry may identify the legal entity and link to its rights page. The broader California privacy-law guide supplies context for those direct rights, but the governing statute and the facts of the request determine whether a right applies.
How to use the registry carefully
The registry is most useful as a structured research tool. A practical review can follow this sequence:
- Open the official
cppa.ca.govregistry and note the filing year and the operating year represented by that edition. - Search the exact legal name first, then try known trade names and domains. A consumer-facing brand may not be the name of the registered entity.
- Open the full record rather than relying on the row preview. Review the websites, public contact information, rights link, data-practice responses, recipient responses, and request metrics.
- Use the category filters to narrow the table, but treat a filter result as a broker’s reported category-level answer, not proof that the broker holds a specific field about you.
- Download the registration data when comparing multiple entries or fields. The Agency says the download contains all submitted public responses, while the on-page view is a preview.
- Check whether the listed rights link resolves to the same legal entity and explains the action you need. Deletion, correction, access, and opt-out are distinct operations.
- If the objective is a centralized broker deletion request, move to the official DROP service. If the objective is another right or a request to one business, use the applicable first-party rights channel.
- Record the registry year, access date, legal entity name, and source URL. Annual filings and permitted contact or website updates can change what a later search shows.
The Agency’s Enforcement Advisory 2025-01 is especially relevant when names do not align. It states that each distinct legal entity that independently meets the definition must register separately; a subsidiary cannot rely on a parent’s registration to cover it. The advisory also emphasizes listing trade names and websites. It cautions that the statutes and regulations control over the advisory if interpretations conflict.
What a search result does not establish
An entry does not establish that the broker holds information about the person searching. The registry contains business-level disclosures and aggregated metrics, not a searchable consumer profile database. Category responses likewise do not reveal which individuals appear in a broker’s systems.
An absent result is not, by itself, a legal conclusion that a company is outside the law. The search may involve the wrong year, an unfamiliar legal name, a trade name, a separately organized affiliate, or a disputed compliance or coverage position. The statutory definition and evidence about the entity’s conduct remain necessary. The CPPA may bring an administrative action for a failure to register, as provided in section 1798.99.82.
The registry also does not certify that a rights request will be granted. A direct request or DROP result can turn on legal coverage, identity matching, statutory exceptions, and the information actually held. Registry request metrics are historical aggregates; they do not predict the result or timing of a particular request.
Finally, a registration should not be treated as a complete audit of a broker’s practices. The registry creates a standardized public record of filed information. It is useful for identifying the responsible entity, comparing disclosures, and locating official rights information, while the statute, regulations, current Agency instructions, and case-specific facts remain controlling.
Updates and historical records
The registration regulations allow a broker to ask the Agency to update specified point-of-contact details, public-facing contact information, and public website addresses after registration. They generally do not allow removal from a posted registry after the period closes except for an erroneous registration, as described in title 11, section 7604. Historical downloads therefore remain useful evidence of what a business reported for a particular filing cycle, even when current contact details later change.
This article provides general information, not legal advice. Questions about whether an entity was required to register, whether a disclosure is accurate, or whether a specific request must be honored require the current official text and the relevant facts.
Frequently asked questions
Is the California Data Broker Registry the same as DROP?
No. The registry publishes information from annual data-broker filings. DROP is the separate Data broker Requests and Opt-out Platform used for centralized deletion requests.
Does a registry listing mean a broker has my personal information?
No. A listing identifies a business that registered as a data broker; it does not establish that the business holds information about a particular person.
Can I submit a deletion request through the public registry?
The public registry is primarily a discovery and disclosure tool. Use DROP for its centralized deletion function or the broker's listed rights page for an applicable direct request.
Why might a company name be absent from a registry search?
Possible reasons include searching a brand instead of the legal entity, reviewing the wrong registration year, or the business taking a different position on coverage. Absence is not a legal determination.
Who is required to register as a California data broker?
A business that meets the statutory data-broker definition must register after a year in which it met that definition, subject to the definition's stated exclusions.
Primary sources
- California Privacy Protection Agency — California Data Broker Registry
- California Legislature — current Civil Code sections 1798.99.80–1798.99.89
- California Privacy Protection Agency — Data Broker Registry and DELETE Act statute effective January 1, 2026
- California Privacy Protection Agency — approved data broker registration regulations
- California Privacy Protection Agency — data broker registration rulemaking
- California Privacy Protection Agency — Enforcement Advisory 2025-01
- CalPrivacy — how DROP works
- California Legislature — SB 362, the DELETE Act
This article provides general information, not legal advice.