03Compliance

Data broker and privacy laws for list buyers

Most of these laws bind the seller of a list. A few reach the buyer too. This page shows which, with the statute or agency page behind each fact.

Updated 8 min readReviewed by the Prospecting Data compliance team

AShort answer

As of 10/10/2026, four states require data brokers to register: California, Vermont, Texas and Oregon. California brokers must process deletion requests through the state DROP platform from 08/01/2026, at least every 45 days. Buyers who only market to a list rarely register, but covered buyers must still honor opt-outs of sale under state privacy laws.

Key facts
Registration statesCalifornia, Vermont, Texas, Oregon
California DROPBrokers process deletions from 08/01/2026, at least every 45 days
California broker fee$6,000 for 2026, registered 01/01 to 01/31 each year
DROP penalty$200 per day per unprocessed request
CCPA fine cap$2,663 per violation, $7,988 if intentional (from 01/01/2025)
FCRA willful damages$100 to $1,000 per consumer

Who these laws bind

Data broker laws bind the business that sells or licenses personal data about people it has no direct relationship with. The buyer is bound in two cases: when it meets a state privacy law's size thresholds, and when it resells the list. Everything else a buyer does is contract and good practice.

California's definition is the model. A data broker is a business that knowingly collects and sells personal information to third parties about a consumer with whom it has no direct relationship (CalPrivacy). Texas defines a data broker as a business that collects, processes or transfers personal data it did not collect directly from the individual, and counts purchasing or renting data as "collecting." Its chapter applies only if, in a 12-month period, more than 50 percent of revenue comes from that data, or revenue comes from the data of more than 50,000 such individuals (Tex. Bus. and Com. Code 510.001 and 510.003). Texas moved this law from chapter 509 to chapter 510 effective 09/01/2025.

The California privacy law reaches buyers by size. A for-profit business is covered if it buys, sells or shares the personal information of 100,000 or more California residents or households, or earns 50% or more of its revenue from selling personal information (California Attorney General), or has gross annual revenue above $26,625,000, the figure in effect from 01/01/2025 (CPPA).

Read the compliance hub for the other rules that sit beside these. Phone and text rules are in TCPA explained.

Which states require data broker registration

Four states run a registry: California, Vermont, Texas and Oregon. Each has a different test, fee and penalty. Fees below appear only where the statute or agency page states them.

State Cite Fee Penalty
California Delete Act, CalPrivacy $6,000 for 2026 plus a payment processing fee up to 2.99%, registered 01/01 to 01/31 $200 per day for failing to register
Vermont 9 V.S.A. 2446 $100, due by 01/31 $50 per day, capped at $10,000 per year, plus fees owed
Texas Bus. and Com. Code ch. 510 $300 to register, $300 to renew At least $100 per day, capped at $10,000 per 12 months, plus unpaid fees
Oregon ORS 646A.593 Set by agency rule, not in statute Up to $500 per violation or per day, $10,000 per calendar year cap

Sources: CalPrivacy fees page, Vermont, Texas 510.005 and 510.008, Oregon.

Oregon exempts a broker whose activity is limited to publicly available business or professional information, or information lawfully available from government records. Texas excludes publicly available information from its chapter. A list built only from public records can therefore sit outside these registries. A list that adds consumer-file attributes usually does not.

California Delete Act and DROP

DROP is the Delete Request and Opt-out Platform. Consumers could begin submitting requests in January 2026. Brokers must access DROP and process requests beginning 08/01/2026, and at least once every 45 days after that (CalPrivacy). The penalty is $200 per day for each request not handled. A broker that is 30 days late on 10 requests owes 10 x 30 x $200 = $60,000 at the statutory rate, before investigation costs.

Which state privacy laws matter to a list buyer

A comprehensive privacy law gives residents rights to opt out of the sale of their data, delete it, and see a notice at collection. These dates come from the statute, the bill record or the attorney general's page. Dates are effective dates; some states phase in other duties later.

State Effective Cite
California (CPRA amendments) 01/01/2023 Attorney General
Colorado 07/01/2023 SB21-190
Connecticut 07/01/2023 Attorney General
Utah 12/31/2023 SB 227
Texas 07/01/2024 Bus. and Com. Code ch. 541
Delaware 01/01/2025 (enforcement period begins under 12D-111) 6 Del. C. ch. 12D
Tennessee 07/01/2025 Attorney General
Minnesota 07/31/2025 Attorney General
Maryland 10/01/2025 SB 541
Indiana 01/01/2026 IC 24-15

Virginia has a law too. Its page confirms the chapter and a penalty of up to $7,500 per violation but no start date, so it is not in the table (Va. Code 59.1-584). More states have passed laws that start later. Check the statute for your target state before a campaign.

Where the B2B exemption ended

California's exemptions for business-to-business and employee data expired 12/31/2022, so its law covers that data from 01/01/2023 (California Attorney General). Virginia defines a consumer as excluding a person "acting in a commercial or employment context." Delaware and New Jersey use similar wording (Delaware, New Jersey). In those states a work email for a sales contact is generally outside the law. In California it is inside.

What a list buyer must actually do

A buyer should do four things whatever the state: honor opt-outs, keep a source record, hold a written contract with the seller, and publish a privacy notice if you are covered.

  1. Honor opt-outs. California requires acting on an opt-out of sale or sharing generally within 15 business days, and responding to deletion requests within 45 calendar days, extendable by another 45 (California Attorney General). Keep one suppression list across all lists you buy.
  2. Keep a source record. For each file store the seller, the date, the record source and what the seller said about consent.
  3. Contract terms. Require the seller to warrant lawful collection, process deletions and opt-outs on a stated schedule, and notify you of any registration lapse. Allow you to delete a file if the seller fails.
  4. Notice. If a privacy law covers you, the notice at collection lists the categories collected and why, and a "Do Not Sell or Share" link if you sell.

The FCRA line

The Fair Credit Reporting Act covers a "consumer report": communication by a consumer reporting agency about a person's creditworthiness, character or mode of living, used or expected to be used to decide credit, insurance or employment eligibility (15 U.S.C. 1681a). A homeowner list built from county records, or a B2B contact list, is not that. A prescreened list of credit offers is. It may be used only for a firm offer of credit or insurance, and a consumer can opt out of such lists by notice to the agency (15 U.S.C. 1681b(c)). Do not use a general marketing list to screen anyone for credit, insurance, employment or tenancy.

One policy for list buyers

  • Suppress every opt-out and deletion request across all channels within 15 business days, and sooner where you can.
  • Buy only from sellers that disclose source and state registration, and that warrant lawful collection in the contract.
  • Log seller, date and source for every file, and keep the log.
  • Do not resell, license or append a purchased list without checking the registry states first.
  • Do not use any list for credit, insurance, employment or tenancy decisions.
  • Publish a privacy notice with an opt-out contact, and apply it to all states.
  • Keep the phone and email rules separate: CAN-SPAM, direct mail and TCPA are not covered by privacy compliance.

Penalty exposure

Law Amount Source
California privacy law fines $2,663 per violation, $7,988 intentional or involving a known minor under 16, from 01/01/2025 CPPA
California DROP and registration $200 per day each CalPrivacy
Virginia Up to $7,500 per violation, after a 30-day cure period Va. Code 59.1-584
Indiana Up to $7,500 per violation, after 30 days' notice and a chance to cure IC 24-15-10
Connecticut Up to $5,000 per violation under CUTPA Attorney General
FCRA willful violation $100 to $1,000 per consumer, plus punitive damages and fees 15 U.S.C. 1681n

What changed in the last 24 months

  • 01/01/2025: California raised its fine caps to $2,663 and $7,988 (CPPA). Delaware's enforcement provisions began.
  • 07/01/2025: Tennessee's law took effect in full. 07/31/2025: Minnesota's law took effect.
  • 09/01/2025: Texas redesignated its data broker law as Business and Commerce Code chapter 510 (Texas).
  • 10/01/2025: Maryland's law took effect.
  • 01/01/2026: Indiana's law took effect. California residents could begin DROP requests in January 2026.
  • 01/31/2026: Minnesota's 30-day notice-and-cure period ended (Minnesota AG).
  • 08/01/2026: California brokers must process DROP deletions, at least every 45 days.

Lists with phone numbers also face the rules in telemarketing penalties. For residential counts by market, see homeowner counts.

Next step

Ask what a list contains before you compare vendors. Request counts for your target markets and check each against the policy above.

This page is a plain-English summary with sources, not legal advice. Last reviewed 10/10/2026.

Questions people ask

Q01Do I need to register as a data broker if I only buy lists?

Usually not. The registry laws target businesses that collect and sell or license personal data about people they have no direct relationship with. Using a list to market your own products is not selling it. Reselling or licensing the list onward can change that.

Q02Does the California Delete Act apply to a business outside California?

It applies to a data broker that sells data about California residents, wherever the broker sits. Location of the seller does not decide it. The registration page defines a broker by the lack of a direct relationship with the consumer.

Q03Do state privacy laws cover business contact data?

California's business-contact exemption ended 12/31/2022, so its law covers it. Virginia, Delaware and New Jersey exclude a person acting in a commercial or employment context. Check the state of the person, not the company.

Q04Is a list of property owners a consumer report?

No, if it is assembled from public records and not used to decide credit, insurance or employment eligibility. Prescreened credit lists are different. They come from a consumer reporting agency and carry firm-offer and opt-out duties.

Q05What should I ask a list seller for?

Ask for the record source, the date of collection, their state broker registration where one applies, how they process deletion requests, and a warranty that the data was lawfully collected. Put each in the contract.

Sources

  1. CalPrivacy: DROP for data brokers (08/01/2026 processing, 45 days, $200 per day)privacy.ca.gov
  2. CalPrivacy: DROP account creation, fees and annual registrationprivacy.ca.gov
  3. Vermont 9 V.S.A. 2446, data broker registrationlegislature.vermont.gov
  4. Oregon ORS 646A.593, data brokersoregonlegislature.gov
  5. Texas Bus. and Com. Code ch. 510, data brokers (Redesignated from ch. 509 effective 09/01/2025)tcss.legis.texas.gov
  6. Texas Bus. and Com. Code ch. 541, Data Privacy and Security Acttcss.legis.texas.gov
  7. California Attorney General: CCPAoag.ca.gov
  8. CPPA: 2025 increases for CCPA finescppa.ca.gov
  9. Virginia Consumer Data Protection Act, Va. Code 59.1-575 and 59.1-584law.lis.virginia.gov
  10. Connecticut Attorney General: CTDPAportal.ct.gov
  11. Colorado SB21-190leg.colorado.gov
  12. Utah SB 227 (2022), Consumer Privacy Actle.utah.gov
  13. Delaware Code Title 6, Chapter 12Ddelcode.delaware.gov
  14. Tennessee Attorney General: TIPA guidancetn.gov
  15. Minnesota Attorney General: MCDPA takes effectag.state.mn.us
  16. Minnesota Attorney General: MCDPA takes full effectag.state.mn.us
  17. Maryland SB 541 (2024), Online Data Privacy Actmgaleg.maryland.gov
  18. New Jersey P.L. 2023, c. 266pub.njleg.state.nj.us
  19. Indiana Code 24-15, Consumer Data Protectioniga.in.gov
  20. 15 U.S.C. 1681a, definitionslaw.cornell.edu
  21. 15 U.S.C. 1681b(c), prescreeninglaw.cornell.edu
  22. 15 U.S.C. 1681n, willful noncompliancelaw.cornell.edu

→Free counts

Counts for your area

Zip codes or counties, who you want to reach, and we reply with counts by channel.

Get counts