Skip to main content
Industry Insights
•9 min read

Data Broker Enforcement and Privacy Rules: 2026 Review

Source-first review of California DROP, FTC privacy orders, CFPB FCRA rule status, and what enforcement actions do and do not change for individual requests.

Rahul Kandoriya
Written byRahul Kandoriya·Last updated August 25, 2026
Data Broker Enforcement and Privacy Rules: 2026 Review
Data Broker Enforcement and Privacy Rules: 2026 Review
Coverage scope: The OfflistMe catalog currently records 1,000+data-broker workflows. Paid access lets you select workflows at once; you review and send or submit the generated requests, while provider eligibility and outcomes remain outside OfflistMe's control.

Privacy enforcement stories often become misleading when a complaint, proposed rule, settlement, and final order are described as if they were the same thing. This source-first roundup separates those evidence states and focuses on developments that have a primary government source. It is a consumer explainer, not legal advice or a complete list of every enforcement matter.

The practical lesson is simple: an enforcement action may change a company's obligations, but it does not automatically remove your information from every broker or search result. Identify the source, confirm the current request route, and keep the provider's response as evidence.

Quick Summary

  • California's Delete Request and Opt-Out Platform (DROP) is a state system for California consumers to submit a single verifiable deletion request to covered data brokers. Beginning August 1, 2026, data brokers must access the mechanism at least once every 45 days and process matching requests, subject to exceptions. California Privacy Protection Agency information for data brokers
  • The California Privacy Protection Agency (CPPA) says the registry and DROP cover active registered data brokers under the California framework. This is not a promise that every website, public-record custodian, foreign service, or search engine will be covered.
  • In January 2026, the FTC finalized an order with General Motors and OnStar over allegations concerning connected-vehicle geolocation and driving-behavior data. The order includes consent, access, deletion, and opt-out obligations with defined exceptions; it is a company-specific order, not a universal connected-car rule. FTC GM and OnStar order
  • The CFPB's proposed data-broker rule was not a final rule. The Bureau states that it withdrew the proposed “Protecting Consumer Information from Harmful Data Broker Practices” rule on May 15, 2025. Do not describe it as a current nationwide expansion of FCRA coverage. CFPB FCRA requirements
  • FTC actions against services such as Avast, GoodRx, and BetterHelp illustrate separate privacy theories and remedies. They should not be generalized into a finding that every data broker or health app follows the same practice.

How to Read an Enforcement Story

Before relying on a headline, identify the document type:

Evidence stateWhat it meansWhat it does not prove
Complaint or allegationAn agency or private party has asserted facts or legal theoriesThat the allegations were proven or that every similar company acts the same way
Proposed ruleAn agency proposed text for notice and commentThat the rule took effect or remains active
Settlement or consent orderA named respondent accepted obligations without necessarily admitting every allegationThat the same remedy applies to unrelated providers
Final judgment or decisionA court or agency issued a binding result in the matterThat all facts are identical in a new request
Registry or statutory requirementA current program or law defines duties for a covered classThat a person is eligible for every remedy or that every source is covered

The date, respondent, jurisdiction, covered data, remedy, and exceptions matter. Use the original agency page or statute rather than a secondary summary that collapses those distinctions.

Request Drafting

Tired of dealing with data exposure?

Choose relevant provider workflows, review the generated drafts in your browser, and send or submit each request yourself. Matching, eligibility, and provider requirements still need checking.

Review Removal Options Free for selected workflows · No opt-out profile stored · No card needed

California DROP and the Delete Act

California's Delete Act created a centralized route for California consumers to submit a deletion request to covered data brokers. The CPPA says California residents may use DROP to submit one request to all active data brokers in the registry. A request is still subject to verification, matching, statutory exceptions, and the limits of the participating broker's records. CPPA data-broker registry

The important dates are not interchangeable:

  • California consumers may submit requests through DROP beginning January 1, 2026.
  • Beginning August 1, 2026, covered data brokers must access the deletion mechanism at least once every 45 days and process matching requests under the Delete Act and regulations.
  • Beginning January 1, 2028, covered data brokers must undergo the independent compliance-audit process described by the CPPA, subject to the statute and implementing rules.

DROP does not delete a county deed, a court record, a social-media post, a search-engine index, or a copy held by an organization outside the covered broker framework. A California resident who sees a source outside DROP should use that source's own correction, deletion, or legal-removal process. A result can also remain visible temporarily in a search engine after the underlying source changes.

FTC Connected-Vehicle Data Order

The FTC's January 2026 final order with General Motors and OnStar is a useful example of a targeted remedy. The FTC said its complaint alleged that the companies collected, used, and sold precise geolocation and driving-behavior data without adequately informing consumers and obtaining affirmative consent. The final order includes a five-year prohibition on sharing certain data with consumer reporting agencies and longer-term requirements concerning consent, access, deletion, and opt-out controls, with exceptions such as emergency-response use.

This matter supports a narrow conclusion: regulators can impose specific obligations when they find a company's disclosures or consent practices inadequate. It does not support the claim that all vehicle manufacturers sell the same data, that every telematics record is a consumer report, or that a consumer can delete every historic copy through a general broker opt-out.

If a person is concerned about connected-vehicle data, start with the manufacturer's current privacy dashboard, vehicle-service settings, and data request route. Preserve the account, vehicle, product, and date information needed for the request. A generic data-broker template may not be the correct route.

CFPB and FCRA: Proposed Rule Versus Current Rule

In December 2024, the CFPB proposed changes intended to address data-broker practices under the Fair Credit Reporting Act. The Bureau's current compliance page says that it withdrew that proposed rule and related guidance on May 15, 2025. A withdrawn proposal is not a current final rule.

The FCRA can apply to consumer reports and consumer reporting agencies when statutory definitions and a permissible purpose fit the activity. Whether a particular data product is a consumer report is fact-specific. Do not tell readers that every people-search page is FCRA-regulated, or that every commercial broker is exempt, without analyzing the product, purpose, and applicable law. The CFPB directs readers to the FCRA and Regulation V for the governing requirements. CFPB FCRA resources

FTC Privacy Enforcement: Compare the Remedy, Not the Headline

The FTC's Avast matter involved allegations and an order concerning the sale or licensing of web-browsing data for advertising. The agency's public materials identify a $16.5 million payment and restrictions on the conduct. That remedy applies to the respondent and the conduct covered by the order; it is not a universal ban on all analytics, browsing data, or data brokers. FTC Avast matter

The FTC's GoodRx and BetterHelp matters similarly involve named companies, health-related information, advertising or disclosure practices, and specified orders or settlements. The FTC maintains separate case pages and health-privacy guidance. Use those pages for the scope and remedy instead of turning a company-specific matter into “HIPAA covers every health app” or “all health data sales are illegal.” FTC health privacy guidance

GDPR and Other Privacy Laws

The GDPR can provide rights such as access, objection, and erasure in circumstances covered by the regulation. The right to erasure includes exceptions, and a controller's duty depends on the processing, legal basis, public-interest role, and other facts. A GDPR request is not a universal instruction to erase public records, journalism, court material, or every downstream copy. Official GDPR text

U.S. state privacy laws also differ in scope, thresholds, covered businesses, verification, response windows, sensitive-data rules, and exemptions. A state law may help with a commercial profile but not with the source record. Check the current official statute, regulator guidance, and provider notice for the person's residence and the data at issue.

What an Enforcement Story Means for an Individual

Use this workflow:

  1. Name the source. Is it a data broker, vehicle manufacturer, app, public agency, employer, search engine, or another publisher?
  2. Preserve evidence. Save the listing URL, date, fields shown, account or vehicle identifier, and any provider response. Avoid collecting more personal information than necessary.
  3. Choose the matching route. Use DROP when the person and broker are eligible, the provider's privacy request when they are not, or a regulator/legal route when the facts support one.
  4. Separate remedies. A deletion request, correction request, opt-out of sale, search-result removal, credit freeze, and breach response address different layers.
  5. Re-check the source. A dashboard status or agency announcement is not proof that a specific profile disappeared. Record what changed and what remains.

OfflistMe can help users review recorded provider routes and prepare browser-local drafts for relevant commercial sources. The user chooses the route, reviews the request, completes any provider verification, submits it, and retains the evidence. A catalog workflow does not extend a law, bypass a regulator's eligibility rules, or guarantee an enforcement outcome.

Frequently Asked Questions

Does California DROP delete every data-broker profile?

It is designed for covered data brokers participating in the California framework and matching the request. It does not cover every publisher or public record, and legal exceptions and verification still apply.

Does an FTC order automatically delete my data?

Usually not. An order may require a named respondent to change practices or respond to consumer requests, but an individual still needs to use the relevant process and confirm what happened.

Is the CFPB data-broker rule active?

The CFPB says the proposed rule was withdrawn in May 2025. Treat current FCRA questions as fact-specific and use the current statute, Regulation V, and official CFPB materials.

Can I use one request for a vehicle, health app, and people-search profile?

Do not assume so. Each controller may have a different account, verification, legal basis, and request route. Submit only what the relevant provider needs.

Does an enforcement headline prove a provider violated the law?

No. Read whether the source is an allegation, proposal, settlement, order, judgment, or registry requirement. The respondent, facts, remedy, and jurisdiction control.

Sources and Review Boundary

Reviewed August 25, 2026. Enforcement status, deadlines, and agency pages can change; verify the live primary source before relying on a legal conclusion.

Related Guides

Take back your privacy today

Review provider-specific routes, prepare your requests locally, and send or submit each one yourself.

Review Provider Routes

Free to review provider routes · Optional one-time unlock from $9.00 · No subscription