Data Broker Enforcement Roundup: First Half of 2026
CalPrivacy fined two brokers for registry violations, the FTC permanently banned Kochava from selling sensitive location data, and the CFPB withdrew its.
The regulatory landscape governing commercial data brokers, people-search engines, and telematics exchanges has shifted from voluntary self-regulation to aggressive statutory enforcement.
Across North America and the European Union, state Attorneys General, the Federal Trade Commission (FTC), the Consumer Financial Protection Bureau (CFPB), and international privacy commissioners have executed historic enforcement actions against covert data collection practices.
Major enforcement targets include connected car telematics exchanges, location data aggregators, commercial health app tracking pixels, AI image scrapers, and non-compliant people-search sites.
This comprehensive 2026 H1 roundup provides an exhaustive statutory analysis of landmark data broker enforcement cases, structural updates to state privacy laws (including California's Delete Act DROP System), FTC Section 5 consent decrees, and what these enforcement actions mean for consumer privacy rights.
Tired of dealing with data exposure?
Your personal data is likely on 1009 data brokers. Use OfflistMe to generate pre-filled opt-out emails for all of them in one go.
Key Takeaways
- California Delete Act DROP system begins enforcement: California's landmark one-stop-shop deletion mechanism allows consumers to issue a single deletion demand that reaches active data brokers covered by California law.
- FTC targets connected car telematics monetization: Federal regulators cracked down on automakers selling driving telemetry (speed, hard braking, location) to LexisNexis and Verisk without explicit consent.
- CFPB expands FCRA rules to cover commercial data brokers: The Consumer Financial Protection Bureau finalized rulemaking classifying commercial data brokers selling credit header files and background data as Consumer Reporting Agencies (CRAs).
- Health app tracking pixel enforcement reaches record fines: The FTC enforced major financial penalties against commercial health and therapy platforms (GoodRx, BetterHelp) for sharing sensitive health data with ad networks.
- Biometric enforcement halts commercial AI facial scraping: State courts enforced multi-million-dollar settlements under Illinois's BIPA and Texas's CIPA, restricting commercial facial recognition scraping.
Major Regulatory & Enforcement Pillars (2026 H1)
┌─────────────────────────────────────────────────────────────────────────┐
│ 2026 H1 REGULATORY ENFORCEMENT MATRIX │
├─────────────────────────────────────────────────────────────────────────┤
│ Pillar 1: California Delete Act (SB 362 & DROP Mechanism) │
│ • Single-request deletion system for 500+ registered California brokers. │
├─────────────────────────────────────────────────────────────────────────┤
│ Pillar 2: FTC Telematics & Connected Vehicle Decrees │
│ • Enforces strict consent rules against automakers selling CAN bus logs. │
├─────────────────────────────────────────────────────────────────────────┤
│ Pillar 3: CFPB Credit Header FCRA Rulemaking │
│ • Treats commercial data brokers as Consumer Reporting Agencies. │
├─────────────────────────────────────────────────────────────────────────┤
│ Pillar 4: Health Privacy & MHMDA State Enforcement │
│ • Bans geofencing & health tracking pixel transfers without opt-in. │
└─────────────────────────────────────────────────────────────────────────┘1. California Delete Act (SB 362) & The DROP System
Passed in late 2023, California's Delete Act (SB 362) transferred data broker oversight to the California Privacy Protection Agency (CPPA).
The DROP Mechanism Implementation & August 1, 2026 Operational Deadline
In 2026, the CPPA launched the Data Broker Request and Opt-Out Platform (DROP):
- One-Stop Deletion: California residents log into a single state portal to submit a single deletion demand.
- Mandatory Compliance & August 1, 2026 Deadline: While consumer submissions began January 1, 2026, August 1, 2026 marks the mandatory legal deadline for registered data brokers to begin accessing DROP at least once every 45 days and processing matching deletion requests within required timelines.
- CPPA Enforcement Sweep Fines: The CPPA's Data Broker Enforcement Strike Force issued landmark fines against non-compliant brokers, including Datamasters (Rickenbacher Data LLC) ($45,000 fine + market ban from selling CA consumer data) and S&P Global ($62,600 fine for administrative registration delays).
- Audit Mandate: Data brokers must undergo independent compliance audits every 3 years to verify deletion enforcement.
- Fines for Non-Compliance: Brokers that fail to process deletion requests face statutory fines of $200 per deletion request per day.
2. FTC Connected Vehicle & Telematics Decrees
Following investigative reporting and class-action litigation (*In re General Motors OnStar Telematics Litigation*), federal regulators turned their focus to automotive surveillance.
Enforcement Action Highlights:
- General Motors OnStar Telematics Settlement: The FTC investigated GM for automatically enrolling drivers into OnStar SmartDriver during dealership purchases. GM subsequently terminated its data-sharing contracts with LexisNexis Risk Solutions and Verisk Telematics Exchange.
- FTC Section 5 Precedent: The FTC established that harvesting sensor telemetry (speed, G-force deceleration, GPS timestamps) under vague "service improvement" clauses and selling it to insurance underwriters constitutes an unfair and deceptive practice under Section 5 of the FTC Act.
3. CFPB Rulemaking on Credit Header Brokers
Under Director Rohit Chopra, the Consumer Financial Protection Bureau (CFPB) executed a landmark rule change closing the Credit Header Loophole:
Closing the FCRA Exemption
- For decades, credit bureaus and data aggregators (Equifax, Experian, TransUnion, LexisNexis) argued that the top portion of credit files ("Credit Headers"—name, address, DOB, phone number) was exempt from FCRA restrictions.
- The CFPB finalized rules clarifying that credit header data IS part of a consumer report.
- Impact: Commercial data brokers can no longer purchase bulk credit header feeds to populate public people-search engines without verifying a valid FCRA permissible purpose.
4. Digital Health Privacy & State MHMDA Enforcement
Following the FTC's landmark consent orders against GoodRx ($1.5M penalty) and BetterHelp ($7.8M settlement), state legislatures enacted targeted health privacy protections.
Washington My Health My Data Act (MHMDA) & Nevada SB370
- Enforced throughout 2025 and 2026, Washington's MHMDA established the nation's strictest non-HIPAA health data law.
- Geofencing Bans: Prohibits placing virtual geofences within 2,000 feet of healthcare facilities (hospitals, family planning centers, addiction clinics) to collect or target patient location data.
- Private Right of Action: Allows consumers to sue health apps, tracking pixel operators, and data brokers directly for unauthorized health data commercialization.
5. FTC Enforcement: Avast, Location Brokers (Kochava, Outlogic) & InMarket
In 2026, federal regulators under Section 5 of the FTC Act (15 U.S.C. § 45) established landmark enforcement baselines prohibiting the un-consented sale of sensitive consumer browsing and location records:
Landmark FTC Consent Orders & Civil Litigation
- FTC v. Avast Limited (FTC Docket No. C-4802): The FTC issued a $16.5 million monetary redress order alongside a permanent ban prohibiting Avast from selling, licensing, or commercializing web browsing clickstream logs to third parties for advertising. Despite marketing its software as an anti-tracking privacy tool, Avast harvested granular browsing histories across millions of users via its Jumpshot subsidiary.
- FTC v. InMarket Media LLC (FTC File No. 202 3088): The FTC prohibited InMarket from selling or licensing precise consumer location data harvested via app SDKs without affirmative express opt-in consent, requiring full deletion of historical location datasets collected without verified permission.
- FTC v. Outlogic (formerly X-Mode Social): The FTC banned Outlogic from commercializing raw mobile location feeds that track individuals to sensitive locations (healthcare clinics, places of worship, domestic violence shelters) and mandated automated sensitive location geofence suppression.
- FTC v. Kochava Action: Federal courts upheld the FTC's position that selling raw, device-level location tracking feeds paired with Mobile Advertising IDs (MAIDs) constitutes an inherent Section 5 violation due to stalking, harassment, and discrimination risks.
6. Biometric AI Scraping & State AG Lawsuits (BIPA, CIPA, & Texas TDPSA)
Biometric identification networks and AI image scrapers faced intense enforcement scrutiny in 2026 H1 from state Attorneys General and private litigants:
Biometric Enforcement Breakthroughs
- Texas Attorney General Settlement (CIPA Enforcement): Texas AG regulators reached multi-million dollar enforcement resolutions under the Texas Capture or Use of Biometric Identifier Act (CIPA) against major tech entities that extracted biometric facial geometry vectors from public photos without explicit consent.
- Clearview AI Injunctions & Global Regulatory Fines: European DPAs (including Italy's Garante and France's CNIL) and US state courts enforced strict bans preventing Clearview AI and similar image-scraping platforms from indexing photos of residents or licensing biometric search databases to non-law-enforcement entities.
- Illinois BIPA Class Actions: Courts reaffirmed that every unauthorized biometric scan (including face-vector extraction by AI background check platforms) constitutes a distinct statutory claim, forcing data brokers to implement rigorous identity verification before indexing facial features.
Comparative Matrix: Key Privacy Statutes Active in 2026
| Statute / Law | Jurisdiction | Key Enforcement Mechanism | Private Right of Action? |
|---|---|---|---|
| California Delete Act (SB 362) | California | CPPA centralized DROP platform; 45-day deletion cycles | No (Enforced by CPPA) |
| Illinois BIPA (740 ILCS 14/) | Illinois | Mandatory consent for face/fingerprint vectors | YES ($1,000–$5,000 per violation) |
| Washington MHMDA | Washington | Strict opt-in for non-HIPAA health data; geofencing ban | YES |
| Texas TDPSA & CIPA | Texas | Texas AG enforcement against biometric scraping | No (Enforced by AG) |
| EU GDPR (Articles 9 & 17) | European Union | Data Protection Authority fines up to 4% of global turnover | YES (via DPA & court claims) |
What These Enforcement Actions Mean for Consumers
- Opt-Out Requests Carry Enforceable Legal Teeth: Data brokers can no longer ignore deletion demands without risking statutory daily fines from regulatory bodies like the CPPA.
- Telematics Tracking Is Becoming Opt-In: Automakers are restructuring mobile apps to require explicit, separate opt-in checkboxes before sharing driving scores with insurance underwriters.
- People-Search Sites Face Ingestion Bottlenecks: CFPB restrictions on credit header bulk sales are reducing the speed at which people-search sites re-list deleted profiles.
- Sensitive Location Data Is Protected by Default: FTC location decrees mean data brokers are legally prohibited from selling sensitive movement patterns harvested from mobile ad IDs.
Summary Action Steps for Consumers
- [ ] If you are a California resident, utilize the CPPA DROP System to issue a single multi-broker deletion demand.
- [ ] Submit LexisNexis and Verisk disclosure requests to inspect your telematics files.
- [ ] Opt out of prescreened offers and credit header marketing at OptOutPrescreen.com.
- [ ] Review mobile app permissions to revoke tracking pixel permissions in health and therapy apps.
- [ ] Periodically check your presence on people-search sites to maintain digital privacy.
Frequently Asked Questions
What is the California Delete Act (SB 362) DROP platform?
The Delete Request and Opt-Out Platform (DROP) is a centralized system created under California SB 362 and operated by the California Privacy Protection Agency (CPPA). It allows California residents to submit a single request to active data brokers covered by California law.
What penalties do data brokers face for failing to comply with deletion requests?
Under the California Delete Act, data brokers failing to comply with deletion requests face statutory fines of $200 per day per unhonored request, alongside mandatory 3-year independent compliance audits.
Related Enforcement & Industry Insights Guides
- How to Remove Your Data from Data Brokers (Pillar Guide): Comprehensive step-by-step framework for deleting your personal data from commercial data brokers.
- California Delete Act Guide: Complete regulatory guide to the CPPA DROP system and California deletion rights.
- Privacy Enforcement Tracker: Live tracker of FTC, CPPA, and state AG enforcement fines against data brokers.
- How Data Broker Compliance is Measured: Audit framework for data broker opt-out compliance.
- US Privacy Laws Comparison: Comprehensive statutory comparison of state privacy laws.
- Explore more market analyses in the Blog Index or use the OfflistMe Opt-Out Directory.
Related Guides
- What is a Data Broker? (Complete Guide): Comprehensive foundational guide on data broker networks and legal opt-out mechanisms.
- OfflistMe Data Removal Plans & Pricing: Learn how OfflistMe generates instant privacy opt-out requests across major data brokers.
Regulatory Landscape: State vs. Federal Privacy Enforcement in 2026
H1 2026 marked a significant shift in the enforcement dynamic between state-level regulators and federal authorities. Understanding the landscape helps consumers know which enforcement pathway is most effective for their situation.
The Federal Enforcement Gap
The United States continues to lack a comprehensive federal consumer data privacy law in 2026. The proposed American Privacy Rights Act (APRA) passed the House Energy and Commerce Committee in 2024 but has not advanced to a full Senate vote as of H1 2026. In the absence of federal legislation:
- The FTC acts under its existing authority (Section 5 of the FTC Act — unfair or deceptive practices) to pursue data broker enforcement actions
- The FCC enforces telemarketing and text message marketing regulations (TCPA) when data broker phone lists are used for unsolicited communications
- The CFPB has signaled interest in expanding enforcement against data brokers using "sensitive financial data" (credit scores and credit header data)
State Enforcement Taking the Lead
| State | Regulator | Active 2026 Enforcement Focus |
|---|---|---|
| California | CPPA | SB 362 DROP non-compliance, data broker registration failures, CCPA opt-out dark patterns |
| Texas | State AG | Data broker failures under TDPSA; telemarketing list violations |
| Connecticut | AG + CTDPA | AI-powered profiling without consent; biometric data collection |
| Colorado | AG + CPA | High-risk AI system transparency under Colorado AI Act (SB 205) |
| Virginia | AG + VCDPA | Sensitive data handling (health, location, financial) opt-out enforcement |
| Illinois | AG + Courts | BIPA class action litigation against facial recognition systems |
Notable H1 2026 Enforcement Actions: Full Case Summaries
CPPA Enforcement Wave: California DROP Non-Compliance (January–June 2026)
The California Privacy Protection Agency issued its first round of formal notices to data brokers that failed to connect their systems to the California DELETE Act's one-stop deletion portal (DROP) by the August 1, 2026 technical integration deadline. Notices were served in Q2 2026.
Scale of enforcement: The CPPA estimated 347 registered data brokers remained non-compliant with DROP technical integration as of June 2026. Fines of $200/day per unprocessed consumer deletion request began accruing August 1, 2026.
Consumer impact: California residents who submitted DROP deletion requests may find that non-compliant brokers have not processed their requests. Check CPPA's public enforcement register and file individual complaints if your DROP request remains unfulfilled.
FTC Impersonation Rule Expansion (February 2026)
The FTC's expanded impersonation rule took effect February 2026, explicitly covering:
- AI-generated voice clones used to impersonate government agencies or businesses
- Data broker-supplied targeting data used to personalize government impersonation scams
The expanded rule enables the FTC to seek civil penalties against data brokers whose data was knowingly supplied to operators running impersonation scams — not just the scam operators themselves. This is a significant expansion of supply-chain liability for data brokers.
CFPB Proposed Rule: Data Broker FCRA Coverage (January 2026)
The Consumer Financial Protection Bureau issued a proposed rule in January 2026 that would classify certain data brokers as "consumer reporting agencies" (CRAs) subject to the full requirements of the Fair Credit Reporting Act. Under this rule:
- Data brokers selling personal information for employment, credit, housing, or insurance decisions would be required to follow FCRA's accuracy, dispute, and permissible purpose requirements
- Consumers would gain the right to dispute inaccurate information held by these brokers
- Data brokers would need to register with the CFPB as CRAs
The rule remains in comment period as of H1 2026 but, if finalized, would represent the most significant federal data broker regulation since FCRA itself.
How Enforcement Actions Affect Consumers: Practical Guidance
If Your Data Was Involved in an Enforced Breach
If a data broker subject to FTC or state AG enforcement was holding your personal information, you may be entitled to:
- Notification: CCPA and GDPR require breach notification within specific timeframes (72 hours for GDPR-regulated entities)
- FTC Redress: In settlements where the FTC establishes a consumer redress fund (as in the Kochava settlement), affected consumers may file claims at the FTC's Redress Portal
- Class action participation: Many data broker enforcement actions generate parallel class action lawsuits where class members (affected consumers) can file claims
How to File a Data Broker Complaint That Regulators Prioritize
Regulators receive thousands of complaints and must triage them. To maximize the chance of your complaint advancing:
- Cite specific statutes: "This company violated CCPA § 1798.135 by failing to provide a conspicuous opt-out link" carries more weight than "this company is sharing my data."
- Attach evidence: Screenshots, timestamps, and URL captures of your opt-out attempt and failure
- Reference prior enforcement actions: If the broker was previously warned or fined, cite that in your complaint — it establishes a pattern
- File with multiple agencies simultaneously: FTC + state AG + CPPA (for California residents) simultaneously increases enforcement probability
See our comprehensive guide on Data Broker Dark Patterns: How Opt-Out Hiding Works for documentation strategies you can use to support regulatory complaints.
Understand your privacy rights
Every removal request cites a specific statute. These plain-English explainers show what each law covers and how enforcement actually works.
Related Data Broker Removal Guides
Take back your privacy today
Remove your personal information from data brokers and platforms in seconds.
Remove Your Personal Data Now100% Free for top brokers · One-time unlock from $9.00 · No subscription
