Data Broker Enforcement and Privacy Rules: 2026 Review
Source-first review of California DROP, FTC privacy orders, CFPB FCRA rule status, and what enforcement actions do and do not change for individual requests.
Privacy enforcement stories often become misleading when a complaint, proposed rule, settlement, and final order are described as if they were the same thing. This source-first roundup separates those evidence states and focuses on developments that have a primary government source. It is a consumer explainer, not legal advice or a complete list of every enforcement matter.
The practical lesson is simple: an enforcement action may change a company's obligations, but it does not automatically remove your information from every broker or search result. Identify the source, confirm the current request route, and keep the provider's response as evidence.
Quick Summary
- California's Delete Request and Opt-Out Platform (DROP) is a state system for California consumers to submit a single verifiable deletion request to covered data brokers. Beginning August 1, 2026, data brokers must access the mechanism at least once every 45 days and process matching requests, subject to exceptions. California Privacy Protection Agency information for data brokers
- The California Privacy Protection Agency (CPPA) says the registry and DROP cover active registered data brokers under the California framework. This is not a promise that every website, public-record custodian, foreign service, or search engine will be covered.
- In January 2026, the FTC finalized an order with General Motors and OnStar over allegations concerning connected-vehicle geolocation and driving-behavior data. The order includes consent, access, deletion, and opt-out obligations with defined exceptions; it is a company-specific order, not a universal connected-car rule. FTC GM and OnStar order
- The CFPB's proposed data-broker rule was not a final rule. The Bureau states that it withdrew the proposed “Protecting Consumer Information from Harmful Data Broker Practices” rule on May 15, 2025. Do not describe it as a current nationwide expansion of FCRA coverage. CFPB FCRA requirements
- FTC actions against services such as Avast, GoodRx, and BetterHelp illustrate separate privacy theories and remedies. They should not be generalized into a finding that every data broker or health app follows the same practice.
How to Read an Enforcement Story
Before relying on a headline, identify the document type:
| Evidence state | What it means | What it does not prove |
|---|---|---|
| Complaint or allegation | An agency or private party has asserted facts or legal theories | That the allegations were proven or that every similar company acts the same way |
| Proposed rule | An agency proposed text for notice and comment | That the rule took effect or remains active |
| Settlement or consent order | A named respondent accepted obligations without necessarily admitting every allegation | That the same remedy applies to unrelated providers |
| Final judgment or decision | A court or agency issued a binding result in the matter | That all facts are identical in a new request |
| Registry or statutory requirement | A current program or law defines duties for a covered class | That a person is eligible for every remedy or that every source is covered |
The date, respondent, jurisdiction, covered data, remedy, and exceptions matter. Use the original agency page or statute rather than a secondary summary that collapses those distinctions.
Tired of dealing with data exposure?
Choose relevant provider workflows, review the generated drafts in your browser, and send or submit each request yourself. Matching, eligibility, and provider requirements still need checking.
California DROP and the Delete Act
California's Delete Act created a centralized route for California consumers to submit a deletion request to covered data brokers. The CPPA says California residents may use DROP to submit one request to all active data brokers in the registry. A request is still subject to verification, matching, statutory exceptions, and the limits of the participating broker's records. CPPA data-broker registry
The important dates are not interchangeable:
- California consumers may submit requests through DROP beginning January 1, 2026.
- Beginning August 1, 2026, covered data brokers must access the deletion mechanism at least once every 45 days and process matching requests under the Delete Act and regulations.
- Beginning January 1, 2028, covered data brokers must undergo the independent compliance-audit process described by the CPPA, subject to the statute and implementing rules.
DROP does not delete a county deed, a court record, a social-media post, a search-engine index, or a copy held by an organization outside the covered broker framework. A California resident who sees a source outside DROP should use that source's own correction, deletion, or legal-removal process. A result can also remain visible temporarily in a search engine after the underlying source changes.
FTC Connected-Vehicle Data Order
The FTC's January 2026 final order with General Motors and OnStar is a useful example of a targeted remedy. The FTC said its complaint alleged that the companies collected, used, and sold precise geolocation and driving-behavior data without adequately informing consumers and obtaining affirmative consent. The final order includes a five-year prohibition on sharing certain data with consumer reporting agencies and longer-term requirements concerning consent, access, deletion, and opt-out controls, with exceptions such as emergency-response use.
This matter supports a narrow conclusion: regulators can impose specific obligations when they find a company's disclosures or consent practices inadequate. It does not support the claim that all vehicle manufacturers sell the same data, that every telematics record is a consumer report, or that a consumer can delete every historic copy through a general broker opt-out.
If a person is concerned about connected-vehicle data, start with the manufacturer's current privacy dashboard, vehicle-service settings, and data request route. Preserve the account, vehicle, product, and date information needed for the request. A generic data-broker template may not be the correct route.
CFPB and FCRA: Proposed Rule Versus Current Rule
In December 2024, the CFPB proposed changes intended to address data-broker practices under the Fair Credit Reporting Act. The Bureau's current compliance page says that it withdrew that proposed rule and related guidance on May 15, 2025. A withdrawn proposal is not a current final rule.
The FCRA can apply to consumer reports and consumer reporting agencies when statutory definitions and a permissible purpose fit the activity. Whether a particular data product is a consumer report is fact-specific. Do not tell readers that every people-search page is FCRA-regulated, or that every commercial broker is exempt, without analyzing the product, purpose, and applicable law. The CFPB directs readers to the FCRA and Regulation V for the governing requirements. CFPB FCRA resources
FTC Privacy Enforcement: Compare the Remedy, Not the Headline
The FTC's Avast matter involved allegations and an order concerning the sale or licensing of web-browsing data for advertising. The agency's public materials identify a $16.5 million payment and restrictions on the conduct. That remedy applies to the respondent and the conduct covered by the order; it is not a universal ban on all analytics, browsing data, or data brokers. FTC Avast matter
The FTC's GoodRx and BetterHelp matters similarly involve named companies, health-related information, advertising or disclosure practices, and specified orders or settlements. The FTC maintains separate case pages and health-privacy guidance. Use those pages for the scope and remedy instead of turning a company-specific matter into “HIPAA covers every health app” or “all health data sales are illegal.” FTC health privacy guidance
GDPR and Other Privacy Laws
The GDPR can provide rights such as access, objection, and erasure in circumstances covered by the regulation. The right to erasure includes exceptions, and a controller's duty depends on the processing, legal basis, public-interest role, and other facts. A GDPR request is not a universal instruction to erase public records, journalism, court material, or every downstream copy. Official GDPR text
U.S. state privacy laws also differ in scope, thresholds, covered businesses, verification, response windows, sensitive-data rules, and exemptions. A state law may help with a commercial profile but not with the source record. Check the current official statute, regulator guidance, and provider notice for the person's residence and the data at issue.
What an Enforcement Story Means for an Individual
Use this workflow:
- Name the source. Is it a data broker, vehicle manufacturer, app, public agency, employer, search engine, or another publisher?
- Preserve evidence. Save the listing URL, date, fields shown, account or vehicle identifier, and any provider response. Avoid collecting more personal information than necessary.
- Choose the matching route. Use DROP when the person and broker are eligible, the provider's privacy request when they are not, or a regulator/legal route when the facts support one.
- Separate remedies. A deletion request, correction request, opt-out of sale, search-result removal, credit freeze, and breach response address different layers.
- Re-check the source. A dashboard status or agency announcement is not proof that a specific profile disappeared. Record what changed and what remains.
OfflistMe can help users review recorded provider routes and prepare browser-local drafts for relevant commercial sources. The user chooses the route, reviews the request, completes any provider verification, submits it, and retains the evidence. A catalog workflow does not extend a law, bypass a regulator's eligibility rules, or guarantee an enforcement outcome.
Frequently Asked Questions
Does California DROP delete every data-broker profile?
It is designed for covered data brokers participating in the California framework and matching the request. It does not cover every publisher or public record, and legal exceptions and verification still apply.
Does an FTC order automatically delete my data?
Usually not. An order may require a named respondent to change practices or respond to consumer requests, but an individual still needs to use the relevant process and confirm what happened.
Is the CFPB data-broker rule active?
The CFPB says the proposed rule was withdrawn in May 2025. Treat current FCRA questions as fact-specific and use the current statute, Regulation V, and official CFPB materials.
Can I use one request for a vehicle, health app, and people-search profile?
Do not assume so. Each controller may have a different account, verification, legal basis, and request route. Submit only what the relevant provider needs.
Does an enforcement headline prove a provider violated the law?
No. Read whether the source is an allegation, proposal, settlement, order, judgment, or registry requirement. The respondent, facts, remedy, and jurisdiction control.
Sources and Review Boundary
- CPPA data-broker information and DROP obligations
- CPPA data-broker registry
- FTC GM and OnStar order
- CFPB current FCRA requirements
- FTC Avast order
- FTC health-privacy guidance
- CalPrivacy January 2026 data-broker enforcement announcement
- CalPrivacy Background Alert settlement
- FTC v. Kochava case record
- FTC GoodRx case record
- FTC BetterHelp case record
- Congressional Joint Economic Committee data-broker report
- Official GDPR text
Reviewed August 25, 2026. Enforcement status, deadlines, and agency pages can change; verify the live primary source before relying on a legal conclusion.
Related Guides
Understand your privacy rights
Where a privacy right is relevant, these plain-English explainers show what each law covers and what to verify before making a request.
Related Data Broker Removal Guides
Take back your privacy today
Review provider-specific routes, prepare your requests locally, and send or submit each one yourself.
Review Provider RoutesFree to review provider routes · Optional one-time unlock from $9.00 · No subscription
