技术

加州强制500家数据经纪商按请求删除用户数据

Adrian Kessler

The 215,000 California residents who had already filed deletion requests through the state’s DROP platform got something new on August 1: the companies sitting on their data are now legally required to act. Starting that date, every registered data broker in California must retrieve pending deletion requests and process them — the first time any U.S. state has centralized that demand across an entire industry simultaneously.

The platform works as a clearinghouse between consumers and a world most people never see. Residents visit drop.privacy.ca.gov, verify their identity through California’s state gateway or login.gov, and provide their name, email address, phone number, and ZIP code. Optionally, they can include their mobile advertising ID — the persistent identifier tied to their phone — and their vehicle identification number. One submission routes a deletion demand to every registered broker at the same time. Previously, consumers had to contact each company individually; some brokers had obscured their opt-out forms from search engines, making the process deliberately difficult.

The companies covered by the law are not household names. Data brokers are the businesses that aggregate purchase histories, build demographic and psychographic profiles for advertisers, and sell location patterns derived from mobile phones, smart TVs, and connected vehicles. Companies like Acxiom, LexisNexis, Spokeo, and BeenVerified operate in this space. So do adtech platforms and audience-segment sellers that most consumers have never heard of — but which likely hold detailed records on them anyway.

The penalty structure is meant to create real cost for non-compliance: $200 for each ignored deletion request, per day, until the broker acts. That number can compound quickly for a company receiving hundreds of requests. California’s privacy enforcement agency has already levied fines for basic registration failures — $42,000 against Datamasters, $62,000 against S&P Global — and expects to ramp up enforcement of the deletion mandate. The fines apply only to registered brokers, though: any company operating without registering never appears in the DROP system at all and faces no automatic deletion obligation under the current framework.

The compliance timeline is slower than consumers might expect. Brokers must access the DROP system at least once every 45 days to retrieve new requests, then have another 45 days to process each one — meaning a deletion request submitted today could take up to three months to complete. Data that re-enters a broker’s database after deletion, purchased from a third party, must also be deleted under suppression rules. HIPAA-covered healthcare entities, GLBA-regulated financial institutions, and companies governed by the Fair Credit Reporting Act are all exempt, carving out portions of the data ecosystem that affect medical histories and credit files.

California’s law is the first centralized deletion mechanism of its kind in the United States. Similar state-level legislation is pending in more than a dozen other states. The next milestone for California itself arrives in 2028, when the law requires registered data brokers to undergo independent privacy audits — with results due to the state’s privacy agency in 2029.

标签: , , , , ,

讨论

有 0 条评论。