California Data Broker Rules Tighten: Miller, Sperling and Montoya Publish Bloomberg Law Guidance on SB-361 Compliance

Article
|
|
Bloomberg Law

Glaser Weil litigation partners Sarah G. Miller and Elizabeth Sperling, together with litigation associate Joseph N. Montoya, have published a timely new article, “California Data Brokers Must Build a New Compliance Playbook,” for Bloomberg Law examining California's rapidly expanding regulation of data brokers and the significant compliance obligations businesses will soon face under SB-361.

As part of California's evolving privacy framework, SB-361 expands the state's Delete Act and will require registered data brokers to regularly monitor the California Privacy Protection Agency's Data Broker Requests and Opt-Out Platform (DROP) for consumer deletion requests. With new compliance requirements taking effect August 1, 2026, and daily penalties for violations, companies that collect, buy, sell or share Californians' personal information should carefully evaluate whether they qualify as data brokers and establish robust compliance procedures now.

Miller, Sperling and Montoya explore several key issues businesses must consider, including:

  • Who qualifies as a data broker under California law, including businesses that may not realize they fall within the statute's broad definition
  • How personal information is defined and why companies outside California may still be subject to enforcement actions
  • The distinction between direct and indirect consumer relationships, and why businesses using third-party tracking technologies may face heightened scrutiny
  • New registration and reporting requirements that require detailed disclosures to the California Privacy Protection Agency
  • The upcoming DROP monitoring requirement, which will require data brokers to review deletion requests at least every 45 days and promptly delete covered information
  • The substantial penalties for noncompliance, including daily fines tied to registration failures and unmet deletion requests
  • Practical compliance strategies for assessing data practices, updating vendor-management procedures and maintaining records of consumer deletion requests

Read the article to learn how businesses can determine whether they are data brokers, prepare for California's new deletion-request requirements and reduce regulatory risk as enforcement by the California Privacy Protection Agency intensifies.

Related Attorneys

  • Sarah G. Miller (Hartman)
    Partner
  • Joseph N. Montoya
    Associate
  • Elizabeth Sperling
    Partner and Co-chair of the Banking and Financial Services Practice

Related Practices

Jump to Page

Glaser Weil Cookie Preference Center Cookie Preference Center

Your Privacy

When you visit our website, we use cookies on your browser to collect information. The information collected might relate to you, your preferences, or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. For more information about how we use Cookies, please see our Privacy Policy.

Strictly Necessary Cookies

Always Active

Necessary cookies enable core functionality such as security, network management, and accessibility. These cookies may only be disabled by changing your browser settings, but this may affect how the website functions.

Functional Cookies

Always Active

Some functions of the site require remembering user choices, for example your cookie preference, or keyword search highlighting. These do not store any personal information.

Form Submissions

Always Active

When submitting your data, for example on a contact form or event registration, a cookie might be used to monitor the state of your submission across pages.

Performance Cookies

Performance cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.

Powered by Firmseek