Marketing Measurement ·

What California's data privacy law means for your marketing data

California's data privacy law keeps changing what marketers can access. Here's what the Delete Act and DROP actually mean for your audience data and measurement.

Listen
0:00 / 0:00
AI-generated audio
What California's data privacy law means for your marketing data

For years, you could walk next door and borrow whatever you needed from your neighbor's shed—a ladder, a drill, a stack of folding chairs for a backyard party—without a second thought. No one thought much of it. You just walked over, grabbed what you needed, and brought it back when you were done.

Then one day, the shed has a padlock on it. Your neighbor got tired of not knowing where their stuff ended up, so now anyone who wants to borrow something has to ask first, in writing, every single time. A few neighbors decided they're done lending altogether.

That's more or less what's happened to a lot of the data marketers have leaned on for years. Third-party lists, broker-sourced audiences, and enrichment data pulled from sources you never had a direct relationship with all worked the same way that shed did: easy access, few questions asked. California's privacy laws changed that, and they keep changing it further every year. The marketers who don't know what's actually in their toolshed, where it came from, and who's allowed to touch it, are the ones who'll get caught flat-footed when a vendor loses access to a data source or a campaign stops performing the way it used to.

This isn't really about becoming a compliance expert. It's about knowing which parts of your marketing stack are built on borrowed data so you're not blindsided when the borrowing gets harder.

Key takeaways

  • California's privacy framework, the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and the Delete Act, gives residents real control over their personal information, including the right to know, delete, correct, and limit how it's used.
  • The Delete Act's Delete Request and Opt-Out Platform (DROP) lets any California resident submit one request that reaches hundreds of registered data brokers at once, and brokers have to start acting on those requests as of August 1, 2026.
  • Not every vendor in your marketing stack counts as a data broker under California law, but plenty of audience, enrichment, and list-based vendors do, and it's worth asking each one directly.
  • Opting out of "sale" and opting out of "share" are two different consumer rights that hit different parts of your marketing stack, so treating them as interchangeable can leave gaps in your compliance.
  • Only businesses that cross certain revenue or data volume thresholds are directly covered by CCPA and CPRA, but many of the vendors you buy audience data from likely are, whether or not your own business is.
  • As broker-sourced lists and pixel-based signals keep shrinking, marketing measurement that depends on tracking individuals is going to get less reliable, regardless of what happens with any single law.

California's privacy law framework, in plain terms

California data privacy law didn't arrive all at once. The state's framework started with the California Consumer Privacy Act (CCPA) in 2018, giving California residents baseline rights over their personal information. California voters then expanded those rights significantly in 2020 by approving the California Privacy Rights Act (CPRA), which added new protections, created a dedicated enforcement agency, and introduced the right to opt out of "sharing" personal information for advertising purposes, separate from opting out of a sale. The Delete Act followed a few years later, tackling a problem neither of the earlier laws fully solved: what happens to your personal information once it's already been sold to dozens of companies you've never heard of.

Two bodies enforce California data privacy law today:

  • The California Privacy Protection Agency, sometimes shortened to CalPrivacy, handles rulemaking and most day-to-day enforcement.
  • The California attorney general retains authority over certain violations as well, particularly ones involving minors' personal information.

Together, the agency and the attorney general have been active: CalPrivacy has already issued fines against data brokers that failed to register, and enforcement sweeps have picked up as more of the Delete Act's deadlines have arrived.

Who actually has to comply

Not every business that touches California residents' personal information falls under CCPA and CPRA. Covered businesses are businesses that meet at least one of three thresholds:

  • It has more than $25 million in annual gross revenue.
  • It buys, sells, or shares the personal information of 100,000 or more California consumers or households in a year.
  • It gets 50% or more of its annual revenue from selling or sharing consumers' personal information.

Smaller marketing teams sometimes assume these thresholds mean the law doesn't touch them at all, but that reasoning misses the more important question: are the vendors you work with covered businesses? A martech platform, list broker, or enrichment tool can clear that 100,000-household threshold in a single dataset of California residents, which means the compliance burden lands on them even if your own business's annual gross revenue never comes close to those numbers. Their business purpose, collecting and reselling data at scale, is exactly the kind of business purpose these thresholds were written to catch.

Covered businesses also have obligations that go beyond just honoring individual requests. CPRA regulations require larger covered businesses to conduct risk assessments before engaging in higher-risk data collection, like selling sensitive personal information or using automated decision-making technology to evaluate consumers. If a vendor in your stack uses automated decision-making to score leads or build lookalike models, that's a category regulators are paying closer attention to.

Businesses can share consumer data with a service provider, like a marketing platform processing data on their behalf, without that counting as a sale, as long as the service provider only uses the personal information for the business purpose specified in the contract. That's different from handing data to a data broker or another business that can use it however it wants. Ask your vendors which category they actually fall into.

What counts as personal information

California defines personal information broadly, so you should double check the scope before you assume your marketing data is exempt. The law's definition covers a wide range of categories businesses collect, including:

  • Direct identifiers, like a name, postal address, or other unique personal identifier.
  • Online and device identifiers, including an internet protocol address, browsing history, and other electronic network activity information.
  • Financial and commercial information, such as account numbers from financial institutions and purchase or transaction history, covered separately under California's Customer Records law.
  • Sensitive personal information, a narrower category that includes a Social Security or driver's license number, precise geolocation, biometric data, health insurance information and other health-related data, and details about race, religion, sexual orientation, or citizenship status.

If your business touches student records, health plans, or protected medical information, keep in mind those categories can also trigger separate laws layered on top of general privacy rules, including sector-specific ones like California's Confidentiality of Medical Information Act. For most marketers, though, the personal information that matters most day to day is the online identifiers and behavioral data that power retargeting, lookalike audiences, and list-based prospecting, not a driver's license number or a health record.

Consumer rights under California privacy law

Every California resident whose personal information your business (or your vendors') collects has a set of consumer rights that didn't exist a decade ago. Understanding these consumer rights matters for two reasons: your own prospects and customers can exercise them against you, and the vendors supplying your audience data have to honor them too, which is exactly what shrinks the pool of California residents' data you have access to.

  • Right to know and access: California residents can request the categories and specific pieces of personal information a business has collected about them.
  • Right to delete: Consumers can submit deletion requests, requiring a business to erase the personal information it holds, subject to some exceptions.
  • Right to correct: Consumers can ask a business to fix inaccurate personal information on file.
  • Right to opt out: Consumers can tell a business to stop selling or sharing their personal information going forward, and businesses have to make it easy to opt out through a clear link or a recognized browser signal.
  • Right to limit sensitive data use: Consumers can restrict how a business uses sensitive personal information, like precise location or biometric data.
  • Right to data portability: Consumers can request their personal information in a format they can take elsewhere.
  • Right to opt-in consent for minors: Businesses need affirmative opt-in consent before selling or sharing the personal information of a consumer under 16.
  • Private right of action: If a business fails to implement reasonable security procedures and that failure leads to a data breach, affected California residents can sue directly and recover actual damages or statutory damages, without needing to prove a specific financial loss.

This private right of action is narrower than people sometimes assume. It only applies to certain data breaches involving nonencrypted and nonredacted personal information, not every privacy complaint. For most other violations, enforcement runs through the California Privacy Protection Agency or the California attorney general instead of a lawsuit filed by an individual consumer.

The Delete Act and DROP, explained

The Delete Act (Senate Bill 362) built the piece that CCPA and CPRA didn't quite solve: a single, centralized way for consumers to reach every registered data broker at once instead of contacting each one individually. That tool, DROP, opened to consumers on January 1, 2026. Data brokers, defined under California law as businesses that knowingly collect and sell the personal information of consumers they don't have a direct relationship with, have had to register annually with CalPrivacy since 2024, paying a $6,000 registration fee.

Registration alone wasn't the real obligation, though. Starting August 1, 2026, registered data brokers have to log into DROP at least once every 45 days, download the current list of consumer requests, match those consumer requests against their own records, and delete anything that matches within 90 days. They also have to report their results back to CalPrivacy. Brokers that skip registration altogether face steep penalties: a recent amendment doubled the daily fine for failing to register to $200 per consumer, per day, which adds up fast even for a broker sitting on a modest list.

DROP applies specifically to businesses that sell personal information to third parties they don't have a relationship with, so it doesn't touch a business that only uses first-party data it collected directly. But if any part of your funnel depends on a vendor that does sell personal information downstream, that vendor's obligations under DROP become your problem the moment their supply shrinks.

One common misconception is the assumption that once the 45-day processing window closes, a broker is free to go collect that same person's data again from scratch. That's not how it works. Once a match is deleted, brokers aren't permitted to recollect and re-add that person's information (full stop) without their explicit permission.

What this actually means for your marketing data

So how is that going to affect you, the marketer? While every brand is a little different because companies use third-party data differently, there are several possible effects to brace for:

Your broker-sourced audiences are going to keep shrinking

If your team buys prospecting lists, uses lookalike modeling built on third-party data, or works with an enrichment vendor to fill in gaps in your CRM, some of that supply chain almost certainly runs through registered data brokers. As DROP requests get processed every 45 days from here forward, those lists get thinner over time, independent of anything your own business does. And this is an ongoing, permanent drag on how much third-party audience data is available to buy.

Sale, share, and delete hit different parts of your stack

These three consumer rights don't affect the same systems. A "sale" under California law covers the exchange of personal information for money or other valuable consideration, and it's the right most closely tied to list purchases and data broker relationships. "Share," a right CPRA added specifically, covers cross-context behavioral advertising, which is the legal term for most pixel- and cookie-based retargeting across sites and apps. A consumer who opts out of "share"—through a "Do not sell or share my personal information" link or a Global Privacy Control signal—is directly undermining the retargeting and lookalike audiences your ad platforms build from pixel data, even if that same consumer never submits a deletion request anywhere. Meanwhile, a deletion request wipes someone out of a purchased or broker-sourced list entirely, even if they never opted out of anything on your own site.

You might already be working with a data broker

The legal definition of a data broker is broader than most marketing teams assume. It doesn't require the vendor to be a household name in the "people search" or background check space. Any business that knowingly collects and sells personal information belonging to people it has no direct relationship with can meet the definition, which covers plenty of audience, identity resolution, and list enrichment platforms that marketing teams use every day without thinking of them as brokers. If you don't already know which of your vendors are registered, it's worth asking directly.

How to protect your marketing stack

None of this requires turning your marketing team into a legal department, but a few practical steps go a long way toward reducing your exposure and keeping your campaigns running smoothly as data sources shift.

  • Audit your vendor list. Ask each data provider, enrichment tool, and identity resolution partner whether they're a registered data broker and how they handle consumer requests to opt out or delete.
  • Separate first-party from purchased data. Know which parts of your CRM come from a direct relationship with your own customers versus data you've bought, licensed, or appended from a third party.
  • Honor opt-out signals everywhere, not just your own site. Make sure your ad platform settings respect "sale" and "share" opt-outs consistently across every channel you run campaigns on, and give California residents an easy way to opt out wherever they interact with your brand.
  • Ask vendors how they handle data breaches. A vendor's data breaches become your liability if you're relying on their personal information to run campaigns, so it's worth knowing their security track record before you build a workflow around them.
  • Reduce how much of your measurement depends on individual-level data. The less your attribution relies on tracking specific people across specific touchpoints, the less exposed you are when broker lists shrink or a platform's tracking capabilities change.

Where Prescient comes in

Marketing measurement built on user-level tracking and purchased audience data was always going to run into this problem. As data broker lists thin out and cross-context tracking gets harder to rely on, any measurement approach that depends on following individual people across the web loses accuracy, not because the methodology got worse, but because the data feeding it keeps getting more restricted. That's true whether you're running a DTC brand or managing omnichannel campaigns across retail partners like Target, Walmart, or Ulta.

Prescient's marketing mix modeling doesn't work that way. Instead of stitching together individual-level tracking data, it looks at the statistical relationship between your actual marketing spend and your revenue outcomes, powered by your own compliant first-party data rather than lists or pixels sourced from data brokers. That approach doesn't depend on cookies, device IDs, or any single consumer's opt-out choice to stay accurate, which means it holds up regardless of how California's privacy laws (or the next state's) continue to evolve. If your team wants a clearer, more durable way to measure what's actually driving revenue, book a demo to see how it works.

FAQs

Does California have data privacy laws?

Yes. California has some of the most comprehensive data privacy laws in the country, built primarily around the CCPA, expanded by the CPRA, and further built on by the Delete Act. Together, these laws give residents the right to know what personal information businesses collect about them, request that it be deleted or corrected, and opt out of having it sold or shared. California also created a dedicated enforcement agency, the California Privacy Protection Agency, to oversee compliance alongside the state attorney general.

What is GDPR vs. CCPA?

The GDPR (General Data Protection Regulation) is the European Union's comprehensive privacy law, while the CCPA is California's state-level equivalent. Both give individuals rights over their personal information, but the terminology differs: the GDPR refers to an individual as a "data subject," while California law uses "consumer." The GDPR also applies more broadly across the EU and generally requires opt-in consent before a business can collect personal information at all. The CCPA, by contrast, generally allows businesses to collect personal information by default and requires them to offer an opt-out for sale and sharing rather than requiring upfront consent for most data collection. The GDPR also applies to businesses regardless of size, while the CCPA only applies to covered businesses that meet specific annual revenue or data volume thresholds and requires reasonable security procedures to protect sensitive personal information and other consumer data, similar in spirit to the GDPR's security requirements.

What are the key changes in California's privacy law in 2026?

The biggest 2026 change is the rollout of the Delete Act's DROP tool. California residents have been able to submit deletion requests to DROP since January 1, 2026, and as of August 1, 2026, registered data brokers are required to check DROP at least every 45 days and process those requests. California also expanded disclosure requirements for data brokers this year, requiring them to report whether they collect sensitive categories like citizenship status or union membership.

Is CCPA still in effect?

Yes, the CCPA is still in effect and remains the foundation of California's privacy framework. It's been amended and expanded significantly by the CPRA and the Delete Act, but the original law's core consumer rights, including the right to know, delete, and opt out, are still active and enforceable today.

The Halo

Exclusive insights, every week.

Subscribe to The Halo for sharper marketing thinking.

Keep reading