← Back to Blog
Data BrokersPrivacyRegulationGuide
Data Broker Compliance in 2026: Only 9% Follow California's Privacy Law (Stanford Study)

Data Broker Compliance in 2026: Only 9% Follow California's Privacy Law (Stanford Study)

A Stanford study found only 9% of registered data brokers fully comply with California's Delete Act — and 64% use dark patterns to block your opt-outs. Here's what it means for you.

👤 CyberForget Team 📅 2026-09-16 ⏱ 10 min read

Published: September 16, 2026 Category: Privacy Regulation, Data Brokers, Guide Reading time: ~10 minutes Meta description: A Stanford study found only 9% of registered data brokers fully comply with California's Delete Act — and 64% use dark patterns to block your opt-outs. Here's what it means for you.


California's Delete Act was supposed to be the strongest data broker law in the United States. Instead, a new Stanford study shows that the companies it regulates are, in large part, simply not following it.

Stanford RegLab and Stanford HAI manually reviewed the privacy policies and rights-request processes of all 522 data brokers registered in California during 2025. The headline finding: only 9% fully complied with the law's transparency requirements. Nearly half — 45% — reported no rights-request metrics at all. And 64% actively made it harder for people to submit a deletion or opt-out request.

That last number matters most if you have ever tried to opt out of a data broker yourself. It is not your imagination that the process is exhausting.


What the Stanford researchers actually found

The Delete Act (SB 362, passed in 2023) set a hard deadline: by July 1, 2025, every registered data broker had to publicly report how many consumer privacy requests it received across six categories, plus the mean and median number of days it took to fulfill each type, and how many requests it honored versus denied.

The Stanford team checked whether brokers actually did that. The results:

FindingResult
Registered data brokers reviewed522
Fully compliant with all transparency requirements9%
Submitted no rights-request metrics at all45%
Added friction to the rights-request process ("dark patterns")64%
The friction finding is the one the researchers describe as the most troubling. Under the law, brokers are explicitly prohibited from using dark patterns — confusing website designs, multiple forms, or excessive verification steps — to obstruct consumers exercising their privacy rights. Two thirds of them did it anyway.

There is also a data-integrity problem underneath. When the team matched brokers across two different reporting sources, only 27 of 457 brokers (5.9%) reported metrics that matched identically. Another 17% reported lower numbers to the state registry than they had published on their own websites.

"California is leading the way in consumer privacy laws, but our findings paint a troubling picture of how these protections have been implemented," said Stanford HAI Privacy and Data Policy Fellow Jennifer King. "Without clear reporting requirements and consistent financial consequences, businesses simply won't do it."

The study — *Privacy Without Remedy: An Assessment of Data Broker Compliance with California Privacy Law* — identifies three reasons for the gap: the system depends on brokers self-registering, penalties have been inconsistent, and the agency enforcing the rules is under-resourced.

> Why this matters: A law you cannot enforce is a suggestion. For years, the practical advice for protecting your data has been "just opt out." This study is the first hard evidence of how well that advice actually works at scale — and the answer is: not very well on its own.


The dark patterns brokers use to block your opt-outs

"Excessive verification" sounds bureaucratic. In practice, it looks like this: before a broker will process your opt-out, it demands more personal information than it needs — including the very identifiers you are trying to protect.

The California Privacy Protection Agency (now branded CalPrivacy) made this the centerpiece of its first enforcement action in August 2026. Its target, LocateSmarter, required Californians to hand over partial Social Security numbers before it would process an opt-out request.

Demanding a sensitive identifier as the price of exercising a privacy right is not verification. It is deterrence. You are being asked to surrender more data to stop the sale of your data.

Other friction patterns documented in the study and in opt-out guides generally:

  • Multiple separate forms for the same request, with no clear indication of which one is authoritative
  • Opt-out pages that are not linked from the homepage or searchable in the site's own search
  • Confirmation steps that silently time out, requiring you to restart from scratch
  • Confirmation emails sent under a different company name, so you cannot tell who processed the request
  • No confirmation at all — some brokers simply never acknowledge the request

If you have worked through a few of our opt-out guides — Spokeo, BeenVerified, Radaris, WhitePages — you have seen the milder versions of these. They are not accidents.


Enforcement has started — the first Delete Act fines

For most of the Delete Act's life, the compliance story has been "required on paper, ignored in practice." That changed in August 2026, when CalPrivacy issued two enforcement actions in a single week.

CompanyFineWhat it was fined for
LocateSmarter$116,490Failing to register as a data broker on time; requiring partial Social Security numbers before processing opt-outs
Cybba, Inc. (Boston)$52,400Missing the 2025 Data Broker Registry registration deadline
The Cybba decision is the more instructive one, because it includes forward-looking terms: Cybba must post metrics about privacy rights requests on its website, connect to the DROP system, and process all future deletion requests through it. The regulator is not just collecting fines — it is writing the Stanford study's findings directly into consent orders.

The scale is still small relative to a multi-billion-dollar industry, and 90% of registered brokers are still out of full compliance. But two actions in one week, immediately after the law's most consequential deadline, is a change in posture. Ford Motor Company, notably, is registered as a data broker — this is not a niche cottage industry.


DROP is live: California's one-click deletion platform

The most practical piece of the Delete Act went live on August 1, 2026: DROP, the Delete Request and Opt-out Platform.

DROP is designed to solve the exact problem the study documented. Instead of submitting 500+ individual opt-out requests through 500+ different forms, a California resident can submit one deletion and opt-out-of-sale request to every registered data broker at once.

The obligations on brokers are strict:

  • On an ongoing basis, every registered broker must retrieve deletion requests from DROP
  • Brokers must delete all personal information related to opted-out consumers every 45 days
  • Covered data includes behavioral, financial, health, location, and relationship data — plus any inferences drawn about the individual from that data

That 45-day cycle is significant. It is the first legally mandated re-deletion cadence in US privacy law, and it directly targets the reason data broker removal is not a one-time job: profiles get rebuilt from fresh public records and re-listed.

If you are a California resident, DROP is currently the single highest-leverage privacy action available to you, and it is free. The researchers' caveat is that its effectiveness depends on public awareness — a platform people do not know about deletes nothing.


Why this matters even if you do not live in California

Data brokers are not geographically constrained. A broker registered in California sells profiles on people in Ohio, Texas, and Florida, and a broker that ignores a Californian's deletion request is very likely ignoring everyone else's too.

There are two broader implications:

1. Your opt-out requests are probably being obstructed, whether or not you have a legal right to them. Only six states currently grant the kind of deletion rights California does. In the other 44, brokers have even less incentive to make the process smooth — and the study shows that even where the obligation is mandatory, 64% add friction.

2. Enforcement models spread. California has been the template for state privacy law in 2026. If the CPPA's enforcement pace holds, the procedural requirements it is imposing — mandatory metrics reporting, DROP connection, real fulfillment timelines — are the ones other states will copy.


What is coming in 2028

One more phase of the Delete Act has not yet landed. By 2028, data brokers will have to undergo third-party audits every three years to assess their compliance with the law.

That is the point at which the stakes rise substantially. A regulator with limited resources has to catch non-compliance. A third-party auditor under a legal duty to report it has to find it. The Stanford researchers are explicit that this, combined with consistent enforcement, is where the meaningful shift is expected.


What you can actually do now

The study's lesson is not that opt-outs are pointless. It is that opt-outs only work when they are submitted correctly and repeated when data reappears. Here is the practical sequence:

Step 1: Find out what is actually exposed. Before opting out of anything, see which brokers hold your information. A free CyberForget scan checks where your personal information is exposed across data brokers and people search sites. You can also do this manually — our guide to finding out what data brokers know about you covers the process.

Step 2: Use the official process, not a search result. Opt-out pages are usually not linked from broker homepages. Use our data broker opt-out list to reach the correct page for each broker rather than relying on a search engine, where lookalike domains are common.

Step 3: Never hand over more than the minimum. A broker asking for your Social Security number, a full date of birth, or a photo ID to process a basic deletion request in a state where deletion is a legal right is running the exact playbook CalPrivacy just fined. If the request cannot proceed without it, document it and move on.

Step 4: Watch for the two failure modes. After submitting, a request either silently expires (no confirmation, or a confirmation link already expired) or succeeds and later gets undone when the broker re-lists your profile from a fresh data source. Both require a re-check within 30 to 60 days.

Step 5: Decide whether manual is sustainable. The full manual process — free, but time-consuming — is an 8-to-12-hour initial sweep that has to be repeated. If that is not realistic for you, automated removal handles the submission-and-re-check cycle continuously.

> Related reading: The Complete Guide to Data Broker Removal (2026) → | What Is a Data Broker? →


Bottom Line

  • Stanford RegLab and Stanford HAI reviewed all 522 registered data brokers and found only 9% fully comply with California's Delete Act transparency requirements.
  • 45% reported no rights-request metrics at all; 64% used dark patterns — confusing designs, multiple forms, excessive verification — to obstruct requests, which the law prohibits.
  • Enforcement began in August 2026: LocateSmarter fined $116,490 and Cybba $52,400, with Cybba ordered to post request metrics and process deletions through DROP.
  • DROP is live as of August 1, 2026, requiring brokers to delete opted-out consumers' data every 45 days. Third-party audits arrive in 2028.
  • The practical takeaway is unchanged but better evidenced: opt-outs work when they are submitted through the correct channel, verified, and repeated. That is the cycle CyberForget automates.

Sources


*Updated: September 16, 2026. Study figures reflect the Stanford RegLab/HAI review of 522 data brokers registered in California during 2025. This article is for informational purposes and does not constitute legal advice.*

🔒 Take Control of Your Data

Ready to remove your personal information from data broker sites? CyberForget automates the entire process. Scan 190+ sites in seconds.

Start Free Scan →
🛡️ Protect Your Browser with CyberForget VPN Military-grade WireGuard encryption. Zero logs. Free Chrome extension.
Add to Chrome ↗
← Browse All Blog Posts