Skip to content

Definitions and comparisons

Does licensing data make you a data broker under California's Delete Act?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Licensing your own business records usually does not make you a data broker under California's Delete Act, because the definition generally targets businesses that knowingly collect and sell personal information about consumers they have no direct relationship with. Test three things: whose data is in the package, whether you dealt with those people directly, and whether personal information remains.

Key takeaways

  • California's data broker definition generally centers on selling personal information about consumers the business has no direct relationship with.
  • A business licensing its own properly de-identified operational records is usually outside that definition.
  • Risk concentrates in records about people you never dealt with: your customers' end users, purchased contacts and people named in emails or tickets.
  • Falling outside broker registration does not remove other California privacy duties, such as the rules on selling personal information.
  • Registration questions are fact-specific and should be assessed with counsel before a license is signed.

What the Delete Act does#

California's Delete Act strengthened the state's existing data broker registration law. It moved registration to the state's privacy regulator, the California Privacy Protection Agency, and directed the agency to build a single deletion mechanism, the Delete Request and Opt-out Platform (DROP), through which a consumer can ask every registered broker to delete their personal information at once.

The law matters to a company considering data licensing because its duties attach to the business, not to a single transaction. A company inside the definition takes on registration, deletion request handling and related obligations for its broker activity. That is why the definitional question deserves a careful answer before a first license, not after.

For most operating companies the practical risk is not deliberate brokerage but drift: records assumed to be first-party turn out to hold people the company never dealt with, through pasted complaints, forwarded emails or enriched CRM fields.

The three-question test#

Whether licensing makes a company a data broker generally turns on three questions: is personal information about consumers in what you license, did you collect it from people you have a direct relationship with, and does the licensed package still identify anyone. A business licensing de-identified records about its own operations usually avoids the risky answer to all three.

If personal information has been properly removed, the broker definition is usually not engaged. If personal information remains and concerns people without a direct relationship to your business, counsel should assess registration before anything is licensed.

  • Whose data: does the package contain personal information about California residents, including individuals named in business records?
  • Direct relationship: did the people in the records deal with your business directly, as customers, employees, applicants or business contacts?
  • Personal or de-identified: after preparation, can anyone in the package reasonably be identified, alone or combined with other data?

Who is in your records, and is there a direct relationship?#

The direct relationship question depends on the person, not the system, so map the categories of people who appear in each record family. Most operating records are dominated by people the company dealt with directly, but a few categories regularly break that pattern.

The regulator's rules add detail on what counts as a direct relationship. They look at how recently the consumer interacted with the business, and a business with a direct relationship can still be treated as a broker for personal information about that person it obtained from other sources. Old customer records and enriched or inherited data therefore deserve a closer look than current accounts.

Software vendors should look hardest at the third row. A SaaS product's tickets and logs often mention the end customers of its business customers, and those people usually never dealt with the vendor.

Who is in your records, and is there a direct relationship?
Person in the recordsDirect relationship?Broker risk if personal information remainsTypical handling
Your customers and their staffUsually, if the interaction is recentLower; other privacy rules still applyRemove names, contact details and account IDs
Your employees and contractorsCollected directlyLower; employee notices matterRemove names and HR details
Your customers' end usersOften noHigher, especially for SaaS vendorsRemove or exclude; check customer agreements
Contacts from purchased or enriched listsNoHigherExclude list-sourced fields entirely
People mentioned in emails, tickets or notesUsually noHigher if identifiableRedact names and identifying details in free text
Contacts inherited from an acquired companyDepends on that company's dealings and noticesModerateCheck the acquired company's notices and terms

Why de-identification carries most of the weight#

De-identification carries most of the weight because the broker definition concerns personal information, and properly de-identified information is generally treated differently under California law. The state's privacy law sets its own conditions for treating information as deidentified: reasonable technical measures against re-identification, a public commitment to keep it deidentified and not re-identify it, and contract terms binding recipients to the same.

Free text is where de-identification usually fails. Ticket bodies, email threads and chat logs carry names, phone numbers, addresses and descriptions that identify people even after structured fields are cleaned. A preparation process that handles free text, followed by a reviewed sample, is what makes a de-identified answer credible.

The contract finishes the job. A license that prohibits re-identification, bars linking with other data and requires the buyer to pass the same duties to anyone it shares with keeps the package de-identified after delivery.

What still applies if you are not a broker#

Staying outside the broker definition does not end the analysis, because California's broader privacy law can still apply to any personal information in a licensed package. Licensing identifiable personal information for value may count as a sale under that law, which brings notice and opt-out duties.

Contracts add a separate layer. Customer agreements and data processing terms may forbid uses that privacy law would otherwise allow, so the rights review and the privacy review should run together.

What still applies if you are not a broker
Rule setWhen it may applyWhat to check
Delete Act registrationSelling personal information about consumers without a direct relationshipWhether any such data remains after preparation
California sale and sharing rulesLicensing identifiable personal information for valueNotices at collection, opt-out handling, contract terms
Customer and vendor contractsRecords covered by confidentiality or data processing termsUse restrictions and deletion duties
Other state broker registriesA few other states run registries with their own definitionsEach state's definition, assessed with counsel

Illustrative: a property management software company checks its tickets#

Illustrative: a fictional property management software company plans to license its support ticket archive and the linked engineering issues. Its customers are property managers, but tickets often mention tenants by name, unit and phone number, because property managers paste tenant complaints into their requests.

The privacy lead maps the people in the archive. Property managers and company staff have a direct relationship with the business. Tenants do not, so licensing tickets with tenant details intact could raise the broker question and would also conflict with the company's customer agreements.

The company removes tenant names, unit numbers and contact details from structured fields and free text, reviews a sample to confirm nothing identifiable remains, and adds a no re-identification clause to the license. Counsel concludes that the de-identified package does not call for registration and records the reasoning with the rights file.

How SourceX approaches the broker question#

SourceX removes personal and confidential details in the Preparation step of the SourceX five-step transaction, before the supplier approves release. The fit check itself collects only metadata, so no personal information moves during the initial assessment.

Each package's SourceX Evidence Packet includes a privacy record describing what was removed and how it was checked, which gives counsel a documented basis for the broker analysis. SourceX works with companies licensing their own first-party business records, not resold personal data.

Frequently asked questions

Does the Delete Act reach business contact data?

It can. California's privacy law can cover information about individuals acting in a business role, such as a purchasing manager's name and work email. If you license identifiable contacts that came from a purchased list rather than your own dealings, counsel should assess the broker question.

Is licensing records to an AI developer a 'sale' under California law?

If the package contains personal information and you receive value for it, it may be a sale under California's privacy law, with notice and opt-out duties. A properly de-identified package generally sits outside those rules. Counsel should review the package and the contract together.

What if a company we acquired bought contact lists?

Inherited data carries its history with it. If an acquired company enriched its CRM with purchased contacts, those records may concern people neither company dealt with directly. Identify list-sourced fields during the rights review and exclude them from any license.

Do SaaS vendors acting as service providers face the same question?

A SaaS vendor processing customer data as a service provider generally may use it only to serve that customer. Licensing such data out would raise contract and privacy problems before the broker question even arises, which is why vendors usually license their own operating records instead.

Do other states have data broker laws?

Yes. A few other states maintain data broker registries, and their definitions and duties differ from California's. A company licensing records that still contain personal information should have counsel check each state where the people in those records live.

Can de-identified data become personal information again?

It can, if a recipient combines it with other data or if preparation missed identifiers in free text or attachments. That is why licenses bar re-identification and linkage, and why the supplier keeps no key that would re-link records. Recheck preparation whenever the scope of a license changes.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify