Pipeline playbooksUpdated Sep 12, 20269 min read

California's Data Broker Crackdown Reaches B2B Contact Data: What DROP Means for Outbound

California's DROP deletion platform and data broker fines now reach B2B contact data. What changed in September 2026 and six steps for Q4 outbound.

Short answerCalifornia's data broker enforcement now reaches B2B contact data. On September 1, 2026, CalPrivacy fined SalesIntel Research $36,400 for failing to register as a data broker and ordered it to process deletions through DROP. Registered brokers must process DROP requests at least every 45 days, so California records will keep leaving vendor databases. Audit vendors, tag record sources, rebuild suppression and lean on first-party channels before Q4.

California's data broker enforcement now reaches B2B contact data. On September 1, 2026, CalPrivacy fined SalesIntel Research $36,400 for failing to register as a data broker and ordered it to process deletion requests through DROP, the state's single deletion platform. Registered brokers must process those requests at least every 45 days, so California contacts will keep leaving vendor databases throughout Q4.

Below: what happened, why it matters even if you do not sell data yourself, and what to change before Q4 sequences go out. Every figure comes from CalPrivacy, statute text or the legislative record, with its date.

What happened in September 2026

Between August 25 and September 3, 2026, while the first 45-day deletion cycle was running, the Delete Act became an operating constraint for anyone using contact data about California residents.

A B2B contact data vendor was fined

On September 1, 2026, the California Privacy Protection Agency Board issued a decision requiring SalesIntel Research, Inc., a Virginia-based company, to pay a $36,400 fine for failing to register on time with the state's Data Broker Registry. The Enforcement Division alleged that the company operated as a data broker without registering by the 2025 deadline.

CalPrivacy described SalesIntel as offering more than 200 million professional contacts, 54 million mobile phone numbers and inferences about career changes. It also pointed to a product that de-anonymizes website traffic and returns contact data, direct dials and verified emails for outreach. That is a description of a standard B2B sales intelligence stack, not a people-search site.

Beyond the fine, the decision requires the company to post privacy request metrics on its website, access DROP and process future deletion requests through it. The same announcement says CalPrivacy has brought more than a dozen enforcement actions against unregistered data brokers.

An enforcement advisory on registry accuracy

On September 3, 2026, CalPrivacy issued Enforcement Advisory 2026-01. It warns that data brokers who file incorrect information in their annual registration are liable for a $200 fine for each day the error stays in the registry, and notes that the Enforcement Division has already brought multiple actions over reporting errors. The registry discloses metrics, the types of data a broker collects and recipients of certain data, so a vendor's entry is now a document you can check.

DROP sign-ups passed half a million

DROP, the Delete Request and Opt-out Platform, opened to consumers on January 1, 2026. On August 25, 2026, CalPrivacy reported:

  • More than 500,000 Californians had registered.
  • 654 data brokers were part of the system.
  • Approximately 25% of brokers had reported processing deletion requests since the August 1, 2026 deadline.
  • 99.9% of users had already had their profile deleted by at least one broker, and the typical user had been removed by over 40 brokers.

The 45-day deletion cycle is running

Under Civil Code section 1798.99.86, beginning August 1, 2026, a registered broker must access DROP at least once every 45 days and process requests within 45 days of receiving them. After deleting a person's data, the broker must delete it again at least once every 45 days and must not sell or share new personal information about that person, subject to limited exceptions.

CalPrivacy's data broker page says brokers had 45 days from August 1 to process their first batch. By our count, that first window closes around September 15, 2026. CalPrivacy lists penalties of $200 per day for failing to register and $200 per day per deletion request for failing to delete, plus the agency's costs. The same statute requires independent audits of brokers beginning January 1, 2028, and every three years after that.

SB 923 is on the Governor's desk

SB 923, the Expanding Privacy Rights Act, would expand the CCPA right to delete so it covers personal information a business collected about a consumer from any source, not only from the consumer. CalPrivacy, which sponsors the bill, welcomed its passage on August 28, 2026. The legislative record shows the bill was enrolled and presented to the Governor on September 2, 2026, and was still with the Governor on September 12, 2026. If it becomes law, a business that did not get the data from the consumer could keep a record of the request and the minimum data needed to make sure the information stays deleted.

Why B2B teams are affected even if you are not a data broker

The Delete Act regulates data brokers, which state law defines as businesses that knowingly collect and sell personal information about consumers they have no direct relationship with. Most companies running outbound buy data rather than sell it. They still feel this in three ways.

Records disappear from vendor databases

Each DROP sign-up removes that person from every registered broker that matches them, and keeps them removed. For a B2B team this shows up as enrichment calls with no direct dial, contacts missing from saved searches and thinner buying groups. No one publishes how many B2B buyers have signed up, so track your own match rates instead of assuming a number.

The copies already sitting in your CRM do not delete themselves. Under today's CCPA, CalPrivacy says the deletion right does not require a business to delete information it collected from a third party. SB 923 would change that. Either way, emailing people from an export your vendor has since purged is hard to defend.

Work contact details are personal information

The CCPA once exempted personal information reflecting business-to-business transactions. According to CalPrivacy's FAQ, that exemption expired on December 31, 2022. Since January 1, 2023, a California resident's work email, direct dial and job title have carried the same CCPA rights as any other personal information for businesses the law covers, including the right to know, delete and opt out of sale or sharing. Our California B2B lead generation page explains how that shapes list building in the state.

Your vendor's status becomes your pipeline risk

If a vendor is fined, ordered into DROP or caught with an inaccurate registration, its data can change quickly. If your Q4 sequences depend on one provider, that is a pipeline risk as much as a compliance one. Ask these questions now:

  • Are you on California's 2026 Data Broker Registry, and is the entry accurate?
  • When did you start processing DROP requests, and how often do you run them?
  • When a record is deleted, what happens to copies you have already delivered to customers?
  • Can you show the source and collection date for each contact you sell us?
  • Do you supply suppression or deletion files we can apply to our CRM?
  • How are you preparing for the independent audits required from January 1, 2028?

If you resell, rent or share lists with agencies or partners, ask counsel whether any part of your business could meet the data broker definition.

What to do before Q4 outbound

Most of this is data hygiene your team should run anyway. The September actions give it a deadline.

  1. Audit vendorsCheck registry status, DROP processing and contract terms for every data source.
  2. Tag every recordAdd source, capture date and collection basis to contacts in the CRM.
  3. Rebuild suppressionOne suppression list and deletion workflow across every channel.
  4. Refresh California listsRe-verify California contacts on a cycle no longer than 45 days.
  5. Shift to first-partyPut more weight on events, webinars, ABM and inbound.
  6. Document itKeep a dated record of sources, checks and counsel review.

1. Audit vendor contracts and DROP compliance

List every source that feeds contact data into your CRM: data platforms, enrichment tools that query several providers, website visitor identification, intent providers, event lists and agencies. For each one, look the company up in the registry linked from CalPrivacy's data broker page, ask for written confirmation of DROP processing dates, and check the contract for privacy warranties, notice of enforcement actions and a right to receive deletion files.

2. Add source, capture date and basis to CRM records

When a California contact asks what you hold or where you got it, answer from the record, not from import logs. Make these fields required on import.

CONTACT DATA LINEAGE FIELDS

Original source        Vendor name, event name, form name or referral
Source record ID       The vendor's ID, so you can trace deletions back
Capture date           When the record entered your systems
Last verified date     When the email or phone was last confirmed
Collection basis       Purchased / event registration / webinar sign-up /
                       inbound form / referral / manual research
Location flag          California / other US / non-US / unknown
Privacy status         Active / opted out / deletion requested / deleted
Status date            When the privacy status last changed

3. Rebuild suppression and deletion workflows

Keep one suppression list shared by email, LinkedIn, calling and ad audiences, and apply it before every import and enrichment job, not only before sends. Otherwise a deleted contact comes back the next time someone uploads a vendor file. When someone asks for deletion, remove the record from every tool and keep only what your counsel agrees you need to stop it being re-imported. Our B2B lead generation service runs a global suppression list across channels for this reason.

4. Refresh California lists more often

A list exported in July was built before the first DROP deletions. As a working rule, do not start a sequence to California contacts from data older than one 45-day cycle. Re-verify with the vendor first, and if the vendor no longer returns a record you hold, suppress it rather than contacting it from your old copy. It costs some volume.

5. Shift weight toward first-party and consented channels

Event registrants, webinar sign-ups, inbound form fills and engaged ABM contacts come with a documented source and a reason to hear from you. They also do not disappear on a broker's deletion cycle. Plan Q4 so that events and webinars, account-based marketing and inbound carry a larger share of meetings, and use purchased data to fill buying groups inside accounts that are already engaged.

For the methods, see pre-booked meetings at conferences and the LinkedIn lead generation playbook. Our yard and port management software program generated $8M in pipeline in 9 months through port-cluster ABM and closed-door CXO roundtables.

6. Document it all

Write a one-page data sourcing record: every source, the date you checked its registry entry and DROP status, your lineage fields, your suppression flow and your refresh cycle. Note the date your counsel reviewed it. Set review dates for the Governor's decision on SB 923, the January registration window each year and the 2028 audit start.

Data practices, risks and vendor questions

Data practiceRiskWhat to ask your vendor
Buying contact lists or database accessVendor is unregistered or not processing DROP, and supply changes after enforcementAre you on the 2026 registry, and when did you start processing DROP requests?
Enrichment of CRM recordsStale copies of people who have since used DROP stay in your sequencesDo you send deletion or suppression files, and how often?
Website visitor identification that returns named contactsCalPrivacy cited this product type in the SalesIntel decisionWhere does the person-level data come from, and is that source registered?
Mobile numbers and direct dialsSold as personal data, and calling rules apply on topWhat is the source and collection date for each number?
Inferred data such as job changesRegistry filings now disclose the types of data a broker collectsWhich inferred data do you sell, and does your registry entry describe it accurately?
Sharing lists with agencies or partnersDeletions and opt-outs do not reach every copyWho else receives our data, and how do deletions reach them?

Federal email and calling rules still apply on top of all this. Our guide to marketing without ads in regulated industries covers CAN-SPAM basics.

This post summarizes public announcements, statute text and bill status as of September 12, 2026. It is not legal advice. Whether the CCPA or the Delete Act applies to your company, and what you must do about it, depends on your size, data flows and contracts. Confirm your obligations with qualified counsel before changing how you collect, keep or delete contact data.

Where Lemniscate fits

Lemniscate Growth builds outbound, ABM and event programs for B2B teams selling into California, with sourcing recorded for every contact and one suppression list across channels. See our California revenue pipeline generation page for how we split the state into its buying regions. We work with 35+ active clients and generate up to $10M in pipeline per client.

Book a free growth audit and we will map where your California pipeline depends on purchased data and where first-party channels can take more of the load.

FAQ. Quick answers.

Still unsure? Ask us directly.

What is DROP in California?

DROP is the Delete Request and Opt-out Platform run by the California Privacy Protection Agency, known as CalPrivacy. It opened to consumers on January 1, 2026 and lets a California resident send one deletion request to every registered data broker. Since August 1, 2026, brokers must access DROP at least once every 45 days, process the requests and keep deleting that person's data on the same cycle.

Does the Delete Act apply to B2B contact data?

It applies to data brokers, meaning businesses that knowingly collect and sell personal information about consumers they have no direct relationship with. A California resident's work email, title and direct dial count as personal information, because the CCPA exemption for business-to-business data expired on December 31, 2022. On September 1, 2026, CalPrivacy fined SalesIntel Research, which sells professional contact data, for failing to register as a data broker.

Is my company a data broker if we buy contact lists for outbound?

The Delete Act definition covers businesses that knowingly collect and sell personal information about people they have no direct relationship with. Buying a list for your own outreach is not selling it, but reselling, renting or sharing lists with other companies can change the analysis. Ask your counsel, because the answer depends on your contracts and how data moves between you, your agencies and your partners.

Will DROP reduce the California contacts in my data vendor?

Expect it to. Registered brokers must delete the data of Californians who signed up for DROP, keep deleting it at least every 45 days and stop selling new data about them. CalPrivacy reported more than 500,000 sign-ups as of August 25, 2026, and said the typical user had already been removed by over 40 brokers. The effect on your lists depends on which of your buyers signed up.

What is SB 923 and does it affect B2B outbound?

SB 923, the Expanding Privacy Rights Act, would extend the CCPA right to delete to personal information a business collected about a consumer from any source, including purchased data. It was presented to the Governor on September 2, 2026 and was still awaiting action on September 12, 2026. If it becomes law, a California contact could ask you to delete records you bought, and you could keep a minimal record so the data stays deleted.

What should we ask our data vendor about DROP?

Ask whether it appears on California's 2026 Data Broker Registry, when it began processing DROP requests and how often it runs them. Ask how deletions reach data already delivered to customers, whether it can show the source and collection date for each record, and whether it supplies suppression files. Finally, ask how it is preparing for the independent audits the Delete Act requires from January 1, 2028.

Turn this into pipeline. We can run it with you.

Tell us the revenue number and the market. We will come back with the stages that matter most for you, and the ones you can skip.

  • 20 minutes with a senior operator, not an SDR
  • Bring your revenue target and markets; we bring the pipeline math
  • Slots across US, Canada, India, Singapore and GCC time zones

Prefer email? growth@lemniscategrowth.com

Pick a 20-minute slotStraight to a senior operator. No SDR screen.