California's data broker enforcement now reaches B2B contact data. On September 1, 2026, CalPrivacy fined SalesIntel Research $36,400 for failing to register as a data broker and ordered it to process deletion requests through DROP, the state's single deletion platform. Registered brokers must process those requests at least every 45 days, so California contacts will keep leaving vendor databases throughout Q4.
Below: what happened, why it matters even if you do not sell data yourself, and what to change before Q4 sequences go out. Every figure comes from CalPrivacy, statute text or the legislative record, with its date.
What happened in September 2026
Between August 25 and September 3, 2026, while the first 45-day deletion cycle was running, the Delete Act became an operating constraint for anyone using contact data about California residents.
A B2B contact data vendor was fined
On September 1, 2026, the California Privacy Protection Agency Board issued a decision requiring SalesIntel Research, Inc., a Virginia-based company, to pay a $36,400 fine for failing to register on time with the state's Data Broker Registry. The Enforcement Division alleged that the company operated as a data broker without registering by the 2025 deadline.
CalPrivacy described SalesIntel as offering more than 200 million professional contacts, 54 million mobile phone numbers and inferences about career changes. It also pointed to a product that de-anonymizes website traffic and returns contact data, direct dials and verified emails for outreach. That is a description of a standard B2B sales intelligence stack, not a people-search site.
Beyond the fine, the decision requires the company to post privacy request metrics on its website, access DROP and process future deletion requests through it. The same announcement says CalPrivacy has brought more than a dozen enforcement actions against unregistered data brokers.
An enforcement advisory on registry accuracy
On September 3, 2026, CalPrivacy issued Enforcement Advisory 2026-01. It warns that data brokers who file incorrect information in their annual registration are liable for a $200 fine for each day the error stays in the registry, and notes that the Enforcement Division has already brought multiple actions over reporting errors. The registry discloses metrics, the types of data a broker collects and recipients of certain data, so a vendor's entry is now a document you can check.
DROP sign-ups passed half a million
DROP, the Delete Request and Opt-out Platform, opened to consumers on January 1, 2026. On August 25, 2026, CalPrivacy reported:
- More than 500,000 Californians had registered.
- 654 data brokers were part of the system.
- Approximately 25% of brokers had reported processing deletion requests since the August 1, 2026 deadline.
- 99.9% of users had already had their profile deleted by at least one broker, and the typical user had been removed by over 40 brokers.
The 45-day deletion cycle is running
Under Civil Code section 1798.99.86, beginning August 1, 2026, a registered broker must access DROP at least once every 45 days and process requests within 45 days of receiving them. After deleting a person's data, the broker must delete it again at least once every 45 days and must not sell or share new personal information about that person, subject to limited exceptions.
CalPrivacy's data broker page says brokers had 45 days from August 1 to process their first batch. By our count, that first window closes around September 15, 2026. CalPrivacy lists penalties of $200 per day for failing to register and $200 per day per deletion request for failing to delete, plus the agency's costs. The same statute requires independent audits of brokers beginning January 1, 2028, and every three years after that.
SB 923 is on the Governor's desk
SB 923, the Expanding Privacy Rights Act, would expand the CCPA right to delete so it covers personal information a business collected about a consumer from any source, not only from the consumer. CalPrivacy, which sponsors the bill, welcomed its passage on August 28, 2026. The legislative record shows the bill was enrolled and presented to the Governor on September 2, 2026, and was still with the Governor on September 12, 2026. If it becomes law, a business that did not get the data from the consumer could keep a record of the request and the minimum data needed to make sure the information stays deleted.
Why B2B teams are affected even if you are not a data broker
The Delete Act regulates data brokers, which state law defines as businesses that knowingly collect and sell personal information about consumers they have no direct relationship with. Most companies running outbound buy data rather than sell it. They still feel this in three ways.
Records disappear from vendor databases
Each DROP sign-up removes that person from every registered broker that matches them, and keeps them removed. For a B2B team this shows up as enrichment calls with no direct dial, contacts missing from saved searches and thinner buying groups. No one publishes how many B2B buyers have signed up, so track your own match rates instead of assuming a number.
The copies already sitting in your CRM do not delete themselves. Under today's CCPA, CalPrivacy says the deletion right does not require a business to delete information it collected from a third party. SB 923 would change that. Either way, emailing people from an export your vendor has since purged is hard to defend.
Work contact details are personal information
The CCPA once exempted personal information reflecting business-to-business transactions. According to CalPrivacy's FAQ, that exemption expired on December 31, 2022. Since January 1, 2023, a California resident's work email, direct dial and job title have carried the same CCPA rights as any other personal information for businesses the law covers, including the right to know, delete and opt out of sale or sharing. Our California B2B lead generation page explains how that shapes list building in the state.
Your vendor's status becomes your pipeline risk
If a vendor is fined, ordered into DROP or caught with an inaccurate registration, its data can change quickly. If your Q4 sequences depend on one provider, that is a pipeline risk as much as a compliance one. Ask these questions now:
- Are you on California's 2026 Data Broker Registry, and is the entry accurate?
- When did you start processing DROP requests, and how often do you run them?
- When a record is deleted, what happens to copies you have already delivered to customers?
- Can you show the source and collection date for each contact you sell us?
- Do you supply suppression or deletion files we can apply to our CRM?
- How are you preparing for the independent audits required from January 1, 2028?
If you resell, rent or share lists with agencies or partners, ask counsel whether any part of your business could meet the data broker definition.
What to do before Q4 outbound
Most of this is data hygiene your team should run anyway. The September actions give it a deadline.
- Audit vendorsCheck registry status, DROP processing and contract terms for every data source.
- Tag every recordAdd source, capture date and collection basis to contacts in the CRM.
- Rebuild suppressionOne suppression list and deletion workflow across every channel.
- Refresh California listsRe-verify California contacts on a cycle no longer than 45 days.
- Shift to first-partyPut more weight on events, webinars, ABM and inbound.
- Document itKeep a dated record of sources, checks and counsel review.
1. Audit vendor contracts and DROP compliance
List every source that feeds contact data into your CRM: data platforms, enrichment tools that query several providers, website visitor identification, intent providers, event lists and agencies. For each one, look the company up in the registry linked from CalPrivacy's data broker page, ask for written confirmation of DROP processing dates, and check the contract for privacy warranties, notice of enforcement actions and a right to receive deletion files.
2. Add source, capture date and basis to CRM records
When a California contact asks what you hold or where you got it, answer from the record, not from import logs. Make these fields required on import.
CONTACT DATA LINEAGE FIELDS
Original source Vendor name, event name, form name or referral
Source record ID The vendor's ID, so you can trace deletions back
Capture date When the record entered your systems
Last verified date When the email or phone was last confirmed
Collection basis Purchased / event registration / webinar sign-up /
inbound form / referral / manual research
Location flag California / other US / non-US / unknown
Privacy status Active / opted out / deletion requested / deleted
Status date When the privacy status last changed
3. Rebuild suppression and deletion workflows
Keep one suppression list shared by email, LinkedIn, calling and ad audiences, and apply it before every import and enrichment job, not only before sends. Otherwise a deleted contact comes back the next time someone uploads a vendor file. When someone asks for deletion, remove the record from every tool and keep only what your counsel agrees you need to stop it being re-imported. Our B2B lead generation service runs a global suppression list across channels for this reason.
4. Refresh California lists more often
A list exported in July was built before the first DROP deletions. As a working rule, do not start a sequence to California contacts from data older than one 45-day cycle. Re-verify with the vendor first, and if the vendor no longer returns a record you hold, suppress it rather than contacting it from your old copy. It costs some volume.
5. Shift weight toward first-party and consented channels
Event registrants, webinar sign-ups, inbound form fills and engaged ABM contacts come with a documented source and a reason to hear from you. They also do not disappear on a broker's deletion cycle. Plan Q4 so that events and webinars, account-based marketing and inbound carry a larger share of meetings, and use purchased data to fill buying groups inside accounts that are already engaged.
For the methods, see pre-booked meetings at conferences and the LinkedIn lead generation playbook. Our yard and port management software program generated $8M in pipeline in 9 months through port-cluster ABM and closed-door CXO roundtables.
6. Document it all
Write a one-page data sourcing record: every source, the date you checked its registry entry and DROP status, your lineage fields, your suppression flow and your refresh cycle. Note the date your counsel reviewed it. Set review dates for the Governor's decision on SB 923, the January registration window each year and the 2028 audit start.
Data practices, risks and vendor questions
| Data practice | Risk | What to ask your vendor |
|---|---|---|
| Buying contact lists or database access | Vendor is unregistered or not processing DROP, and supply changes after enforcement | Are you on the 2026 registry, and when did you start processing DROP requests? |
| Enrichment of CRM records | Stale copies of people who have since used DROP stay in your sequences | Do you send deletion or suppression files, and how often? |
| Website visitor identification that returns named contacts | CalPrivacy cited this product type in the SalesIntel decision | Where does the person-level data come from, and is that source registered? |
| Mobile numbers and direct dials | Sold as personal data, and calling rules apply on top | What is the source and collection date for each number? |
| Inferred data such as job changes | Registry filings now disclose the types of data a broker collects | Which inferred data do you sell, and does your registry entry describe it accurately? |
| Sharing lists with agencies or partners | Deletions and opt-outs do not reach every copy | Who else receives our data, and how do deletions reach them? |
Federal email and calling rules still apply on top of all this. Our guide to marketing without ads in regulated industries covers CAN-SPAM basics.
This is not legal advice
This post summarizes public announcements, statute text and bill status as of September 12, 2026. It is not legal advice. Whether the CCPA or the Delete Act applies to your company, and what you must do about it, depends on your size, data flows and contracts. Confirm your obligations with qualified counsel before changing how you collect, keep or delete contact data.
Where Lemniscate fits
Lemniscate Growth builds outbound, ABM and event programs for B2B teams selling into California, with sourcing recorded for every contact and one suppression list across channels. See our California revenue pipeline generation page for how we split the state into its buying regions. We work with 35+ active clients and generate up to $10M in pipeline per client.
Book a free growth audit and we will map where your California pipeline depends on purchased data and where first-party channels can take more of the load.
