TL;DR

California's Delete Request and Opt-Out Platform (DROP) became operative for registered data brokers on August 1, 2026. Brokers must now access it at least once every 45 days and process consumer deletion requests submitted through it. The CPPA has said hundreds of thousands of Californians have signed up, and California doesn't cap penalties for non-compliance — so the exposure compounds.

Connecticut has enacted its own data broker registration law, and other states are moving in the same direction.

The question this raises for anyone who extracts contact data: does any of this apply to me?

The short answer, and the one most people get wrong in the reassuring direction:

What you doLikely a data broker?
Extract contacts, use them for your own outreachNo
Extract contacts, enrich your own CRMNo
Extract contacts, sell the listVery likely yes
Extract contacts, share with partners for their usePossibly yes
Build a contact database as your productYes
Extract for a client as a serviceIt depends — read on

The pivot is the direct relationship test: a data broker sells or shares personal information about consumers with whom it does not have a direct relationship. Using data yourself isn't brokering. Supplying it to others generally is.

ScrapeMaster keeps extracted data in your browser — nothing is uploaded — which is a good architectural default but doesn't answer the legal question. That depends entirely on what you do next.

General information, not legal advice. Definitions and thresholds vary by state and change. If you're near the line, get counsel.


What DROP actually requires

California's Delete Act created something that didn't exist before: one place a consumer submits a deletion request, and every registered data broker has to honour it.

The timeline:

DateWhat happened
January 1, 2026Consumer platform opened for submissions
August 1, 2026Data brokers must access DROP at least every 45 days
OngoingProcess valid deletion requests within each 45-day cycle
AnnuallyRegistration renewal with the CPPA

Two features make this materially different from the pre-existing deletion-request regime:

It's a pull, not a push. Brokers don't wait for a request to arrive; they have to go and check. "We never received it" stops being available as an explanation.

It's continuous. Every 45 days, indefinitely. Deleting a record once doesn't discharge the obligation — a broker that re-acquires the same person's data from a new source has to delete it again on the next check.

Penalties aren't capped, so exposure accumulates for as long as non-compliance continues.

Connecticut's law follows a similar registration model with its own requirements. The direction of travel across states is consistent, and it's toward more registration, not less.


The definition, taken seriously

The core statutory concept in California: a business that knowingly collects and sells personal information about consumers with whom the business does not have a direct relationship.

Three elements, all of which have to be present.

"Personal information"

Broad. Anything reasonably capable of being associated with a particular consumer or household.

Where this catches people out: business contact information about a named individual counts. jane.okafor@company.com identifies Jane Okafor. That it's a work address doesn't remove it from scope.

info@company.com is different — it identifies an organisation, not a person. That distinction is worth building into how you collect in the first place.

"Sells"

Broader than a cash transaction. California's definition of "sell" extends to sharing, disclosing, or making available personal information to another business for monetary or other valuable consideration.

"Other valuable consideration" is the phrase that does the work. Common arrangements that can qualify:

  • Trading lists with a partner
  • Providing data as part of a bundled service
  • Sharing data in exchange for reciprocal access
  • Contributing to a shared database in return for querying it

What generally isn't a sale: using data yourself, or a service provider processing it strictly on your instructions under a compliant contract and prohibited from using it for its own purposes.

"No direct relationship"

The one that decides most cases.

You have a direct relationship with someone who signed up, bought from you, subscribed, or contacted you.

You don't with someone whose details you extracted from a website they never gave you.

So: extract 500 contacts and email them yourself → no direct relationship, but no sale, so not a broker. Extract 500 contacts and sell the list → no relationship and a sale. That's the pattern.


Working through the real cases

Sales team building a prospect list

Extract company sites for named contacts, load into the CRM, run outreach.

Not a data broker. No sale. This is first-party use.

Still applies to you: GDPR or UK GDPR if any contacts are in Europe (lawful basis, privacy notice, honour objections), CAN-SPAM for US commercial email (accurate headers, physical address, working opt-out), and state privacy law obligations toward the individuals whose data you hold — including deletion requests they send you directly.

Not being a broker doesn't mean nothing applies. It means the registration regime doesn't.

Agency running outreach for a client

Extract contacts, run the campaign on the client's behalf.

Probably not a broker, if you're structured as a service provider: a written contract limiting you to processing on the client's instructions, prohibiting your own use, and prohibiting onward sale.

Where it breaks: if you build one contact database and reuse it across clients, you're no longer processing on one client's instructions. You're operating a product. Get advice before doing that.

Selling a list

Yes. No relationship, and a sale. Registration obligations attach.

Contact database as a product

Yes, clearly. This is the archetype the laws were written for.

"Free" enrichment tools

Users query your database, you don't charge them, they contribute data back.

Look very carefully. "Free" is not the test — "valuable consideration" is, and reciprocal data contribution is plausibly consideration. This is a model that needs actual legal analysis, not a blog post.

Academic or journalistic research

Generally outside the broker regime — no sale — and there are often specific exemptions. Data protection law still applies to personal data, with its own research provisions.


What compliance looks like if you are one

Not exhaustive, and jurisdiction-specific, but the shape:

Register. With the CPPA in California, and with Connecticut separately if in scope. Annual renewal, with a fee.

Access DROP every 45 days. Build it into an operational calendar with an owner, not someone's memory.

Process deletions across every system. Production database, backups, exports, anything you sent to a partner. Partial deletion isn't deletion.

Handle re-acquisition. If your pipeline pulls the same person back in from a new source next month, you have to delete again. In practice this means maintaining a suppression list keyed to deleted identities — which is the awkward part, since you're keeping a record of people who asked to be removed. Do it on a minimal, hashed basis and document why.

Keep provenance. Source and date per record. You may have to explain where data came from, and "our database" is not an answer.

Disclose in your privacy policy what you collect, sources, purposes, and who you share with.

Document your assessments. Risk assessments where required, and the reasoning behind your classification decisions.

That last one is worth doing even if you concluded you're not a broker. A dated memo explaining why is far more useful than reconstructing the reasoning under pressure two years from now.


Practices that keep you clearly on the right side

Regardless of classification, these reduce risk and cost almost nothing:

Prefer role-based addresses. sales@, info@, press@ are organisational rather than personal. Where either works, take the role-based one.

Collect only what you'll use. Data minimisation is a legal principle and a hygiene practice. Extracting every field because it's there creates obligations for data you'll never touch.

Record source and date on every row. Non-negotiable.

Honour opt-outs immediately, everywhere. One suppression list, checked before every send.

Don't bypass access controls. Logging in usually means you accepted terms, which usually restrict automated extraction. ScrapeMaster doesn't bypass paywalls, logins, or CAPTCHAs — it extracts what's already visible in your browser — but the terms you accepted still bind you.

Set a retention period and actually enforce it. Contact data decays fast: people change jobs, companies fold. An 18-month-old record is usually wrong anyway, so deleting it costs you nothing and reduces your exposure.

Keep data local where you can. Extracted records living in your browser rather than a vendor's cloud is fewer copies in fewer places under fewer processing agreements.


Comparison of the state regimes

CaliforniaConnecticutMost other states
Broker registrationYes, CPPAYesVaries (Texas, Oregon, Vermont have regimes)
Centralised deletion platformYes — DROP, live Aug 1, 2026No equivalent yetNo
Deletion checking cadenceEvery 45 days
Penalty capNoneStatutoryVaries
Direct-relationship testYesYesCommon

California's centralised platform is the structural innovation, and it's the one worth watching — because the pattern of brokers must come and check rather than consumers must find every broker is the part other states are most likely to copy.


Frequently asked questions

Am I a data broker if I scrape contacts for my own sales outreach?

Almost certainly not. The definition requires that you sell or share personal information about people you have no direct relationship with. Using extracted contacts for your own outreach involves no sale, so the broker registration regime doesn't attach. Data protection obligations still do — lawful basis under GDPR for European contacts, CAN-SPAM for US commercial email, and honouring deletion requests sent to you directly.

What changed on August 1, 2026?

Registered data brokers in California became obliged to access the Delete Request and Opt-Out Platform (DROP) at least once every 45 days and process the consumer deletion requests they find there. Before that date the platform was accepting consumer submissions but brokers weren't yet required to act on them. California doesn't cap penalties for violations.

Does selling a contact list once make me a data broker?

The definitions turn on knowingly collecting and selling personal information about consumers you have no direct relationship with, and a single sale can satisfy that. Whether registration obligations attach depends on the specific statutory thresholds in each state and how your activity is characterised. If you're contemplating selling a list you assembled, get advice before rather than after.

Is business contact information covered?

If it identifies an individual, yes — jane.okafor@company.com is personal information even though it's a work address. Role-based addresses like info@company.com identify an organisation rather than a person and are treated differently. Where either will serve your purpose, collecting the role-based address is the lower-risk choice.

What counts as "selling" data?

More than a cash sale. California's definition extends to sharing, disclosing, or making data available to another business for monetary or other valuable consideration — which can include trading lists, reciprocal data-sharing arrangements, or bundling data into a service. A genuine service provider processing strictly on a client's instructions under a compliant contract generally isn't selling.

If I run outreach for clients, am I a broker?

Usually not, if you're structured as a service provider: a written contract limiting you to the client's instructions, barring your own use of the data, and barring onward sale. It changes if you build one contact database and reuse it across clients — at that point you're operating a product rather than processing on instruction, and it needs real legal review.

Does keeping extracted data local help with compliance?

It helps with the practical parts: fewer copies, fewer third parties, fewer processing agreements, and a clearer answer to "where does this data live". ScrapeMaster stores extracted records in your browser's IndexedDB rather than a cloud service. It doesn't change your legal classification, which depends on what you do with the data afterwards.


Bottom line

The activity that makes you a data broker isn't extraction — it's supply. Collect contacts and use them yourself, and the registration regimes generally don't reach you. Sell or share them with businesses that had no relationship with those people, and they do.

August 1, 2026 sharpened this in California specifically: DROP now requires brokers to check for deletion requests every 45 days, indefinitely, with no cap on penalties for failing to. Connecticut has its own registration law and more states are following.

If you're anywhere near the line, the useful step this week is cheap: write down what you collect, where it comes from, who else gets it, and on what basis. That memo answers the classification question, and if the answer is "not a broker", it's the document that shows you asked.

ScrapeMaster is free, keeps extracted data in your browser, and doesn't bypass logins or access controls. For the wider legal picture see is web scraping legal, and for the extraction craft itself, extracting owner and manager details from company websites.

Unrelated, also free: CineMan AI.