HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

California Data Brokers Miss 70% of Deletion Requests and Violate Opt‑Out Rules, Highlighting CCPA Compliance Gaps

Researchers sent deletion and opt‑out requests to every California‑registered data broker; about 70 % of deletions were ignored and many opt‑outs demanded prohibited ID verification. The findings reveal widespread CCPA non‑compliance, underscoring the need for documented privacy‑request processes and audit‑ready evidence.

LiveThreat™ Intelligence · 📅 July 10, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
helpnetsecurity.com

Most Data Brokers Miss 70% of California Deletion Requests and Violate Opt‑Out Rules

What Happened — Researchers at UC Irvine sent 322 deletion and ~360 opt‑out requests to every data broker listed on California’s public registry. Roughly 70 % of deletion requests received no response, and overall response rates ranged from 26 % to 38 %. About 22 % of brokers that did reply demanded identity verification for an opt‑out, a practice expressly prohibited by the CCPA.

Why It Matters for Compliance & Audit Readiness

  • The study exposes a systemic failure to meet statutory privacy obligations, a scenario SOC 2 CC5.2 (Privacy) controls are designed to detect, document, and remediate.
  • Continuous evidence of DSAR handling, opt‑out processing, and verification of lawful friction‑less flows is essential to prove CCPA/GDPR readiness during audits.
  • Verifiable audit trails for each request (receipt, action, confirmation) become critical evidence for regulators and for internal risk‑based assessments.

Who Is Affected — Data‑broker firms, marketing‑technology platforms that source broker data, and any downstream organizations (employers, insurers, landlords, government agencies) that rely on broker‑supplied personal information.

Recommended Actions — Map CCPA deletion and opt‑out obligations to SOC 2 CC5.2 controls, implement a privacy‑request management workflow that automatically logs receipt, action, and confirmation, and collect immutable evidence for audit purposes. Periodically test the workflow against a sample of broker partners to verify compliance. Source: Help Net Security

Technical Notes — No software flaw is involved; the issue is procedural non‑compliance and excessive identity‑verification friction that breaches CCPA §1798.120. The data types at stake are personally identifiable information (PII) such as name, address, email, and demographic details. Source: same article

📰 Original Source
https://www.helpnetsecurity.com/2026/07/10/trouble-with-data-broker-deletion-requests/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

Data exposure is where consent and DSAR readiness get tested.

When personal data leaks, regulators ask what consent you held and how fast you can answer a subject request. The Verisq AI Trust Operations platform, with CookiePLUS, keeps that posture audit-ready under GDPR and CCPA.

Explore the Verisq AI Trust Operations platform →