Most Data Brokers Miss 70% of California Deletion Requests and Violate Opt‑Out Rules
What Happened — Researchers at UC Irvine sent 322 deletion and ~360 opt‑out requests to every data broker listed on California’s public registry. Roughly 70 % of deletion requests received no response, and overall response rates ranged from 26 % to 38 %. About 22 % of brokers that did reply demanded identity verification for an opt‑out, a practice expressly prohibited by the CCPA.
Why It Matters for Compliance & Audit Readiness
- The study exposes a systemic failure to meet statutory privacy obligations, a scenario SOC 2 CC5.2 (Privacy) controls are designed to detect, document, and remediate.
- Continuous evidence of DSAR handling, opt‑out processing, and verification of lawful friction‑less flows is essential to prove CCPA/GDPR readiness during audits.
- Verifiable audit trails for each request (receipt, action, confirmation) become critical evidence for regulators and for internal risk‑based assessments.
Who Is Affected — Data‑broker firms, marketing‑technology platforms that source broker data, and any downstream organizations (employers, insurers, landlords, government agencies) that rely on broker‑supplied personal information.
Recommended Actions — Map CCPA deletion and opt‑out obligations to SOC 2 CC5.2 controls, implement a privacy‑request management workflow that automatically logs receipt, action, and confirmation, and collect immutable evidence for audit purposes. Periodically test the workflow against a sample of broker partners to verify compliance. Source: Help Net Security
Technical Notes — No software flaw is involved; the issue is procedural non‑compliance and excessive identity‑verification friction that breaches CCPA §1798.120. The data types at stake are personally identifiable information (PII) such as name, address, email, and demographic details. Source: same article