PrivacySignal
News

California to increase data broker registration fees, start audit rulemaking

MLex · · International · Privacy Law

California is moving to raise the fees data brokers must pay to register with the state and is beginning the rulemaking process to establish audit requirements for those companies. The changes would expand the regulatory pressure on an industry that profits from collecting and selling personal information.

Why this matters: Data brokers sell your personal information to anyone willing to pay, and most people have no idea it is happening. California has required these companies to register for a few years, but registration without enforcement is just a list. Starting an audit process is the part that could actually matter. It means the state may start checking whether brokers are following the rules, not just whether they filed the paperwork. Higher fees will not bother the big players much, but real audits could. Watch what the audit rules actually require when they come out.

Who should care: Lawyers · Compliance · General readers · Privacy officers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

The Attacker Did Not Need to Sleep

Spain received its first reported personal-data breach carried out by an AI agent. The techniques were familiar. The speed and autonomy were not.

· 4 min read Read →

Related stories

News
Inside Privacy (Covington) · · International

California Enacts Several Minors’ Privacy and Safety Laws

Recently, California Governor Gavin Newsom signed a sweeping set of laws related to minors’ privacy and safety, including new laws that restrict covered platforms from providing certain features to users under 16, impose a duty of care on social media platforms, revise the state’s Age-Appropriate Design Code, modify the state’s age-assurance requirements governing age signals,... Continue Reading…

Who should care: General readers · Privacy officers · Policy

News
Inside Privacy (Covington) · · International

The EU KIDS Act Proposal: Towards a New Regulatory Framework for the Protection of Children Online

On September 17, 2026, the European Commission (the “Commission”) published its proposal for a new EU framework on child safety online (the “KIDS Act”). The proposed Regulation aims to introduce EU-harmonized age-based account restrictions, safety-by-design rules, and age-assurance obligations across a broad range of digital services and systems. The proposal is the latest of a... Continue Reading…

Who should care: Lawyers · Compliance

#regulation Read original →