California Has Proposed Rules Requiring Data Brokers to Be Audited — and the Broker Signs the Independence Certification
On 7 August 2026 the California Privacy Protection Agency board voted a package of proposed data broker audit regulations out to formal rulemaking. They are proposed sections 7630 through 7633, and if you are a registered data broker they are the most consequential thing on your horizon that nobody in your building is talking about yet.
Two housekeeping points before anything else, because they get garbled constantly:
- These are proposed. They are not in force. Nothing below is a current legal obligation.
- The public comment window is not open. As of this writing the Agency's regulations page states that it has no proposed regulation packages pending. The comment clock does not start on a board vote; it starts on publication of the notice in the California Regulatory Notice Register. If you have read that a forty-five day window is running, that is wrong.
With that said, here is what the package would do.
The clock already started, even though the rule has not
This is the single most important sentence in the package, and it is easy to skim past.
Proposed § 7630(a) would require a data broker's first audit report by 1 November 2028, covering the period 1 August 2026 through 1 August 2028. Audits at least every three years after that.
Read the audit period again. It opened on 1 August 2026 — the same day DROP processing obligations began, and a month before this paragraph was written. The rule that would require the audit is not final. The window it would examine is already open and accumulating.
That is not a trap; it is simply how a rule that looks backward at a statutory obligation has to work. But it has a practical consequence for every registered broker: the evidence an auditor would examine in 2028 is the evidence you are creating or failing to create right now. Records not kept in September 2026 cannot be reconstructed in 2028.
What the audit would actually test
Proposed § 7632 is not a paperwork review. It is a testing scope, and it reads like one:
- accuracy of deletion-list selection
- timeliness of DROP access against the forty-five day requirement
- accuracy of the hashing process
- accuracy of identifier matching
- completion of the actions the broker determined to take
- accuracy of the status the broker reported
- maintenance of the suppression list
- direction given to service providers and contractors
Every one of those is a claim about a system's behavior over time. You cannot answer any of them with a policy document. You answer them with logs, timestamps, samples, and dated observations — or you do not answer them.
The independence provision, which is the part with teeth
Proposed § 7631(a) would require the auditor to apply "procedures and standards generally accepted in the auditing profession," with at least one auditor knowledgeable about data deletion practices and the Delete Act, and at least one competent in the relevant data systems.
Then § 7631(b)(1) disqualifies the auditor. The auditor must not:
(A) "Be employed by or an independent contractor of the data broker for any other purpose than conducting the DROP audit"
(B) "Be an officer or director of the data broker"
(C) "Have or be affiliated with an entity that has a financial interest in the data broker or any of its affiliates"
(D) "Have participated in business activities that the auditor will assess in the audit, including developing procedures, preparing the business's documents, making recommendations regarding the business's data broker processing operations (separate from articulating audit findings), or designing, implementing, operating or maintaining the data broker's deletion processing systems, controls, or procedures"
Subsection (D) is doing enormous work. Note precisely where it draws its line: articulating audit findings is carved out; making recommendations about the broker's processing operations is not. A firm that tells a broker how to fix its deletion pipeline has, by the plain text, participated in the business activities it would later be assessing.
And note what the package does not contain. The definitions section does not define "independent contractor." There is no de minimis threshold, no materiality qualifier, and no carve-out for arm's-length or commodity purchases. As drafted, the text does not on its face distinguish a multi-year consulting engagement from a routine vendor relationship. Whether that is intended is exactly the kind of question a comment period exists to resolve — which is one more reason to know when the window actually opens.
The certification, and who signs it
Here is the design choice that changes the incentives.
Proposed § 7633(a)(12) would require the audit report to include a certification, by the data broker's executive management, under penalty of perjury, that the auditor met the § 7631 independence requirements.
Not the auditor certifying its own independence. The broker's executives certifying it, personally, on penalty of perjury, about a firm they hired.
Think about what that does to a procurement conversation. Every prior commercial relationship between the broker and the audit firm becomes something an executive has to be willing to swear about. The natural response of any competent general counsel is to insist on an auditor with no prior commercial history with the company at all — because "probably fine" is not a comfortable posture when the sentence ends in "under penalty of perjury."
The likely market effect, if this text survives to final: the vendors closest to brokers' deletion operations today — the ones who built the pipelines, who advise on the workflows, who sit in the DROP integration meetings — are the ones least able to sign the audit in 2028.
What a registered broker should do about it now
Not legal advice; a list of things that are cheap now and impossible later.
- Start keeping the evidence § 7632 would test. Access timestamps against the forty-five day floor. Matching outcomes. Status reported and when. Suppression-list state over time. If you keep nothing else, keep dated records.
- Take dated outside observations. An internal log is your own account of your own behavior. A third-party observation taken on a date you did not control is a different kind of record, and the audit period is running now.
- Map your vendor bench against § 7631(b)(1). Not to act on it yet — the rule is proposed — but so that you know today which of your current advisors would be disqualified from auditing you, before you deepen a relationship you will have to unwind.
- Watch the Regulatory Notice Register, not the news. The comment window is the only moment the text is movable, it opens on publication, and by the time it is being discussed publicly a meaningful fraction of it has usually elapsed.
Frequently asked questions
Are these rules in effect?
No. They are proposed. They were voted out to formal rulemaking on 7 August 2026 and would take effect only after the rulemaking process concludes.
Is the public comment period open?
Not as of this writing. The Agency's regulations page states it has no proposed regulation packages pending. The comment period begins on publication of the notice in the California Regulatory Notice Register.
When would the first audit report be due?
Under proposed § 7630(a), 1 November 2028, covering 1 August 2026 through 1 August 2028, and at least every three years thereafter.
Can a broker's existing privacy vendor perform the audit?
Under the proposed text, that depends on § 7631(b)(1) — in particular whether the vendor is an "independent contractor of the data broker for any other purpose," holds or is affiliated with a financial interest, or participated in the activities being assessed, including making recommendations regarding the broker's data broker processing operations. The term "independent contractor" is not defined in the package, which is a genuine open question rather than a settled one.
Who certifies the auditor's independence?
Under proposed § 7633(a)(12), the data broker's executive management, under penalty of perjury.
Disclosure
I run Sirveil, a small California company whose service determines whether a named individual's information is publicly indexed at a named website at a given moment, and reports that observation as INDEXED, NOT INDEXED, or INDETERMINATE. We do not audit anyone and we do not certify anyone's compliance; index presence is not proof that a deletion request was ignored, and index absence is not proof that data was deleted. I have a commercial interest in how deletion and verification get regulated, including a plain interest in how these particular sections come out, and I disclose it wherever I write. That is a reason to read this skeptically. It is not a reason to leave the text unread.
Sources: proposed CCPA regulations §§ 7630–7633 as advanced to formal rulemaking by the California Privacy Protection Agency board on 7 August 2026; CPPA regulations page. Read 5 September 2026.
NONE OF THIS CONSTITUTES LEGAL ADVICE. The author writes as a commercial party with a disclosed interest, not as counsel. Every provision discussed here is proposed and subject to change or withdrawal during rulemaking. Confirm the current text and status with the Agency and with your own counsel before relying on any of it.