Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Data Brokers topic
No spam. Unsubscribe anytime.
California officials brief Vermont senators on data-broker registry and mass-deletion system
Summary
California Privacy Protection Agency officials described their data-broker registry, 'drop' mass-deletion platform and funding model — including fees borne by brokers — and offered to collaborate as Vermont lawmakers weigh H211 and possible alignment with S71.
Get email alerts on the Data Brokers topic
No spam. Unsubscribe anytime.
Californians who run the state's privacy agency told the Vermont Senate Economic Development, Housing & General Affairs committee that the state’s data-broker registry and deletion platform aim to give residents more control over third-party data and that the system has been funded by broker registration fees rather than the general fund.
Tom Kemp, executive director of the California Privacy Protection Agency, told senators the agency supports the registry-and-delete combination in H211 and said California’s approach pairs a public registry of brokers with a 'drop' system that can process deletions at scale. "We do share enforcement with the attorney general of California," Kemp said, and he described the agency’s role implementing the state’s delete act and related registry rules.
Why it matters: Vermont’s H211 would create a data-broker registry and some deletion tools; California’s experience shows trade-offs for scale, cost and enforcement. Committee members pressed witnesses on security, costs and whether California might license or share its platform so Vermont would not have to build a similar system from scratch.
Kemp outlined key operational features. The registry lists companies that collect and sell data; California requires brokers to register and pay a fee (Kemp said the current registration fee is $6,000), and the state’s registry has grown to several hundred registered brokers. "The data broker fees ... paid for the registry and the drop system," Kemp said. He added that the drop platform stores a hashed verification of users so the agency cannot identify them, ties into identity verification options such as login.gov, and allows users to submit a short profile (email, phone, zip, date of birth and optional mobile advertising ID) to seek deletions and ongoing suppression.
Kemp said California expects a phased rollout: the registry went live and the deletion workflow will begin when brokers must match and process deletion requests (Kemp said deletions are slated to start in August). He also said consumers have already begun using the system: "over 286,000 Californians have already signed up in the first few months," Kemp said, noting that public uptake may grow as deletion processing begins.
Enforcement and penalties were a focal point. Kemp described statutory penalties for failure to register or to process deletions (he cited a $200-per-day figure used in California’s framework, explaining failure-to-delete fines can be assessed per consumer request) and said auditing of deletion compliance is part of the statutory scheme (Kemp noted audits start in 2028 under California’s schedule).
Committee members raised several practical concerns. Senators asked whether the registry itself could become a security target, who ultimately bears compliance costs, and how the system handles entities exempt under federal law (for example, credit reporting agencies covered by the Fair Credit Reporting Act). Kemp said credit-reporting agencies are exempt under federal law but may operate subsidiaries that act as data brokers; he also said California’s model is funded by data-broker fees and suggested Vermont could consider using registry fees rather than general funds to pay for a study or platform.
Several members also asked whether California would permit other states to subscribe to or license its deletion technology. Kemp said California is open to collaboration and sharing where permissible but cannot promise a specific licensing arrangement without more detail on Vermont’s needs.
The session included examples of harms the deletion regime aims to address: Kemp cited large broker dossiers that can be many pages long, sales of inferred sensitive attributes and instances of broker data used by actors with malicious intent. He referenced an external report attributing large consumer costs to broker breaches; committee members used that account to press the witnesses about registry security and transparency.
What’s next: Cal Privacy officials offered to continue discussions and to share more technical and legal detail as Vermont staff and the secretary of state's office evaluate whether to adopt similar registry or deletion approaches. The committee will continue work on H211 and consider whether to incorporate additional elements from S71 or to pursue a separate alignment process.

