Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

INADVERTENT CLASSIFICATION: IS YOUR B2B ENTERPRISE A DATA BROKER?

Дата публикации: 07-10-2026 20:35:50



Основное содержимое страницы с новостью.

INADVERTENT CLASSIFICATION: IS YOUR B2B ENTERPRISE A DATA BROKER?

Wednesday, October 7, 2026

The Registry Does Not Read Your Pitch Deck

Ask the chief executive of a sales intelligence platform whether the company is a data broker, and you will get the look usually reserved for someone who asks whether a craft brewery is “basically a bar.”  Data brokers are other people: the people-search sites, the list merchants, and the firms whose home pages feature a stock photo of a padlock.  Your company sells “revenue intelligence.”  It licenses “firmographic enrichment.”  It has a mission statement about who and what the company is.

Unfortunately, state legislatures did not consult companies’ mission statements before enacting legislation.  The short answer for most companies that license business contact databases, customer insights, or enrichment application programming interfaces (APIs) is this: you sit closer to the registry than you think, and in Texas the line moved toward you on September 1, 2025.  These statutes regulate what a company does with information about people it never met.  They do not ask whether those people were at work when you profiled them.  A vice president of procurement remains, inconveniently, an individual.

Texas Rewrote the Definition While You Were Shipping Features

When Texas enacted its data broker law in 2023, the definition reached only a business “whose principal source of revenue” came from collecting, processing, or transferring personal data it did not collect directly from the individual.[1]  A software company with a data feature could read that sentence and go back to work.

Senate Bill 2121 ended that comfort.  Governor Abbott signed the bill on June 20, 2025, and it took effect on September 1, 2025.[2]  A data broker is now “a business entity that collects, processes, or transfers personal data that the business entity did not collect directly from the individual linked or linkable to the data.”[3]  The principal-revenue qualifier is gone.  The Legislature acted at the request of the Office of the Attorney General, which reported that companies were using a mismatch between the definition and the applicability section to argue that the law did not apply to them.[4]  When the enforcement agency drafts the fix, counsel should assume the agency plans to use the updated enforcement scope.

Some details deserve closer inspection.  First, the verbs are “collects, processes, or transfers.”  The statute does not require a sale.  A company that buys third-party data and processes it to generate revenue can qualify, which means the customer on the receiving end of an enrichment API has the same question to answer as the vendor.[5]  Second, a housekeeping note that will save an afternoon of confusion: the 2023 act and most commentary cite Chapter 509 of the Business and Commerce Code, while the Secretary of State now administers the program under Chapter 510.[6]  The state updated some of its Chapter numbering.  This article uses the Chapter 510 numbering.

The Statutory Thresholds

Chapter 510 applies only to a data broker that, in a 12-month period, derives either (1) more than 50 percent of its revenue directly from processing or transferring personal data that it did not collect directly from the individuals, or (2) revenue directly from processing or transferring the personal data of more than 50,000 individuals that it did not collect directly from those individuals.[7]

The first prong describes a traditional data broker.  The second prong describes almost everyone else.  Fifty thousand records is a rounding error in a contact database and a slow Tuesday for an enrichment API.  The statute sets no minimum dollar amount; it asks only whether revenue flows directly from the processing or transfer.

That word “directly” is new, undefined, and unexplained by any legislative history.  Commentators have noted that a company might argue its revenue comes from software subscriptions or campaign results and only indirectly from the data underneath.[8]  The argument is respectable, and a strong one in my opinion.  However, the argument is also untested, and the Attorney General will likely test it with someone as the defendant.  If your price list charges per record, per match, or per API call, or if the customer would cancel the subscription the day the database went dark, you should plan as though the revenue is directly tied to the second prong.

What Registration Actually Costs

The filing itself is almost insultingly cheap: a registration statement and $300, renewed each year for another $300.[9]  The cost sits in what comes with it.

A registered broker appears on a public, searchable registry that discloses the categories of data it processes, its purchaser credentialing practices, and the number of security breaches it suffered in the prior year.[10]  It must post a conspicuous notice on its website or mobile application stating that it is a data broker, and a companion 2025 bill, Senate Bill 1343, requires that notice to tell consumers how to exercise their rights under the Texas Data Privacy and Security Act.[11]  Marketing and sales departments tend to have feelings about that banner.

The heavier lift is the comprehensive information security program.  The statute requires a written program with a designated employee in charge, a risk assessment process, training for employees and contractors (including temporary ones), contractual security requirements for service providers, encryption of personal data on laptops and portable devices, annual review, and a documented post-incident review after every breach.[12]  A company that never considered itself a broker has likely never measured itself against that list.

The civil penalty for failing to register is $100 per day, capped at $10,000 in a 12-month period, plus unpaid fees.[13]  That cap invites a cynical calculation that the financial risk is nominal, and the calculation is wrong.  The Attorney General treats violations of the chapter as deceptive trade practices; the registry makes non-registration easy to prove.  The Attorney General may seek up to $10,000 per violation, consumer restitution, and injunctive sanctions among other remedies. The Texas Attorney General office has shown its interest.[14]  In June 2024, it sent letters to more than 100 companies that appeared to have skipped registration.[15]  In January 2025, it sued Allstate and its analytics subsidiary, Arity, alleging among other claims that Arity derived revenue from processing and transferring the personal data of more than 45 million app users without registering.[16]  Arity sold analytics to businesses.  It presumably did not think of itself as a data broker.

The Exits, None of Which Is Marked “B2B”

Chapter 510 offers several ways out of the classification.  Counsel should test each one against the facts, not against the sales team’s description of the product.

1.      Direct collection.  Data the company collects directly from the individual falls outside the definition.  A form the prospect filled out counts.  A record your customer uploaded about that prospect does not.

2.      Service provider status.  The chapter does not apply to a service provider, meaning a company that processes personal data on behalf of, and at the direction of, another business.[17]  This exit closes the moment the company keeps, pools, or reuses customer-supplied records to improve its own database.

3.      Affiliate sharing.  The chapter exempts data collected from an entity related by common ownership or corporate control, but only where a reasonable consumer would expect the entities to share data.[18]  Shared ownership that the consumer has never heard of is a risky foundation.

4.      Publicly available, deidentified, and employee data.  The definition of personal data excludes all three.[19]  This is the exit B2B vendors reach for first, and it holds for a name, title, and employer drawn from widely distributed sources.  It strains under direct-dial mobile numbers, personal email addresses, device or IP resolution, and “intent” signals.  The employee data exclusion protects an employer handling its own workforce records; it does not bless a third party’s database of other companies’ employees.

5.      Federal financial statutes.  The chapter exempts financial institutions subject to Title V of the Gramm-Leach-Bliley Act, and consumer reporting agencies and furnishers to the extent they engage in activity the Fair Credit Reporting Act regulates.[20]  Confirm that the exempt entity is the one doing the brokering. 

Notice what the list omits.  The Texas comprehensive privacy statute excludes individuals acting in a commercial or employment context; the listed exceptions in Chapter 510 contain no parallel carve-out for business contact data.  A B2B label describes your customer.  It does not describe the people in your database.

Texas Is Not the Only Registry

A company that licenses person-level data nationally faces at least five registration regimes, and each draws its line in a different place.

State Trigger The B2B angle Cost of missing it
Texas Collects, processes, or transfers personal data not collected directly, plus one of two revenue thresholds.[21] No sale required.  No listed carve-out for business contact data. $100 per day, capped at $10,000 per 12 months, plus deceptive trade practice exposure.[22]
California Knowingly collects and sells personal information of a consumer with whom the business has no direct relationship.[23] A direct relationship requires the consumer’s intentional interaction within three years.  A business with that relationship is still a broker for data it obtained elsewhere.[24] $200 per day with no cap; registration fee rising from $6,000 to $9,500 in January 2027.[25]
Vermont Knowingly collects and sells or licenses brokered personal information of a consumer with no direct relationship.[26] Excludes publicly available information related to a consumer’s business or profession, the closest thing to a true B2B safe harbor in any of these statutes.[27] 2026 amendments set a $900 fee, a $20,000 bond, and $200 per day for failure to register.[28]
Oregon Collects and sells or licenses brokered personal data to another person.[29] Excludes data about the company’s own customers and employees. Up to $500 per day, capped at $10,000 per calendar year.[30]
New Jersey Covers data brokers and “data collectors” that sell or license data to brokers.[31] Reaches the originating business, not only the aggregator. Registry opens March 27, 2027; fees from $5,000 to $1.5 million; $2,500 per day.

California supplies a strong cautionary tale.  In December 2025, the California Privacy Protection Agency (nka CalPrivacy) fined S&P Global Inc. $62,600 for failing to register.  The company is a financial analytics firm, about as far from a people-search site as a business can get.  It intended to register, believed it had finished, and discovered during the agency’s investigation that the filing never went through.  The agency charged $200 for each of 313 days.[32]  The order also confirms that a business that independently meets the definition must register on its own, whatever its position in the corporate family.[33]  If a company with S&P’s compliance budget can pay five figures for an unfinished web form, yours can too.

Ten Questions Counsel Should Ask

1.      Where did each person-level field come from?  Sort every field into collected directly, supplied by a customer, purchased, scraped, or inferred.  Only the first category is safe by definition.

2.      How many individuals?  Count distinct individuals whose data the company did not collect directly over a rolling 12 months.  If the number exceeds 50,000, the Texas analysis turns entirely on revenue.

3.      Does revenue flow directly from that data?  Read the price list and the order forms.  Per-record, per-match, and per-call pricing answers the question.  So does a seat license for a product that is, functionally, the database.

4.      Are we a service provider in practice?  Check whether the contracts confine processing to the customer’s direction and whether engineering honors that limit.  “Give to get” contributory networks and shared identity graphs defeat the exemption.

5.      Is the data truly publicly available?  Test each field against the statutory definition.  Ask where the mobile numbers and personal email addresses originated, and whether any inference reveals sensitive data.

6.      Do we sell, license, or share data about former customers?  California’s three-year rule converts dormant customer records into brokered data.[34]

7.      Which legal entity does the brokering?  Map the activity to the entity, then test that entity’s exemptions and registration duty on its own.

8.      Does our vendor’s data make us a broker?  Under the Texas verbs, processing purchased third-party data for revenue is enough.[35]  Review inbound data licenses with the same care as outbound ones.

9.      What changed since last year?  Acquisitions, new enrichment features, and new data partnerships move companies across the line.  Calendar the analysis annually and on every product launch that adds a data source.

10.    If we must register, who owns the filing, and can we pass the security program today?  Assign a named owner, confirm the filing actually completed, and measure the written security program against the statutory checklist before the notice goes on the website.

The Good News

None of this requires a new business model.  The analysis is finite: a data inventory, a headcount, a revenue trace, and a written conclusion that counsel can defend.  A company that reaches “yes” in Texas pays $300 and adopts a security program that closely tracks what its enterprise customers already demand in procurement questionnaires.  A company that reaches “no” holds a memorandum explaining why, which is worth far more than an assumption when the Attorney General’s letter arrives.

The work is usable across multiple states.  The same inventory answers California, Vermont, Oregon, and New Jersey, and it will likely answer the next state that copies them.  Registered status has become a selling point with buyers whose own counsel now ask where vendor data comes from.  The companies that do this exercise on their own schedule spend a few weeks and a modest budget.  The companies that wait do the same exercise later, with a regulator setting the deadlines.

If your organization licenses contact data, customer insights, or enrichment services and has not yet answered these questions in writing, the Troutman Amin team welcomes the conversation.  Please reach out to discuss how the firm may assist with a classification assessment, registration, or the security program that follows.

Disclaimer: This article provides general informational and educational content only and does not constitute formal legal advice.  The information contained herein may not reflect the most current legal developments, verdicts, or settlements.  Reading this article, transmitting information through related platforms, or contacting the author does not create an attorney-client relationship.  Readers should not act or refrain from acting based on any information in this article without seeking professional legal counsel tailored to their specific jurisdiction, facts, and circumstances.  The author expressly disclaims all liability with respect to actions taken or not taken based on any or all contents of this publication.

Endnotes

[1] Office of the Attorney General of Texas.  “Texas Data Broker Act.”  Texas Attorney General, https://www.texasattorneygeneral.gov/consumer-protection/file-consumer-complaint/consumer-privacy-rights/texas-data-broker-act.  Accessed October 7, 2026.

[2] Nahra, Kirk J., et al.  “Texas Expands and Modifies Data Broker Registration Law.”  WilmerHale Privacy and Cybersecurity Law Blog, September 4, 2025, https://www.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20250904-texas-expands-and-modifies-data-broker-registration-law.

[3] Texas State, Legislature.  Senate Bill 2121.  Texas Legislature Online, 89th Legislature, Regular Session, enrolled 2025, https://capitol.texas.gov/tlodocs/89R/billtext/html/SB02121F.htm.

[4] Texas State, Senate Research Center.  “Bill Analysis: S.B. 2121.”  Texas Legislature Online, 2025, https://capitol.texas.gov/tlodocs/89R/analysis/html/SB02121F.htm.

[5] Rozen, Marci, and Lucia Martinez.  “Data Broker Rules from Regulators May Catch Businesses Off Guard.”  Bloomberg Law, April 2, 2026, https://news.bloomberglaw.com/legal-exchange-insights-and-commentary/data-broker-rules-from-regulators-may-catch-businesses-off-guard.

[6] Texas Secretary of State.  “Data Brokers.”  Texas Secretary of State, https://www.sos.texas.gov/statdoc/data-brokers.shtml.  Accessed October 7, 2026.

[7] Texas State, Legislature, Senate Bill 2121.

[8] “Texas Legislature Amends Data Broker Law to Broaden Definition, Arguably Narrow Applicability Thresholds.”  Privacy World, Squire Patton Boggs, July 2025, https://natlawreview.com/article/texas-legislature-amends-data-broker-law-broaden-definition-arguably-narrow. 

[9] Texas Secretary of State.  “Frequently Asked Questions for Data Brokers.”  Texas Secretary of State, https://www.sos.state.tx.us/statdoc/faqs4000.shtml.  Accessed October 7, 2026.

[10] Texas Secretary of State, “Frequently Asked Questions.”

[11] Nahra et al., “Texas Expands.”

[12] Texas State, Legislature.  Senate Bill 2105.  Texas Legislature Online, 88th Legislature, Regular Session, enrolled 2023, https://capitol.texas.gov/tlodocs/88R/billtext/html/SB02105E.htm.

[13] Office of the Attorney General of Texas, “Texas Data Broker Act.”

[14] Office of the Attorney General of Texas, “Texas Data Broker Act.”

[15] Office of the Attorney General of Texas.  “Attorney General Ken Paxton Notifies Over 100 Companies of Their Apparent Failure to Comply with the Texas Data Broker Law That Protects Consumer Privacy.”  Texas Attorney General, June 18, 2024, https://texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-notifies-over-100-companies-their-apparent-failure-comply-texas-data.

[16] Nahra, Kirk J., et al.  “Texas AG Brings First Ever Lawsuit Under a State Comprehensive Privacy Law.”  WilmerHale Privacy and Cybersecurity Law Blog, January 21, 2025, https://www.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20250121-texas-ag-brings-first-ever-lawsuit-under-a-state-comprehensive-privacy-law.

[17] Texas State, Legislature, Senate Bill 2105.

[18] Texas State, Legislature, Senate Bill 2105.

[19] Texas State, Legislature, Senate Bill 2105.

[20] Texas State, Legislature, Senate Bill 2105.

[21] Texas State, Legislature, Senate Bill 2121.

[22] Office of the Attorney General of Texas, “Texas Data Broker Act.”

[23] Yadav, Shivangi.  “Data Broker Regulation Framework: A Comparative Analysis of California, Texas, Vermont and Oregon.”  California Lawyers Association, April 21, 2026, https://calawyers.org/privacy-law/data-broker-regulation-framework-a-comparative-analysis-of-california-texas-vermont-and-oregon/.

[24] Lyon, Christine, et al.  “California Expands Its Data Broker Rules in the B2C Context: Unpacking California’s New Delete Act Regulations.”  Freshfields Risk and Compliance Blog, November 25, 2024, https://www.freshfields.com/en/our-thinking/blogs/risk-and-compliance/california-expands-its-data-broker-rules-in-the-b2c-context-unpacking-california-102jpj1.

[25] “California Data Broker Updates.”  WilmerHale Privacy and Cybersecurity Law Blog, August 19, 2026, https://www.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20260819-california-data-broker-updates.

[26] Vermont State, Legislature.  Vermont Statutes Annotated, Title 9, Section 2430.  Vermont General Assembly, https://legislature.vermont.gov/statutes/section/09/062/02430.  Accessed October 7, 2026.

[27] Vermont Statutes Annotated, Title 9, Section 2430.

[28] Vermont State, Legislature.  Act No. 138 (H.211), An Act Relating to Data Brokers and Personal Information.  Vermont General Assembly, June 16, 2026, https://legislature.vermont.gov/Documents/2026/Docs/ACTS/ACT138/ACT138%20As%20Enacted.pdf.

[29] Oregon State, Legislature.  Oregon Revised Statutes, Section 646A.593.  Oregon Public Law, https://oregon.public.law/statutes/ors_646a.593.  Accessed October 7, 2026.

[30] Oregon Revised Statutes, Section 646A.593.

[31] “New Jersey Enacts Sweeping Data Broker and Data Collector Registration Law.”  Faegre Drinker Biddle & Reath LLP, July 2026, https://www.faegredrinker.com/en/insights/publications/2026/7/new-jersey-enacts-sweeping-data-broker-and-data-collector-registration-law.

[32] California Privacy Protection Agency.  In the Matter of S&P Global Inc., Final Order.  December 22, 2025, https://cppa.ca.gov/pdf/sp_global_inc_fo_signed.pdf.

[33] Cohen, Allison.  “CPPA Acts to Enforce Against Data Brokers’ Failure to Register.”  Loeb & Loeb LLP, January 9, 2026, https://www.loeb.com/en/insights/passle/2026/01/cppa-acts-to-enforce-against-data-brokers-failure-to-register.

[34] Lyon et al.

[35] Rozen and Martinez.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1California’s Expanded Pay Data Categories: Now Is the Time to Start SOC Mapping01007-10-2026
2Web Scraping vs API for Social Media Data: Which Is Better for Brands?05.7519-03-2026
3Global AI and Data Compliance: Why U.S. Employers Can’t Afford a U.S.-Only Lens017.6907-10-2026
4Trending Music: A Hidden Copyright Risk in Influencer Marketing01007-10-2026
5UK Expands Iran Sanctions: What the 2026 Regulations May Mean for Businesses018.3307-10-2026
6Are you the ‘digital PA’ for your parents?01026-09-2026
7Ответы ИИ: говорят ли нейросети о вашей компании? Листайте карточки ...03.7329-09-2026
8What Your Software Company Is Worth Now01007-10-2026
9IDC Survey Spotlight: How Do B2B Buyers Across Market Segments Use Social Channels?07.3225-09-2026
10An SEO guide for B2B marketers06.416-04-2026

Классификация: . Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 10. Источник: www.natlawreview.com.