Outbound teams have treated purchased contact data the way offices treat stationery: a procurement line, renewed annually, chosen on coverage and price. Three separate regulatory developments landed between February and August that make that framing untenable, and the most consequential of them went live three weeks ago with almost no coverage in the sales press.
What went operational on 1 August
Under California's Delete Act, registered data brokers must now access the state's accessible deletion mechanism — DROP — at least once every 45 days and process the consumer deletion requests they find there. That obligation became operational on 1 August 2026. Registration ran through January 2026 at $6,000 a year, with a $200-per-day penalty for late registration.
The enforcement is not theoretical, and it is not aimed at the consumer-data industry the law was written about in the abstract. The California Privacy Protection Agency's Data Broker Enforcement Strike Force, announced 19 November 2025, has settled with Growbots, Inc. and UpLead LLC for roughly $35,000 each. Both are B2B sales-prospecting data vendors. The agency has also proposed a $46,000 fine against a registrant 230 days late, and ordered Background Alert, Inc. to shut down or pay $50,000.
Read the names again. These are not brokers selling household demographics. They are the tools sitting in the outbound stack of a large number of B2B companies.
Deletion flows to the source. It does not flow to the copy. If your CRM holds records a vendor has been ordered to delete, nothing automatically reaches into your instance and removes them — and nobody has built the reconciliation that would.
The copy problem
This is the part worth sitting with, because it is where the exposure quietly transfers from vendor to buyer.
A deletion request processed by a broker removes a record from the broker's database. Every enrichment sync you ran before that date already deposited a copy in your CRM, your engagement platform, your data warehouse and probably a marketing automation instance. Those copies do not carry a pointer back to the source. When the source deletes, your copies persist — and they persist in systems you are actively sequencing from.
Most enrichment contracts describe what happens when you stop paying. Very few describe what happens when the vendor is compelled to delete a record you have already ingested, and almost none establish a suppression feed you could act on. That gap is not a technicality. It is the difference between a vendor's compliance problem and yours.
Two more moved in the same window
The Delete Act did not arrive alone, and the pattern across the three is more interesting than any of them individually.
Visual 1 — Three regimes, one practice
Development | Date | What it touches | Where the exposure sits |
|---|---|---|---|
California Delete Act / DROP | Operational 1 Aug 2026; 45-day processing duty | Purchased and enriched contact data | Brokers directly; downstream holders through retained copies with no suppression path |
EU AI Act, Article 50 | Applies 2 Aug 2026; grace to 2 Dec 2026 for marking pre-existing systems | AI SDRs, chat qualification bots, AI-written outbound reaching EU recipients | The deployer — you — must disclose that the counterpart is an AI system. Up to €15m or 3% of worldwide turnover |
TCPA consent standard | Fifth Circuit, Bradford v. Sovereign Pest Control, 25 Feb 2026 | Automated and prerecorded calls to mobiles | Fragmenting: the court rejected the FCC's written-consent requirement, but only within the Fifth Circuit. The FCC's revoke-all rule still lands 31 Jan 2027 |
How to read it: Three unrelated regimes converged within six months on the same activity — outreach at scale, using acquired data, increasingly executed by software. The common demand is provenance and disclosure: prove where the record came from, and say what is doing the talking.
The one most teams will get wrong
Article 50 deserves separating out, because there is a widespread and expensive misreading of what happened in Brussels this summer.
The EU's Digital Omnibus deferred the AI Act's high-risk obligations substantially — stand-alone high-risk systems moved from August 2026 to 2 December 2027. A great many teams heard "AI Act delayed" and stopped there. Article 50 was not delayed. From 2 August 2026, systems that interact directly with people must disclose that the person is dealing with an AI system, and AI-generated content requires machine-readable marking, with a four-month grace to 2 December 2026 for systems already on the market.
An AI SDR emailing or chatting with an EU-based prospect is squarely in scope. The disclosure obligation is not onerous — it is a line of copy and a configuration change. The exposure for skipping it, up to €15m or three per cent of worldwide turnover, is not proportionate to how easy it is to fix, which is precisely why it is worth fixing this month rather than next quarter.
Why this is not simply a legal problem
The instinct will be to route this to counsel and carry on. That underrates how much of it is operational and how little of it lawyers can do for you.
Nobody in the legal function can tell you which of your 400,000 CRM contacts came from which vendor, on which date, under which contract. In most organisations that lineage was never recorded, because enrichment is designed to be invisible — it fills fields, it does not stamp them. Reconstructing provenance after the fact ranges from tedious to impossible, and it is the single thing every one of these regimes ultimately asks you to produce.
What to establish this quarter
Source lineage on every contact record. Which vendor, which date, which contract, which legal basis. If the field does not exist, add it now — it only gets harder as the database grows.
A contractual deletion pass-through. At the next renewal, require the vendor to provide a suppression feed of records they have been compelled to delete, and require it on a defined cadence rather than on request.
A suppression reconciliation cadence. A standing job that applies the feed to CRM, engagement platform and warehouse. One of those three will be forgotten; it is usually the warehouse.
An AI disclosure audit of every automated touchpoint. Every sequence, chat widget and voice agent reaching an EU recipient. Article 50 is live now.
Stop treating a vendor's registration as your compliance. A registered broker is a broker who has told the state it exists. It says nothing about the lawfulness of the record now sitting in your instance.
The direction of travel
There is a reasonable case that none of this changes outbound materially. The fines so far are small — $35,000 does not restructure a market. The TCPA ruling arguably loosens one constraint rather than tightening it. And the EU's high-risk deferral genuinely bought vendors sixteen months.
The case against that reading is the direction. A regulator stood up a dedicated strike force, then named B2B prospecting vendors in its first tranche of settlements. A deletion mechanism that was an idea in statute is now a live system with a 45-day clock attached. A disclosure duty with a percentage-of-turnover penalty attached to it went live this month. None of those things gets smaller.
Outbound teams have spent a decade optimising for coverage and deliverability. The variable that has quietly become more important than either is whether you can say, on demand, where a record came from and what is speaking on your behalf. Most teams cannot answer either question today, and both answers have to be built before they are asked for.
Sources and method. A SalesHubMedia original. California Privacy Protection Agency, data broker registration and DROP obligations (45-day processing duty operational 1 August 2026; $6,000 annual fee; $200/day late penalty); Data Broker Enforcement Strike Force announcement, 19 November 2025; further enforcement actions, 8 January 2026; Crowell & Moring client alert, 6 January 2026 (Growbots and UpLead settlements, ~$35,000 each). EU AI Act Article 50: European Commission, 2 August 2026; deferral of high-risk obligations to 2 December 2027 per Gibson Dunn. TCPA: Bradford v. Sovereign Pest Control of TX, Inc., 5th Cir., 25 February 2026, per Holland & Knight; effect limited to the Fifth Circuit. Journalism, not procurement advice, and not legal advice — the regimes described differ by jurisdiction and facts. Corrections will be made openly on this article.

