August 1 Is Day One. The Data-Broker Era Is Ending — and the Enterprise Isn't Ready.
On August 1, 2026, California flips a switch that most enterprise security teams still haven't priced into their threat model.
That's the day the state's Delete Request and Opt-out Platform — DROP — begins forwarding deletion requests to every registered data broker in California. More than 322,000 Californians have already signed up to have their locations, finances, health details, and personal lives purged in the first round. Brokers who fail to comply face $200 per person per day. Companies that should have registered but didn't face the same penalties as the ones that did.
This is the first time in American history that a government agency, not an individual consumer, is going to sit between the public and the data-broker industry at scale. And it lands during a quarter in which Louisiana and Vermont joined the roster of comprehensive state privacy laws, California reached a record $12.75 million CCPA settlement, and multiple existing state laws quietly expanded broker registration, reporting, and consumer-rights obligations on July 1.
The regulatory ground is moving. The threat ground is moving faster.
What DROP Doesn't Do
I want to be honest about the limits of what August 1 gives us, because the celebration deserves an asterisk.
DROP is a one-time, consumer-initiated request routed through registered brokers in a single state. That's a genuine milestone — and it's also a fraction of the exposure that actually matters for a working enterprise.
It reaches the brokers the state knows about. Californians who signed up by August 1 represent less than 1% of the state's population, and the DROP registry can only reach brokers who registered.
It doesn't touch the long tail of people-search sites, niche marketing brokers, and offshore aggregators that don't register anywhere.
It doesn't cover the employee whose home address, phone, DOB fragment, and manager's name are being used right now to social-engineer your help desk.
It doesn't cover the executive who lives in Texas but whose family is being doxxed out of a Florida broker.
And it does nothing about the next dataset a broker ingests six months from now.
DROP is a good floor. It is not a ceiling. If you run a CISO organization, an executive protection program, or a customer-trust function, "we told our employees about DROP" is not a control.
Where the Attack Actually Landed
Passkeys work. That's the plot twist of 2026.
FIDO Alliance data cited in The Hacker News shows 75% of global consumers have enabled a passkey on at least one account and 68% of enterprises are rolling passkeys out to employees. Credential-stuffing economics are collapsing under their own weight.
So the attack moved. It moved to the exact place we've been warning about for two years: the human verification layer. Account recovery. Device re-enrollment. Step-up authentication. The magic link. The help-desk callback. The identity-proofing selfie.
Veriff's 2026 fraud data says 4.18% of verification attempts were fraudulent, digitally presented media is 300% more likely to be AI-generated than a year ago, and impersonation now accounts for more than 85% of the attacks they observe. That's the new front line.
And here's the part the verification-tooling vendors don't say out loud: every one of those attacks is dramatically cheaper when the attacker can buy the target's home address, phone number, date-of-birth fragments, employment history, manager's name, and org chart from a data broker for the price of a gym membership.
That's the ShinyHunters playbook. That's the Scattered Spider playbook. That is exactly what UNC3944 used to walk into help desks at MGM, Caesars, and a growing list of companies whose names haven't hit the wire yet. It's what North Korean IT-worker operations used to construct plausible American identities. It's the fuel behind the executive-swatting and legislator-targeting cases that are now court-documented, not theoretical.
Passkeys didn't kill account takeover. They relocated it from the front door to the concierge desk — and the concierge desk runs on data your brokers are selling.
Agentic AI Just Made the Broker Layer a Bigger Problem, Not a Smaller One
There's a fashionable argument that AI agents will reduce the value of scattered personal data because agents will authenticate cryptographically and act on their principals' behalf.
I think that's exactly backwards.
The moment an autonomous agent can be dispatched to gather information, initiate transactions, or negotiate on behalf of a person, the inputs the agent uses to identify, verify, and target humans become higher-leverage than they've ever been. A dossier that used to fuel a single manual vishing call now fuels ten thousand agent-driven social-engineering attempts before lunch. Every extra field a broker holds about your CFO is a variable an adversary's agent can condition on.
Frontier-model intrusion capability is not a hypothetical. Neither is agent-executed reconnaissance. And neither will slow down to wait for a stronger consumer privacy law to pass Congress.
The counter-move is unglamorous and it's the one thing we control: shrink the input. Remove the broker records. Break the identity graph. Take the raw material off the shelf before someone's agent — or someone's agent's agent — buys it.
What "Enterprise Data Removal" Actually Has to Look Like Now
At Priwall we've been building for this world since before it had a name. A few things we believe more strongly today than we did six months ago:
1. Coverage is a floor, not a headline. Priwall removes across 700+ U.S. data brokers, including the niche and high-risk sites that don't show up in registered-broker lists. The interesting broker is usually the one no state has a file on yet.
2. Efficacy has to be measured, not marketed. Our enterprise deployment data shows >98% successful removals within 8 weeks. The industry needs to move to third-party validation — agreed-upon-procedures engagements, limited assurance, published methodology. We're going there, and we're going to keep pushing every other vendor in this category to go there with us.
3. Removal is a control, not a benefit. Data-broker removal belongs on the same shelf as EDR, IAM, and executive protection — a measurable reduction in identity-based attack surface for workforce, executives, and their families. Priced accordingly. Deployed with SSO, SCIM, SOC 2 Type 2, and proof-of-removal evidence.
4. Institutions, not individuals, are the right unit of protection. DROP is a consumer product; the enterprise still has to protect its 40,000 employees, its board, and its incident-response subjects on its own. That's the job we take.
5. The API layer matters. The digital-risk platform, brand-protection vendor, MDR provider, and executive-protection firm your enterprise already pays should be able to offer removal as a native capability. That's why we built the Priwall enterprise API and published partner documentation at docs.priwall.io. Removal shouldn't be a separate purchase order — it should be an embedded control inside the platforms you already trust.
What August 1 Should Actually Mean to a CISO
If you run security or trust at a serious company, here is what I would do this week.
Assume DROP is not enough. For your workforce, your executives, and any incident-response subject you're actively protecting, you need continuous removal that spans the long tail — not a one-time state-registered request.
Look at the verification layer. Where does your organization still rely on knowledge-based information — DOB fragments, addresses, prior employers, manager names — to prove a human is who they claim to be? Every one of those fields is on sale somewhere. Assume the attacker has them.
Treat broker exposure as an attack surface. Not a compliance checkbox. Not a wellness perk. A quantifiable input to your identity-fraud risk, alongside your MFA telemetry and help-desk playbook.
Pilot before you procure. Ours is a 60-day pilot, priced anchored around $300 per protected user per year, with volume options for workforce coverage. If we can't show measurable removal in your environment, we don't deserve the renewal.
The Next Twelve Months
I'll say the quiet part out loud. The data-broker business model — buy exhaust data from platforms, correlate it, sell it to anyone with a credit card and a use case — is going to lose its social license in the next 24 months. Not because Congress will act quickly (Congress rarely does), but because states are acting, regulators are acting, courts are acting, and enterprises are finally connecting broker exposure to real, priced-in cyber loss.
August 1 is the beginning of that transition, not the end of it. The companies that treat it as a checkbox will still be reading breach notifications about their own executives twelve months from now. The companies that treat it as a signal — that the era of tolerated third-party PII exhaust is closing — will spend the next year methodically shrinking the attack surface that credential attackers, deepfake operators, and autonomous agents all rely on.
We built Priwall for that second group.
If your organization is in it, we should talk before August 1.
Ready to try Priwall by mePrism yourself?
If you are an individual executive evaluating personal coverage outside an employer-funded program, you can start with a free exposure scan.
Sign up for Priwall by mePrism coverage.Tom Daly is the founder and CEO of Priwall by mePrism, the enterprise open-source data-removal platform used by security, executive-protection, and digital-risk teams to shrink broker exposure across 700+ U.S. data brokers. He writes on data privacy, cybersecurity, and constitutional privacy at the Priwall blog and on LinkedIn.