◈MCStanding

Data broker compliance you can prove

MCStanding runs the California DELETE Act's 45-day DROP cycle, screens every file you acquire against consumers who already asked to be deleted, and produces evidence an auditor can verify on their own machine. Across eleven jurisdictions, without your customer data ever leaving your browser.

$50,000 × one record

New Jersey has prohibited selling or licensing sensitive data outright since 30 June 2026, at $50,000 per record. California runs its own meter at $200 per request per day with no cure period, and has already fined LocateSmarter LLC $116,490 on 11 August 2026 and Cybba Inc. $52,400 two days later — every action, with links to the orders.

What the California DELETE Act requires

Since 1 August 2026, every registered data broker must access California's Delete Request and Opt-out Platform (DROP) at least once every 45 days, download the consumer deletion list, match it against their own records, act on every request, and report an outcome for each one. There is no cure period, and brokers are forbidden from verifying the requester.

Penalties accrue at $200 per request, per day, uncapped. Registration with CalPrivacy costs $6,000 a year and is due between 1 and 31 January. From 1 January 2028 an independent third-party audit is required every three years, with records retained six years and produced within five business days of a written request.

The part that catches people out

DROP compliance fails quietly. Identifiers are matched as SHA-256 hashes, so if your normalisation is wrong by a single rule, every hash you generate is wrong, every match misses, and you report "not found" for consumers who are sitting in your database. The platform accepts it. Nobody objects. The discrepancy surfaces at the audit, with the penalty compounded.

Suppression: deletion is a state, not an event

Brokers must ensure deleted consumers stay deleted. Someone removed in July who reappears in a list purchased in September must not be re-ingested — and re-acquisition is invisible, because the cycle that processed them was correct and the outcome reported was correct.

MCStanding builds a hash-only suppression list from everything you have already processed and screens each inbound file against it before the data reaches your systems, returning a cleaned file and a report of what was blocked. It is the operation you run on every acquisition, not once every 45 days.

Eleven jurisdictions from one record

TypeJurisdictionNotes
Registry and deletion platformCalifornia — DELETE Act / DROP$6,000/yr, Jan 1–31, $200 per request per day
RegistryConnecticutEffective 1 Oct 2026; registration from 1 Jan 2027; own deletion mechanism 2028
RegistryTexas · Oregon · VermontRegistration and disclosure duties
Individual erasureEU GDPR · UK GDPROne month, extendable; Article 19 downstream notice
Individual erasureBrazil LGPD15 days — the tightest clock
Individual erasureCanada PIPEDA · Québec Law 2530 days; Law 25 adds de-indexation

Erasure regimes attach to processing, not to broker status — a business can fail every prong of the US broker definition and still owe a one-month GDPR erasure response. Every date, fee and penalty in the software carries its statutory citation so you or your counsel can check it.

Why it runs in your browser

DROP publishes deletion requests as hashes rather than plaintext, which makes matching a deterministic offline computation. It never required a cloud platform.

Every alternative in this category is a hosted service, so complying means sending your customer database to a third party. MCStanding does the same computation locally. The site sends connect-src 'none', meaning the page cannot open a network connection at all — your security team can confirm that from the response headers in about ten seconds, without reading any code or taking our word for it.

Common questions

Do we have to register if we stopped being a data broker last year?
Yes. Registration turns on whether you met the definition for any period of time in the prior year, even briefly. CalPrivacy enforces this explicitly, and ceasing the activity does not erase the obligation.
We share data but we don't sell it. Are we in scope?
Probably. "Sell" covers disclosure for money or any other valuable consideration, and treating an exchange as sharing rather than selling is the most common route to a mistaken out-of-scope conclusion. Recent enforcement has challenged that distinction directly.
Can a parent company register on our behalf?
No. Each legal entity registers separately and needs its own DROP account. Restructuring to avoid registration is named in CalPrivacy's enforcement advisory as "hiding the ball".
What happens to our records if we stop subscribing?
You keep everything. Logs, exports, suppression list and evidence files are on your machine and continue to work — the evidence file re-derives its own hashes in any browser with no dependency on us.

See it before you buy

Open the app and choose "See a worked example". A fictional broker with a real history loads in about a minute, deliberately including problems worth finding. No account, no card, nothing to install and nothing uploaded.