Privacy and data compliance questions come up a lot, especially when your legal or procurement team is doing due diligence on a new vendor, and we'd rather give you a real answer than a one-line assurance. Below is the full picture of how we manage this, in enough detail that you can forward it directly to your team or attach it to your own review.
The short version: we handle privacy compliance by partnering with
Superset, a compliance platform built specifically for companies that handle consumer data at scale. Here's what that covers.
Why This Question Matters for Our Data
Our
AI Discovery capability identifies anonymous website visitors, in-market candidates, and dormant leads showing renewed interest, often before anyone fills out a form. Our
Licensed Custom Audiences also pull in third-party behavioral, demographic, and interest data so you can reach candidates who haven't interacted with your site yet.
That combination, first-party candidate signals plus licensed third-party audience data, is exactly what a growing list of state privacy laws was written to regulate. If your team wants more background before your own review, we've published a full
US Data Privacy Compliance Checklist and a breakdown of
CCPA rights every business must honor. What follows is how we put that guidance into practice on our end, day to day.
Our Compliance Partner: Superset
We wanted a partner built for exactly this problem, not a generic legal tool retrofitted for it. Superset is a New York-based compliance platform
, founded and led by Zane Witherspoon, CIPP/US, a Certified Information Privacy Professional
. Its mission statement is "to make legal compliance as simple and hands-off as possible for businesses of all sizes" . It is built around independently validating data privacy practices for data brokers and similar businesses.
Superset connects to our existing systems and adds a compliance layer on top of them rather than replacing anything
. Here's what that covers, point by point, in case your team needs to check off specific items.
Superset makes legal compliance as simple and hands-off as possible for businesses of all sizes.
State Data Broker Registrations
A growing number of states require companies that collect and transfer consumer data to register annually or face steep fines. Four states currently require this: California, Texas, Vermont, and Oregon, each with its own filing window and fee. Non-compliance across these four states can add up to roughly $103,000 in fines per year, on top of administrative costs, and California has already issued $70,000 in fines to data brokers for registration failures.
Connecticut just joined this group. On May 27, 2026, it became the 5th state to require data broker registration, and the first state after California to adopt a single-request deletion model, with a registration deadline of January 1, 2027
.
Superset files directly with the California Privacy Protection Agency (CPPA) on our behalf, with a stated turnaround of about 11 minutes for a completed filing, plus ongoing monitoring of what's been filed
. Superset's own
case study walks through everything that goes into a single registration, from assessing which laws apply, to filing with the CPPA (down to handling the physical check payment), to supplying compliant privacy policy language, to confirming certification once it's done.
Non-compliance to state data broker regulations can add up to roughly $103,000 in fines per year,
California's DROP System
If your team has heard about California's Delete Request and Opt-Out Platform,
DROP, and is wondering whether it affects data you share with us, here's the relevant detail:
- DROP is a state-run database where California residents can request that every registered data broker stop selling or delete their information in one place.
- It went live for consumers on January 1, 2026, and had more than 300,000 signups by early June 2026. A sandbox for broker testing opened in April 2026, with full production going live August 1, 2026.
- Registered data brokers have to pull DROP requests and process them at least every 45 days. The penalty for missing that is $200 per day, per consumer.
We use Superset to set up and maintain our DROP account so that 45-day cycle gets processed on schedule, without any manual tracking on our end.
How We Handle Consumer Privacy Requests
If a consumer emails us asking what data we hold on them, or asking to have it deleted, that's legally a Data Subject Request (DSR), sometimes called a DSAR when it's specifically an access request. Most privacy laws require us to offer at least two ways to submit a request, and to respond within roughly 30-45 days, sometimes with a possible extension
.
We run our privacy inbox through Superset's Privacy Inbox Automation, which connects to the inbox, flags valid requests, responds to invalid ones, and pulls the information needed to process legitimate ones automatically
. Superset's founder has described this feature as monitoring a privacy inbox around the clock and automating both detection and response.
One detail worth flagging for your legal team specifically: over-verifying identity can create its own liability. Requiring something like a government ID for a simple request has led to real penalties elsewhere, including a $275,000 CPPA fine against Charles Schwab for exactly that
. We keep our verification steps proportionate to the request for that reason.
Data Mapping
Superset integrates with more than 6,000 business systems to map where customer data is stored, and runs automated agents that watch for new code and system changes so that map stays current
. Superset markets this data mapping and inbox automation combination as "PrivacyOps 10x Faster", which is the piece that's saved us the most manual triage time.
Superset also runs a set of AI agents at
ai.trustsuperset.com that we lean on for spot checks between full reviews. That includes a Privacy Policy Review Agent that analyzes an uploaded privacy policy for compliance issues, and a RAG-based compliance research chatbot trained on data privacy laws. Superset also runs a separate compliance agent, at
agent.trustsuperset.com, that compares documents against applicable regulations and our own internal policies, flagging anything out of compliance
.
Coverage Beyond U.S. Data Broker Laws
If your compliance review also touches international data, here's the relevant piece: Superset's EU Representative Agent service appoints a physical representative within an EU member state on our behalf and monitors incoming communications from EU regulators or data subjects, which GDPR requires for companies serving European users
. Superset has done the same for itself, appointing its own EU representative under Article 27 of the GDPR
, and its company page lists GDPR representation, privacy policy review, and DSAR email triage among the areas it automates for clients like us.
Independent Certification
Superset also runs a Data Broker Compliance Certification program, auditing a company's practices across five categories: registrations, notices, DSR handling, procedural documentation, and security, and issuing a certification badge once a business passes
. It's a useful external benchmark if your team wants a third-party point of reference beyond what we've outlined here.
If Your Team Needs More
If your legal or procurement team needs anything beyond this, our
AI & Data Privacy article and our
Legal Agreements and Privacy Policy cover the rest of our data handling and contractual terms, including our Data Processing Addendum. For anything specific to your account, a security questionnaire, or documentation you need for your own review, reach out to your Franchise Ninja account team and we'll get you what you need directly.
If Your Team Needs More on Superset
Zane Witherspoon
CEO
URL: trustsuperset.com