In November 2024, a single short-seller report erased roughly a third of Zeta Global’s market value in a matter of days. The company’s software had not stopped working. Its clients had not left. Investors simply started asking a different question: whether the consumer data powering that software was legally sound.
That question sits at the centre of everything that has happened since. Zeta Global is not structured like a conventional enterprise software vendor. Its competitive advantage is not a codebase; it is a proprietary consumer data repository and the targeting models built on top of it. For a software firm, compliance costs are peripheral. For a data-centric firm, the right regulatory action can invalidate the asset itself.
Understanding Zeta Global regulatory risk means understanding that distinction, and it produces a framework you can apply to any data-driven company. This piece walks through the specific mechanisms, active court cases, state deletion mandates, and Federal Trade Commission (FTC) disgorgement precedent, that determine whether a data moat is durable.
Why Zeta’s data repository is the company’s competitive moat, not just an asset
Most enterprise software companies sell a product. Zeta sells access to data and the ability to act on it. Enterprises pay Zeta both to reach consumers and to execute campaigns built on Zeta’s profiles, which makes the data repository the primary input to revenue rather than a supporting feature.
That structure changes what regulatory risk means. When a traditional software firm faces a regulatory action, the core codebase usually survives intact. Compliance becomes an operating cost, an adjustment, a line item. The asset base is not the thing under attack.
When the data repository is the moat, the calculus inverts. Any legal challenge to how that data was collected, consented to, or retained is a direct strike on the firm’s intangible asset base, not an operational nuisance.
The market has already priced this. The November 2024 short-seller report did not allege that Zeta’s technology failed; it questioned whether the data was legitimately obtained, and roughly a third of the company’s value evaporated within days. That reaction tells you the share price was, even before any lawsuit, resting on an assumption about data legitimacy that is now being formally tested in two federal courts at once.
Two further facts sharpen the picture. Zeta has characterised its dataset as “opted-in,” and that exact representation is now the central allegation in the securities class action. Zeta’s own financial disclosures state it cannot quantify the potential financial exposure from the active litigation.
Here is the contrast that should reframe how you categorise this risk:
| Risk dimension | Traditional software firm | Data-centric firm (Zeta) |
|---|---|---|
| Asset affected | Peripheral (usage terms, features) | The core moat itself (the data repository) |
| Nature of compliance cost | Operating expense, product tweak | Potential invalidation of the primary input |
| Worst-case regulatory outcome | Fines, forward-looking restrictions | Forced deletion of data and derived models |
| Framework to apply | Compliance risk | Asset integrity risk |
Investors who file Zeta under ordinary compliance risk are applying the wrong analytical framework entirely. The asset that generates the revenue is the same asset now under legal and regulatory attack.
When big ASX news breaks, our subscribers know first
Two active lawsuits, two distinct attack vectors on the same data asset
Zeta faces two federal class actions, and it is tempting to read them as parallel news items. They are better understood as two prongs of a single problem, each attacking the data asset from a different angle, each capable of feeding the other.
The first is the securities class action, In re Zeta Global Holdings Corporation Securities Litigation, before Judge Dale E. Ho in the Southern District of New York. Its core allegation is deception of investors: that Zeta represented its consumer data as “opted-in” and legitimately consented, when it allegedly relied on a “consent farm” database and other questionable methods to inflate its metrics. This is a claim about what shareholders were told, not about direct consumer harm.
The second is the consumer privacy class action, In re Zeta Global Data Privacy Litigation, before Judge Paul A. Engelmayer in the same court. Its theory is distinct: that Zeta intercepted, collected, and monetised personally identifiable information, including IP addresses, email addresses, and the substance of users’ private queries, without proper consent, in violation of the Electronic Communications Privacy Act (ECPA) and various state consumer protection laws. The allegations trace to data practices tied to the People.com newsletter and related Dotdash Meredith properties, giving the case a concrete collection context.
The procedural asymmetry is where the analysis gets interesting.
On 8 July 2026, Judge Ho denied Zeta’s motion to dismiss the securities case, holding that investors had adequately alleged materially misleading statements about the “opted-in” data set. The case proceeds past the pleading stage.
By contrast, motions to dismiss in the privacy case remain pending as of mid-2026, with no comparable ruling yet issued.
Here is what the dismissal denial actually means for you as an analyst. It is not just a procedural milestone. A federal judge has agreed that the “opted-in” characterisation was plausibly misleading. That shifts the litigation from a nuisance risk to a disclosure-quality risk, and it should change how you model Zeta’s data asset on a forward basis rather than treating the suit as background noise.
| Case | Court and judge | Core allegation | Status (mid-2026) |
|---|---|---|---|
| Securities class action (No. 1:24-cv-08961-DEH) | S.D.N.Y., Judge Dale E. Ho | Misrepresented “opted-in” data to investors; alleged “consent farm” reliance | Motion to dismiss denied 8 July 2026; proceeding |
| Data privacy class action (No. 1:25-cv-05780-PAE) | S.D.N.Y., Judge Paul A. Engelmayer | Unlawful interception and monetisation of PII under ECPA and state law | Motions to dismiss pending |
The compounding dynamic is the point. The securities case puts Zeta’s representations about consent under a legal microscope. The privacy case puts the actual collection practices under scrutiny. Public discovery in either could expose Zeta’s data collection mechanisms and potentially trigger parallel FTC or state attorney general investigations, which is how a civil dispute becomes a regulatory one.
The pattern of data litigation mispricing is not unique to Zeta; across Meta, Snap, Alphabet, and TikTok, analysts underweighting injunctive relief as a structural revenue constraint rather than a one-time charge are applying the same compliance-risk framing to what is functionally an asset-integrity problem.
What state data broker laws and California’s DROP platform mean in practice
Litigation is the acute risk. The slower, structural risk comes from legislation, and it works differently. As of July 2026, seven US states have enacted data broker laws, each imposing some combination of registration, deletion and opt-out compliance, ongoing documentation, and fines for non-compliance.
| State | Law status | Key obligations | Key effective date |
|---|---|---|---|
| California | Enacted; DELETE Act and DROP live | Registration, centralised deletion via DROP, 45-day sweeps | Broker deletion duty from 1 August 2026 |
| Oregon | Enacted | Registration, opt-out, documentation | In effect |
| Texas | Enacted | Registration, opt-out, documentation | In effect |
| Vermont | Enacted | Registration, opt-out, documentation | In effect |
| Montana | Enacted | Registration, opt-out, documentation | In effect |
| Connecticut | Enacted | Registration, deletion, transparency | Key provisions from 1 October 2026 |
| New Jersey | Enacted (A5328) | Registration, fees, compliance burden | Registration from 27 March 2027 |
California’s Data Removal Opt-Out Platform (DROP) is the mechanism that makes this more than a paperwork exercise. It lets an eligible California resident submit a single deletion request that propagates to every registered data broker at once, and the deletion pressure recurs rather than resolving.
The compliance sequence works like this:
- A resident confirms California residency, creates a profile, and submits one deletion request through DROP.
- That single request propagates to all registered data brokers simultaneously, currently over 600 on the platform.
- From 1 August 2026, brokers must honour those requests, with deletion sweeps recurring every 45 calendar days.
- Brokers that fail to register face fines of $200 per day.
Adoption is not hypothetical. The California Privacy Protection Agency reported that more than 300,000 Californians had signed up for DROP by June 2026, and in a 18 February 2026 press release, California Attorney General Rob Bonta actively reminded residents to use it. When the state’s chief law officer is promoting consumer opt-out, the growth curve is unlikely to flatten on its own.
For a company whose data volume and profile depth are competitive differentiators, the recurring 45-day sweep is not a one-time compliance event. It is a structural drain on the asset base that compounds each cycle if sign-up rates keep climbing.
The gap between “manageable” and “structural” risk
Two genuinely competing interpretations exist here, and this is not false balance. Large, well-resourced platforms frame these laws as significant but manageable compliance overhead: registration, fees, more frequent data hygiene, all absorbable at scale. Nothing in the statutes bans the core business.
The cautious investor view reads the same facts differently. DROP’s one-to-many design and recurring sweeps create compounding erosion, and coordinated opt-outs could systematically shrink large holdings over time, particularly if public awareness keeps building. The IAPP has already characterised New Jersey’s law as “costly” for registrants, which cuts against the frictionless-compliance narrative.
Two variables tip the outcome. The first is consumer adoption velocity for DROP. The second is whether attorney general enforcement actions actually materialise. Watch both, because they determine which interpretation turns out to be right.
Algorithmic disgorgement and why fines are not the worst-case outcome
Fines are the risk investors instinctively price. They are also not the worst case. The worst case has a name, a legal basis, and a documented track record: algorithmic disgorgement.
Statutory penalty multipliers across multiple states can produce theoretical exposure figures that dwarf a company’s market capitalisation, as the attorney general actions against Meta illustrate, and that arithmetic reframes litigation tail risk as a valuation input rather than a qualitative footnote.
Algorithmic disgorgement is the FTC’s power to require a company to delete not just unlawfully obtained data, but also every model and algorithm trained on that data. The point is to strip out the economic value of “tainted” datasets and the systems derived from them, so the firm cannot keep profiting from illegal collection. It attacks the models directly, not just the raw records.
The FTC would likely proceed under Section 5 of the FTC Act, which prohibits unfair or deceptive practices. Disgorgement is more common in settled consent orders than litigated judgments, because consent orders let the agency negotiate detailed remedial terms without testing novel theories in court.
This becomes most realistic for a public data company under two conditions: when material portions of the data assets were collected through deceptive or unlawful means, and when that tainted data is deeply embedded in the models powering core products, so prospective compliance alone cannot fix it.
The precedents are not speculative.
| Company | Year | Data issue | Remedy imposed |
|---|---|---|---|
| Everalbum | 2021 | Facial recognition data via misrepresented practices | Deletion of data and the models built on it |
| WW International / Kurbo | 2022 | Children’s data collected unlawfully | Deletion of data and any models trained on it |
| Rite Aid | 2023 | AI facial recognition surveillance | System halted; related data and technology deleted |
| Kochava | 2022 (complaint) | Sale of granular location data | FTC sought halt to sales and deletion of records |
The Everalbum order is the analytical anchor. It confirms the FTC will delete the model, not just the data. For Zeta, that means the targeting algorithms themselves, not merely the data records, could be the remedial target if consent practices are found unlawful.
Organisations including the Electronic Privacy Information Center (EPIC) and the Future of Privacy Forum have framed disgorgement precisely as a tool to stop firms benefiting from illegal collection by attacking the economic value of the models. That framing matters because it signals regulatory intent, not just capability.
Applying the disgorgement framework to Zeta’s specific exposure
Stack the two lawsuits on top of the precedent and a conditional logic chain appears. If the securities case produces findings of misrepresentation about consent, and if the privacy case produces findings of unlawful interception, the combination supplies the evidentiary basis regulators would need to pursue disgorgement.
Zeta’s own disclosures reinforce the read. Management explicitly states it cannot quantify the exposure, and an inability to quantify is itself a signal that the tail risk is being treated as non-trivial rather than remote.
This is the mechanism that converts a litigation loss into an asset impairment event. Fines hit earnings; disgorgement hits the moat.
A framework for evaluating regulatory risk in data-dependent business models
Zeta is a case study, but the value is the framework it hands you. Any time you evaluate a company whose competitive edge is proprietary consumer data rather than a software stack, the same diagnostic questions apply.
Run through these before you size a position:
- How dependent is the revenue model on a proprietary data asset versus the software layer?
- What is the consent basis for the data, and is it independently verifiable, or does it rest solely on the company’s own characterisation?
- Are there active legal or regulatory proceedings that specifically challenge the data’s legality rather than its usage?
- Is the company exposed to state deletion mandates like DROP that erode data volume on a recurring basis?
- How deeply is the underlying data embedded in the models powering core products?
- Do the company’s disclosures quantify regulatory exposure, or concede they cannot?
The single most useful distinction sits underneath all of them.
The distinction between compliance risk and asset integrity risk maps directly onto the value investor’s definition of permanent capital loss: a fine is an earnings event, but disgorgement of the models powering core revenue is a permanent reduction in intrinsic value that no subsequent quarter can recover.
Compliance risk is peripheral to the asset base. Asset integrity risk is a direct threat to the moat. Treating the second as if it were the first is the most common analytical error in data-centric investing.
Two mechanisms convert regulatory pressure into measurable economic harm: DROP-style deletion mandates, which shrink the asset over time, and algorithmic disgorgement, which can destroy the models outright. Zeta demonstrates all three core risk pathways at once: civil litigation challenging consent representations, state mandates creating recurring erosion, and FTC precedent establishing the worst-case impairment scenario. Its securities case also proves that data legitimacy questions can produce direct securities-law exposure, not merely operational risk, which means the legal pathway runs both civil and regulatory at the same time.
What the Zeta case signals for data-driven investing in the regulatory transition
The reason to study Zeta now is that the signals arrive early. Waiting for a final court ruling or an FTC action before updating your risk model leaves you behind the information curve, because the meaningful data points, litigation survival, regulatory deadlines, and consumer adoption figures, are all visible today.
Three indicators are worth tracking over the next 12 to 18 months:
- The privacy case’s motion-to-dismiss outcome. A denial, mirroring the securities ruling, would put actual collection practices on a path to discovery and sharply raise the disgorgement probability.
- DROP adoption velocity. Sign-ups above the June 2026 figure of over 300,000, pushed further by the 1 August 2026 enforcement deadline, would confirm the structural-erosion thesis over the manageable-cost one.
- Any FTC or state attorney general investigation. Even an inquiry stemming from either lawsuit’s discovery would convert tail risk into active risk.
Zeta is not an outlier. As Connecticut’s provisions take effect on 1 October 2026 and New Jersey’s registration follows on 27 March 2027, the deletion and compliance pressure Zeta faces becomes a structural condition of the data broker industry. More state laws, plus higher DROP adoption, plus live litigation, describes a deteriorating environment across 2026 and 2027, not a static one.
For any company whose moat is a data asset rather than a software stack, the due diligence question is no longer whether regulatory risk exists. It is whether the consent and collection basis for the data can survive sustained legal scrutiny.
The data quality advantage that delivers outperformance for AI leaders assumes the underlying datasets are legally sound; a data asset that is simultaneously a competitive moat and a regulatory liability can flip from compounding advantage to compounding risk if collection practices are found unlawful.
This article is for informational purposes only and should not be considered financial advice. Investors should conduct their own research and consult with financial professionals before making investment decisions. Financial projections and forward-looking assessments are speculative and subject to change based on legal, regulatory, and market developments.
