Key Takeaways
- On August 11, 2026, the California Privacy Protection Agency (“CalPrivacy”) announced its first enforcement action against a data broker under the California Consumer Privacy Act (“CCPA”), fining Iowa-based LocateSmarter LLC $116,490 for both failing to register under the Delete Act (SB 362)—California’s data broker registration law—and violating the CCPA by requiring consumers to provide Social Security numbers in order to exercise opt-out rights.[1]
- Days later, CalPrivacy announced a second action against data broker Cybba, Inc., imposing a $52,400 fine for failure to register under the Delete Act—demonstrating what CalPrivacy called a “steady drumbeat” of enforcement.[2]
- With the launch of California’s Delete Request and Opt-Out Platform, and the submission already of over 475,000 consumer deletion requests, companies that collect and sell personal information should evaluate whether they qualify as “data brokers” under California law and ensure compliance with both the Delete Act and the CCPA.[3]
Background
CalPrivacy has significantly escalated its enforcement posture toward the data broker industry in 2026.[4]
In November 2025, the agency established a dedicated Data Broker Enforcement Strike Force to monitor compliance with the Delete Act (SB 362)—a law enacted in October 2023 that requires data brokers to register annually with CalPrivacy and pay an annual registration fee.
The Delete Act defines “data brokers” broadly as businesses that collect and sell personal information about consumers with whom they do not have a direct relationship. Failure to register by the January 31 annual deadline carries administrative fines of $200 per day.[5] A central feature of the Delete Act is the Delete Request and Opt-Out Platform (“DROP”), which became fully operational on August 1, 2026.[6] DROP, the first mechanism of its kind, allows consumers to submit a single deletion request that is transmitted to all registered data brokers—more than 600 as of this writing.[7] Data brokers must access DROP at least once every 45 days and process those requests, or face fines of $200 per deletion request per day.[8] Over 475,000 Californians have already submitted deletion requests through DROP.[9]
These enforcement actions build on more than a dozen prior CalPrivacy actions against data brokers—but the LocateSmarter action marks a significant escalation because it is the first to implicate both the CCPA and the Delete Act.
The LocateSmarter Action
On August 11, 2026, CalPrivacy’s Board issued a stipulated final order against LocateSmarter LLC, an Iowa-based data broker, marking the agency’s inaugural CCPA enforcement action against a data broker and the first action to arise under both the CCPA and the Delete Act.[10]
Delete Act Violations. CalPrivacy alleged that LocateSmarter qualifies as a covered data broker because it collects personal information—including names, dates of birth, Social Security numbers, telephone numbers, email addresses, employment information, driver’s license information, and litigation records—through licensing agreements, and makes this information available to its customers. The agency further noted that LocateSmarter drew inferences about consumer characteristics, such as whether an individual was “litigious.” Because the Delete Act’s data broker definition turns on whether a business collects and sells “personal information”—and inferences are an enumerated category of personal information under that definition—this activity further supported LocateSmarter’s classification as a data broker required to register.
Despite this activity, LocateSmarter failed to register as a data broker by the January 31 deadline for the 2025 calendar year.
CCPA Violations. CalPrivacy separately alleged that LocateSmarter had violated the CCPA by requiring California consumers to provide the last four digits of their Social Security numbers before they could exercise their right to opt out of the sale of their personal data. CalPrivacy also determined that requirement violated the CCPA’s data minimization provisions, which limit businesses to collecting only necessary information for a requested service or task.
Penalties and Remedial Measures. The order requires LocateSmarter to pay a combined $116,490—$30,600 for the Delete Act violation and $79,890 for the CCPA violations.
Notably, because CCPA administrative fines are assessed on a per-violation basis—up to $7,500 per intentional violation—even a small number of affected consumers can generate significant penalties. CalPrivacy Executive Director Tom Kemp emphasized that the Board imposed “a substantial fine even though a mere handful of consumers submitted requests to opt out, underscoring the need for businesses to take privacy rights seriously for each and every Californian.”[11]
The order also requires LocateSmarter to: register as a data broker for future operating years; disclose required metrics regarding CCPA requests received, complied with, and denied; process deletion requests submitted through DROP; and modify its opt-out methods to “be easy, require minimal steps, and . . . not require more information than necessary to complete the request.”
The Cybba Action
Just two days later, on August 13, 2026, CalPrivacy’s Board, the agency’s governing body established by the California Privacy Rights Act (Proposition 24), adopted a stipulated final order resolving an enforcement action against Cybba, Inc., a Boston-based company that sells personal information—including geolocation data, internet activity data, and inferences—to third-party businesses for advertising purposes.[12] According to CalPrivacy, Cybba operated as a data broker in 2024 but failed to register with CalPrivacy’s Data Broker Registry by the January 31, 2025 deadline.[13] The order required Cybba to pay a $52,400 fine, post privacy rights metrics on its website, access DROP, and process future deletion requests through that system.[14]
In announcing the Cybba action, CalPrivacy’s head of enforcement, Michael Macko, stated: “CalPrivacy has been bringing a steady drumbeat of enforcement actions under both the Delete Act and the CCPA, and I don’t see the enforcement activity slowing down anytime soon.”[15]
Broader Enforcement Trends
CalPrivacy’s recent actions are consistent with several enforcement trends:
Multi-statute enforcement. CalPrivacy has signaled it will “evaluate conduct through the lens of multiple laws” to identify the best fit for protecting consumers.[16] The LocateSmarter action demonstrates this approach by combining Delete Act and CCPA claims.
Multi-agency collaboration. Prior enforcement actions involved CalPrivacy partnering with the California Attorney General and four district attorneys.[17] CalPrivacy has also launched a bipartisan Consortium of Privacy Regulators to collaborate with other U.S. states, and it has partnered with data protection authorities in Korea, France, and the United Kingdom.[18]
Focus on data rights friction. CalPrivacy has repeatedly targeted companies that erect barriers for consumers to exercise their data privacy rights, including the right to opt out.
Substantive penalties. Both the California Attorney General and CalPrivacy have imposed increasingly significant penalties for privacy violations. The Attorney General brought the first-ever CCPA settlement against Sephora in 2022 for $1.2 million.[19] CalPrivacy, which began bringing its own enforcement actions in 2025, has similarly imposed escalating fines: from initial Delete Act registration penalties of $46,000–$56,600 to $1.35 million for CCPA violations. The overall trajectory reflects an enforcement posture in which regulators are willing to pursue substantial monetary penalties.[20]
Implications for Businesses
In light of CalPrivacy’s intensifying enforcement posture, companies should consider:
- Determining data broker status. Businesses should consider evaluating whether their data practices bring them within the Delete Act’s broad definition of “data broker”—which is any business collecting and selling personal data about consumers with whom it has no direct relationship. Businesses implementing “Do Not Sell or Share My Personal Information” notices and rights under the CCPA may still qualify as data brokers.
- Ensuring timely registration. Companies meeting the data broker definition must register with CalPrivacy by January 31 each year and pay the $6,000 annual fee.[21]
- Operationalizing DROP compliance. As of August 1, 2026, data brokers must access DROP at least every 45 days and process consumer deletion requests—with potential fines of $200 per request per day for noncompliance. According to CalPrivacy, there have already been more than 475,000 deletion requests.[22]
- Reviewing opt-out mechanisms. The LocateSmarter action suggests that requiring identity verification, Social Security numbers, or other friction points before honoring an opt-out request may expose companies to CCPA enforcement.
- Preparing for multi-statute scrutiny. CalPrivacy has demonstrated a willingness to deploy all available legal theories in a single action. In light of CalPrivacy’s recent actions, businesses considering compliance with the CCPA and the Delete Act may also want to consider compliance with the Unfair Competition Law, False Advertising Law, and sector-specific regulations that may apply to their data practices.
* * *
[1]CalPrivacy, “CalPrivacy Brings First Action Against a Data Broker Under Both the CCPA and Delete Act” (Aug. 11, 2026), https://privacy.ca.gov/2026/08/calprivacy-brings-first-action-against-a-data-broker-under-both-the-ccpa-and-delete-act/.
[2]CalPrivacy, “CalPrivacy Announces Second Data Broker Enforcement Action in Less than a Week” (Aug. 13, 2026), https://privacy.ca.gov/2026/08/calprivacy-announces-second-data-broker-enforcement-action-in-less-than-a-week/.
[3]Office of Governor Gavin Newsom, “ICYMI: California takes historic action against data brokers” (Aug. 13, 2026), https://www.gov.ca.gov/2026/08/13/icymi-california-takes-historic-action-against-data-brokers/.
[4]See CalPrivacy Newsroom, https://privacy.ca.gov/about-us/newsroom/ (listing enforcement actions in 2026). For a detailed discussion of Q1 2026 California privacy enforcement activity, see Paul, Weiss, California Privacy Updates: Q1 2026 (May 22, 2026), available here.
[5]CalPrivacy, “Delete Request and Opt-Out Platform (DROP),” https://cppa.ca.gov/data_brokers/; CalPrivacy, “DROP for data brokers,” https://privacy.ca.gov/drop-for-data-brokers.
[6]CalPrivacy, “DROP for data brokers,” https://privacy.ca.gov/drop-for-data-brokers.
[7]CalPrivacy, “About DROP and the Delete Act,” https://privacy.ca.gov/drop/about-drop-and-the-delete-act/.
[8]CalPrivacy, “DROP for data brokers,” https://privacy.ca.gov/drop-for-data-brokers.
[9]Office of Governor Gavin Newsom, “ICYMI: California takes historic action against data brokers” (Aug. 13, 2026), https://www.gov.ca.gov/2026/08/13/icymi-california-takes-historic-action-against-data-brokers/.
[10]CalPrivacy, “CalPrivacy Brings First Action Against a Data Broker Under Both the CCPA and Delete Act” (Aug. 11, 2026), https://privacy.ca.gov/2026/08/calprivacy-brings-first-action-against-a-data-broker-under-both-the-ccpa-and-delete-act/.
[11]CalPrivacy, “CalPrivacy Brings First Action Against a Data Broker Under Both the CCPA and Delete Act” (Aug. 11, 2026), https://privacy.ca.gov/2026/08/calprivacy-brings-first-action-against-a-data-broker-under-both-the-ccpa-and-delete-act/.
[12]CalPrivacy, “CalPrivacy Announces Second Data Broker Enforcement Action in Less than a Week” (Aug. 13, 2026), https://privacy.ca.gov/2026/08/calprivacy-announces-second-data-broker-enforcement-action-in-less-than-a-week.
[13]Id.
[14]Id.
[15]Id.
[16]CalPrivacy, “CalPrivacy Brings First Action Against a Data Broker Under Both the CCPA and Delete Act” (Aug. 11, 2026), https://privacy.ca.gov/2026/08/calprivacy-brings-first-action-against-a-data-broker-under-both-the-ccpa-and-delete-act/.
[17]California Attorney General Rob Bonta, “When It Comes to Data Privacy, Consumers Must Be in the Driver’s Seat” (May 8, 2026), https://oag.ca.gov/news/press-releases/when-it-comes-data-privacy-consumers-must-be-driver%E2%80%99s-seat-attorney-general.
[18]CalPrivacy, “CalPrivacy Brings First Action Against a Data Broker Under Both the CCPA and Delete Act” (Aug. 11, 2026), https://privacy.ca.gov/2026/08/calprivacy-brings-first-action-against-a-data-broker-under-both-the-ccpa-and-delete-act/.
[19]California Attorney General Rob Bonta, “Attorney General Bonta Announces Settlement with Sephora as Part of Ongoing Enforcement of California Consumer Privacy Act” (Aug. 24, 2022), https://oag.ca.gov/news/press-releases/attorney-general-bonta-announces-settlement-sephora-part-ongoing-enforcement.
[20]CalPrivacy, “CalPrivacy Announces Second Data Broker Enforcement Action in Less than a Week” (Aug. 13, 2026), https://privacy.ca.gov/2026/08/calprivacy-announces-second-data-broker-enforcement-action-in-less-than-a-week/; CalPrivacy, “CalPrivacy Issues Enforcement Advisory Highlighting Data Broker Registration Deadline” (Dec. 17, 2025), https://cppa.ca.gov/announcements/2025/20251217.html.
[21]CalPrivacy, “Delete Request and Opt-Out Platform (DROP),” https://cppa.ca.gov/data_brokers/.
[22]CalPrivacy, “DROP for data brokers,” https://privacy.ca.gov/drop-for-data-brokers/.