First CCPA Fines Hit Data Brokers: $169K in a Single Week

Two fines in three days. That's the pace California's privacy regulator set this week, and if you think it doesn't touch you because you're not a "data broker," read the second half of this post. One of the two rulings turns on a rule that applies to every business collecting personal information in California.

What Happened

On August 11, 2026, the California Privacy Protection Agency (CalPrivacy) ordered Iowa-based LocateSmarter LLC to pay $116,490. It was the agency's first enforcement action against a data broker under both the CCPA and the Delete Act. The broker had failed to register on time, and it demanded that Californians hand over the last four digits of their Social Security number before it would process an opt-out.

The Board found two problems with that Social Security requirement. An opt-out of sale or sharing is a request a business must honor without verifying identity, so forcing consumers to authenticate an unverifiable request was unlawful on its face. Demanding sensitive identifiers to complete a simple opt-out also broke the CCPA's data-minimization rule, which says you can't collect more than you reasonably need for the task.

"The Board's decision imposes a substantial fine even though a mere handful of consumers submitted requests to opt out, underscoring the need for businesses to take privacy rights seriously," said Executive Director Tom Kemp.

Then, on August 13, CalPrivacy hit Boston-based Cybba, Inc. with a second decision: a $52,400 penalty for operating as a data broker in 2024 and never registering by the January 31, 2025 deadline. Cybba also has to publish privacy-rights metrics on its site and start honoring deletion requests through the state's DROP platform. Head of Enforcement Michael Macko put it plainly: he doesn't see "the enforcement activity slowing down anytime soon."

Together the two actions total $168,890, and they mark the moment California's data-broker regime went from paperwork to penalties.

Why This Reaches Past Data Brokers

The registration piece is broker-specific. Under the Delete Act, a data broker is a business that knowingly collects and sells personal information about consumers it has no direct relationship with, and plenty of ad-tech, lead-gen, and analytics companies fit that description without ever having filed. If you buy or license consumer data and resell or share it, check whether you owe a registration.

The LocateSmarter holding is the part everyone should notice. Data minimization and the rule against over-verifying opt-outs aren't broker rules; they're baseline CCPA obligations. Any site that makes a user create an account, upload an ID, or answer extra questions just to click "Do Not Sell or Share" is running the same risk LocateSmarter just paid for. And the fine landed after only a handful of opt-out requests, so low volume is no shield.

What to do: strip your opt-out flow down to the minimum. A request to stop selling or sharing shouldn't require identity verification at all. Honor the Global Privacy Control signal as a valid opt-out. If you collect data on people you don't serve directly, confirm your registration status before the next annual deadline. See the CCPA enforcement tracker for the full record of CalPrivacy and California AG actions.

Where Privisy Fits

Privisy scans your live site the way a regulator would look at it. The opt-out completeness check flags "Do Not Sell or Share" flows that bury the choice or demand information they shouldn't, which is exactly the friction that cost LocateSmarter. The GPC validation stage re-visits your pages with the signal switched on and watches whether trackers actually stop firing, catching the gap between claiming to respect an opt-out and honoring it. You find the problem before an enforcement letter does.

See What a Regulator Would See

Privisy audits your opt-out flows, GPC handling, and tracker behavior against the exact CCPA rules CalPrivacy is now enforcing.

Get Your Audit