Skip to Main Content
Main Menu

Research & Alerts This is a sample of a Nymity Research Regulatory Insight & Alert

Data Broker: CalPrivacy Makes First Ever Enforcement Under CCPA and Delete Act

Aug 12, 2026
CalPrivacy fined LocateSmarter, an Iowa data broker, a combined $110,490 for missing its 2026 Delete Act registration deadline and requiring consumers to verify their opt-out requests of data sales/sharing by disclosing their partial Social Security number, and in addition to the fine, LocateSmarter must pay the $6,000 registration fee for 2025, register its activities going forward, update its opt-out process, and report CCPA request metrics in its privacy policy.
Document Status
Final (Stipulated Final Order — effective immediately)
Jurisdiction
United States – California
Applies To
California data brokers that meet the CCPA definition of a business and operate in California; respondent: LocateSmarter, LLC, an Iowa company.
Regulation
California Consumer Privacy Act (CCPA) — Section 1798.100(c); Delete Act — Section 1798.99.82(a); CCPA Regulations — Sections 7002(d), 7013(e)/(f)(2), 7026(d)
Issuing Authority
California Privacy Protection Agency (CalPrivacy)
Effective Date
August 10, 2026
Enforcement Date
August 10, 2026
Last Reviewed
August 2026
Topics
Data Broker, Penalties and Fines, CCPA, Delete Act, Enforcement
[Alt text]
Keywords
Data Broker Penalties And Fines CCPA Delete Act Enforcement

What’s Happening

On August 10, 2026, the California Privacy Protection Agency (CalPrivacy) adopted a Stipulated Final Order with LocateSmarter, LLC. (an Iowa data broker operating in California) for being the first data broker to have violated both the California Consumer Privacy Act (CCPA) and the Delete Act.

This order of decision is effective immediately.

At a Glance

LocateSmarter buys personal information from third-party licensors, including names, dates of birth, Social Security numbers, addresses, email addresses, etc., and resells it to clients through a variety of its data solutions. That volume of activity made it a “business” under the CCPA and a data broker under the Delete Act for 2025.

Following an investigation, LocateSmarter committed 2 violations, each under the Delete Act and the CCPA:

  • under the Delete Act, LocateSmarter missed the January 31, 2026 deadline to register as a data broker for its 2025 activity, therefore, its failure to register violated Section 1798.99.82(a); and
  • under the CCPA and its Regulations, LocateSmarter’s online opt-out form to opt-out of data sales/sharing required consumers to verify themselves and their request by requesting them to disclose their full name, mailing address, and the last four digits of their Social Security number:
    • resulting in excessive collection and processing of personal information; and
    • violating Section 1798.100(c) of the CCPA and Sections 7002(d) and 7026(d) of the CCPA Regulations.
Request Free Trial

How the $110,490 fine was calculated

  • CalPrivacy allocated approximately $46,745 of the fine to the Delete Act registration failure and approximately $63,745 to the CCPA opt-out verification violation, applying the CCPA Regulations’ aggravating-factor test (nature and seriousness of the violation, number of consumers affected, and duration of noncompliance);
  • the Agency treated the registration lapse as a single continuing violation rather than a per-day penalty, but noted it could have assessed daily penalties had LocateSmarter not registered voluntarily once notified; and
  • the opt-out violation was scored more heavily because it affected every consumer who submitted a request during the review period, not just a subset.

Additional remediation timeline

  • Within 10 business days: pay the $6,000 delinquent 2025 registration fee and the combined $110,490 fine;
  • within 30 days: remove the full name, mailing address, and partial Social Security number fields from the opt-out form and replace them with a privacy-protective verification method;
  • within 90 days: certify to CalPrivacy that downstream clients and licensees have been notified of the corrected opt-out process; and
  • ongoing: register as a data broker for each calendar year the Delete Act threshold is met, and publish annual CCPA request metrics in the privacy policy.

CalPrivacy’s order also notes this is the first enforcement action to cite Section 7013(e) and (f)(2) of the CCPA Regulations — the provisions governing what a business may and may not require to verify a request to opt-out of sale/sharing — giving data brokers their first concrete enforcement guidance on where the line sits between reasonable verification and excessive collection.

In Depth

Primary compliance obligations under the Stipulated Final Order.

Requirement Description
Delinquent Registration Fee Pay the outstanding $6,000 data broker registration fee for 2025 activity, on top of the combined $110,490 administrative fine, within 10 business days of the order’s effective date.
Ongoing Delete Act Registration Register as a data broker with CalPrivacy for each subsequent calendar year in which LocateSmarter meets the Delete Act threshold, no later than each January 31 deadline, and keep the registration profile current with any change in data categories collected or sold.
Opt-Out Verification Overhaul Remove the full Social Security number, mailing address, and full-name verification fields from the online opt-out form within 30 days; replace with a privacy-protective method (e.g., a matching token, email confirmation, or truncated identifier) that does not require collecting more personal information than needed to process the request.
CCPA Metrics Reporting Publish annual aggregate metrics in the privacy policy — number of requests to know, delete, and opt-out received, complied with, and denied, plus median and mean response times — consistent with CCPA Regulations reporting thresholds.
Compliance Monitoring Period Submit compliance status reports to CalPrivacy on a fixed cadence for a defined monitoring period following the order, documenting registration status, opt-out form changes, and metrics reporting.
Recordkeeping & Audit Trail Retain records of opt-out requests, verification method changes, and registration filings for a minimum retention period so CalPrivacy can reconstruct compliance history on request during or after the monitoring period.
Staff Training Train customer-facing, engineering, and privacy staff on the updated privacy-protective verification standard within 60 days, with documented completion tracked as part of the compliance file.
Third-Party Vendor Flow-Down Update contracts with downstream licensees and resale clients to require the same privacy-protective opt-out verification standard, rather than leaving legacy verification logic in place further down the data supply chain.

CalPrivacy’s staff report accompanying the order frames this as the Agency’s first action to charge violations under the CCPA and the Delete Act in the same proceeding, and signals that the two enforcement regimes will increasingly be pursued together rather than treated as separate compliance tracks.

Investigators identified the registration lapse through CalPrivacy’s own data broker registry cross-check against licensor and marketing filings that named LocateSmarter as a reseller, rather than through a consumer complaint — indicating the Agency is proactively auditing registry completeness rather than waiting for complaints to surface gaps.

On the opt-out finding, the order specifically calls out that requiring a partial Social Security number for a sale/sharing opt-out — a request that does not require confirming the requester’s full identity to the same degree as, for example, a request to know specific pieces of personal information — exceeds what Section 1798.100(c) and the implementing regulations permit as “reasonably necessary” verification, and reinforces CalPrivacy’s regulatory guidance that opt-out requests should generally be the easiest CCPA right to exercise.

The order also directs LocateSmarter to certify, within 90 days, that its downstream clients and licensees have been notified of the corrected opt-out process, extending the remediation obligation beyond LocateSmarter’s own systems.

CalPrivacy noted that the $110,490 figure sits well below the CCPA’s statutory maximum — up to $2,500 per violation, or $7,500 per intentional violation — because the order treats the registration lapse and the opt-out defect as two discrete violations rather than assessing a separate penalty for every consumer request processed through the noncompliant form; the Agency reserved the right to calculate future violations on a per-request basis if the corrective measures are not implemented on schedule.

The order arrives as CalPrivacy continues a broader registry sweep begun earlier in 2026, cross-referencing the Delete Act’s data broker registry against licensing records, marketing databases, and complaint intake to identify unregistered brokers; staff commentary accompanying the order suggests additional actions from this sweep are still working through the investigation pipeline.

The stipulated (rather than contested) posture of the order also matters for other data brokers: it reflects a negotiated settlement in which LocateSmarter agreed to the findings and remedial terms without an administrative hearing, which CalPrivacy has signaled it will continue to offer to companies that cooperate promptly once a registry gap or opt-out defect is flagged.

Source Title and Documents

The order applies to any entity meeting the CCPA’s definition of a “business” that also qualifies as a “data broker” under the Delete Act — broadly, a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business has no direct relationship, subject to the Delete Act’s registration thresholds.

LocateSmarter’s status as an out-of-state (Iowa) company did not exempt it from California’s data broker registry or CCPA obligations: both regimes apply based on whether the business collects and monetizes personal information about California residents, not on where the business is incorporated or headquartered.

  • Data brokers and people-search sites — squarely in scope; this order is the clearest signal yet that registry non-compliance will be paired with an active audit of opt-out and verification practices.
  • Marketing and consumer-data resellers — in scope where licensed data is resold to third parties without a direct consumer relationship, even if the reseller does not brand itself as a “data broker.”
  • Businesses with in-house opt-out forms generally — the excessive-verification finding applies independently of data broker status, and is relevant to any CCPA “business” operating a sale/sharing opt-out mechanism.

Related source documents referenced in the case file include the Stipulated Final Order itself, CalPrivacy’s Notice of Investigation, the staff investigative report summarizing the registry cross-check and opt-out form review, and the Agency’s public enforcement case docket for ENF26-05-D-LO, which will host status updates through the close of the compliance monitoring period.

Nymity Research tracks each of these documents as they are published, along with CalPrivacy’s prior Delete Act registry sweep actions and its broader CCPA opt-out enforcement history, so subscribers can see how this order fits the Agency’s enforcement pattern rather than reading it as an isolated case.

Back to Top