On August 11, 2026, and August 13, 2026, the California Privacy Protection Agency (“CalPrivacy”) announced settlements with two data brokers, LocateSmarter LLC (“LocateSmarter”) and Cybba, Inc. (“Cybba”), respectively, resolving allegations that both companies failed to register as data brokers under California’s data broker law, the Delete Act. The LocateSmarter settlement also resolved claims for alleged violations of the California Consumer Privacy Act (“CCPA”), for requiring consumers to provide unnecessary sensitive personal information to exercise their opt-out rights. The LocateSmarter case marks CalPrivacy’s first enforcement action for alleged violations of both the CCPA and Delete Act.
LocateSmarter is an Iowa-based company that provides data solutions and analytics services, including location and contact services, fraud identification and detection and compliance products. The company collects personal information from third-party sources and sells it to clients through various means, including through an online search platform and data licensing products. The personal information sold includes consumers’ names, dates of birth, Social Security numbers, physical addresses, telephone numbers, email addresses, business and employment information, driver’s license information and bankruptcy and litigation data.
Cybba is a Boston-based company that sells personal information, including geolocation information, Internet activity data and identifiers, about consumers with whom it has no direct relationship to third-party businesses for marketing and advertising purposes.
Failure to Register as a Data Broker
Under California’s Delete Act, a “business” that knowingly collects and “sells” “personal information” (as such terms are defined in the CCPA) of consumers with whom it does not have a “direct relationship” (as defined in the Delete Act regulations) must register with CalPrivacy by January 31 following each year of such activity.
LocateSmarter allegedly operated as a data broker during the 2025 calendar year but failed to register by the January 31, 2026 deadline. Similarly, Cybba allegedly operated as a data broker in 2024 but did not register with CalPrivacy the following year. Cybba subsequently registered after CalPrivacy opened an investigation and contacted the company.
Unlawful Opt-Out Requirements
CalPrivacy also found that LocateSmarter violated the CCPA’s data minimization requirements by making its opt-out process unnecessarily burdensome. In 2025, LocateSmarter’s online opt-out form required consumers to provide their full name, the last four digits of their Social Security number and their mailing address before they could submit an opt-out request for the sale or sharing of their personal information.
Under the CCPA and its implementing regulations, businesses may not require consumers to submit verifiable consumer requests to exercise their right to opt out of sale or sharing because the potential harm from an imposter submitting such a request is minimal or nonexistent. CalPrivacy found that LocateSmarter essentially required consumers to verify themselves with sensitive personal information despite this prohibition. The agency further noted that even if additional information were necessary to complete an opt-out request, LocateSmarter possessed other sensitive data points it could have used instead of a Social Security number.
CalPrivacy emphasized that requiring a Social Security number to submit an opt-out request could intimidate consumers from exercising their privacy rights, which conflicts with the CCPA’s mandate that consumers be able to easily exercise those rights. The agency noted that only a “tiny fraction” of consumers actually submitted opt-out requests to LocateSmarter out of California’s nearly 40 million residents.
Settlement Terms
LocateSmarter. Under the settlement with LocateSmarter, the company agreed to pay $30,600 in administrative fines for the alleged Delete Act registration violation and $79,890 for the alleged CCPA violations, for a combined total of $110,490. LocateSmarter must also pay a $6,000 data broker registration fee and submit its 2026 data broker registration within 14 days of the order.
In addition to the monetary penalties, the settlement requires LocateSmarter to modify its opt-out process to ensure it is easy, requires minimal steps and does not require more information than necessary. Specifically, LocateSmarter may no longer require consumers to provide any portion of their Social Security number to opt out. The company must also comply with CalPrivacy’s Delete Request and Opt-Out Platform (“DROP”), provide updated CCPA training to all personnel handling consumer requests and disclose required metrics in its privacy policy regarding the number of CCPA requests received, complied with and denied.
Cybba. Under CalPrivacy’s settlement order with Cybba, the company agreed to pay $52,400 in administrative fines for failing to register as a data broker. Cybba is also required to post metrics about the number of California consumers’ privacy rights requests received the previous calendar year, including requests to delete personal information, and the number of requests with which it has complied. Additionally, CalPrivacy ordered Cybba to access and process all requests sent through DROP, which allows Californians to direct all registered brokers in the state to delete their data through a single request.
Key Takeaways
These settlements underscore CalPrivacy’s continued focus on data broker compliance and its willingness to take enforcement action against companies that fail to register or that create unnecessary barriers to the exercise of consumer privacy rights. Companies operating as data brokers in California should timely register in compliance with the Delete Act, comply with deletion requests submitted through DROP, and ensure that their consumer rights request processes do not impose unnecessary burdens on consumers.
Search
Recent Posts
Categories
- Behavioral Advertising
- Centre for Information Policy Leadership
- Children’s Privacy
- Cyber Insurance
- Cybersecurity
- Enforcement
- European Union
- Events
- FCRA
- Financial Privacy
- General
- Health Privacy
- Identity Theft
- Information Security
- International
- Marketing
- Multimedia Resources
- Online Privacy
- Security Breach
- U.S. Federal Law
- U.S. State Law
- Workplace Privacy
Tags
- Aaron P. Simpson
- Accountability
- Adequacy
- Advertisement
- Advertising
- Age Appropriate Design Code
- Age Verification
- Alabama
- American Privacy Rights Act
- Anna Pateraki
- Anonymization
- Anti-terrorism
- APEC
- Apple Inc.
- Argentina
- Arkansas
- Article 29 Working Party
- Artificial Intelligence (AI)
- Attorney General
- Audit
- Australia
- Austria
- Automated Decisionmaking
- Baltimore
- Bankruptcy
- Belgium
- Biden Administration
- Big Data
- Binding Corporate Rules
- Biometric Data
- Blockchain
- Bojana Bellamy
- Brazil
- Brexit
- British Columbia
- Brittany Bacon
- Brussels
- Business Associate Agreement
- BYOD
- California
- CalPrivacy
- CAN-SPAM
- Canada
- Cayman Islands
- CCPA
- CCTV
- Centre for Information Policy Leadership (CIPL)
- Chatbot
- Children’s Online Privacy Protection Act (COPPA)
- Chile
- China
- Chinese Taipei
- Christopher Graham
- CIPA
- Class Action
- Clinical Trial
- Cloud
- Cloud Computing
- CNIL
- Colombia
- Colorado
- Committee on Foreign Investment in the United States
- Commodity Futures Trading Commission
- Compliance
- Computer Fraud and Abuse Act
- Congress
- Connecticut
- Consent
- Consent Order
- Consumer Protection
- Consumer Rights
- Cookies
- COPPA
- Coronavirus/COVID-19
- Council of Europe
- Council of the European Union
- Court of Justice of the European Union
- CPPA
- CPRA
- Credit Monitoring
- Credit Report
- Criminal Law
- Critical Infrastructure
- Croatia
- Cross-Border Data Flow
- Cross-Border Data Transfer
- Cyber Attack
- Cybersecurity
- Cybersecurity and Infrastructure Security Agency
- Data Breach
- Data Brokers
- Data Controller
- Data Localization
- Data Minimization
- Data Privacy Framework
- Data Processor
- Data Protection Act
- Data Protection Authority
- Data Protection Impact Assessment
- Data Protection Officer
- Data Security
- Data Transfer
- David Dumont
- David Vladeck
- Deceptive Trade Practices
- Delaware
- Denmark
- Department of Commerce
- Department of Defense
- Department of Health and Human Services
- Department of Homeland Security (DHS)
- Department of Justice
- Department of the Treasury
- Design
- Digital Markets Act
- District of Columbia
- Do Not Call
- Do Not Track
- Dobbs
- Dodd-Frank Act
- DORA
- DPIA
- E-Privacy
- E-Privacy Directive
- Ecuador
- Ed Tech
- Edith Ramirez
- Electronic Communications Privacy Act
- Electronic Privacy Information Center
- Electronic Protected Health Information
- Elizabeth Denham
- Employee Monitoring
- Encryption
- ENISA
- EU Data Protection Directive
- EU General Data Protection Regulation (GDPR)
- EU Member States
- European Commission
- European Data Protection Board
- European Data Protection Supervisor
- European Parliament
- European Union
- Facial Recognition Technology
- FACTA
- Fair Credit Reporting Act
- Fair Information Practice Principles
- Federal Aviation Administration
- Federal Bureau of Investigation
- Federal Communications Commission
- Federal Data Protection Act
- Federal Trade Commission
- FERC
- Financial Data
- FinTech
- Florida
- Food and Drug Administration
- Foreign Intelligence Surveillance Act
- France
- Franchise
- Fred Cate
- Freedom of Information Act
- Freedom of Speech
- Fundamental Rights
- GDPR
- Genetic Data
- Geofencing
- Geolocation
- Geolocation Data
- Georgia
- Germany
- Global Privacy Assembly
- Global Privacy Enforcement Network
- Gramm Leach Bliley Act
- Grok
- Hacker
- Hawaii
- Health Data
- HIPAA
- HITECH Act
- Hong Kong
- House of Representatives
- Hungary
- Illinois
- India
- Indiana
- Indonesia
- Information Commissioners Office
- Information Sharing
- Insurance Provider
- Internal Revenue Service
- International Association of Privacy Professionals
- International Commissioners Office
- Internet
- Internet of Things
- Iowa
- IP Address
- Ireland
- Israel
- Italy
- Jacob Kohnstamm
- Japan
- Jason Beach
- Jay Rockefeller
- Jenna Rode
- Jennifer Stoddart
- Jersey
- Jessica Rich
- John Delionado
- John Edwards
- Kentucky
- Korea
- Large Language Model
- Latin America
- Laura Leonard
- Law Enforcement
- Lawrence Strickling
- Legislation
- Liability
- Lisa Sotto
- Litigation
- Location-Based Services
- London
- Louisiana
- Madrid Resolution
- Maine
- Malaysia
- Maryland
- Massachusetts
- Meta
- Mexico
- Michigan
- Microsoft
- Minnesota
- Missouri
- Mobile
- Mobile App
- Mobile Device
- Montana
- Morocco
- MySpace
- Natascha Gerlach
- National Institute of Standards and Technology
- National Labor Relations Board
- National Science and Technology Council
- National Security
- National Security Agency
- National Telecommunications and Information Administration
- Nebraska
- NEDPA
- Netherlands
- Nevada
- New Hampshire
- New Jersey
- New Mexico
- New York
- New Zealand
- Nigeria
- Ninth Circuit
- North Carolina
- North Dakota
- North Korea
- Norway
- Obama Administration
- OCPA
- OECD
- Office for Civil Rights (OCR)
- Office of Foreign Assets Control
- Ohio
- Oklahoma
- Online Behavioral Advertising
- Online Privacy
- Opt-In Consent
- Opt-Out
- Oregon
- Outsourcing
- Pakistan
- Parental Consent
- Payment Card
- PCI DSS
- Penalty
- Pennsylvania
- Personal Data
- Personal Health Information
- Personal Information
- Personally Identifiable Information
- Peru
- Philippines
- Poland
- PRISM
- Privacy
- Privacy and Information Security Law
- Privacy By Design
- Privacy Notice
- Privacy Policy
- Privacy Rights
- Privacy Rule
- Privacy Shield
- Profiling
- Protected Health Information
- Purpose Limitation
- Ransomware
- Record Retention
- Red Flags Rule
- Rhode Island
- Richard Thomas
- Right to Be Forgotten
- Right to Privacy
- Risk Assessment
- Risk-Based Approach
- ROSCA
- Rosemary Jay
- Russia
- Safe Harbor
- Salesforce
- Sanctions
- Schrems
- Scott Kimpel
- SECURE Data Act
- Securities and Exchange Commission
- Security Rule
- Senate
- Sensitive Data
- Serbia
- Service Provider
- Singapore
- Smart Grid
- Smart Metering
- Social Media
- Social Security Number
- South Africa
- South Carolina
- South Dakota
- South Korea
- Spain
- Spyware
- Standard Contractual Clauses
- State Attorneys General
- Steven Haas
- Stick With Security Series
- Stored Communications Act
- Student Data
- Supreme Court
- Surveillance
- Surveillance Pricing
- Sweden
- Switzerland
- Taiwan
- Targeted Advertising
- Telecommunications
- Telemarketing
- Telephone Consumer Protection Act
- Tennessee
- Terry McAuliffe
- Texas
- Text Message
- Thailand
- Transparency
- Transportation Security Administration
- Trump Administration
- United Arab Emirates
- United Kingdom
- United States
- Unmanned Aircraft Systems
- Uruguay
- Utah
- Vermont
- Video Privacy Protection Act
- Video Surveillance
- Virginia
- Viviane Reding
- Washington
- Whistleblowing
- Wireless Network
- Wiretap
- ZIP Code