This browser is not actively supported anymore. For the best passle experience, we strongly recommend you upgrade your browser.

Technology Law

| 2 minute read

California's DROP-Era Enforcement Begins: Targets Data Broker Registration and Opt-Out Practices

Just days after the Delete Request and Opt-Out Platform (DROP) went live, CalPrivacy issued two orders against data brokers that failed to register under the Delete Act. Yesterday, the Agency announced a decision against Cybba, Inc., a digital marketing company that agreed to pay a $52,400 administrative fine. Cybba was deemed a data broker because it sold personal information such as geolocation data, internet activity, and inferences about consumers with whom it had no direct relationship, using it to build custom audiences for targeted advertising. Cybba was the fourteenth data broker penalized for failing to register.

The thirteenth case, however, is the more instructive one. On August 11, 2026, CalPrivacy fined LocateSmarter, LLC, an Iowa-based data analytics provider, $110,490 for violations of both the Delete Act and the CCPA. LocateSmarter failed to register as a data broker and required consumers to provide sensitive personal information to opt out of the sale or sharing of their information. The company must also pay the $6,000 DROP registration fee. The case shows how a registration violation can lead regulators to scrutinize a company's broader privacy practices.

Failure to Register for DROP

The first violation is familiar territory. LocateSmarter qualified as a data broker because it obtains consumer personal information from third-party sources, including data licensors, analytics providers, and other suppliers, and licenses it to other third parties. That made it a data broker for 2025, triggering an obligation to register by January 31, 2026. It didn't. CalPrivacy imposed a $30,600 fine, ordered LocateSmarter to pay the $6,000 annual registration fee, and required the company to register with DROP within fourteen days.

A Broader Lesson on Opt-Out Requests

The more instructive violation for businesses subject to the CCPA involves LocateSmarter's website opt-out process. Opt-out rights have emerged as another enforcement focus, highlighted by recent actions against Honda, Todd Snyder, and Ford, all involving unnecessary verification of consumers exercising their opt-out rights. Here, LocateSmarter required consumers seeking to opt out to provide their full name, mailing address, and the last four digits of their Social Security number. CalPrivacy asserted that this violated the CCPA because, unlike requests to delete, know, or correct, businesses generally may not require consumers to verify their identity to process an opt-out request, nor collect more information than reasonably necessary to do so.

As this decision and others make clear, CalPrivacy views data minimization, the principle that businesses should collect only the personal information reasonably necessary for a disclosed purpose, as a foundational CCPA requirement. Requiring a mailing address and part of a Social Security number, among the most sensitive categories, was unnecessary and could discourage consumers from exercising their rights. CalPrivacy argued, even if more information were needed, LocateSmarter could have used other non-sensitive data points.

Takeaways

  • DROP readiness alone is not enough. Data brokers should review their website opt-out processes for compliance with the CCPA's data minimization requirements.
  • Privacy compliance is interconnected. Failing one obligation may draw attention to broader practices and expose additional deficiencies.
  • CalPrivacy noted only a "mere handful" of consumers submitted opt-out requests. An unusually low volume may signal that the process is hard to find, understand, or complete, drawing regulatory scrutiny.

Tags

drop, delete act, ccpa, privacy, data brokers, technology law updates, technology law, california