
This month, California’s privacy regulator, the California Privacy Protection Agency (CalPrivacy), announced its settlement of an enforcement action against a data broker, LocateSmarter LLC. The settlement signals that CalPrivacy can and will seek to enforce both the CCPA and California’s new Delete Act regulations against data brokers.
Under California’s Delete Act, a data broker is generally a business that knowingly collects and sells to third parties the personal information of consumers with whom the business does not have a direct relationship. Because California’s definition of “sale” is broad, many marketing, analytics, or lead-generation vendors qualify as data brokers even if they would never describe themselves as such.
Among the Delete Act’s principal requirements, data brokers must register with CalPrivacy every January and pay an annual fee that supports the public Data Broker Registry and the statewide Delete Request and Opt-Out Platform (DROP). Additionally, they must honor applicable consumer rights requests submitted directly under the CCPA and, beginning August 1, 2026, access DROP at least once every 45 days to download and process consumer deletion requests, including associated restrictions on the sale or sharing of personal information where applicable. In addition to these requirements under the Delete Act, because most data brokers are also businesses subject to the CCPA, they must comply with broader CCPA duties such as providing clear privacy notices, and following data-minimization principles. Failure to comply with these requirements can result in significant penalties.
LocateSmarter LLC, an Iowa-based data broker, failed to register under the Delete Act by the January 31, 2026 deadline applicable to its 2025 activities. The company also violated the CCPA’s data-minimization rule by forcing Californians to provide the last four digits of their Social Security number and a mailing address before processing an opt-out request. CalPrivacy noted that this request for additional information created friction by requiring consumers seeking to exercise their rights under the CCPA to provide sensitive information. CalPrivacy’s settlement requires LocateSmarter to pay a total of $116,490 (with $30,600 applicable to Delete Act violations, $79,890 attributable to CCPA violations, and a $6,000 data broker registration fee), register as a data broker, eliminate requests for sensitive data from its consumer opt-out or deletion request flow, comply with the Delete Act by honoring requests made through DROP, and retrain personnel on CCPA compliance. In short, the disruption resulting from these violations extends beyond monetary penalties; business practices must now change in the wake of the settlement terms.
First, the LocateSmarter order confirms that CalPrivacy will combine the CCPA and the Delete Act in a single action, thereby creating potential exposure under separate CCPA and Delete Act penalty regimes for businesses subject to both laws.
Second, data brokers must honor applicable consumer rights requests submitted directly under the CCPA and, beginning August 1, 2026, access DROP at least once every 45 days to download and process consumer deletion requests, which may also restrict the broker’s ability to sell or share matching personal information.
Finally, the agency has once again made clear that the consumer’s experience helps define CCPA compliance. CalPrivacy’s focus on the “unnecessary friction” created in LocateSmarter’s consumer request flows continues a trend established in its pursuit of prior enforcement actions against Disney (whose asymmetry between consumer tracking capabilities and consumer opt-out request flows constituted this “unnecessary friction” under the CCPA), PlayOn Sports (a digital ticketing platform ordered to pay a $1.10 million fine for violations including failure to create easy opt-out request processes for consumers), and Ford (whose penalties arising from unnecessary friction in consumer request processes we have previously written about HERE: https://www.pag.law/publications/california-privacy-regulators-target-friction-in-consumer-opt-out-processes-key-lessons-from-the-ford-enforcement-action). The fact that LocateSmarter received only a handful of opt-out requests yet still faced a six-figure penalty shows that enforcement hinges on the seriousness of the violation and not simply on how many consumers complain. Beyond just the letter of the law, the intended impact of data privacy regulation on user experience is clearly encompassed in California’s compliance regime.
Even if you do not market yourself as a “data broker,” if your business processes or transacts in personal data, your compliance team should take the following steps:
Compliance is now being judged by consumer experience, not merely paperwork. Working with data privacy experts to perform a relatively simple audit of your data privacy practices and workflows can now save your business time and money in the future by avoiding regulatory violations. PAG Law’s Data Privacy, Cybersecurity & AI Governance practice is ready to work with your business and tailor a compliance program that meets your needs.
Zachary Soto is a Partner at PAG Law PLLC, where he chairs the Privacy Law, Cybersecurity, and AI Governance practice. He has practiced privacy, cybersecurity, and corporate transactional law for over 16 years and is certified by the International Association of Privacy Professionals as a Certified Information Privacy Professional (CIPP/US) and AI Governance Professional (AIGP).
Disclaimer: This publication is provided by PAG Law PLLC for general informational purposes only and does not constitute legal advice or create an attorney-client relationship between PAG Law and the reader. The content reflects the views of the author as of the date of publication and may not reflect subsequent developments in law, regulation, or policy. Readers should not act or refrain from acting on the basis of any information contained herein without seeking professional legal counsel tailored to their specific circumstances and jurisdiction. PAG Law expressly disclaims all liability with respect to actions taken or not taken based on any or all of the contents of this publication. This material may be considered attorney advertising in some jurisdictions.
On May 9, 2024, Maryland Governor Wes Moore signed the Maryland Online Data Privacy Act of 2024 (MODPA), making Maryland the 18th state to enact comprehensive privacy...
On May 9, 2024, Maryland Governor Wes Moore signed the Maryland Online Data Privacy Act of 2024 (MODPA), making Maryland the 18th state to enact comprehensive privacy...
On May 9, 2024, Maryland Governor Wes Moore signed the Maryland Online Data Privacy Act of 2024 (MODPA), making Maryland the 18th state to enact comprehensive privacy...
Our commitment to excellence has driven numerous
successful outcomes in complex legal matters.
