The latest news and blogs

California Brings First Joint CCPA and Delete Act Enforcement Action Against Data Broker

Zac Soto
August 25, 2026

This month, California’s privacy regulator, the California Privacy Protection Agency (CalPrivacy), announced its settlement of an enforcement action against a data broker, LocateSmarter LLC. The settlement signals that CalPrivacy can and will seek to enforce both the CCPA and California’s new Delete Act regulations against data brokers.

What is a “data broker” in California, and what regulatory requirements apply to data brokers?

Under California’s Delete Act, a data broker is generally a business that knowingly collects and sells to third parties the personal information of consumers with whom the business does not have a direct relationship. Because California’s definition of “sale” is broad, many marketing, analytics, or lead-generation vendors qualify as data brokers even if they would never describe themselves as such.

Among the Delete Act’s principal requirements, data brokers must register with CalPrivacy every January and pay an annual fee that supports the public Data Broker Registry and the statewide Delete Request and Opt-Out Platform (DROP). Additionally, they must honor applicable consumer rights requests submitted directly under the CCPA and, beginning August 1, 2026, access DROP at least once every 45 days to download and process consumer deletion requests, including associated restrictions on the sale or sharing of personal information where applicable. In addition to these requirements under the Delete Act, because most data brokers are also businesses subject to the CCPA, they must comply with broader CCPA duties such as providing clear privacy notices, and following data-minimization principles. Failure to comply with these requirements can result in significant penalties.

LocateSmarter’s Violations: Failure to register and friction in consumer request Flows.

LocateSmarter LLC, an Iowa-based data broker, failed to register under the Delete Act by the January 31, 2026 deadline applicable to its 2025 activities. The company also violated the CCPA’s data-minimization rule by forcing Californians to provide the last four digits of their Social Security number and a mailing address before processing an opt-out request. CalPrivacy noted that this request for additional information created friction by requiring consumers seeking to exercise their rights under the CCPA to provide sensitive information. CalPrivacy’s settlement requires LocateSmarter to pay a total of $116,490 (with $30,600 applicable to Delete Act violations, $79,890 attributable to CCPA violations, and a $6,000 data broker registration fee), register as a data broker, eliminate requests for sensitive data from its consumer opt-out or deletion request flow, comply with the Delete Act by honoring requests made through DROP, and retrain personnel on CCPA compliance. In short, the disruption resulting from these violations extends beyond monetary penalties; business practices must now change in the wake of the settlement terms.

Why this matters beyond data brokers:

First, the LocateSmarter order confirms that CalPrivacy will combine the CCPA and the Delete Act in a single action, thereby creating potential exposure under separate CCPA and Delete Act penalty regimes for businesses subject to both laws.

Second, data brokers must honor applicable consumer rights requests submitted directly under the CCPA and, beginning August 1, 2026, access DROP at least once every 45 days to download and process consumer deletion requests, which may also restrict the broker’s ability to sell or share matching personal information.

Finally, the agency has once again made clear that the consumer’s experience helps define CCPA compliance. CalPrivacy’s focus on the “unnecessary friction” created in LocateSmarter’s consumer request flows continues a trend established in its pursuit of prior enforcement actions against Disney (whose asymmetry between consumer tracking capabilities and consumer opt-out request flows constituted this “unnecessary friction” under the CCPA), PlayOn Sports (a digital ticketing platform ordered to pay a $1.10 million fine for violations including failure to create easy opt-out request processes for consumers), and Ford (whose penalties arising from unnecessary friction in consumer request processes we have previously written about HERE: https://www.pag.law/publications/california-privacy-regulators-target-friction-in-consumer-opt-out-processes-key-lessons-from-the-ford-enforcement-action). The fact that LocateSmarter received only a handful of opt-out requests yet still faced a six-figure penalty shows that enforcement hinges on the seriousness of the violation and not simply on how many consumers complain. Beyond just the letter of the law, the intended impact of data privacy regulation on user experience is clearly encompassed in California’s compliance regime.

Five action items for your organization:

Even if you do not market yourself as a “data broker,” if your business processes or transacts in personal data, your compliance team should take the following steps:

  1. 1. Map your data flows. If you collect data from third parties with whom you do not have a direct relationship and resell, share, or license it, even indirectly, you may be a data broker under the Delete Act and subject to its requirements.

  1. 2. Register as a data broker (or document why you are exempt). Registration is not an overly long process, and currently costs around $6,000. To the extent your assessment indicates that registration as a data broker is not necessary, document the rationale behind this determination and revisit this assessment as your business and its processes evolve.

  1. 3. Simplify opt-out and deletion request processes. Remove any fields requiring consumers to input data that is not reasonably necessary in order to process applicable requests regarding their data.

  1. 4. Test for “dark patterns.” Under California privacy regulations, “dark patterns” are website or app designs that confuse or manipulate users into making choices regarding their personal data that they would not otherwise make. Examine your rights-request flow on desktop and mobile. Count clicks required, look for confusing language, and ensure that the opt-out preference signals, such as the Global Privacy Control, actually work.

  1. 5. Ensure You Can Use DROP. Confirm you can download, match, process, and report on consumer deletion requests submitted through DROP, including implementing applicable restrictions on the sale or sharing of personal information.

Compliance is now being judged by consumer experience, not merely paperwork. Working with data privacy experts to perform a relatively simple audit of your data privacy practices and workflows can now save your business time and money in the future by avoiding regulatory violations. PAG Law’s Data Privacy, Cybersecurity & AI Governance practice is ready to work with your business and tailor a compliance program that meets your needs.

Zachary Soto is a Partner at PAG Law PLLC, where he chairs the Privacy Law, Cybersecurity, and AI Governance practice. He has practiced privacy, cybersecurity, and corporate transactional law for over 16 years and is certified by the International Association of Privacy Professionals as a Certified Information Privacy Professional (CIPP/US) and AI Governance Professional (AIGP).

Disclaimer: This publication is provided by PAG Law PLLC for general informational purposes only and does not constitute legal advice or create an attorney-client relationship between PAG Law and the reader. The content reflects the views of the author as of the date of publication and may not reflect subsequent developments in law, regulation, or policy. Readers should not act or refrain from acting on the basis of any information contained herein without seeking professional legal counsel tailored to their specific circumstances and jurisdiction. PAG Law expressly disclaims all liability with respect to actions taken or not taken based on any or all of the contents of this publication. This material may be considered attorney advertising in some jurisdictions.

August 25, 2026

California Brings First Joint CCPA and Delete Act Enforcement Action Against Data Broker

On May 9, 2024, Maryland Governor Wes Moore signed the Maryland Online Data Privacy Act of 2024 (MODPA), making Maryland the 18th state to enact comprehensive privacy...

PUBLICATIONS
Enforcement
California
Data Privacy
Zac Soto
5 mins
August 25, 2026
August 12, 2026

Anthropic’s New Watermarks for Claude-Generated Content: What You Need to Know

On May 9, 2024, Maryland Governor Wes Moore signed the Maryland Online Data Privacy Act of 2024 (MODPA), making Maryland the 18th state to enact comprehensive privacy...

PUBLICATIONS
Ai law
Ai tools
Zac Soto
5 mins
August 12, 2026
June 11, 2026

Connecticut's CART Act: New Comprehensive AI Regulation for Employers, Social Media, Chatbots, and Synthetic Content

On May 9, 2024, Maryland Governor Wes Moore signed the Maryland Online Data Privacy Act of 2024 (MODPA), making Maryland the 18th state to enact comprehensive privacy...

Ai law
Regulation
Zachary Soto
6 mins
June 11, 2026