What Happened
On August 10, 2026, the California Privacy Protection Agency issued an order against LocateSmarter, LLC, an Iowa-based data broker, for violations of both California's data broker law and the California Consumer Privacy Act. The company required consumers wanting to opt out of the sale or sharing of their personal data to submit their mailing address and the last four digits of their Social Security number.
CalPrivacy determined this practice violated CCPA on three grounds: it required verification information for an opt-out request, which CCPA prohibits; it demanded more information than necessary to process the request; and it created an intimidation barrier that conflicts with CCPA's mandate for easy exercise of privacy rights.
The agency fined LocateSmarter over $30,000 for Delete Act violations and nearly $80,000 for CCPA violations, plus a $6,000 registration fee. Within days, CalPrivacy announced similar enforcement actions against Cybba Inc. and SalesIntel Research Inc. for failing to register as data brokers, with fines of $52,400 and $36,400 respectively.
Timeline
August 1, 2026: California's Delete Act data broker deletion requirements take effect.
August 10, 2026: CalPrivacy announces order against LocateSmarter.
August 13, 2026: CalPrivacy announces order against Cybba Inc.
August 14, 2026: Order signed with SalesIntel Research Inc.
August 25, 2026: CalPrivacy reports over 500,000 California residents have filed deletion requests through the Delete Request and Opt-Out Platform.
September 1, 2026: CalPrivacy publicly announces SalesIntel order.
Which Controls Failed or Were Missing
LocateSmarter's opt-out mechanism failed in process design. The company built friction into a consumer rights workflow that CCPA requires to be frictionless. Three specific breakdowns occurred:
No verification gate for opt-out requests. The company treated opt-out like access or deletion requests, which do require identity verification under CCPA Section 1798.140(o). Opt-out requests don't carry the same identity theft risk, so CCPA doesn't permit verification requirements.
Excessive data collection for the stated purpose. Even if verification were permitted, a mailing address alone would suffice to identify a consumer in a data broker's records. Adding partial SSN collection exceeded what's necessary under the data minimization principle.
Chilling effect on rights exercise. Asking for SSN fragments creates hesitation. Many consumers won't submit that information to a company they've never directly engaged with, effectively blocking their ability to exercise rights.
For Cybba and SalesIntel, the failure was simpler: they operated as data brokers without registering. Both companies collected and sold personal data to facilitate targeted advertising but didn't file the required annual registration or pay the fee.
What the Relevant Standard Requires
California Consumer Privacy Act Section 1798.135(a)(4) states that a business shall not require a consumer to create an account or provide additional information beyond what is necessary to direct the business not to sell or share the consumer's personal information. The statute explicitly prohibits verification requirements for opt-out requests.
California Civil Code Section 1798.99.82 requires any business that meets the data broker definition to register with CalPrivacy annually and pay a registration fee. The definition captures businesses that knowingly collect and sell personal data about consumers with whom the business doesn't have a direct relationship.
California Civil Code Section 1798.99.85 (the Delete Act) requires registered data brokers to process consumer deletion requests submitted through CalPrivacy's centralized platform. The law went into effect August 1, 2026, giving data brokers no grace period between the effective date and enforcement.
The Colorado AI Act, effective January 1, 2027, adds another layer. Under proposed Section 6.6.B.(3) of the draft regulations, deployers of covered automated decision-making technology must identify all sources of personal data by name if a consumer requests information after an adverse consequential decision. This includes original sources and any intermediary vendors, meaning you can't just list "data broker" -- you must name the specific company and trace the data lineage back to first-party collection.
Lessons and Action Items for Your Team
Audit your opt-out workflows today. Walk through each consumer rights request type and confirm you're not asking for information you don't need. If you're requiring account creation, email verification, or identity documents for opt-out requests, remove those steps. You can verify identity for access and deletion requests under CCPA Section 1798.140(o), but opt-out must be zero-friction.
Map your data sales and sharing relationships. If you transfer personal data to advertising platforms, analytics vendors, or marketing technology providers who use that data for their own commercial purposes, you're likely selling or sharing under CCPA definitions. Document every recipient by name. Colorado's proposed AI regulations will require this level of specificity if you deploy automated decision-making technology that affects Colorado consumers, including employees.
Determine if you meet the data broker definition in every jurisdiction where you operate. California defines a data broker as a business that knowingly collects and sells personal data about consumers with whom it doesn't have a direct relationship. If you're enriching customer records with third-party data and then licensing those enriched profiles, you may qualify. Check registration requirements in California, Vermont, and Texas, which all maintain data broker registries.
Review vendor contracts for registration and compliance obligations. Your marketing and advertising agreements should require vendors to maintain all necessary licenses and registrations. Add a notification clause: vendors must inform you within 10 days if they become subject to a regulatory order, consent decree, or enforcement action. This gives you time to assess whether continued use of that vendor creates compliance or reputational risk.
Document your data sources for any automated decision-making system. If you're using algorithms, models, or automated systems to make employment, credit, housing, or other consequential decisions, start building a data lineage map now. Colorado's regulations will require you to name every source, including intermediaries. "We bought data from Acme Data Services, who sourced it from public records and social media platforms" won't satisfy the requirement unless you can name which public records systems and which social media companies.
The LocateSmarter case shows that regulators will enforce against process design failures, not just data breaches or unauthorized disclosures. Your opt-out mechanism is a consumer-facing control. If it creates barriers, you're out of compliance regardless of your intent.



