Skip to content
RiskTemplates · The Daily Brief Tuesday, August 18, 2026
Wire FINRA's 24 Enforcement Review Recommendations: Read Them as Proposals, Not Rules AUG 11

Feature Data Privacy

California Just Fined a Data Broker $116K for Making Opt-Out Too Hard. Your Fintech's Data Practices Are Next.

CalPrivacy ordered LocateSmarter to pay $116,490 over registration and opt-out violations, then fined Cybba $52,400 two days later.

By Rebecca Leung · August 14, 2026 ·
Table of Contents

California announced a $116,490 decision against an Iowa data broker on August 11. Two days later, the state announced a second data-broker penalty. A dedicated enforcement strike force is now working this category.

The question practitioners keep asking wrong is “are we a data broker?” The right question is: “are we sure we’re not?”

TL;DR

  • CalPrivacy announced the LocateSmarter decision on August 11, 2026: $116,490 for late registration and an opt-out process that required partial Social Security numbers
  • On August 13, CalPrivacy announced a separate $52,400 decision against Cybba for failing to register after operating as a data broker during 2024
  • As of August 1, 2026, 600+ registered data brokers must process consumer deletion requests through DROP within 45 days or face $200/day fines
  • Fintechs that collect consumer personal information and make it available to third parties may qualify as data brokers under CCPA — the definition is wider than most compliance teams realize

What Happened: Two Fines, One Week, One Governor’s Statement

On August 11, 2026, CalPrivacy announced its LocateSmarter decision—the agency’s first action against a data broker under the CCPA and its first action arising under both the CCPA and Delete Act. Governor Newsom’s office highlighted the action in an August 13 release.

LocateSmarter, LLC — an Iowa-based data broker — aggregated consumer profiles drawing from licensing agreements, making available names, dates of birth, Social Security numbers, telephone numbers, email addresses, employment information, and driver’s license data. Two violations:

  1. Failure to register timely with the California Data Broker Registry
  2. Requiring the last four digits of a consumer’s Social Security number before allowing them to opt out

The penalty: $116,490, plus a mandate to change practices, register as a data broker, and redesign the opt-out flow to remove the SSN requirement.

Two days later, CalPrivacy announced a second decision against Cybba, Inc. — a Boston-based company that sells personal information including geolocation data, internet activity, and consumer behavioral inferences to facilitate targeted advertising. According to the agency’s decision, Cybba operated as a data broker during 2024 without registering by the applicable deadline.

The penalty: $52,400, plus requirements to publish privacy rights metrics, access the DROP platform, and process future deletion requests.

CalPrivacy called this its second data broker enforcement action in less than a week, with more to follow.

The August 1 Deadline That Changed the Game

Understanding why this week matters requires rewinding to a January 2026 milestone that didn’t get nearly enough attention.

The California DELETE Act created DROP — the Delete Request and Opt-Out Platform — a centralized state tool letting California residents submit a single deletion request that reaches every registered data broker. DROP opened to consumers on January 1, 2026. By that date, more than 600 data brokers were registered with the state.

August 1, 2026 was the compliance inflection point. Starting that date, registered data brokers must:

  • Access DROP at minimum every 45 days
  • Process all verified deletion requests within 45 days of receipt
  • Treat unverifiable deletion requests as opt-outs from sale and sharing
  • Direct service providers and contractors to delete relevant data
  • Continue deleting newly collected data about consumers who’ve previously requested deletion, on the same 45-day cycle

The financial consequence of non-compliance: $200 per day, per violation — doubled from the original $100 rate by SB 361. For a company ignoring DROP for six months, that’s real exposure.

Why Your Fintech Might Be a Data Broker

Here’s where the compliance conversation gets uncomfortable.

Under the CCPA, a “data broker” is any business that knowingly collects and sells or shares personal information of consumers with whom it does not have a direct relationship. The key phrase is the last one: the consumer hasn’t directly engaged with you in a transaction — you’ve obtained their data and monetized it.

Fintechs that frequently trigger data broker obligations — even when they don’t think of themselves that way:

Lead aggregators and affiliate networks. If you collect consumer financial data (credit scores, income ranges, contact information, expressed financial interests) and sell or share it with lenders, insurers, or other buyers, that’s a data broker activity.

Transaction data resellers. Fintechs that monetize anonymized or pseudonymized spending data by selling it to retailers, marketers, or data analytics firms are selling consumer personal information. The fact that it’s aggregated or pseudonymized doesn’t automatically take you out of the definition.

Marketing analytics platforms. If your business model involves building consumer behavioral profiles from multiple data sources and making those available to advertisers or marketers — you may be Cybba.

Identity verification and background check services. A provider using information about consumers with whom it has no direct relationship may need a data-broker analysis; the answer turns on the statutory definition and the provider’s actual collection, sale, and sharing practices.

Financial health data aggregators. If you aggregate consumer financial account data and share it with third parties beyond the consumer’s expressed transaction purpose, the data broker question applies.

The test isn’t your industry label. It’s whether you’re collecting consumer personal information and making it available to third parties as a business purpose — not merely as a mechanism to serve that same consumer’s account.

If you haven’t run a formal data broker classification analysis for California, you haven’t answered the question.

The High-Friction Opt-Out Violation: A Pattern Fintechs Recognize

LocateSmarter’s second violation is the one that translates directly to fintech operations.

The CCPA gives consumers the right to opt out of the sale or sharing of their personal information. The implementing regulations require that opt-out mechanisms be easy to use and that companies cannot impose requirements that are “unnecessarily burdensome, difficult, or intimidating” — requirements that functionally deter consumers from exercising their rights.

Requiring the last four digits of an SSN to opt out crossed that line clearly. But the pattern of high-friction opt-out design isn’t unique to LocateSmarter. Look at your own consumer-facing privacy flows and ask:

  • Does the opt-out require a phone call when digital submission is available for every other account action?
  • Is the opt-out link buried three or four clicks from the main privacy policy page?
  • Does the flow require consumers to log in to an account they may have closed?
  • Is the opt-out form designed to redirect consumers who start the process before they complete it?
  • Does the opt-out confirmation email actually explain what opt-out means and doesn’t mean?

These patterns are not hypothetical. CalPrivacy’s enforcement focus explicitly includes the “effectiveness and accessibility” of opt-out mechanisms — not just whether they technically exist.

The Strike Force Is Escalating

CalPrivacy has confirmed publicly that the Data Broker Strike Force is expanding its focus beyond unregistered small data brokers into two areas:

  1. Health data brokers — companies that collect and share health-adjacent consumer data (fitness, medical history, location traces to healthcare facilities) without registering under the appropriate California frameworks
  2. Large multinational companies — enterprises with global data operations that may not have assessed their California data broker obligations against their US data product lines

The two public decisions show how CalPrivacy is applying the registration and opt-out rules. They are enforcement signals, not court precedent, and later matters will depend on their own facts.

If your fintech is a business-to-business data products company, a consumer financial data aggregator, or operates any kind of consumer behavioral analytics product — this escalation is about you.

The Registration Question Is Not Academic

Fintech legal teams sometimes treat California data broker registration as a checkbox that doesn’t apply to their business model. The LocateSmarter and Cybba actions suggest that assumption needs to be stress-tested.

Registration requires an annual filing, required disclosures, and the applicable fee. For registrations completed in 2026, CalPrivacy lists a $6,000 fee plus an electronic-payment processing fee. DROP access and processing duties also apply on the statutory schedule.

Failing to register doesn’t just create a $200/day fine risk — it also means you’re not in the DROP system, which means you’re not processing consumer deletion requests, which is itself a separate violation once the mandatory DROP period is active. The non-registration problem compounds.

Washington’s My Health My Data Act has a private right of action covering health data collected by any entity — including fintechs. California’s enforcement is regulator-driven with no private right of action under the Delete Act, but the CPPA’s Strike Force is demonstrating it doesn’t need plaintiff’s firms to bring volume.

Location data enforcement already covers this supply chain end to end — the FTC finalized consent orders against GM/OnStar and Kochava in the first half of 2026, and Texas AG has active litigation against Allstate/Arity. California’s data broker enforcement actions close the loop: it’s not just the data collector being scrutinized, it’s every intermediary.

And the GLBA state privacy preemption landscape means that federal financial privacy law doesn’t necessarily shield you from California’s consumer data rights framework. The CCPA contains a financial-data exception, but it’s narrower than most compliance teams assume.

So What? A Four-Part Audit

If you’re reading this and you process personal information about California consumers as part of any product or data monetization activity, run this checklist:

1. Classification. Does your fintech qualify as a data broker under the CCPA? Apply the statutory definition, not your brand identity. If you collect consumer personal information and share or sell it to third parties who didn’t acquire it directly from those consumers — run the analysis.

2. Registration status. If the answer to #1 is “possibly,” check whether you’re registered in the California Data Broker Registry. If you’re not registered and you should be, the clock is already running on daily fines.

3. DROP integration. If you’re registered, you should already have accessed DROP at least once since August 1. If you haven’t, that’s a compliance failure to remediate immediately.

4. Opt-out flow audit. Run your consumer-facing opt-out flow from a fresh incognito session. Count the clicks. Note every piece of information required. Test it on mobile. Ask whether each friction point is genuinely necessary for identity verification or whether it serves only to deter the consumer from completing the process.

The LocateSmarter decision is a concrete enforcement example showing that unnecessary friction in an opt-out flow can create liability. Other businesses still require a fact-specific analysis.

Enforcement Is Outrunning Compliance

Two enforcement actions in one week. A Strike Force that’s explicitly expanding its target profile. A governor’s office issuing press releases calling the actions “historic.” A $200/day fine structure that compounds automatically.

This is not California issuing guidance and waiting for voluntary compliance. DROP processing duties began August 1, and CalPrivacy announced the LocateSmarter decision on August 11.

If your fintech’s data broker status hasn’t been formally analyzed in the last six months, this week is the reason to do it now.


Sources: CalPrivacy LocateSmarter Decision and Stipulated Order | CalPrivacy First Action Under CCPA and Delete Act | CalPrivacy Second Data Broker Enforcement Action | Governor Newsom’s Office — Historic Action Against Data Brokers | CalPrivacy 2026 account, fee, and annual-registration instructions | CalPrivacy DROP information for data brokers

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is the California DELETE Act and the DROP platform?
The Delete Act (SB 362, 2023) requires data brokers registered with the California Privacy Protection Agency to process consumer deletion requests through a centralized state-run tool called DROP — the Delete Request and Opt-Out Platform. As of January 1, 2026, Californians can submit a single deletion request that reaches all 600+ registered data brokers. As of August 1, 2026, registered brokers must access DROP at least every 45 days and process verified deletion requests within 45 days. Failure to comply carries fines of $200 per day.
Does my fintech need to register as a data broker under California law?
Under the CCPA, a 'data broker' is a business that knowingly collects and sells or shares the personal information of consumers with whom it does not have a direct relationship. If your fintech collects consumer personal information and makes it available to third parties — for advertising, lead generation, analytics, or resale — you may qualify as a data broker regardless of your primary business. Lead aggregators, affiliate networks, marketing analytics platforms, and transaction data resellers are common fintech archetypes that trigger data broker obligations.
What counts as a 'high-friction' opt-out process under the CCPA?
The CCPA prohibits opt-out processes that are 'burdensome, difficult, or intimidating' such that they deter consumers from exercising their rights. The LocateSmarter action specifically cited requiring the last four digits of a Social Security number as a verification condition before consumers could opt out. Other high-friction patterns regulators scrutinize include multi-step phone-based opt-out flows when digital options exist, burying opt-out links more than two clicks from the homepage, requiring account login to opt out when the account may be closed, and providing an email address as the sole opt-out mechanism.
What are the penalties for failing to register as a data broker in California?
Under the Delete Act as amended by SB 361, the daily administrative fine for failing to register with the California Data Broker Registry is $200 per day. This is doubled from the original $100 rate. In the Cybba action, the company was fined $52,400 for failing to register despite operating as a data broker throughout 2024. The LocateSmarter fine of $116,490 covered both registration failures and CCPA opt-out violations.
Does the California Delete Act apply to companies headquartered outside California?
Yes. Both LocateSmarter (Iowa) and Cybba Inc. (Boston) are headquartered outside California. The CCPA and Delete Act apply to any business that collects personal information about California residents and meets the thresholds — not just California-based companies. If you collect data about California consumers and share or sell it to third parties, registration obligations apply regardless of where your company is incorporated or headquartered.
What is the CPPA Data Broker Strike Force and what is it investigating?
The California Privacy Protection Agency launched a dedicated Data Broker Enforcement Strike Force in November 2025 to investigate privacy violations by the data broker industry. The Strike Force is focused on compliance with both the CCPA's data broker registration requirement and the Delete Act's opt-out and deletion processing obligations. The CPPA has publicly indicated the Strike Force is escalating enforcement into health data brokers and large multinational companies.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.