Feature Data Privacy
California Just Fined a Data Broker $116K for Making Opt-Out Too Hard. Your Fintech's Data Practices Are Next.
CalPrivacy ordered LocateSmarter to pay $116,490 over registration and opt-out violations, then fined Cybba $52,400 two days later.
Table of Contents
California announced a $116,490 decision against an Iowa data broker on August 11. Two days later, the state announced a second data-broker penalty. A dedicated enforcement strike force is now working this category.
The question practitioners keep asking wrong is “are we a data broker?” The right question is: “are we sure we’re not?”
TL;DR
- CalPrivacy announced the LocateSmarter decision on August 11, 2026: $116,490 for late registration and an opt-out process that required partial Social Security numbers
- On August 13, CalPrivacy announced a separate $52,400 decision against Cybba for failing to register after operating as a data broker during 2024
- As of August 1, 2026, 600+ registered data brokers must process consumer deletion requests through DROP within 45 days or face $200/day fines
- Fintechs that collect consumer personal information and make it available to third parties may qualify as data brokers under CCPA — the definition is wider than most compliance teams realize
What Happened: Two Fines, One Week, One Governor’s Statement
On August 11, 2026, CalPrivacy announced its LocateSmarter decision—the agency’s first action against a data broker under the CCPA and its first action arising under both the CCPA and Delete Act. Governor Newsom’s office highlighted the action in an August 13 release.
LocateSmarter, LLC — an Iowa-based data broker — aggregated consumer profiles drawing from licensing agreements, making available names, dates of birth, Social Security numbers, telephone numbers, email addresses, employment information, and driver’s license data. Two violations:
- Failure to register timely with the California Data Broker Registry
- Requiring the last four digits of a consumer’s Social Security number before allowing them to opt out
The penalty: $116,490, plus a mandate to change practices, register as a data broker, and redesign the opt-out flow to remove the SSN requirement.
Two days later, CalPrivacy announced a second decision against Cybba, Inc. — a Boston-based company that sells personal information including geolocation data, internet activity, and consumer behavioral inferences to facilitate targeted advertising. According to the agency’s decision, Cybba operated as a data broker during 2024 without registering by the applicable deadline.
The penalty: $52,400, plus requirements to publish privacy rights metrics, access the DROP platform, and process future deletion requests.
CalPrivacy called this its second data broker enforcement action in less than a week, with more to follow.
The August 1 Deadline That Changed the Game
Understanding why this week matters requires rewinding to a January 2026 milestone that didn’t get nearly enough attention.
The California DELETE Act created DROP — the Delete Request and Opt-Out Platform — a centralized state tool letting California residents submit a single deletion request that reaches every registered data broker. DROP opened to consumers on January 1, 2026. By that date, more than 600 data brokers were registered with the state.
August 1, 2026 was the compliance inflection point. Starting that date, registered data brokers must:
- Access DROP at minimum every 45 days
- Process all verified deletion requests within 45 days of receipt
- Treat unverifiable deletion requests as opt-outs from sale and sharing
- Direct service providers and contractors to delete relevant data
- Continue deleting newly collected data about consumers who’ve previously requested deletion, on the same 45-day cycle
The financial consequence of non-compliance: $200 per day, per violation — doubled from the original $100 rate by SB 361. For a company ignoring DROP for six months, that’s real exposure.
Why Your Fintech Might Be a Data Broker
Here’s where the compliance conversation gets uncomfortable.
Under the CCPA, a “data broker” is any business that knowingly collects and sells or shares personal information of consumers with whom it does not have a direct relationship. The key phrase is the last one: the consumer hasn’t directly engaged with you in a transaction — you’ve obtained their data and monetized it.
Fintechs that frequently trigger data broker obligations — even when they don’t think of themselves that way:
Lead aggregators and affiliate networks. If you collect consumer financial data (credit scores, income ranges, contact information, expressed financial interests) and sell or share it with lenders, insurers, or other buyers, that’s a data broker activity.
Transaction data resellers. Fintechs that monetize anonymized or pseudonymized spending data by selling it to retailers, marketers, or data analytics firms are selling consumer personal information. The fact that it’s aggregated or pseudonymized doesn’t automatically take you out of the definition.
Marketing analytics platforms. If your business model involves building consumer behavioral profiles from multiple data sources and making those available to advertisers or marketers — you may be Cybba.
Identity verification and background check services. A provider using information about consumers with whom it has no direct relationship may need a data-broker analysis; the answer turns on the statutory definition and the provider’s actual collection, sale, and sharing practices.
Financial health data aggregators. If you aggregate consumer financial account data and share it with third parties beyond the consumer’s expressed transaction purpose, the data broker question applies.
The test isn’t your industry label. It’s whether you’re collecting consumer personal information and making it available to third parties as a business purpose — not merely as a mechanism to serve that same consumer’s account.
If you haven’t run a formal data broker classification analysis for California, you haven’t answered the question.
The High-Friction Opt-Out Violation: A Pattern Fintechs Recognize
LocateSmarter’s second violation is the one that translates directly to fintech operations.
The CCPA gives consumers the right to opt out of the sale or sharing of their personal information. The implementing regulations require that opt-out mechanisms be easy to use and that companies cannot impose requirements that are “unnecessarily burdensome, difficult, or intimidating” — requirements that functionally deter consumers from exercising their rights.
Requiring the last four digits of an SSN to opt out crossed that line clearly. But the pattern of high-friction opt-out design isn’t unique to LocateSmarter. Look at your own consumer-facing privacy flows and ask:
- Does the opt-out require a phone call when digital submission is available for every other account action?
- Is the opt-out link buried three or four clicks from the main privacy policy page?
- Does the flow require consumers to log in to an account they may have closed?
- Is the opt-out form designed to redirect consumers who start the process before they complete it?
- Does the opt-out confirmation email actually explain what opt-out means and doesn’t mean?
These patterns are not hypothetical. CalPrivacy’s enforcement focus explicitly includes the “effectiveness and accessibility” of opt-out mechanisms — not just whether they technically exist.
The Strike Force Is Escalating
CalPrivacy has confirmed publicly that the Data Broker Strike Force is expanding its focus beyond unregistered small data brokers into two areas:
- Health data brokers — companies that collect and share health-adjacent consumer data (fitness, medical history, location traces to healthcare facilities) without registering under the appropriate California frameworks
- Large multinational companies — enterprises with global data operations that may not have assessed their California data broker obligations against their US data product lines
The two public decisions show how CalPrivacy is applying the registration and opt-out rules. They are enforcement signals, not court precedent, and later matters will depend on their own facts.
If your fintech is a business-to-business data products company, a consumer financial data aggregator, or operates any kind of consumer behavioral analytics product — this escalation is about you.
The Registration Question Is Not Academic
Fintech legal teams sometimes treat California data broker registration as a checkbox that doesn’t apply to their business model. The LocateSmarter and Cybba actions suggest that assumption needs to be stress-tested.
Registration requires an annual filing, required disclosures, and the applicable fee. For registrations completed in 2026, CalPrivacy lists a $6,000 fee plus an electronic-payment processing fee. DROP access and processing duties also apply on the statutory schedule.
Failing to register doesn’t just create a $200/day fine risk — it also means you’re not in the DROP system, which means you’re not processing consumer deletion requests, which is itself a separate violation once the mandatory DROP period is active. The non-registration problem compounds.
Washington’s My Health My Data Act has a private right of action covering health data collected by any entity — including fintechs. California’s enforcement is regulator-driven with no private right of action under the Delete Act, but the CPPA’s Strike Force is demonstrating it doesn’t need plaintiff’s firms to bring volume.
Location data enforcement already covers this supply chain end to end — the FTC finalized consent orders against GM/OnStar and Kochava in the first half of 2026, and Texas AG has active litigation against Allstate/Arity. California’s data broker enforcement actions close the loop: it’s not just the data collector being scrutinized, it’s every intermediary.
And the GLBA state privacy preemption landscape means that federal financial privacy law doesn’t necessarily shield you from California’s consumer data rights framework. The CCPA contains a financial-data exception, but it’s narrower than most compliance teams assume.
So What? A Four-Part Audit
If you’re reading this and you process personal information about California consumers as part of any product or data monetization activity, run this checklist:
1. Classification. Does your fintech qualify as a data broker under the CCPA? Apply the statutory definition, not your brand identity. If you collect consumer personal information and share or sell it to third parties who didn’t acquire it directly from those consumers — run the analysis.
2. Registration status. If the answer to #1 is “possibly,” check whether you’re registered in the California Data Broker Registry. If you’re not registered and you should be, the clock is already running on daily fines.
3. DROP integration. If you’re registered, you should already have accessed DROP at least once since August 1. If you haven’t, that’s a compliance failure to remediate immediately.
4. Opt-out flow audit. Run your consumer-facing opt-out flow from a fresh incognito session. Count the clicks. Note every piece of information required. Test it on mobile. Ask whether each friction point is genuinely necessary for identity verification or whether it serves only to deter the consumer from completing the process.
The LocateSmarter decision is a concrete enforcement example showing that unnecessary friction in an opt-out flow can create liability. Other businesses still require a fact-specific analysis.
Enforcement Is Outrunning Compliance
Two enforcement actions in one week. A Strike Force that’s explicitly expanding its target profile. A governor’s office issuing press releases calling the actions “historic.” A $200/day fine structure that compounds automatically.
This is not California issuing guidance and waiting for voluntary compliance. DROP processing duties began August 1, and CalPrivacy announced the LocateSmarter decision on August 11.
If your fintech’s data broker status hasn’t been formally analyzed in the last six months, this week is the reason to do it now.
Sources: CalPrivacy LocateSmarter Decision and Stipulated Order | CalPrivacy First Action Under CCPA and Delete Act | CalPrivacy Second Data Broker Enforcement Action | Governor Newsom’s Office — Historic Action Against Data Brokers | CalPrivacy 2026 account, fee, and annual-registration instructions | CalPrivacy DROP information for data brokers
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is the California DELETE Act and the DROP platform?
Does my fintech need to register as a data broker under California law?
What counts as a 'high-friction' opt-out process under the CCPA?
What are the penalties for failing to register as a data broker in California?
Does the California Delete Act apply to companies headquartered outside California?
What is the CPPA Data Broker Strike Force and what is it investigating?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Keep reading
Related posts.
Data Privacy
Global Privacy Control for Financial Services: A State-by-State Scope Test
A practical Global Privacy Control guide for financial services: state scope, GLBA exemptions, signal handling, testing, and evidence.
Aug 17, 2026
Data Privacy
Washington MHMDA for Fintech: The GLBA Data Exemption and CPA Enforcement
Washington's My Health My Data Act has a data-level GLBA exemption and uses the Consumer Protection Act for public and private enforcement.
Aug 12, 2026
Data Privacy
Location Data Enforcement in 2026: Kochava, GM/OnStar, and Allstate/Arity
Separate the 2026 Kochava and GM orders, California's GM settlement, Texas's Allstate/Arity suit, and private location-data litigation.
Aug 8, 2026