CalPrivacy Fines LocateSmarter $110K in First Combined Delete Act–CCPA Case

California's privacy agency hit Iowa-based data broker LocateSmarter with a $110,490–$116,490 penalty on August 11, 2026, for skipping data-broker registration and demanding a Social Security number fragment before honoring opt-outs…

What turns a routine data-broker registration lapse into a full privacy audit? CalPrivacy’s answer, delivered in its August 11, 2026 order against LocateSmarter LLC, is that missing the Delete Act’s January 31 registration deadline is now an invitation for regulators to comb through everything else a company does with consumer data. LocateSmarter, an Iowa-based data analytics provider, failed to register as a data broker and separately required consumers to hand over their full name, mailing address, and the last four digits of their Social Security number just to opt out of having their information sold — a demand CalPrivacy says violates the CCPA’s data minimization mandate.

The evidence backs up that reading. Frankfurt Kurnit Klein & Selz pegs the total penalty at $110,490 plus a $6,000 DROP registration fee; Bloomberg Law News reports $116,490. Either figure marks the same milestone: it’s the agency’s first enforcement action stacking Delete Act and CCPA violations in one order, and the fourteenth data-broker registration case overall following a $52,400 fine against Cybba, Inc. and a $45,000 fine against Rickenbacher Data LLC in January, according to Inside Privacy.

The $110,490 LocateSmarter penalty is less a story about missed paperwork than about CalPrivacy using the Delete Act registry as a tripwire for full-scale CCPA audits.

The opt-out mechanics matter as much as the fine. CalPrivacy noted that only a “tiny fraction” of consumers submitted opt-out requests to LocateSmarter, per Bloomberg Law News, and the agency treated that low volume as evidence the process itself was designed to discourage use rather than as proof consumers didn’t care. That logic extends recent actions against Honda, Todd Snyder, and Ford over unnecessary identity verification, and it puts every data broker’s opt-out flow — not just its registration status — on the compliance checklist.

For brokers still treating DROP registration as a box-checking exercise, LocateSmarter is a warning that the exercise doesn’t end there. Companies should audit whether their opt-out forms ask for anything beyond what’s reasonably necessary, especially sensitive identifiers like partial Social Security numbers, since CalPrivacy has signaled it will read a thin trickle of opt-out requests as a red flag rather than a clean bill of health. With enforcement chief Michael Macko explicitly framing this as the same multi-statute approach the agency used against General Motors’ $12.75 million location-data settlement in May, expect CalPrivacy’s next targets to be judged simultaneously against the Delete Act, the CCPA, and whatever other statute the facts touch.

"Any such intimidation would conflict with the CCPA's mandate that consumers be able to easily exercise their privacy rights," Tuesday's order said.

JD Supra

Read the full story at JD Supra →

The Data Commenter, in your inbox

Data markets, alt data, and the AI training-data economy. No spam, unsubscribe anytime.

Discussion lives in the inline notes attached to article passages.