CalPrivacy Fines LocateSmarter $116,490, Cybba $52,400 in Dual Sweep

California's privacy agency issued its first-ever dual CCPA/Delete Act enforcement order against Iowa-based LocateSmarter LLC and, days later, a second action against Boston's Cybba Inc., totaling $168,890 in fines announced…

What’s established: on Aug. 13, 2026, the California Privacy Protection Agency Board fined LocateSmarter LLC $116,490 for missing the Jan. 31 data-broker registration deadline and for requiring the last four digits of a Social Security number before processing opt-out requests — a practice CalPrivacy says violated data-minimization rules. Within the same week, per natlawreview.com and KEYT, the agency issued a second order fining Boston-based Cybba Inc. $52,400 for late registration and selling geolocation and behavioral data without registering. Both are confirmed by CalPrivacy’s own final orders and corroborated across multiple outlets.

The fine breakdown is the most concrete evidence of where enforcement teeth actually land.

The $116,490 LocateSmarter penalty splits into $79,890 of administrative fines versus a $6,000 registration fee — proof CalPrivacy is punishing the SSN-gated opt-out mechanism, not merely the missed paperwork.

That distinction matters for every data broker doing consumer-facing opt-out flows in California: a late registration is a $6,000 problem, but designing an opt-out that discourages consumers from using it is a six-figure problem.

Where the record turns to claim rather than fact: agency enforcement chief Michael Macko told KEYT he sees a “steady drumbeat” of enforcement and doesn’t expect it to slow, and Gov. Newsom’s office, in an Aug. 13, 2026 release, touted 475,000 Californians who have used the DROP deletion platform since its Jan. 1 launch as proof the law is working. Both are agency and administration framing, not independently verified enforcement cadence — this is only the agency’s second-ever data-broker case and its first two actions under the CCPA/Delete Act combination, issued via back-to-back press releases in the same week, which natlawreview.com flagged explicitly. Two orders in one week could be a genuine acceleration or a batch of cases cleared together; nothing in the public record yet distinguishes the two.

What would validate Macko’s claim: a quarterly enforcement count from CalPrivacy showing a rising rate of actions beyond this initial pair, and disclosure of how many of the 580-plus registered brokers CalPrivacy is currently investigating. Until then, the safer read for data brokers is narrower — CalPrivacy has demonstrated it will fine SSN-gated opt-outs and late registration when it finds them, not that it is running a continuous audit program.

CalPrivacy has been bringing a steady drumbeat of enforcement actions under both the Delete Act and the CCPA [California Privacy Protection Agency], and I don't see the enforcement activity slowing down anytime soon. Especially with the launch of DROP, businesses should take a close look at their activities.

Yo! Venice!

Read the full story at Yo! Venice! →

The Data Commenter, in your inbox

Data markets, alt data, and the AI training-data economy. No spam, unsubscribe anytime.

Discussion lives in the inline notes attached to article passages.