The September 1 action against SalesIntel Research is the latest in a rapid series of California data broker cases, arriving just one month after DROP deletion processing went live.
California privacy regulators have opened September with another data broker enforcement action.
On September 1, 2026, the California Privacy Protection Agency announced that SalesIntel Research, Inc. will pay a $36,400 fine and change its privacy practices after the agency alleged the Virginia-based company failed to timely register with California’s Data Broker Registry.
The penalty itself is relatively modest compared with some of CalPrivacy’s recent settlements. What makes the SalesIntel case important is the larger enforcement pattern developing around it.
SalesIntel is the latest company caught in what CalPrivacy now openly calls an “enforcement blitz” against data brokers. The action follows an August $116,490 order against LocateSmarter and a $52,400 penalty against Cybba, while California’s new universal data broker deletion system, DROP, has moved from preparation into active processing.
For companies involved in advertising technology, audience intelligence, lead generation, data enrichment and other data-driven services, California is sending a fairly direct message: determining whether the company meets the state’s definition of a data broker is now a compliance issue with real enforcement consequences.
What SalesIntel Does
SalesIntel operates a B2B data and sales intelligence platform used by companies to identify potential customers and buying signals.
According to CalPrivacy, SalesIntel sells consumers’ personal information and maintains more than 200 million professional contacts and 54 million mobile phone numbers. The regulator also pointed to services involving inferences about career changes and a product designed to identify people or accounts visiting a business’s website.
SalesIntel’s own website currently advertises more than 200 million verified B2B contacts, 54 million verified mobile numbers, thousands of human researchers and extensive intent and technographic data.
That scale makes the enforcement action more notable than the dollar amount might initially suggest. This is not an obscure broker operating a small consumer list. SalesIntel is an established commercial data company selling intelligence to sales, marketing and revenue teams.
CalPrivacy alleged that the company nevertheless operated as a data broker without registering by the applicable 2025 deadline.
SalesIntel Must Do More Than Pay $36,400
The stipulated order does not end with the monetary penalty.
CalPrivacy is also requiring SalesIntel to:
- publish metrics concerning consumer privacy rights on its website;
- access California’s Delete Request and Opt-out Platform, known as DROP; and
- process future consumer deletion requests submitted through DROP.
SalesIntel appears to have already incorporated some of these requirements into its public-facing privacy program. Its current privacy policy identifies SalesIntel as a registered California data broker, states that it participates in DROP and contains a section reporting consumer request metrics.
That illustrates an increasingly important feature of privacy enforcement: regulators are not only collecting penalties. Orders can force companies to make operational and public-facing changes that remain in place long after the fine is paid.
California Has Started Treating Data Broker Registration as an Enforcement Priority
A company could previously have viewed data broker registration as a relatively administrative obligation.
That is becoming a dangerous assumption.
California law generally defines a data broker as a business that knowingly collects and sells to third parties personal information belonging to consumers with whom the business does not have a direct relationship.
CalPrivacy has repeatedly warned businesses to examine whether their activities bring them within that definition.
Its enforcement guidance says a data broker that fails to register can face an administrative fine of $200 for each day of noncompliance, along with registration fees and potentially expenses incurred by the agency in investigating and administering the enforcement action.
That means a registration issue can accumulate into a meaningful penalty even without an allegation that the company suffered a breach, mishandled a consumer request or improperly disclosed a particular consumer’s information.
The SalesIntel action is a good example.
CalPrivacy’s September 1 announcement centers on the alleged failure to register by the required deadline. Unlike some other recent cases, the agency’s announcement does not accuse SalesIntel of interfering with a consumer privacy request or identify a separate substantive CCPA violation.
Registration itself was enough to produce an enforcement action.
SalesIntel Follows LocateSmarter and Cybba
The timing is difficult to ignore.
On August 11, CalPrivacy ordered Iowa-based data broker LocateSmarter LLC to pay $116,490 after the company allegedly failed to timely register and required consumers to provide partial Social Security numbers before exercising certain opt-out rights.
That case was particularly significant because CalPrivacy described it as its first enforcement action against a data broker under both the California Consumer Privacy Act and the Delete Act.
Two days later, on August 13, the agency announced another decision.
Cybba, Inc. agreed to pay $52,400 after allegedly failing to meet the 2025 Data Broker Registry deadline. CalPrivacy described Cybba as selling information including geolocation data, internet activity and consumer inferences used for targeted advertising. Like SalesIntel, Cybba was also required to access DROP and process future deletion requests.
SalesIntel is now the third publicly announced action in this recent sequence.
The three penalties total approximately $205,000:
LocateSmarter: $116,490
Cybba: $52,400
SalesIntel: $36,400
More important than the cumulative dollars is the consistency of the cases. CalPrivacy appears to be systematically identifying companies that meet California’s data broker definition and comparing their activity against registration requirements.
The agency says it has already brought more than a dozen actions against unregistered data brokers.
DROP Changes the Enforcement Equation
The SalesIntel action also comes at a particularly important moment for California’s Delete Act.
California launched DROP for consumers on January 1, 2026.
Instead of locating individual data brokers and sending separate deletion requests to each one, a California resident can use DROP to submit a single request directing participating data brokers to delete qualifying personal information.
The operational side of the system became mandatory for brokers on August 1, 2026.
Data brokers are now required to access DROP and process deletion requests. CalPrivacy says brokers must download applicable deletion lists at least once every 45 days.
Consumer adoption has been substantial.
By August 25, more than 500,000 Californians had registered with DROP. CalPrivacy reported that 654 data brokers were participating in the system and that approximately 25% had already reported processing deletion requests. The agency said tens of millions of records had already been reported deleted.
That changes the significance of data broker registration.
The registry is no longer simply a public directory containing the names and disclosures of data brokers. Registration connects companies to an active state-operated deletion infrastructure used by hundreds of thousands of consumers.
A broker that stays outside that system does not simply miss a filing deadline. It may also remain outside the mechanism California created to transmit and track deletion requests across the industry.
CalPrivacy Executive Director Tom Kemp specifically connected the agency’s growing enforcement exposure to the launch of DROP, warning that the risks are increasing now that brokers have begun processing requests through the platform.
AdTech and Data Companies Should Revisit Their Classification
The SalesIntel case is also a warning for companies that do not ordinarily describe themselves as “data brokers.”
SalesIntel markets itself as a pipeline generation and B2B intelligence platform. Other companies may describe themselves as advertising technology providers, identity platforms, audience intelligence companies, data enrichment providers, lead generation companies or analytics businesses.
Those labels do not determine whether California considers the company a data broker.
The underlying collection and sale of personal information does.
Michael Macko, CalPrivacy’s head of enforcement, specifically directed the agency’s warning toward companies operating in the AdTech ecosystem, telling businesses to examine whether they engage in data broker activity and whether they have properly registered.
For businesses evaluating their obligations, the questions therefore need to go beyond the company’s marketing description.
Where does the information come from? Does the business have a direct relationship with the individuals represented in its data? What information is collected? Is that information sold to third parties? Which legal entity conducts that activity? Are multiple subsidiaries, websites or trade names involved?
Those facts can determine whether California’s registration requirements apply.
Registration Is Only the Beginning
Companies that determine they are data brokers now have substantially more to manage than an annual filing.
CalPrivacy says brokers operating during 2025 must register through DROP in 2026, and the current registration fee is $6,000 plus the applicable payment-processing charge. Each business entity operating as a data broker must maintain its own DROP account.
Once inside DROP, companies also need the technical and organizational processes necessary to retrieve consumer deletion lists, match identifiers against their own databases, process qualifying deletion requests, account for applicable exemptions and report the appropriate status.
This is increasingly a data governance problem rather than a form-filing exercise.
Companies need to understand where consumer information resides, which systems and vendors contain copies of it, what information has been sold or distributed and whether a deletion request can actually propagate through those systems.
A company that technically registers but cannot operationalize deletion may simply move from one enforcement risk to another.
The Larger California Privacy Enforcement Trend
SalesIntel also joins a much broader run of CalPrivacy enforcement activity.
Recent agency actions have included a $1.1 million penalty against PlayOn Sports, $375,703 against Ford Motor Company and previous penalties against Tractor Supply, Todd Snyder and American Honda. CalPrivacy also participated with the California Attorney General and district attorneys in a $12.75 million General Motors privacy settlement.
Not every case involves the same statute or alleged violation.
But together they show a California privacy regulator that has moved well beyond rulemaking and educational guidance.
The SalesIntel penalty is particularly useful because it shows how little drama is required to attract enforcement. There was no breach announced. There was no multimillion-dollar consumer harm calculation in CalPrivacy’s release.
The agency says SalesIntel was a data broker and did not register on time.
That was enough.
For businesses whose products depend on collecting, enriching, licensing, selling or distributing information about people they do not directly serve, California’s message on September 1 is straightforward: determine whether the Delete Act applies before CalPrivacy makes that determination for you.