In the span of less than a week, the California Privacy Protection Agency has issued two separate enforcement actions against data brokers, underscoring a deliberate acceleration in regulatory pressure under both the California Consumer Privacy Act and the Delete Act.

Two days later, on August 13, the Board followed with a $52,400 fine against Boston-based Cybba, Inc. for missing the 2025 Data Broker Registry deadline. Cybba sells geolocation data, internet activity data, and inferences used for targeted advertising, including services that analyze purchasing behavior to identify likely repeat buyers. Beyond the fine, the order requires Cybba to publish privacy rights metrics on its website, connect to the state’s Delete Request and Opt-Out Platform (DROP), and route all future deletion requests through that system.
Together, the two cases mark a clear escalation. Registration failures are no longer treated as minor administrative oversights. Friction in consumer rights processes is being treated as a substantive violation. And the agency is pairing monetary penalties with operational mandates that force companies into the state’s new centralized deletion infrastructure.
DROP Moves from Concept to Compliance Obligation
The Delete Act’s centerpiece is DROP, a first-of-its-kind platform that allows California residents to submit a single request directing all registered data brokers to delete their personal information. Data brokers must register annually in January, pay a fee that funds both the registry and DROP, and process deletion requests through the platform once it is fully operational.
Cybba’s order explicitly requires the company to access DROP and process future requests through it. This is more than a technical mandate. It converts a previously decentralized, broker-by-broker deletion process into a supervised, auditable system. For brokers that have historically treated deletion requests as low-volume or low-priority, the shift is significant. Metrics reporting requirements add another layer of transparency and potential scrutiny.
CalPrivacy leadership has been explicit about the direction of travel. Enforcement chief Michael Macko described a “steady drumbeat” of actions under both the Delete Act and the CCPA and said he does not expect the pace to slow. Executive Director Tom Kemp called DROP a “game changer” for consumers seeking protection from the data broker ecosystem.
Regulatory Enforcement Versus Private Litigation: Two Parallel Risks
While CalPrivacy is building an administrative enforcement machine around registration, data minimization, and centralized deletion, a parallel track of private litigation continues under the California Invasion of Privacy Act (CIPA) and related wiretapping theories. These two regimes create distinct but overlapping compliance pressures.
CalPrivacy’s approach is governmental, investigative, and injunctive. Penalties are calibrated, remediation is ordered, and the agency can compel companies into systems like DROP. The focus is structural: registration status, opt-out friction, data minimization, and systemic compliance with the CCPA and Delete Act. The LocateSmarter and Cybba actions fit squarely in this model—targeted, relatively modest fines paired with mandatory operational changes.
CIPA and wiretapping claims operate differently. These are private rights of action, frequently pursued by specialized plaintiffs’ firms seeking statutory damages. CIPA claims commonly target session replay software, website chat tools, tracking pixels, and call recording practices, alleging that the capture of electronic communications without proper consent constitutes illegal eavesdropping or wiretapping. Statutory damages can reach $5,000 per violation, and cases are often structured as class actions. Outcomes are driven by settlement leverage rather than regulatory negotiation, and the theories continue to evolve as courts interpret the boundaries of “communication,” “consent,” and “eavesdropping” in digital contexts.
The practical difference for companies is significant. CalPrivacy actions tend to focus on data brokers and companies whose core business involves the sale or sharing of personal information at scale. CIPA litigation has swept more broadly, reaching retailers, media companies, software vendors, and any business that deploys certain third-party tracking or analytics tools on consumer-facing websites or apps. One regime emphasizes registration, deletion infrastructure, and frictionless rights exercise. The other emphasizes notice, consent architecture, and the technical details of how communications are intercepted or recorded.
Data brokers and companies that both sell data and operate consumer-facing digital properties can find themselves exposed on both fronts simultaneously. A company might face CalPrivacy scrutiny over registry status and DROP readiness while also defending CIPA claims over the same tracking technologies that generate the data being sold.
What the Current Wave Reveals
The LocateSmarter and Cybba actions, viewed alongside earlier settlements involving General Motors, Ford, Tractor Supply, Honda, and other data brokers, show CalPrivacy moving methodically across multiple violation categories: unregistered brokers, opt-out friction, sensitive data collection for rights requests, and connected vehicle data practices. The agency is also expanding coordination through the Consortium of Privacy Regulators and international partnerships.
At the same time, the private CIPA docket remains active and inventive. The two tracks are not coordinated, but they reinforce each other. Regulatory actions raise the baseline of expected compliance. Private litigation raises the cost of technical and consent failures. Companies that treat one as the primary risk while ignoring the other are managing only half the California privacy exposure.
For data brokers specifically, the message from this week is unambiguous. Annual registration is mandatory. Opt-out and deletion processes must be low-friction and free of unnecessary data collection. DROP is no longer optional infrastructure. And the agency is prepared to move quickly and repeatedly.
The broader lesson extends beyond brokers. California now operates a dual enforcement environment in which administrative regulators and private litigators pursue related but distinct theories of privacy harm. Organizations that map their data flows, registration status, deletion capabilities, tracking technologies, and consent mechanisms against both regimes will be better positioned than those that continue to treat CCPA compliance and CIPA risk as separate workstreams.
Two enforcement actions in five days is not an anomaly. It is a signal of sustained regulatory attention, arriving at the same time that private CIPA and wiretapping litigation continues to test the edges of digital communications law. The companies that adapt to both tracks will define the next phase of California privacy compliance.