California Issues First Dual Fine Under CCPA and Delete Act Against Data Broker LocateSmarter

Table of Contents

California’s privacy regulator has handed down its first enforcement action that simultaneously targets violations of both the California Consumer Privacy Act (CCPA) and the state’s data broker registration law known as the Delete Act.

Breaking news just now, the California Privacy Protection Agency (CalPrivacy) announced a $116,490 penalty against LocateSmarter LLC, an Iowa-based data broker. The agency found that the company failed to register as a data broker while operating as one and imposed burdensome, privacy-invasive requirements on consumers trying to stop the sale of their personal information.

What LocateSmarter Did Wrong
According to the agency, LocateSmarter collected and sold a range of personal data including names, driver’s license numbers, dates of birth, employment history, bankruptcy records, and litigation information. Despite engaging in data broker activities covered by California law, the company never registered with the state’s data broker registry.

More critically for consumers, LocateSmarter required individuals to provide the last four digits of their Social Security numbers before it would process opt-out requests. CalPrivacy determined this practice violated the CCPA’s data minimization principles. The agency noted that the extra sensitive-data hurdle intimidated people and resulted in only a “tiny fraction” of consumers submitting opt-out requests.

The enforcement order states that such barriers conflict with the CCPA’s core requirement that consumers must be able to exercise their privacy rights easily.

Why This Case Matters
This is the first time CalPrivacy has enforced both the CCPA and the Delete Act in a single action. The agency signaled that it is deliberately examining company behavior through the lens of multiple overlapping privacy statutes and will continue doing so.

Michael Macko, CalPrivacy’s head of enforcement, pointed to the agency’s earlier collaboration with the Attorney General and district attorneys in the General Motors investigation as a model. In May, that multi-agency effort produced a $12.75 million settlement—the largest CCPA penalty to date—over claims that GM sold location and driving data of hundreds of thousands of California residents to data brokers.

A majority of registered California data brokers report receiving relatively few (or zero) deletion or opt-out requests, according to reviews of the state registry. Cases like LocateSmarter’s illustrate one reason: friction built into the request process can suppress consumer action even when the legal right exists.

Required Remedies
Under the order, LocateSmarter must:
– Register as a data broker
– Eliminate unnecessary data collection for opt-out requests
– Make it simpler for consumers to exercise their rights to stop the sale or sharing of their personal information
– Change its overall practices to comply with both the CCPA and the Delete Act

DROP Act Enforcement Has Kicked Off
The action arrives amid growing multi-state coordination on data privacy. Vermont recently joined a multi-state data privacy enforcement consortium, and California continues to scrutinize both traditional data brokers and companies that function as brokers without acknowledging the designation.

For data brokers and any company that sells or shares personal information at scale, the message is clear: registration is non-negotiable, opt-out processes must be low-friction, and collecting extra sensitive data solely to process privacy requests creates enforcement risk.

CalPrivacy’s willingness to stack CCPA and Delete Act violations in a single case raises the stakes. Companies that previously treated registration failures and CCPA compliance as separate issues should reassess their exposure under both frameworks.

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.