What $697,290 in California data-broker fines actually looked like
Short answer: if you operate as a data broker in California and don’t register, the state fines you $200 per day with no grace period (Civil Code §1798.99.82(c)(1), doubled from $100/day by SB 361 effective January 1, 2026), on top of the registration fee itself. Twelve of the fourteen CPPA enforcement actions to date started this way; in the two cases below with a fully itemized penalty (Cybba, SalesIntel Research), the daily count ran only through the date the company registered, not indefinitely.
Fourteen data brokers have been fined by California’s privacy regulator since November 2024. The total is $697,290, as of September 1, 2026. Twelve of those cases are about the same thing: a company that didn’t register. Two, announced August 11 and 13, 2026, add a data-minimization angle on top of a registration failure. None is about a bad deletion cycle. That obligation only started August 1, 2026, and no fine has been assessed under it yet.
That makes the registration cases a preview, not a coincidence. They show exactly what the agency looks for, and exactly what a paper trail would have changed. Six cases make the pattern clear.
Background Alert: the company that never had a defense
Background Alert built consumer profiles by scraping billions of public records, then sold them through backgroundalert.com with the tagline “it’s scary how much information you can dig up on someone.” It didn’t register between February 2024 and October 2024, when California law required it. The California Privacy Protection Agency’s settlement, announced February 27, 2025, forces the company to shut down entirely through 2028, or pay $50,000. This wasn’t a documentation failure. Nothing in Background Alert’s business model left room to argue it wasn’t a data broker. The fix here was never a better record. It was a $6,000 registration fee and a form, filed on time.
ROR Partners: the company that guessed wrong about its own status
ROR Partners, a marketing firm, built consumer profiles from data on more than 262 million Americans and sold custom audience segments to advertisers. In one documented instance, that meant selling a list of likely fitness-club attendees to health clubs. ROR Partners apparently believed that bundling personal data inside a broader marketing service meant the sale didn’t count as data brokering. The CPPA’s December 3, 2025 order was blunt: “a sale is a sale.” A business cannot avoid the Delete Act by wrapping a data sale inside a bigger package. The fine was $56,600. What would have changed the outcome: a written, dated determination of whether the business met the broker definition, made before the product launched, not after an investigator called. That’s a one-page memo. ROR Partners didn’t have one on file.
Unsure which side of that definition your own business sits on? Take the six-question self-test; it mirrors the statute’s wording, runs in your browser, and stores nothing.
Accurate Append: the company that meant to get to it
Accurate Append was doing business as a data broker in 2023 and missed the January 31, 2024 registration deadline. It only registered after a CPPA investigator contacted the company directly, mid-investigation. The agency fined it $55,400, plus its own legal costs. There’s no indication in the record that Accurate Append disputed being a broker; this looks like the ordinary small-business failure mode, not evasion. What would have changed the outcome: a calendar with an owner’s name on it, not a mental note. The fine wasn’t for being a data broker. It was for a form that didn’t get filed until a state investigator asked why not.
LocateSmarter: the first case under both the CCPA and the Delete Act
LocateSmarter, a Cedar Falls, Iowa skip-tracing firm selling “batch skip tracing products,” is the first company CalPrivacy has fined under both the CCPA and the Delete Act at once. The August 11, 2026 order breaks into three pieces: $30,600 for missing the January 31, 2026 registration deadline, $79,890 under the CCPA’s data-minimization rule for demanding a consumer’s full name, last-4 SSN, and mailing address just to process an opt-out request, and the $6,000 registration fee itself, paid as part of the settlement. Total: $116,490, the largest single action to date. What would have changed the outcome: registering on time, and an opt-out form that asked for only what was needed to find the record, not a photocopy of the consumer’s identity. This is a data-minimization fine layered on a registration fine. It is still not a deletion-cycle fine; LocateSmarter wasn’t cited for mishandling a DROP deletion request.
Cybba: a registration case, on the current $200-a-day math
Cybba, a Boston ad-tech and digital-marketing firm, operated as a broker through 2024 without registering by the January 31, 2025 deadline. CalPrivacy’s order, announced around August 13, 2026, fined the company $52,400, roughly 262 days of exposure at the state’s per-day registration-failure rate. Both this order and LocateSmarter’s require the company to stay current on DROP going forward. Like every case before it, this is a registration failure, not a deletion-cycle violation.
SalesIntel Research: a straight registration case, mid-fine range
SalesIntel Research, a Vienna, Virginia firm, operated unregistered from February 1 to June 29, 2025 before registering in 2026. CalPrivacy’s order, signed August 27 and announced September 1, 2026, fined the company $36,400: a $29,800 administrative fine, matching $200/day across those 149 unregistered days, plus the $6,600 registration fee itself. The order cites the Delete Act’s registration requirement only; it doesn’t allege a deletion-cycle violation. Same lesson as Background Alert and Accurate Append: the fine is for the missing form, not for being a data broker.
The pattern
Six companies, six different mistakes: no defense, a wrong guess, a missed deadline, an over-broad opt-out form, a registration gap that ran the daily fine up, and another registration gap that did the same. In every case, the fix that would have prevented it was cheap, boring, and already legally required. That’s what a compliance record actually buys: not innocence, but the ability to show an investigator “we already did this,” instead of scrambling to fix it while they watch. No CPPA action to date, including LocateSmarter, Cybba, and SalesIntel Research, has fined a broker for violating the 45-day DROP deletion cycle itself; every case so far is a registration and/or CCPA violation. The 2028 audits apply the same recordkeeping logic to the deletion cycle itself: the record either exists when they ask, or it doesn’t. For the running total as new actions are announced, see the DROP Compliance Index.
Sources: CPPA, “Data Broker Promoting Ability to Dig Up ‘Scary’ Amounts of Information Agrees to Shut Down,” Feb. 27, 2025; CPPA, “CalPrivacy Fines Marketing Firm for Selling Custom Audiences Without Data Broker Registration,” Dec. 3, 2025; Hunton Andrews Kurth on the Accurate Append action, July 2025; CPPA, “CalPrivacy Brings First Action Against a Data Broker Under Both the CCPA and Delete Act,” Aug. 11, 2026; Governor’s Office, “ICYMI: California Takes Historic Action Against Data Brokers,” Aug. 13, 2026; privacy.ca.gov, “CalPrivacy Continues Enforcement Blitz with Action Against Virginia Data Broker,” Sep. 1, 2026.
Common questions
Has anyone been fined for a bad deletion cycle yet?
Not yet. All 14 CPPA enforcement actions since November 2024, $697,290 in total, are registration cases or CCPA data-minimization cases, including three since August 2026. The deletion-cycle obligation only started August 1, 2026, so those cases haven't begun. The registration cases are the preview: they show the agency enforces the cheap, boring, clearly required steps first.
Does bundling data sales inside a bigger service avoid the Delete Act?
No. That was ROR Partners' theory, and the CPPA's December 3, 2025 order rejected it in three words: a sale is a sale. A business cannot avoid the data-broker definition by wrapping the sale of personal data inside a broader marketing or analytics package. The fine was $56,600.
What would have prevented these fines?
In every case, something cheap and already required: a registration form filed on time, a written determination of broker status made before launch, a calendar with an owner's name on it, or not asking for a full name and last-4 SSN just to process an opt-out. The pattern is that the agency fines the absence of a boring record, not exotic misconduct.