What $492,000 in California data-broker fines actually looked like
Eleven data brokers have been fined by California’s privacy regulator since November 2024. The total is $492,000. Every single case is about the same thing: a company that didn’t register. None is about a bad deletion cycle. That obligation only started August 1, 2026, and no fine has been assessed under it yet.
That makes the registration cases a preview, not a coincidence. They show exactly what the agency looks for, and exactly what a paper trail would have changed. Three cases make the pattern clear.
Background Alert: the company that never had a defense
Background Alert built consumer profiles by scraping billions of public records, then sold them through backgroundalert.com with the tagline “it’s scary how much information you can dig up on someone.” It didn’t register between February 2024 and October 2024, when California law required it. The California Privacy Protection Agency’s settlement, announced February 27, 2025, forces the company to shut down entirely through 2028, or pay $50,000. This wasn’t a documentation failure. Nothing in Background Alert’s business model left room to argue it wasn’t a data broker. The fix here was never a better record. It was a $6,000 registration fee and a form, filed on time.
ROR Partners: the company that guessed wrong about its own status
ROR Partners, a marketing firm, built consumer profiles from data on more than 262 million Americans and sold custom audience segments to advertisers. In one documented instance, that meant selling a list of likely fitness-club attendees to health clubs. ROR Partners apparently believed that bundling personal data inside a broader marketing service meant the sale didn’t count as data brokering. The CPPA’s December 3, 2025 order was blunt: “a sale is a sale.” A business cannot avoid the Delete Act by wrapping a data sale inside a bigger package. The fine was $56,600. What would have changed the outcome: a written, dated determination of whether the business met the broker definition, made before the product launched, not after an investigator called. That’s a one-page memo. ROR Partners didn’t have one on file.
Unsure which side of that definition your own business sits on? Take the six-question self-test; it mirrors the statute’s wording, runs in your browser, and stores nothing.
Accurate Append: the company that meant to get to it
Accurate Append was doing business as a data broker in 2023 and missed the January 31, 2024 registration deadline. It only registered after a CPPA investigator contacted the company directly, mid-investigation. The agency fined it $55,400, plus its own legal costs. There’s no indication in the record that Accurate Append disputed being a broker; this looks like the ordinary small-business failure mode, not evasion. What would have changed the outcome: a calendar with an owner’s name on it, not a mental note. The fine wasn’t for being a data broker. It was for a form that didn’t get filed until a state investigator asked why not.
The pattern
Three companies, three different mistakes: no defense, a wrong guess, a missed deadline. In every case, the fix that would have prevented it was cheap, boring, and already legally required. That’s what a compliance record actually buys: not innocence, but the ability to show an investigator “we already did this,” instead of scrambling to fix it while they watch. The 2028 audits apply the same logic to the deletion cycle itself: the record either exists when they ask, or it doesn’t.
Sources: CPPA, “Data Broker Promoting Ability to Dig Up ‘Scary’ Amounts of Information Agrees to Shut Down,” Feb. 27, 2025; CPPA, “CalPrivacy Fines Marketing Firm for Selling Custom Audiences Without Data Broker Registration,” Dec. 3, 2025; Hunton Andrews Kurth on the Accurate Append action, July 2025.
Common questions
Has anyone been fined for a bad deletion cycle yet?
Not yet. All 11 CPPA enforcement actions since November 2024, $492,000 in total, have been registration cases. The deletion-cycle obligation only started August 1, 2026, so those cases haven't begun. The registration cases are the preview: they show the agency enforces the cheap, boring, clearly required steps first.
Does bundling data sales inside a bigger service avoid the Delete Act?
No. That was ROR Partners' theory, and the CPPA's December 3, 2025 order rejected it in three words: a sale is a sale. A business cannot avoid the data-broker definition by wrapping the sale of personal data inside a broader marketing or analytics package. The fine was $56,600.
What would have prevented these fines?
In every case, something cheap and already required: a registration form filed on time, a written determination of broker status made before launch, or a calendar with an owner's name on it. The pattern is that the agency fines the absence of a boring record, not exotic misconduct.