We wrote a few weeks ago about California’s DROP platform — the free, state-run tool that lets any California resident send one deletion request to every registered data broker at once. The pitch is simple: one request, every broker, done. What we didn’t dwell on then is what happens when a broker doesn’t play along. California just answered that, twice, in the space of about six weeks.
A broker asked for your Social Security number just to let you say no
On August 10, 2026, the California Privacy Protection Agency (CalPrivacy) settled its first-ever enforcement action combining both the CCPA and the Delete Act in a single case, against a data broker called LocateSmarter, LLC. The total came to $116,490 — $79,890 for the CCPA violation, $30,600 under the Delete Act, plus a $6,000 registration fee LocateSmarter should have paid to begin with.
The CCPA piece is the part worth sitting with. LocateSmarter’s opt-out process required consumers to hand over their full name, mailing address, and the last four digits of their Social Security number before the company would honor a request to stop selling their data. CalPrivacy’s finding: that’s a data-minimization violation, and the principle applies to the opt-out form itself, not just to what a company does with your data afterward. The agency’s own reasoning, as reported by outlets covering the case, was blunt — the worst-case outcome of an erroneous opt-out is that someone gets marketed to slightly less, which doesn’t justify demanding a piece of information as sensitive as an SSN fragment just to process it. Regulators called out that this kind of ask can intimidate people out of exercising a right they’re legally entitled to for free.
The same week, CalPrivacy settled with a second broker, Cybba, Inc., for $52,400, for a more familiar failure: not registering with the state’s Data Broker Registry by the deadline, and only doing so after the agency came calling. Cybba’s business — selling geolocation data, browsing activity, and behavioral inferences used to identify “likely purchasers” for targeted ads — is exactly the kind of data trail DROP is supposed to let you clear out in one request. It couldn’t, because Cybba wasn’t in the system yet.
Then California warned brokers that “we didn’t mean to” isn’t a defense
Three weeks later, on September 3, 2026, CalPrivacy issued a formal enforcement advisory aimed at a quieter problem: brokers who are registered, but with wrong information. The agency’s message was direct — a $200-per-day fine applies whether the error was an honest mistake or a deliberate misrepresentation. The law doesn’t distinguish between the two.
The advisory walked through the kinds of mistakes that trigger it: a business that expanded into new markets mid-year and started collecting more sensitive data (driver’s license numbers, passport numbers, Social Security numbers) without updating its registration to reflect that; brokers misclassifying who’s actually buying their data; companies fudging the consumer-rights-request metrics they’re required to report. None of it requires bad intent to be a violation.
Why this matters if you’re counting on DROP
DROP’s whole design depends on two things being true: that a broker is actually registered, and that its registration accurately describes what it does. Cybba shows what happens when the first one fails. LocateSmarter shows that even a registered broker can still make opting out needlessly hard — and get fined for it, which is a real, working check, not a hypothetical one. The September advisory shows California is now looking specifically for brokers whose registration doesn’t match reality, which is the exact failure mode that would let a company sit in the registry looking compliant while DROP requests don’t actually reach the right side of their business.
That’s a genuinely good sign for anyone relying on DROP — a regulator that’s fining brokers within months of the platform going live, not years. It’s also exactly why we don’t tell people that submitting one request, to DROP or to anyone, is the end of the story. New brokers keep appearing. Existing ones keep testing what they can get away with, until a regulator or a customer notices. We can’t promise removal from every broker, and we’re not going to pretend a single request — however well-designed the platform behind it — closes the loop permanently. Enforcement like this is what keeps the system honest; it isn’t a substitute for checking back.
Per-claim source list
- DROP lets a single request reach all California-registered data brokers — ScrubTrace’s own 2026-09-15 blog post (this log), sourced there to cppa.ca.gov and privacy.ca.gov; referenced here for context, not re-cited as new.
- LocateSmarter, LLC settlement, August 10, 2026, first combined CCPA + Delete Act enforcement action — Fisher Phillips, “California Announces Groundbreaking Data Broker Fines”
- LocateSmarter total fine $116,490 ($79,890 CCPA + $30,600 Delete Act + $6,000 registration fee) — Fisher Phillips
- LocateSmarter opt-out process required full name, mailing address, and last four digits of Social Security number before honoring opt-outs — Fisher Phillips; corroborated by MyPrivacy.Blog, “California fines Cybba, LocateSmarter over broker opt-outs”
- CalPrivacy found data minimization applies to the opt-out request form itself; “worst case of an erroneous opt-out is that someone gets marketed to slightly less” framing; risk of intimidating consumers from exercising rights — MyPrivacy.Blog; Fisher Phillips
- Cybba, Inc. settlement, $52,400, for failing to register with the Data Broker Registry by the deadline, registered only after CalPrivacy enforcement contact — privacy.ca.gov, “CalPrivacy Announces Second Data Broker Enforcement Action in Less than a Week”; Fisher Phillips
- Cybba’s business: selling geolocation data, internet/browsing activity data, and inferences (e.g., identifying “likely purchasers”) for targeted advertising — privacy.ca.gov
- CalPrivacy Enforcement Advisory 2026-01, issued September 3, 2026, on inaccurate data broker registration information — privacy.ca.gov, “Enforcement Advisory Targets Incorrect Information in Data Broker Registration”; Fisher Phillips, “CalPrivacy Warns Data Brokers About Incorrect Registration Info”
- $200-per-day fine applies equally to honest mistakes and intentional misrepresentation in registration — Fisher Phillips, “CalPrivacy Warns Data Brokers About Incorrect Registration Info”
- Examples of registration errors cited in the advisory (mid-year expansion into new sensitive-data categories without updating registration; misclassifying customers; misreporting CCPA rights-request metrics) — Fisher Phillips
- ScrubTrace’s own stated limitation (can’t promise removal from every broker, ongoing monitoring rather than one-and-done) — ScrubTrace’s own existing brand-voice position per
content-agent-operating-design.md, not an external citation.
Note on a minor figure discrepancy: some secondary sources give Cybba’s settlement date as August 11 or 13 rather than August 10, and one gives LocateSmarter’s CCPA+Delete Act subtotal as $110,490 rather than $116,490 (omitting the $6,000 registration fee). I used Fisher Phillips’ breakdown throughout since it was the most itemized and internally consistent; both events are described here only as “the same week” in early-to-mid August 2026 rather than pinned to a single contested date.
Now let me log this to the project.
This week’s Content Agent run drafted a post and logged it to content-agent-log.md, per the operating design — no notification sent directly, since this agent’s designed flow is to fold into Simon’s next daily brief for John’s review, not to alert him itself.
What happened: no device access this run (cloud-only scheduled fire), so ScrubTrace’s own founders-log.md wasn’t reachable — same recurring gap as prior runs. ideation-log.md had nothing new and reusable since last check. Web research turned up two genuinely new, dated California enforcement developments since the last post (09-18): CalPrivacy’s first-ever combined CCPA + Delete Act settlement (August 10, 2026) against LocateSmarter, LLC ($116,490, for requiring consumers to hand over SSN digits just to opt out) and Cybba, Inc. ($52,400, for failing to register), plus a September 3, 2026 enforcement advisory warning brokers that inaccurate registration info draws the same $200/day fine whether the error was honest or intentional.

Leave a Reply