On 11 August and again on 13 August 2026, the California Privacy Protection Agency — now operating as CalPrivacy — announced settlements with two data brokers. Two enforcement actions in three days, against companies most people have never heard of, for amounts that would not fund a Super Bowl advert.

The money is not the point. One of these orders establishes a legal theory that applies to every company on the internet that has ever built a privacy request form.

The Easy One: Cybba

Cybba, Inc., a Boston-based company, was ordered to pay $52,400 for failing to register with California’s Data Broker Registry by the 2025 deadline.

Cybba is a textbook broker: it sells personal information — geolocation, internet activity data, and identifiers — about consumers with whom it has no direct relationship to third parties for marketing and advertising. That last clause is the statutory definition of a data broker in California, and it is the reason the registry exists at all. You cannot exercise a right against a company you have never heard of and cannot name.

Registration is the cheapest obligation in California privacy law: file once a year, pay a $6,000 fee, appear on a public list. Failing to do it carries a $200 per day penalty, which is how a paperwork violation becomes a five-figure order. This is enforcement as bookkeeping, and it is exactly what the Delete Act needs to function — DROP can only route a deletion request to brokers the state knows about.

The Important One: LocateSmarter

LocateSmarter, LLC paid $116,490 in total: a $79,890 CCPA administrative fine, a $30,600 Delete Act fine, and its $6,000 registration fee. It is CalPrivacy’s first enforcement action alleging violations of both the CCPA and the Delete Act together.

The registration failure is the familiar half. The CCPA half is new, and it is the one to read twice.

According to the agency, LocateSmarter violated the CCPA’s data minimization requirement by demanding, from any consumer who wanted to submit an opt-out request, their:

  • full name
  • last four digits of their Social Security number
  • mailing address

Think about what that means. To tell a data broker to stop selling your personal information, you first had to give the data broker more personal information — including a partial SSN, one of the most sensitive identifiers in American life, handed over to a company whose entire business is trading identifiers.

CalPrivacy’s holding is that data minimization applies to the privacy request process itself. A business may collect only what is reasonably necessary and proportionate to verify an identity for the specific request being made. An opt-out of sale is a low-risk request — the worst case of an erroneous opt-out is that someone gets marketed to slightly less. It does not warrant SSN-grade verification.

Why This Theory Travels So Far

Almost every privacy request form on the internet asks for more than it needs, and almost all of them do it for defensible-sounding reasons: fraud prevention, identity assurance, avoiding malicious opt-outs on someone else’s behalf.

CalPrivacy has now put a price on that reasoning being wrong. And the logic is not California-specific. Data minimization is a load-bearing principle in GDPR Article 5(1)(c), in every US state comprehensive privacy law passed since 2021, in Brazil’s LGPD, and in India’s DPDP Act. A regulator anywhere can now point at this order and say: the request mechanism is processing too, and it is subject to the same limits as everything else.

There is also a quieter incentive being addressed. A verification process is a friction dial. A broker that wants fewer opt-outs does not have to refuse them — it just has to make them uncomfortable enough that most people abandon the form. Demanding an SSN fragment is extremely effective at that, and it is deniable, because it looks like security. This order says the dial is regulated.

The proportionality principle it implies is worth writing down, because it is now the operating rule:

  • Opt-out of sale or sharing — the lowest bar. Under the CCPA, a business generally may not require verification at all for an opt-out. An email address or a Global Privacy Control signal should be enough.
  • Right to know / access — moderate. You are handing data out, so you need reasonable confidence in who is asking. Two data points already on file.
  • Deletion — higher, because it is irreversible and an attacker could use it destructively.
  • None of them — an SSN, a government ID scan, or a selfie, unless the account itself is that sensitive.

The Bigger Picture

August has been the month California’s privacy machinery started producing outputs rather than announcements. DROP went live for brokers on 1 August, requiring registered brokers to process deletion requests submitted through the state platform, with status reporting on defined timelines. Two enforcement orders arrived within a fortnight. Washington State published its first Data Privacy Report recommending a broker registry of its own.

The sequence matters: registry → deletion platform → enforcement of the registry → enforcement of the request process. Each stage only works because the previous one exists. A deletion platform is useless without a complete registry, and a registry is a fiction without a penalty for skipping it.

Which is why a $52,400 paperwork fine is not trivial and a $116,490 order is not small. They are the two mechanisms by which the most functional consumer privacy system in the United States becomes real for people who will never read a word about it.

What To Do

  1. California residents: use DROP. One request at the state platform reaches every registered broker. It has been live for brokers since 1 August and it is the single highest-leverage privacy action available to a Californian.

  2. Never give a partial SSN to exercise a privacy right. If a form demands one for an opt-out, that is now demonstrably unlawful in California and arguable nearly everywhere else. Refuse, and complain.

  3. Complain, specifically. CalPrivacy takes consumer complaints at privacy.ca.gov. Both of these actions began as ordinary observations about ordinary companies. Name the company, quote the form, attach a screenshot.

  4. Turn on Global Privacy Control. Firefox and Brave support it natively; extensions exist for Chrome. In California it is a legally binding opt-out signal that requires no form and no verification at all — which is precisely why brokers prefer forms.

  5. Outside California, cite minimization anyway. Colorado, Connecticut, Oregon, Texas, Virginia and the rest all carry the same principle. The theory is portable even where the enforcer is quieter.