Key point: CalPrivacy’s latest enforcement action demonstrates a continued focus on the data broker industry, but all businesses subject to the CCPA should take note of the opt-out and data minimization violations at issue.
On August 11, 2026, the California Privacy Protection Agency (CalPrivacy) announced a decision requiring a data broker to pay a $116,490 fine for violations of the California Consumer Privacy Act (CCPA) and the Delete Act. CalPrivacy has previously fined several data brokers for failing to register, but this is the first time it has also fined a data broker for CCPA violations.
Although this enforcement action targets a data broker, its CCPA violations offer important compliance lessons for all CCPA-regulated businesses. This article reviews the enforcement action and the violations, then analyzes what they mean for data brokers and CCPA-regulated businesses generally.
For more information on all CCPA enforcement actions, see the new Enforcement Tracker in our U.S. State Privacy and AI Resource Center (SPARC).
Overview of the Enforcement Action
A. Failure to Register as a Data Broker
According to the Stipulated Final Order, the company collects personal information from third-party sources, such as “data licensors, data analytics providers, data brokers, and/or data suppliers.” It then sells personal information to third parties through four products: batch data, API data, an online search platform, and data licensing.
The types of personal information it sells include consumers’ names, dates of birth, Social Security numbers, physical addresses, telephone numbers, email addresses, business and employment information, driver’s license information, bankruptcy and litigation information, and military and deceased status. It also sells inferences, such as whether consumers are litigious.
Based on its data processing activities, the company qualified as a data broker during the 2025 calendar year, but it did not register as a data broker with CalPrivacy by the January 31, 2026 deadline.
CalPrivacy fined the company $30,600 for failing to register and required it to pay the $6,000 annual registration fee and register as a data broker. CalPrivacy also ordered the company to disclose the required CCPA consumer request metrics in its privacy policy, access CalPrivacy’s Delete Request and Opt-out Platform (DROP), and process consumer deletion requests.
B. Improper Opt-Out of Sales/Shares Process
Beyond the registration failure, CalPrivacy found that the company also violated the CCPA by requiring consumers to provide their full name, the last four digits of their Social Security number, and their address before allowing them to opt out of the sale or sharing of their personal information.
The CCPA allows businesses to require consumers to verify their identity only for requests to access/know, delete, and correct. Businesses are not permitted to require verification for requests to opt out. According to the Order, when the company required consumers to provide this information, it functionally required them to verify their identities in violation of the CCPA.
CalPrivacy also found that the company’s opt-out process violated the CCPA’s data minimization provisions because it required consumers to provide more information than necessary to exercise their right to opt-out. CalPrivacy noted that the CCPA’s data minimization provisions “apply to any collection of personal information by a business, including the collection of personal information to process consumer requests.”
The Order notes that the company possessed “other non-sensitive data points it could have used instead of a Social Security number” and that requiring consumers to submit a Social Security number could “intimidate consumers from exercising their privacy rights.” Notably, this section of the Order does not consistently distinguish between the company requiring consumers to submit the last four digits of their Social Security number (which is what the company’s webform requested) and requiring their full Social Security number. Finally, CalPrivacy noted that the company had received only a small number of requests, which it correlated with the company’s practice of requesting Social Security numbers.
For its CCPA violations, CalPrivacy issued a $79,890 administrative fine. It also required the company to modify its opt-out process so that it no longer requires verification of requests or requires consumers to submit “any portion of their Social Security number to exercise their right to opt-out of sale/sharing.”
Analysis
Although this enforcement action targets a data broker, it offers lessons for all CCPA-regulated businesses. The right to opt out of sale/sharing remains a central focus of CalPrivacy’s and the California attorney general’s enforcement actions: of the twelve prior CCPA enforcement actions, every one involved the CCPA’s right to opt out of sale/sharing in some way. See our Enforcement Tracker for more information on these actions.
This is also the fourth time CalPrivacy has brought an enforcement action against a company for improperly verifying opt-out requests. In March 2026, it fined an automaker over $370,000; in May 2025, it fined a clothing retailer over $345,000; and in March 2025, it fined an automaker over $632,000. Further, rather than just focusing on whether a business states that it will verify opt-out requests, CalPrivacy focuses on the practical impact of how the business has structured its process. If the business’s process functionally operates as a verification, CalPrivacy will find it violates the CCPA.
This enforcement action also reinforces that the amount and types of data elements businesses request to process consumer requests matter. CalPrivacy previously noted this issue in a similar 2025 enforcement action. Here, CalPrivacy characterized this as a violation of both the CCPA’s opt-out requirements and its data minimization requirements, finding that the data minimization requirements apply equally to the personal information businesses request to process consumer requests and collect as part of their services. CalPrivacy’s focus on the company’s request that consumers provide the last four digits of their Social Security number is particularly notable, especially given that CalPrivacy viewed this as “intimidation.” Businesses should avoid requesting sensitive personal information and request only the data elements they need.
Finally, for data brokers, this action underscores that CalPrivacy remains closely focused on their compliance. CalPrivacy’s press release states that its Data Broker Enforcement Strike Force handled the enforcement action. CalPrivacy created the Strike Force in November 2025 to investigate privacy violations by the data broker industry, and its press release announcing the Strike Force explained that the Strike Force would focus not only on Delete Act violations but also on CCPA violations. While this is the first time CalPrivacy has expanded its data broker enforcement beyond registration fines, it will not be the last.

