Amounts, violations and links to the primary orders. We keep this because the penalties have changed shape twice in a year, and most summaries still quote the old numbers. Every figure below links to the agency announcement or the order itself, so you can check it rather than take our word for it.
The agency stood up a Data Broker Enforcement Strike Force in November 2025 to review the industry for both Delete Act registration and CCPA compliance. DROP processing obligations began on 1 August 2026.
Not an action against one company — a warning to all of them. A data broker that files its annual registration with incorrect information is liable for $200 for every day the information stays wrong in the registry. The Enforcement Division says it has already brought multiple actions over reporting errors.
The registration asks for request metrics, the categories of data you collect, and who you share it with. Those are numbers most brokers assemble once a year under time pressure, and an error in them now accrues daily whether or not anyone has complained.
CalPrivacy announcement· Advisory (PDF)· Nelson Mullins analysis
The Virginia company failed to register with the Data Broker Registry by the 2025 deadline. Executive director Tom Kemp said the action shows CalPrivacy “takes seriously the failure to register by the deadline,” and that exposure is rising now that brokers are processing requests through DROP.
Failed to register in time while selling Californians' personal information — geolocation data, internet activity data, inferences, identifiers and commercial data — through its marketing products.
The Iowa company failed to register, and required consumers to hand over the last four digits of their Social Security number before they could opt out of the sale of their data. CalPrivacy found that demanding more personal information than necessary violates the CCPA's data minimisation requirement, and pointed to the resulting “tiny fraction” of opt-out requests as evidence that the mechanism itself was the violation.
The agency said it is now evaluating conduct “through the lens of multiple laws” and will continue to do so as multi-state collaboration grows.
CalPrivacy announcement· Order of Decision (PDF)· Bloomberg Law· MLex· National Law Review
Failed to register as a data broker. The agency attributed the lapse to an administrative error — which is the point worth noting: intent was not a defence, and neither was size.
Failed to register. The Texas reseller bought and resold the names, addresses, phone numbers and email addresses of millions of people with Alzheimer's disease, drug addiction, bladder incontinence and other health conditions, for targeted advertising.
Failed to register. The Nevada marketing firm used “billions of data points” to build custom audience lists, producing a repository of demographic, socioeconomic and behavioural data on more than 262 million Americans.
What a CalPrivacy data broker penalty grew to in eight months, from the December 2025 registration findings to the August 2026 combined action. The jump is not inflation — it is the shift from registration-only findings to actions brought under the CCPA and the Delete Act together.
CalPrivacy's CCPA enforcement reaches any business that sells or shares personal information, and the amounts are an order of magnitude larger than the registration fines.
Brought with Attorney General Rob Bonta and four District Attorneys. The largest penalty under California's privacy law, resolving claims that GM sold hundreds of thousands of Californians' location and driving data to data brokers.
CCPA enforcement against a retailer, not a broker.
Settling charges first filed in August 2022, Kochava and the subsidiary that took over its data broker business are prohibited from selling, licensing or disclosing sensitive location data without a consumer's affirmative express consent. The original complaint concerned location data from hundreds of millions of mobile devices that could trace individuals to reproductive health clinics, places of worship and other sensitive locations.
The order also requires a sensitive-location data programme, supplier consent assessments, incident reports to the FTC, a consumer-facing disclosure of who their location data was sold to, an easy way to withdraw consent, and a data retention schedule requiring deletion on a fixed timeframe.
FTC press release· Stipulated order (PDF)· Original 2022 complaint
Prohibited from selling sensitive location data. The companion action that established the pattern rather than the exception.
Until August 2026, a data broker reading these actions could reasonably conclude that the risk was administrative: register on time, respond to requests, keep the paperwork. The LocateSmarter order moved the line.
The finding was not that requests were ignored. It was that almost nobody could successfully make one — and the agency treated a low opt-out count as evidence of a defective mechanism rather than as evidence of low consumer interest. That reasoning generalises. Any friction that suppresses request volume is now a documented enforcement theory, and request volume is a number every registered broker publishes about itself in the state registry.
Two things follow operationally. First, the count of requests you receive is a signal a regulator can read without visiting your site. Second, obligations now stack: registration, DROP processing, opt-out mechanics and data minimisation were assessed together in a single action.
If a figure here is wrong or out of date, we want to know — the point of the page is that every number is checkable against the linked source. Amounts are quoted as stated in the agency announcement or order. Where an announcement covers several actions, the linked page is the announcement rather than an individual order.