Free exposure scan. Complete cleanup is $5.99/mo. Start cleanup →
Home/Blog/Delete Act: The First Fines
Back to Blog
Privacy Law

California Started Fining Data Brokers — But Not for Ignoring You

12 min read

The Delete Act deadline landed on August 1, 2026. Three weeks later, California has issued its first fines against data brokers — and they are real money, not warning letters. But read what the brokers were actually fined for and a pattern shows up immediately: every single penalty is for failing to sign up. Not one is for receiving a lawful deletion request and ignoring it. We have sent 20,354 of those requests. Here is what comes back instead.

What August 1 Actually Required

It helps to be precise about the obligation, because most coverage of the deadline was written months before it arrived. Since August 1, every data broker registered with California must:

  • Check DROP at least once every 45 days and process the deletion requests waiting there.
  • Report the status of each request in DROP within 45 days of retrieving it.
  • Keep a list of the deletion requests it has received, so that deleted information stays deleted rather than reappearing on the next scrape.

Failure can draw fines of $200 per request, per day, plus expenses. Multiply that by a broker sitting on a few thousand unprocessed requests and the arithmetic gets frightening quickly. That is the theory. The practice, so far, is narrower.

The Fines, in Order

California's privacy regulator set up a dedicated Data Broker Enforcement Strike Force inside its Enforcement Division in November 2025, months ahead of the deadline. Here is everything it has produced so far.

CompanyAnnouncedAmountWhat for
ROR Partners, LLCDecember 2025$56,600Operating as an unregistered data broker
LocateSmarter, LLCAugust 11, 2026$116,490Failure to register; excessive ID demands to opt out
Cybba, Inc.August 13, 2026$52,400Failure to register for its 2024 activities

ROR Partners is a Nevada marketing firm that, according to the agency's decision, held a repository of demographic, socioeconomic and behavioural data covering more than 262 million Americans and used it to build custom audience segments for clients — while not appearing on California's data broker registry at all.

LocateSmarter drew the largest penalty and the only one with a second count attached. Beyond failing to register, the agency found it required consumers to hand over their full name, the last four digits of their Social Security number, and their mailing address merely to opt out. That is a data minimisation violation with a particular sting to it: the price of asking a broker to stop holding your data was giving that broker more of it.

Cybba is the most instructive of the three, and the least discussed. It had registered on time for its 2025 activities. The fine was for missing the January 31, 2025 registration deadline covering its 2024 activities — a company that came into compliance and was penalised for the year before. Among its required remedies: process deletion requests through DROP.

The Pattern Nobody Is Naming

Every Delete Act fine so far is for not signing up

Three enforcement actions, roughly $225,000 in total penalties, and not one of them says: you received a valid deletion request from a Californian and you did not honour it. The violations are registration failures, a late filing, and one opt-out form that asked for too much.

This is not a criticism of the agency. Registration is the correct place to start, because registration is the one obligation a regulator can verify from the outside. You compare a list of companies that trade in personal data against a list of companies that filed. The gap is your docket. It is cheap, it is provable, and it establishes that the statute has teeth.

Whether a specific broker actually deleted a specific person's record is a completely different evidentiary problem. The regulator cannot see inside the database. It largely depends on the consumer noticing, and complaining, and being able to describe what happened — which brings us to the part we can measure.

What 20,354 Deletion Demands Got Back

We run a data removal service. Every month we file deletion demands under the CCPA on behalf of our customers, and every broker reply comes back into a system that reads it, classifies it and files the evidence. That gives us something regulators and journalists mostly do not have: a large, first-party record of what brokers say when a lawful deletion demand lands in their inbox.

As of today:

GhostVault filing data — August 21, 2026

  • 603 — registered data brokers we file against
  • 20,354 — deletion demands sent
  • 3,150 — brokers that answered in some form
  • 503 — records cleared (deletion proven, or the broker states it holds nothing)
  • 133 — deletions confirmed in writing

Resist the obvious arithmetic. 133 out of 20,354 is not a 0.65% success rate, and anyone quoting it that way — including us, if we were being sloppy — would be describing something other than reality. Most of those demands are still inside the statutory response window, which the Delete Act sets at 45 days and which the CCPA allows a broker to extend. A demand sent three weeks ago is not a failure; it is pending.

The number that is immediately meaningful is the shape of the replies. When a broker answers us, the single most common substantive response is not a confirmation and not a refusal. It is a redirect.

"Please Use Our Web Form"

Across our corpus of categorised replies, the largest group by a wide margin is what our system files as action required — a reply that puts the ball back in the consumer's court. And when we read those replies, roughly 95% of them say the same thing: we do not accept deletion requests by email, please submit through our privacy portal.

Sometimes it is a courteous paragraph with a link. Sometimes it is a bare autoresponder. Occasionally it is a consent-management platform's templated bounce. The substance is identical, and so is the effect: the deletion stops. It stops in a place that looks like compliance from every angle a regulator can inspect. The broker answered. The broker provided a lawful mechanism. The broker can point to a portal that genuinely works.

It just requires the human being to go and fill it in, one broker at a time, with an identity verification step at the end of each one. Which is precisely the thing a single-request deletion platform was invented to abolish.

Why this is invisible to enforcement

A broker that ignores you leaves a trail: an unanswered request, a consumer complaint, a missed deadline in DROP. A broker that redirects you leaves nothing. You did not complain — you were given a link. You may not even have realised the request went nowhere. There is no docket entry for a deletion that was politely deferred back to the person who asked for it.

The Second Thing We See: Identity Walls

The LocateSmarter count — demanding a name, an address and four SSN digits to process an opt-out — is not an outlier. It is a genre. A meaningful share of the replies we handle ask for identity documentation before the request will be considered: a government ID scan, a utility bill, a notarised affidavit, a signed authorisation, or a "verification link" that expires in 48 hours.

Some of that is legitimate. A broker that deletes records for anyone who emails is a broker with a new attack surface, and the CCPA does permit verification. But there is a line between confirming a requester is who they say they are and using verification as a toll booth, and a lot of brokers sit on the wrong side of it. The agency's action against LocateSmarter is the first sign that this line is going to be policed. It should not be the last.

What This Means If You Live in California

  1. Use DROP. It is free and it is now backed by real penalties. One submission reaches every broker registered with the state, and from August 1 those brokers have an affirmative duty to check for it every 45 days. It is the single highest-leverage thing a Californian can do about data brokers, and it costs nothing.
  2. Do not assume DROP finished the job. It reaches registered brokers only. The entire enforcement story above exists because a meaningful number of companies trading in personal data never registered at all — and a company that ignored the registry is not going to be checking the platform.
  3. Expect the portal redirect, and budget for it. Whether you file yourself or use a service, a large fraction of brokers will hand the work back to you. There is currently no way around this, because the operative step genuinely can only be completed by the consumer. What a good service can do is track exactly which brokers are waiting on you and stop pretending those requests are handled.
  4. Keep your evidence. The Delete Act's teeth are $200 per request per day, and that clock only ever starts if someone can show a request was made and a deadline was missed. Dated proof of what you asked for, and when, is the raw material of every enforcement action on the table above.
  5. Re-check in 90 days. Deletion is not a one-time state. Brokers rebuild profiles from public records continuously, and nothing in the Delete Act stops a record from being re-scraped after it is deleted — the record-keeping requirement is aimed squarely at this, and it is brand new and untested.

What We Would Like to See Next

The first three fines prove the statute is enforceable and that the agency is willing to spend resources on it. That matters, and it is more than most privacy laws achieve in their first year. The question the next twelve months will answer is whether enforcement can reach past the registry into the behaviour that actually determines whether anyone's data gets deleted.

Concretely, that would mean an action against a broker that is registered, did receive requests through DROP, and used a portal redirect or an identity wall to run out the 45-day clock. That case is harder to build than a registration case. It is also the only kind of case that changes what happens to the 20,354 demands sitting in our system.

We will publish the numbers again when the first post-deadline cohort clears its 45-day window in mid-September. If the deadline changed broker behaviour, it will show up there first — and if it did not, that is worth saying out loud too.


Methodology: figures are drawn from GhostVault's production filing records as of August 21, 2026, covering deletion demands sent on behalf of customer accounts against the 603 data brokers in our registry. They exclude our own staff and test accounts, which were removed from the dataset on the day of publication — that correction alone took 12 confirmed deletions out of the total, and we would rather report the smaller number than one padded with our own filings. "Confirmed in writing" means a broker stated in a reply that the record was deleted. "Records cleared" additionally counts brokers that stated they hold no data on the consumer. Reply categories are assigned by an automated classifier with a human review pass over the templates it could not decide. Enforcement figures are from the California Privacy Protection Agency's published announcements and decisions.

This is one possible source in a much larger personal-data ecosystem.

Scan supported sources for free, then use Ghost to organize requests, follow-ups, and verified outcomes.

Try a free scan →

Related guides

Popular on GhostVault