Blog
August 14, 2026
5 mins
CCPA-CPRA
US

CalPrivacy’s First CCPA + Delete Act Case Against a Data Broker

On August 11, 2026, CalPrivacy ordered Iowa data broker LocateSmarter to pay $116,490 for late registration and for forcing Californians to share partial SSNs before opting out. Here is a plain-English guide to what happened, why it matters under the CCPA and Delete Act, and what Shopify stores should check next.
Consentmo illustration of California privacy law enforcement and compliance requirements.

TLDR:

  • Who: LocateSmarter LLC, an Iowa data broker.
  • What: CalPrivacy ordered a $116,490 penalty plus practice changes.
  • Why: Late data-broker registration and making Californians hand over partial Social Security numbers before they could opt out of data sales.
  • Firsts: First data-broker case under the CCPA, and first case under both the CCPA and the Delete Act.
  • Big lesson for every business: Extra friction or extra data on privacy requests can violate data minimization, even if only a few people complain. DROP now makes it easier for consumers to wipe broker files in one go.

What is this case about in simple terms?

Think of a data broker as a company that collects personal details (often from many sources), packages them, and sells or licenses access to other businesses.

CalPrivacy says LocateSmarter:

  1. Sold or licensed Californians’ data without registering on time as a data broker under the Delete Act.
  2. Blocked easy opt-outs by asking for unnecessary identity data, including the last four digits of a Social Security number, before processing “do not sell” style requests.

The Board’s decision requires the company to pay $116,490 and fix its practices. The Agency notes it has already brought more than a dozen broker actions, but this one is special: it is the first against a data broker under the CCPA, and the first under both the CCPA and the Delete Act.

What personal information did the broker handle?

According to the decision, LocateSmarter collected personal information in part through licensing agreements, then made it available to customers. That information included:

  • Names and dates of birth
  • Social Security numbers
  • Phone numbers and email addresses
  • Employment information
  • Driver’s license information
  • Bankruptcy and litigation information
  • Inferences about people (for example, whether someone is “litigious”)

Under California law, inferences count as personal information too. Brokers do not get a free pass because a field is “scored” or “derived” instead of typed in by the consumer.

What is the Delete Act, and what is DROP?

Delete Act (for data brokers)

California’s Delete Act targets companies in the business of buying, selling, or sharing personal information about consumers with whom they often have no direct relationship.

Key duty highlighted in this case: data brokers must register with CalPrivacy every January and pay a fee that funds the registry and consumer tools. Details for brokers live on CalPrivacy’s data broker pages and the Data Broker Registry.

DROP (for consumers)

DROP means Delete Request and Opt-out Platform. It is California’s one-stop tool so people do not have to hunt every broker one by one. CalPrivacy describes DROP as a first-of-its-kind system that lets consumers direct all registered data brokers to delete their personal information in a single request.

Executive Director Tom Kemp stressed that the fine is substantial even though only a handful of consumers submitted opt-out requests. Each Californian’s rights matter, not only high-volume complaint spikes.

Why does CalPrivacy call this a “first” under both laws?

Enforcement head Michael Macko said the Agency looks through the lens of multiple laws to pick the best fit for consumers. The same multi-tool approach showed up in the General Motors matter, where CalPrivacy partnered with the Attorney General and district attorneys on a large connected-vehicle privacy settlement.

So brokers (and other businesses) should assume:

  • Registration failures can trigger Delete Act exposure.
  • Bad request handling, dark patterns, or over-collection can trigger CCPA exposure.
  • One investigation can stack both.

Does this only matter if I am a data broker?

No. Most Shopify merchants are not LocateSmarter. The patterns still apply:

Pattern in the case Store takeaway
Late / missing registration Know your role. If you sell or share personal data in broker-like ways, confirm whether Delete Act duties apply.
Extra fields on opt-out forms Review DSAR / “Do Not Sell or Share” forms. Drop SSN, full DL, or other sensitive fields unless you truly need them to verify identity.
Friction that discourages rights One-click or low-friction opt-outs beat multi-step “prove yourself with secrets” flows for sale/share opt-outs.
Inferences still count as PI Profiles, scores, and “lookalike” traits need the same care as raw contact fields.
Small request volume ≠ small risk CalPrivacy fined based on conduct and principles, not a viral complaint storm.

For a broader merchant checklist, see Consentmo’s CCPA-CPRA guide for Shopify stores (2026) and our breakdown of how the Disney CCPA fine changes opt-out rules.

What should Shopify stores do this week?

1. Map your “sale” and “share” activity

List pixels, ad partners, analytics, and apps that receive personal information. If California “sale” or “sharing” applies, your opt-out path must work in practice, not only on paper. Consentmo’s Smart Cookie Policy page surfaces the trackers and scripts in play so you can see sale/share exposure clearly.

2. Audit verification on privacy requests

Ask only for the minimum needed to locate the person and stop the sale/share or fulfill the request type. Sensitive identifiers as a default gate for every opt-out are a red flag after this case. Consentmo handles CCPA privacy requests and Do Not Sell requests, and both can complete with just a simple email.

3. Remove dark patterns

No guilt screens, no buried links, no “call us during business hours only” traps for rights that the law expects you to honor online when you operate online. Consentmo keeps a live, up-to-date compliance page with auto-monitoring so you can spot gaps in an instant check.

4. Keep policies and banners aligned

Your privacy policy, cookie banner, and request pages should tell the same story. Consentmo pairs your cookie policy with scheduled scans so disclosures stay current as your stack changes.

5. Train your team

Support teams should never invent extra ID hurdles. Give them a short script: what you can ask, what you must not ask, and how fast to route CCPA requests.

6. Watch broker and vendor contracts

If a vendor resells or enriches customer data, ask how they register, how they honor DROP-driven deletions where relevant, and how they verify consumers without over-collection.

Where do I read the official materials?

Conclusion

LocateSmarter is a data-broker story on the surface. Underneath, it is a consumer-request design story. California will stack the CCPA and the Delete Act, punish late registration, and treat SSN-gated opt-outs as both intimidation and over-collection.

If you run a Shopify store, you may never touch a broker registry form. You still own the moment a Californian tries to say stop selling or sharing my data.

Keep that moment short, clear, and light on sensitive fields. Pair honest disclosures with a consent and request stack you can actually operate. That is how you stay on the right side of the same principles CalPrivacy just enforced in public.

Mariya Petrova
Growth & Product Marketing
With over 7 years of experience in advertising across agencies and e-commerce brands, Mariya has made marketing her core element. Today, she supports Consentmo users by guiding them through the realms of compliance, Shopify, and all things marketing.