Skip to content
RiskTemplates · The Daily Brief Friday, September 11, 2026
Wire SEC's $3.02M Doximity Insider Trading Judgment: The MNPI Control Test SEP 10

Feature Data Privacy

CalPrivacy Has Issued Eight Data Broker Fines and Is Still Going. What the September 2026 Enforcement Advisory Means for Your Fintech.

California's Privacy Protection Agency issued Enforcement Advisory 2026-01 on September 3, making clear that inaccurate data broker registration is a live $200-per-day penalty risk. Two August 2026 settlements and eight prior enforcement actions signal that CalPrivacy is done with warnings. Here's what fintech compliance teams need to know.

By Rebecca Leung · September 7, 2026 ·
Table of Contents

TL;DR

  • CalPrivacy issued Enforcement Advisory 2026-01 on September 3, 2026, making inaccurate data broker registration a live $200/day penalty risk — not a hypothetical one
  • August 2026 settlements with LocateSmarter ($110,490 combined) and Cybba showed CalPrivacy pursuing companies that failed to register at all
  • Eight prior enforcement actions and $4.22M+ in Q1 2026 penalties make clear this is an active program, not a warning phase
  • Many fintechs assume GLBA exempts them from data broker obligations — that assumption is often wrong

California’s Privacy Protection Agency has been running an enforcement program against data brokers since 2025. As of September 2026, they’re eight fines in, two fresh settlements confirmed, and they just issued a formal advisory making sure the industry understands exactly what the $200-per-day penalty mechanism covers.

If your fintech shares consumer data with third parties for consideration — even as a secondary revenue stream — and you haven’t run a serious data broker determination analysis, you have exposure that’s accruing daily.

What Enforcement Advisory 2026-01 Actually Says

On September 3, 2026, CalPrivacy issued Enforcement Advisory 2026-01 with a specific focus: data brokers that submit inaccurate information in their annual registration with California’s data broker registry are liable for a fine of $200 for each day the incorrect information remains in the registry.

This isn’t a new penalty — it’s been in the Delete Act since the beginning. What’s new is that CalPrivacy is explicitly flagging it as an active enforcement target, separate from the failure-to-register problem it’s been pursuing.

The advisory matters because it signals a second wave. Wave one was: find companies that haven’t registered at all, force registration or fine them. Wave two is: now that the registry exists and companies have registered, verify the accuracy of what they disclosed. Companies that registered to avoid the failure-to-register penalty but disclosed incomplete or inaccurate information are the next target.

What “inaccurate” means in practice includes:

  • Understating the categories of personal information sold or shared
  • Not disclosing all third-party recipient categories accurately
  • Mischaracterizing whether data is sold versus “shared for commercial purposes”
  • Incorrect consumer counts or demographic data
  • Failing to update the registration when business practices change

Two August 2026 Settlements: What Actually Got Companies Fined

The January 2026 enforcement announcement brought a new round of actions, and two August settlements illustrate the pattern CalPrivacy is running.

LocateSmarter LLC: Settled for a combined $110,490 — $30,600 for Delete Act registration violations and $79,890 for CCPA violations. The CCPA penalty stemmed from a specific violation: requiring consumers to provide unnecessary sensitive personal information in order to exercise their opt-out rights. LocateSmarter operates in the people-search and data enrichment space. The dual-penalty structure (Delete Act + CCPA) is notable — failure to register properly creates exposure under multiple frameworks simultaneously.

Cybba, Inc.: Cybba allegedly operated as a data broker in 2024 but did not register with CalPrivacy for 2025 — the year-over-year registration cycle. Cybba registered after CalPrivacy opened an investigation and contacted the company. The lesson from Cybba isn’t just “register.” It’s that CalPrivacy is actively scanning for companies whose business model matches data broker activity and cross-checking that against the registry. If you show up in a data broker directory or have a data monetization product and you’re not registered, CalPrivacy may already have you in a queue.

The combined settlements are calibrated penalties, not maximum exposure. A company that fails to register for a full year at $200/day is looking at $73,000 in registration-failure penalties alone — before any CCPA violations.

The Eight-Fine Pattern: What CalPrivacy’s Enforcement Looks Like in Practice

By December 2025, CalPrivacy had publicly disclosed at least eight enforcement actions against data brokers for registration failures. In Q1 2026 alone, CalPrivacy and the California AG collectively issued penalties exceeding $4.22 million across data privacy enforcement actions.

The eight-fine pattern shows a consistent CalPrivacy approach:

  1. Identify targets through market intelligence — app stores, data broker directories, privacy policy language, B2B marketing
  2. Confirm data broker status — analyze business model, data flows, and third-party sharing arrangements
  3. Verify non-registration or inaccurate registration — check the registry against the business
  4. Open investigation and contact company — companies that cooperate (like Cybba) move through the process faster
  5. Issue settlement or administrative fine — amount scaled to period of non-compliance and severity of violation

The DROP system added a new trigger. Starting August 1, 2026, registered data brokers must process consumer deletion requests submitted through the California Delete Request and Opt-Out Platform within 45 days. For companies that registered but haven’t operationalized DROP request processing, there’s a separate $200/day exposure per request not processed on time.

The GLBA Exemption Problem: Why Many Fintechs Are Miscalibrated

The most common misunderstanding in fintech about California data broker requirements is the scope of the GLBA exemption.

GLBA-covered financial institutions are exempt from certain CCPA provisions — specifically, personal information collected, processed, sold, or disclosed in a financial services context governed by GLBA. This is real and meaningful for core banking data, lending data, and payment processing information.

But the exemption doesn’t cover the whole business. It covers specific data in specific contexts.

Data TypeGLBA ContextGLBA Exemption Likely Applies?
Loan application data, payment historyCore financial servicesYes
Device fingerprinting data sold to fraud analytics firmsData monetizationUncertain — fact-specific
Location data shared with marketing data brokersMarketing functionLikely no
Behavioral data sold to data enrichment companiesSecondary revenueLikely no
Consumer financial data shared with BaaS partners for complianceProgram operationsFact-specific

The Wipfli analysis of California privacy laws and fintechs found that companies often operate data practices beyond their core financial services function that fall outside the GLBA exemption and may qualify as data broker activity. If your fintech has any of the following, you need a specific legal analysis before assuming GLBA exemption:

  • A data enrichment or analytics product that uses consumer data from your platform
  • Revenue from selling or licensing consumer data to any third party
  • Behavioral data sharing arrangements with marketing technology companies
  • A people-search or identity verification product using third-party data sources

What the Delete Act Actually Requires if You Qualify

If you determine your business meets the data broker definition, here’s what California requires:

Registration: Register annually with CalPrivacy by January 31 for the prior calendar year’s data broker activity. The registration requires disclosing the categories of personal information collected and sold, the types of data recipients, whether the business collects “sensitive personal information,” and annual metrics on consumer data request volumes.

DROP Processing: Starting August 1, 2026, process consumer deletion requests submitted through the DROP system within 45 days of receipt. Applicable to all registered data brokers — there’s no size exemption.

Accuracy and updates: Keep registration information current. If your business practices change — new data categories sold, new recipient types, new product lines — the registration should be updated. This is the specific target of Advisory 2026-01.

Opt-out pathway: Do not require consumers to provide unnecessary personal information (especially sensitive personal information) to exercise opt-out rights. The LocateSmarter CCPA penalty grew specifically from this requirement.

So What? Three Concrete Steps

If you haven’t run a formal data broker determination analysis for your fintech, that’s the starting point. Here’s the practical sequence:

Step 1: Map your data flows for third-party sharing. Pull a list of every third party that receives consumer data from your platform. For each one, identify: what data they receive, what they pay or provide in exchange, and whether your fintech has a direct relationship with the consumers whose data flows to them. Any third-party sharing arrangement where your fintech receives value and the consumers aren’t your direct customers is potentially within scope of the data broker analysis.

Step 2: Run the four-part definition test. California defines a data broker as a business that (1) knowingly collects and (2) sells or shares (3) personal information of consumers (4) with whom it has no direct relationship. Each element matters — and “direct relationship” is the one that trips up fintechs that assume all their data flows are covered by their customer agreement.

Step 3: If you qualify, register and operationalize. Registration itself takes a few hours. Operationalizing DROP request processing takes longer — you need a process to receive requests from the DROP portal, route them to the right data systems, and document completion within 45 days. If you qualified in 2024 and didn’t register by January 31, 2025 — or 2025 and didn’t register by January 31, 2026 — consult counsel on the retroactive exposure before registering, because registration will trigger questions CalPrivacy may use in an investigation.

The California Privacy Protection Agency has moved through its warning phase. Enforcement Advisory 2026-01, two fresh August settlements, and eight prior actions together make one thing clear: if your fintech qualifies as a data broker and hasn’t engaged seriously with the Delete Act, the question isn’t whether CalPrivacy will come calling — it’s when.

If you’re working through a multi-state privacy compliance stack and need templates covering CCPA, GLBA, and 19 state privacy laws, the Data Privacy Compliance Kit includes a 19-state applicability matrix, DSAR workflow templates, and the privacy impact assessment framework for this kind of analysis.


Also relevant on the California enforcement beat: For context on the GLBA exemption analysis and what the DELETE Act DROP system requires operationally, see California’s DELETE Act: The August 1, 2026 DROP Deadline and the GLBA Exemption Test Every Fintech Needs to Pass. For a related California enforcement case where data-sharing without consent triggered penalties, see GM Paid $12.75M for Selling Driver Data Without Consent — Your Fintech May Have the Same Problem. And for what happens when a federal data broker law meets fintech financial data: PADFAA Is Real Enforcement Now.

Sources: CalPrivacy Enforcement Advisory 2026-01 · CalPrivacy January 2026 Enforcement Announcement · CalPrivacy $45,000 Fine — Inside Privacy · LocateSmarter and Cybba Settlements · Fisher Phillips — California Data Broker Fines Analysis

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is a 'data broker' under California's Delete Act?
Under California law, a data broker is a business that knowingly collects and sells or shares the personal information of consumers with whom it does not have a direct relationship. The critical element is the third-party data sale or sharing — not just data collection. If your fintech monetizes consumer data by selling, licensing, or sharing it with analytics firms, credit bureaus, or marketing partners for consideration, you may qualify regardless of whether you also have a direct customer relationship.
Does GLBA exempt my fintech from California data broker registration?
The GLBA exemption from California's CCPA and Delete Act is narrower than most fintechs assume. GLBA-covered financial institutions are exempt from CCPA's consumer rights provisions for personal information collected, processed, sold, or disclosed in the financial services context governed by GLBA. But many fintechs operate data practices beyond their core financial services function — sharing location data, device data, or behavioral data with third parties for non-financial purposes — that fall outside the GLBA exemption and could qualify as data broker activity subject to Delete Act registration.
What does 'inaccurate information' in a registration look like in practice?
Enforcement Advisory 2026-01 targets registration entries where the disclosed data types, recipient categories, or business activity metrics don't match the company's actual practices. This includes understating the categories of personal information sold, not disclosing all data recipient types (claiming no sales to data brokers when you do), and incorrect consumer counts. CalPrivacy cross-references registration data against observed market practices and third-party data flows — errors aren't just a paperwork problem, they signal the underlying activity.
We missed the January 31 registration deadline — what now?
Register immediately. Every day without registration — if you qualify as a data broker — accrues penalty exposure. The penalty for failure to register is separate from the $200/day inaccurate-information penalty: it's $200 per day of unregistered operation during the calendar year you were required to register, plus up to $3,000 per intentional violation. Cybba registered after CalPrivacy opened an investigation; they likely avoided larger penalties by doing so quickly. The longer you wait, the higher the accrued exposure.
What is the DROP system and does it apply to us?
The California Delete Request and Opt-Out Platform (DROP) is the centralized deletion request system created by the Delete Act. Starting August 1, 2026, registered data brokers must process consumer deletion requests submitted through DROP within 45 days. The $200-per-day penalty structure applies to failure to process those requests — so registration triggers DROP obligations. If you qualify as a data broker but haven't registered, you're not processing deletion requests either, and that exposure compounds daily.
What triggers CalPrivacy's attention to a specific data broker?
CalPrivacy uses a combination of approaches: proactive searches of app stores, data broker directories, and marketing materials to identify unregistered entities; cross-referencing its registry against known data brokers; and reviewing consumer complaints. The LocateSmarter and Cybba cases both suggest CalPrivacy is actively scanning for companies whose business model matches data broker activity but who haven't registered. Having a people-search product, data enrichment service, or analytics offering targeting consumer data is a pattern CalPrivacy is tracking.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Data Privacy Compliance Kit

Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.

◆ Keep reading

Related posts.

Data Privacy

FTC Chairman Ferguson Says a Privacy Enforcement Surge Is Coming in H2 2026. Here's What Financial Services Companies Need in Place.

FTC Chairman Andrew Ferguson publicly warned that reporters covering the FTC will 'have a hard time keeping up' with the number of privacy enforcement cases coming in the second half of 2026. The Kochava settlement and new Section 5 standalone data-security cases telegraph exactly what's in the crosshairs. Here's what financial services companies need to have documented before the cases start landing.

Sep 9, 2026

Data Privacy

PADFAA Is Real Enforcement Now: What Fintech Data Companies Need to Know Before the FTC Files Its First Case

The Protecting Americans' Data from Foreign Adversaries Act prohibits data brokers from selling sensitive consumer data — including financial records — to entities in China, Russia, Iran, North Korea, Cuba, and Venezuela. The FTC sent 13 warning letters in February 2026. Here's what counts as a data broker, what data is covered, and what your compliance program needs before enforcement begins.

Sep 5, 2026

Data Privacy

GM Paid $12.75M for Selling Driver Data Without Consent. Your Fintech May Have the Same Problem.

California's record $12.75M CCPA settlement with General Motors over unconsented data sales to LexisNexis and Verisk exposes a pattern that runs through fintech: sharing consumer data with analytics firms, credit bureaus, and third parties without adequate notice or consent. Here's what the enforcement signal means for financial services compliance teams.

Sep 3, 2026

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.