SACRAMENTO, 20 AUG 2026 — California's privacy regulator has fined a data broker for demanding personal information from consumers who wanted to stop it selling their personal information. LocateSmarter required the last four digits of a Social Security number and a mailing address before it would process an opt-out.
The total comes to US$116,490. A broker of any size can absorb that without noticing, so the reasoning attached to it will outlast the penalty.
The order
The California Privacy Protection Agency alleged that the Iowa-based broker failed to register under the state's Delete Act, and separately violated the consumer privacy act by requiring consumers to hand over unnecessary data before they could opt out of the sale of their personal information.
The settlement splits into a US$79,890 administrative fine under the consumer privacy act, US$30,600 under the Delete Act, and the US$6,000 annual data broker registration fee the company had not paid.
Worth knowing what a data broker is, since almost nobody has knowingly dealt with one. These are firms that assemble profiles from public records, purchase histories, location feeds and other companies' customer lists, then sell access to skip-tracers, marketers, insurers, employers and anyone else willing to pay. The subject of the file has typically never heard of the company, never agreed to anything, and cannot easily find out what it holds. The registration requirement and the opt-out right exist to give somebody in that position a route in, which a hostile opt-out process quietly closes again.
Data minimisation applied to the opt-out itself
Nearly every modern privacy law contains a data minimisation principle: collect only what you need for the stated purpose. It is normally applied to the product — to signup forms, to analytics, to whatever the service does with a customer's information.
The agency's move was to apply this principle to the rights mechanism itself. The stated purpose of an opt-out request is to stop processing, and the regulator's position is that a company cannot demand more sensitive data as the price of granting it. A Social Security number is not necessary to stop selling somebody's records; if the broker holds a file on a person, it can locate that file without being handed the most sensitive identifier the person possesses.
Very little about that reasoning is specific to data brokers, or to California. Any organisation that asks for identity documents or other new data to process a deletion or opt-out request is on the same ground, even with better intentions.
The registration failure is the less-discussed half of the case. A register exists so that people can find out which brokers hold data on them and exercise rights against all of them from one place. A broker that does not register is invisible to that mechanism, and no amount of consumer diligence fixes it. Charging the unpaid fee back as part of the settlement is a small detail that says the agency treats registration as the foundation the rest of the scheme sits on.
Friction as a business model
The commercial logic of a hostile opt-out is straightforward and rarely stated.
A broker's inventory is the number of records it can sell. Every successful opt-out reduces it. A company in that position has no incentive to make the process easy, and every incremental step — an extra form field, a document upload, a demand for a sensitive identifier — reduces completion. None of those steps has to be refused outright to be effective, because most people simply stop.
Framing that friction as a security measure is what makes it durable. Verification sounds responsible, and some of it is necessary. A business that deletes records on an unverified request can be used to attack its own customers. So the regulator has landed on proportionality instead of a ban. Verify using what you already hold on the person, rather than using the request as an opportunity to collect more.
Small fine, useful precedent
A hundred and sixteen thousand dollars will not, on its own, change a data broker's behaviour. The value of this action is that it establishes what the agency will act on before anyone has to litigate it.
Two elements of the order give it force. The first is the combination: registration failure under one statute and a rights-mechanism violation under another, which shows the regulator will assemble a case across both rather than treating them separately. The second is that it is a stipulated order — the company agreed, so there is no contested finding, and no precedent a future defendant can distinguish on the facts. That cuts both ways.
Reporting also indicates a second data broker was penalised within days, which is what an agency does when it is setting an expectation rather than punishing an outlier.
Why the principle travels to this region
Frameworks in the region — Singapore's, Indonesia's, and others taking shape across ASEAN — already contain the two necessary ingredients. They impose a purpose-limitation or minimisation duty, and they grant a consumer right to withdraw consent or request deletion.
What none of them has produced yet is an enforcement action about the mechanism of the right rather than about a breach. Regional privacy enforcement has overwhelmingly concerned incidents — data lost, systems compromised, notifications delayed. This is a regulator saying that a rights process designed to fail is itself the violation, with no breach required.
Any organisation in the region operating a deletion or withdrawal process should read its own flow with that lens. If withdrawing consent takes more steps than granting it, or asks for identification that granting it did not, the argument made in California applies without much translation.
What we could not establish
How many consumers were affected. The reporting describes a small number of opt-out requests, and the order does not appear to quantify how many people abandoned the process or how many records remained saleable as a result.
We also could not establish how the fine was calculated — whether from revenue, harm, or a formula. Other open questions include what practices the company agreed to change, how many brokers remain unregistered, whether the agency plans similar actions, and if the second penalty rests on the same reasoning.
What to watch
The argument matters most if it survives a contested case. A stipulated order settles one company's conduct and creates nothing another defendant has to answer; a litigated finding would, and that is the version regulators elsewhere would cite.
Registration numbers are the cheap measure of whether any of this worked. Small fines exist to signal, and a wave of previously unregistered brokers appearing on the register would be the signal landing.
Finally, watch for the first regional equivalent. If a privacy regulator in this region acts on a flawed opt-out process, rather than a data breach, it will mark a significant shift in local compliance. The reasoning from California is available off the shelf.