California crackdown on data brokers highlights push for easier opt-out processes

California’s privacy regulator has issued a settlement against LocateSmarter LLC, emphasising the need for streamlined opt-out systems and tighter data minimisation, signaling a tougher stance on data broker compliance amid upcoming enforcement measures.

California’s privacy regulator has sharpened its enforcement message to data brokers, with a settlement against LocateSmarter LLC underlining that registration duties, consumer opt-out handling and data minimisation are now being examined together. The California Privacy Protection Agency said the Iowa-based company agreed to pay $116,490 after allegations that it operated as a data broker without properly registering and made it unnecessarily difficult for people to opt out of the sale of their personal information. According to the agency, the company also asked consumers to provide the last four digits of their Social Security number before it would accept an opt-out request.

The case matters because the CPPA has spent the past year formalising the mechanics of the Delete Act, including the Delete Request and Opt-Out Platform, known as DROP. The agency says data brokers must use the system to process consumer deletion requests, with the operative requirement taking effect on 1 January 2026 and the platform available for consumer requests from 1 August 2026. The CPPA also says registered brokers must create an account in DROP and handle requests subject to limited exceptions. In parallel, the state Department of Justice’s registry shows LocateSmarter is in fact registered as a data broker, but the company’s own opt-out process still requires a full name, mailing address and the last four digits of a Social Security number to verify the requester.

That tension is at the centre of the enforcement risk. California’s regulator said requiring more personal information than is reasonably needed can clash with the state’s data minimisation standards, particularly when the information sought is sensitive. In LocateSmarter’s case, the agency said the company collected names, driver’s licence details, dates of birth and records relating to employment, bankruptcy and litigation, raising the stakes of any unnecessary identity check. The broader warning for the sector is that a low number of opt-out requests may not mean a programme is working well if the process itself is hard to use or intimidating.

The agency’s wider guidance suggests that California expects brokers to treat registration, consumer rights workflows and technical DROP compliance as parts of one system, not separate obligations. The CPPA has also issued an enforcement advisory this year stressing annual registration, disclosure of trade names and web addresses, and the payment of fees that fund both the registry and DROP. For companies that fall within California’s broad definition of a data broker, the practical lesson is simple: opt-out tools should be easy to use, data collection for verification should be tightly limited and registration status should be checked against actual business practices rather than assumed on paper.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.