CalPrivacy 2nd Fine in As Many Days Against a data broker

richartruddie1 pts1 comments

CalPrivacy Hits Second Data Broker in Days: Cybba Fined $52,400 for Skipping Registry - Captain Compliance

Skip to content

Sign in

Create FREE Account

Home » News » CalPrivacy Hits Second Data Broker in Days: Cybba Fined $52,400 for Skipping Registry

CalPrivacy Hits Second Data Broker in Days: Cybba Fined $52,400 for Skipping Registry

Published<br>August 13, 2026

Table of Contents

Just two days after fining LocateSmarter, the California Privacy Protection Agency has issued its second data broker enforcement action of the week.

On August 13, 2026, the CalPrivacy Board ordered Boston-based Cybba, Inc. to pay a $52,400 fine for failing to register with the state’s Data Broker Registry by the 2025 deadline. The company sells personal information—including geolocation data, internet activity data, and inferences—primarily to support targeted advertising. One of its services analyzes purchasing behavior signals to identify likely repeat customers and other high-intent buyers.

Registration Failure and Required Fixes

Under the Delete Act, data brokers must register annually in January and pay a fee that funds both the Data Broker Registry and the state’s Delete Request and Opt-Out Platform (DROP). Cybba missed the 2025 registration deadline.

In addition to the monetary penalty, the decision requires Cybba to:

– Post metrics about privacy rights requests on its website

– Access CalPrivacy’s DROP system

– Process all future deletion requests through DROP

“CalPrivacy has been bringing a steady drumbeat of enforcement actions under both the Delete Act and the CCPA, and I don’t see the enforcement activity slowing down anytime soon,” said Michael Macko, the Agency’s head of enforcement. “Especially with the launch of DROP, businesses should take a close look at their activities.”

Tom Kemp, CalPrivacy’s executive director, called DROP “a game changer for Californians seeking to protect themselves from the data broker ecosystem” and reaffirmed the agency’s commitment to consistent enforcement.

The case was handled by the Agency’s Data Broker Enforcement Strike Force, with attorneys Neelofer Shaikh and Gary Lee leading the matter.

Part of a Broader Enforcement Push

This action follows the $116,490 penalty against LocateSmarter earlier this week—the first dual CCPA and Delete Act case. CalPrivacy is signaling that both registration failures and operational friction around consumer rights will draw scrutiny.

Recent enforcement highlights listed by the agency include:

– The $12.75 million General Motors settlement over connected vehicle data sharing

– A $1.10 million fine against PlayOn Sports

– A $375,703 penalty against Ford for opt-out friction

– Actions against data brokers such as Datamasters and Background Alert

– Multiple cases against other unregistered data brokers

– Fines against Tractor Supply ($1.35 million), Todd Snyder ($345,178), and American Honda ($632,500)

The agency is also expanding multi-state and international cooperation through the Consortium of Privacy Regulators and partnerships with authorities in Korea, France, and the United Kingdom.

Bottom Line for Data Brokers

Missing the annual registration deadline is no longer a low-risk administrative oversight. CalPrivacy is pairing registration enforcement with requirements to plug into DROP, publish metrics, and streamline deletion processing. Companies that collect and sell geolocation, browsing, purchase-behavior, or inferred data should treat both the registry obligation and DROP readiness as immediate compliance priorities.

With two data broker actions in less than a week, the agency’s message is consistent: the enforcement pace is not slowing down.

Written by Richart Ruddie

Relevant Posts

Creating a Full-Year AI Audit Program

AI Labs Want to Slow Risky Model Testing. Competition With China May Not Allow It

How AI Could Overwhelm the British State

New Jersey Enacts Kids Code Act with Age-Appropriate Design Rules and Private Right of Action

Building a Year-Round AI Audit Portfolio Instead of One-Off Reviews

Herbert Smith Freehills Kramer, Goodwin Procter, Blank Rome and More Disclose Data Breaches as Law Firm Cyberattacks Continue

Recent Posts

PDPA Law Thailand: Checklist for Compliance

Oregon Consumer Privacy Act Complaints

Vivek Shah CIPA Demand Letters: Inside the Court-Declared Vexatious Litigant’s Website Wiretapping Claims

New York’s Privacy Crackdown: Why National General’s Data Fumble Signals Trouble for Your Business—and Yes, You Need That Cookie Banner

DPDPA India: The Complete Guide to India’s Digital Personal Data Protection Act 2023

Australia Privacy Act Rights: Comprehensive Overview

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.

Book a Demo

data calprivacy broker enforcement privacy against

Related Articles