CalPrivacy Hits Second Data Broker in Days: Cybba Fined $52,400 for Skipping Registry - Captain Compliance
Skip to content
Sign in
Create FREE Account
Home » News » CalPrivacy Hits Second Data Broker in Days: Cybba Fined $52,400 for Skipping Registry
CalPrivacy Hits Second Data Broker in Days: Cybba Fined $52,400 for Skipping Registry
Published<br>August 13, 2026
Table of Contents
Just two days after fining LocateSmarter, the California Privacy Protection Agency has issued its second data broker enforcement action of the week.
On August 13, 2026, the CalPrivacy Board ordered Boston-based Cybba, Inc. to pay a $52,400 fine for failing to register with the state’s Data Broker Registry by the 2025 deadline. The company sells personal information—including geolocation data, internet activity data, and inferences—primarily to support targeted advertising. One of its services analyzes purchasing behavior signals to identify likely repeat customers and other high-intent buyers.
Registration Failure and Required Fixes
Under the Delete Act, data brokers must register annually in January and pay a fee that funds both the Data Broker Registry and the state’s Delete Request and Opt-Out Platform (DROP). Cybba missed the 2025 registration deadline.
In addition to the monetary penalty, the decision requires Cybba to:
– Post metrics about privacy rights requests on its website
– Access CalPrivacy’s DROP system
– Process all future deletion requests through DROP
“CalPrivacy has been bringing a steady drumbeat of enforcement actions under both the Delete Act and the CCPA, and I don’t see the enforcement activity slowing down anytime soon,” said Michael Macko, the Agency’s head of enforcement. “Especially with the launch of DROP, businesses should take a close look at their activities.”
Tom Kemp, CalPrivacy’s executive director, called DROP “a game changer for Californians seeking to protect themselves from the data broker ecosystem” and reaffirmed the agency’s commitment to consistent enforcement.
The case was handled by the Agency’s Data Broker Enforcement Strike Force, with attorneys Neelofer Shaikh and Gary Lee leading the matter.
Part of a Broader Enforcement Push
This action follows the $116,490 penalty against LocateSmarter earlier this week—the first dual CCPA and Delete Act case. CalPrivacy is signaling that both registration failures and operational friction around consumer rights will draw scrutiny.
Recent enforcement highlights listed by the agency include:
– The $12.75 million General Motors settlement over connected vehicle data sharing
– A $1.10 million fine against PlayOn Sports
– A $375,703 penalty against Ford for opt-out friction
– Actions against data brokers such as Datamasters and Background Alert
– Multiple cases against other unregistered data brokers
– Fines against Tractor Supply ($1.35 million), Todd Snyder ($345,178), and American Honda ($632,500)
The agency is also expanding multi-state and international cooperation through the Consortium of Privacy Regulators and partnerships with authorities in Korea, France, and the United Kingdom.
Bottom Line for Data Brokers
Missing the annual registration deadline is no longer a low-risk administrative oversight. CalPrivacy is pairing registration enforcement with requirements to plug into DROP, publish metrics, and streamline deletion processing. Companies that collect and sell geolocation, browsing, purchase-behavior, or inferred data should treat both the registry obligation and DROP readiness as immediate compliance priorities.
With two data broker actions in less than a week, the agency’s message is consistent: the enforcement pace is not slowing down.
Written by Richart Ruddie
Relevant Posts
Creating a Full-Year AI Audit Program
AI Labs Want to Slow Risky Model Testing. Competition With China May Not Allow It
How AI Could Overwhelm the British State
New Jersey Enacts Kids Code Act with Age-Appropriate Design Rules and Private Right of Action
Building a Year-Round AI Audit Portfolio Instead of One-Off Reviews
Herbert Smith Freehills Kramer, Goodwin Procter, Blank Rome and More Disclose Data Breaches as Law Firm Cyberattacks Continue
Recent Posts
PDPA Law Thailand: Checklist for Compliance
Oregon Consumer Privacy Act Complaints
Vivek Shah CIPA Demand Letters: Inside the Court-Declared Vexatious Litigant’s Website Wiretapping Claims
New York’s Privacy Crackdown: Why National General’s Data Fumble Signals Trouble for Your Business—and Yes, You Need That Cookie Banner
DPDPA India: The Complete Guide to India’s Digital Personal Data Protection Act 2023
Australia Privacy Act Rights: Comprehensive Overview
Online Privacy Compliance Made Easy
Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.
Book a Demo