Eight state regulators, including the California Privacy Protection Agency and attorneys general from seven states, formed the bipartisan Consortium of Privacy Regulators to collaborate on the implementation and enforcement of their privacy laws. The group aims to share expertise, resources, and coordinate investigations to protect consumer privacy across jurisdictions.
This announcement does not involve a specific enforcement action, but it signals increased coordination among state regulators, which may lead to more consistent and aggressive enforcement across jurisdictions. In-house legal teams should review their data processing and sharing agreements to ensure compliance with all applicable state privacy laws, particularly regarding consumer rights (access, delete, opt-out), and consider including provisions that address multi-state regulatory requirements. Vendor agreements should be audited for clauses on data use, consent mechanisms, and breach notification that align with the common features of state laws highlighted by the consortium.
Entity
Consortium of Privacy Regulators (California, Colorado, Connecticut, Delaware, Indiana, New Jersey, Oregon)
Industry
Other"The Consortium of Privacy Regulators is a bipartisan effort that includes state Attorneys General and the California Privacy Protection Agency."
"the California Consumer Privacy Act"
"Eight state regulators are collaborating on the implementation and enforcement of their privacy laws with the shared goal of protecting consumers."
CalPrivacy (the California Privacy Protection Agency) issued Enforcement Advisory 2026-01 warning data brokers that providing incorrect information in their annual registration with California's data broker registry carries liability of a $200 fine per day. The advisory observes that the Enforcement Division has already brought multiple enforcement actions over reporting errors, and emphasizes that accurate registry disclosures are what make the newly launched Delete Request and Opt-Out Platform (DROP) work for Californians. No specific company was named and no penalty was imposed by the advisory itself; it functions as forward-looking guidance.
$36K
The California Privacy Protection Agency Board issued a Decision and Final Stipulated Order requiring Virginia-based data broker SalesIntel Research, Inc. to pay a $36,400 fine for operating as a data broker without registering by the 2025 deadline under the Delete Act. SalesIntel sells consumer personal information, including more than 200 million professional contacts and de-anonymized website traffic data, for targeted advertising. In addition to the fine, the company must post privacy rights metrics on its website, integrate with CalPrivacy's Delete Request and Opt-out Platform (DROP), and process future deletion requests through that system.
The California Privacy Protection Agency announced that more than 500,000 Californians have registered for the Delete Request and Opt-out Platform (DROP) since its January 1, 2026 launch. After the August 1, 2026 deadline for brokers to begin processing requests, 654 data brokers are in the system and approximately 25% have reported processing deletion requests, with tens of millions of records already deleted. No enforcement action has been announced yet; the agency warned that brokers who fail to delete eligible personal information face significant fines.
$52K
The California Privacy Protection Agency Board issued an Order of Decision and Stipulated Final Order requiring Boston-based data broker Cybba, Inc. to pay a $52,400 fine for failing to register with the Agency's Data Broker Registry by the 2025 deadline, as required by the Delete Act. The order also requires Cybba to post metrics about privacy rights on its website, access the Agency's Delete Request and Opt-Out Platform (DROP), and process future deletion requests through that system. This is CalPrivacy's second data broker enforcement action announced in less than a week, following its action against LocateSmarter.
$116K
The California Privacy Protection Agency Board issued a decision and stipulated order requiring Iowa data broker LocateSmarter LLC to pay $116,490 and change its practices. The company failed to timely register as a data broker and unlawfully required Californians to provide the last four digits of their Social Security numbers before exercising opt-out rights, violating the CCPA's data minimization requirements. This is the first action against a data broker under both the CCPA and the Delete Act.
The California Privacy Protection Agency announced that over 300,000 Californians have signed up for the Delete Request and Opt-out Platform (DROP) since its launch five months ago. The Data Broker Registry now includes 581 registered data brokers, the highest number since the registry was established in 2020. Beginning August 1, 2026, all data brokers will be required to access DROP and process deletion requests.