The CPPA’s latest enforcement action is both something we have and have not seen before.
LocateSmarter was late in registering as a data broker and only honored opt-out requests if consumers provided excessive information, like the last four digits of their Social Security numbers. For those violations, it's the agency's first action brought under both the state's data privacy and data broker laws.
Out of California's nearly 40 million residents, very few tried to opt out of LocateSmarter's sales. But the CPPA hit the data broker with a $116,490 fine anyway. That’s because putting up barriers to exercising consumer rights is in and of itself a violation, even if these barriers reduced the amount of unnecessary data processing LocateSmarter would have to carry out to handle the few opt-out requests it did receive.
And that's why the LocateSmarter action is something we've seen before. Earlier this and last year, Ford and Honda suffered a fine for a similar violation. Under the CCPA, there must not be any attempt to verify a consumer’s identity for simple opt-out requests. When it comes to opt-outs for Californians, “frictionless” is your watchword.
Best,
Arlo
In Case You Missed It...
Blog: Why Companies Are Leaving OneTrust in 2026
Unpredictable renewal pricing, months-long implementations, and support that favors the biggest accounts—mid-market teams are naming the same friction points as they evaluate OneTrust alternatives this year.
Top Privacy Stories of the Week
New Mexico Orders Meta to Pay $567M More in Child Safety Case
A New Mexico judge just ordered Meta to pay $567 million on top of an earlier $375 million fine, calling the company a "public nuisance" for design choices (endless scrolling, autoplay, notification loops) that the court found fueled depression, anxiety, and worse among the state's kids.
Samsung Beats Biometric Privacy Suit on a Key Technicality
Samsung just won a biometric privacy case that plaintiffs' lawyers will be studying closely. The 7th Circuit ruled that Samsung's Gallery app, which generates face-recognition templates entirely on the device to group photos, doesn't trigger BIPA liability because Samsung never took control of the data.
Privacy Insurance Claims Doubled in H1 2026 Due to CIPA
Privacy-related insurance claims doubled in the first half of 2026, and the biggest driver isn't a new law. It's a 1967 wiretapping statute. Nearly three-quarters of the claims cite California's Invasion of Privacy Act (CIPA), and one self-represented litigant alone generated more demand letters than every law firm combined, targeting ordinary tools like cookie banners and analytics scripts.
California's Privacy Agency Notches First Combined CCPA/Delete Act Enforcement Action
California's privacy agency just notched a first: a $116,490 enforcement action against data broker LocateSmarter that runs on both the CCPA and the Delete Act at once. LocateSmarter violated these laws by failing to register as a data broker in a timely fashion and introducing friction into the opt-out process by requiring partial Social Security numbers before processing requests.
Vermont Joins the Consortium of Privacy Regulators
Vermont just joined the Consortium of Privacy Regulators, bringing the coalition of state privacy enforcers to a dozen just weeks after signing its own comprehensive privacy law, the VDPOSA. The Consortium's pitch is straightforward: pool enforcement expertise and resources so state regulators can coordinate rather than duplicate investigations. For compliance teams already tracking two dozen-plus state privacy laws, that kind of cross-border coordination is worth watching.
Like What You See in the Privacy Insider newsletter?
There's more to explore:
🎙️The Privacy Insider Podcast
We go deeper into additional privacy topics with incredible guests monthly. Available on Spotify or Apple.
📱 The Osano Subreddit
Join our official subreddit to stay up to date on the latest news, analysis, guidance, and content from Osano!
đź“– The Privacy Insider: How to Embrace Data Privacy and Join the Next Wave of Trusted Brands
The book inspired by this newsletter: Osano CEO, Arlo Gilbert, covers the history of data privacy and how companies can start building a privacy program from the ground up. More details here.
If you’re interested in working at Osano, check out our Careers page!
Arlo Gilbert
Arlo Gilbert
Arlo Gilbert is the CIO & co-founder of Osano. A native of Austin, Texas, he has been building software companies for more than 25 years in categories including telecom, payments, procurement, and compliance. In 2005 Arlo invented voice commerce, he has testified before congress on technology issues, and is a frequent speaker on data privacy rights.
