The CPPA’s latest enforcement action is both something we have and have not seen before.
LocateSmarter was late in registering as a data broker and only honored opt-out requests if consumers provided excessive information, like the last four digits of their Social Security numbers. For those violations, it's the agency's first action brought under both the state's data privacy and data broker laws.
Out of California's nearly 40 million residents, very few tried to opt out of LocateSmarter's sales. But the CPPA hit the data broker with a $116,490 fine anyway. That’s because putting up barriers to exercising consumer rights is in and of itself a violation, even if these barriers reduced the amount of unnecessary data processing LocateSmarter would have to carry out to handle the few opt-out requests it did receive.
And that's why the LocateSmarter action is something we've seen before. Earlier this and last year, Ford and Honda suffered a fine for a similar violation. Under the CCPA, there must not be any attempt to verify a consumer’s identity for simple opt-out requests. When it comes to opt-outs for Californians, “frictionless” is your watchword.
Best,
Arlo
Blog: Why Companies Are Leaving OneTrust in 2026
Unpredictable renewal pricing, months-long implementations, and support that favors the biggest accounts—mid-market teams are naming the same friction points as they evaluate OneTrust alternatives this year.
A New Mexico judge just ordered Meta to pay $567 million on top of an earlier $375 million fine, calling the company a "public nuisance" for design choices (endless scrolling, autoplay, notification loops) that the court found fueled depression, anxiety, and worse among the state's kids.
Samsung just won a biometric privacy case that plaintiffs' lawyers will be studying closely. The 7th Circuit ruled that Samsung's Gallery app, which generates face-recognition templates entirely on the device to group photos, doesn't trigger BIPA liability because Samsung never took control of the data.
Privacy-related insurance claims doubled in the first half of 2026, and the biggest driver isn't a new law. It's a 1967 wiretapping statute. Nearly three-quarters of the claims cite California's Invasion of Privacy Act (CIPA), and one self-represented litigant alone generated more demand letters than every law firm combined, targeting ordinary tools like cookie banners and analytics scripts.
California's privacy agency just notched a first: a $116,490 enforcement action against data broker LocateSmarter that runs on both the CCPA and the Delete Act at once. LocateSmarter violated these laws by failing to register as a data broker in a timely fashion and introducing friction into the opt-out process by requiring partial Social Security numbers before processing requests.
Vermont just joined the Consortium of Privacy Regulators, bringing the coalition of state privacy enforcers to a dozen just weeks after signing its own comprehensive privacy law, the VDPOSA. The Consortium's pitch is straightforward: pool enforcement expertise and resources so state regulators can coordinate rather than duplicate investigations. For compliance teams already tracking two dozen-plus state privacy laws, that kind of cross-border coordination is worth watching.
There's more to explore:
We go deeper into additional privacy topics with incredible guests monthly. Available on Spotify or Apple.
Join our official subreddit to stay up to date on the latest news, analysis, guidance, and content from Osano!
The book inspired by this newsletter: Osano CEO, Arlo Gilbert, covers the history of data privacy and how companies can start building a privacy program from the ground up. More details here.
If you’re interested in working at Osano, check out our Careers page!