Data Broker Registry Fine: What CalPrivacy's $52,400 Cybba Penalty Says About Unregistered Brokers

On August 13, 2026, the California Privacy Protection Agency (which now calls itself CalPrivacy) fined Cybba, Inc. $52,400 for selling Californians' personal information without ever registering as a data broker. It was the agency's second data broker registry fine in three days, following the $116,490 penalty against LocateSmarter LLC announced on August 11. The two cases involve different companies and different failures, and together they show what enforcement of California's Delete Act looks like now that the registry has teeth: a Boston ad-tech firm that stayed off the list entirely, and an Iowa people-search operator that registered late and then asked for part of your Social Security number before it would stop selling your data.

What the Cybba data broker registry fine was for

Cybba is a Boston-based advertising technology company. According to CalPrivacy's decision, it sells personal information including geolocation data, internet activity data, identifiers, commercial data and inferences, and it packages them for targeted advertising. One of its services reads signals from consumers' purchasing behavior to flag likely repeat customers and people who are more likely to buy. The people being profiled never see any of this and never agreed to it, which is exactly the kind of business California's Delete Act was written to catch.

The Delete Act requires any company meeting the state's definition of a data broker to register with CalPrivacy every January and pay the annual fee. Cybba did not register by the 2025 deadline. The Board's order fines it $52,400 and, more consequentially, folds it into the system it had been operating outside of: Cybba must now post its privacy-rights metrics on its own website, set up access to DROP (the Delete Request and Opt-Out Platform), and process every future deletion request that arrives through it.

CalPrivacy's head of enforcement, Michael Macko, said in the announcement that the agency has been bringing "a steady drumbeat of enforcement actions under both the Delete Act and the CCPA," and the release notes that beyond the named cases the agency has brought more than a dozen actions against other unregistered brokers.

LocateSmarter: registered late, then asked for your SSN to opt out

The LocateSmarter decision, announced two days earlier, is the more unusual of the two. LocateSmarter LLC is an Iowa broker, and its $116,490 penalty combines two statutes. Part of it is a Delete Act fine for failing to register on time. The larger part is a CCPA penalty for requiring Californians to hand over the last four digits of their Social Security number before it would process an opt-out of sale. CalPrivacy's position was blunt: a broker does not need a partial SSN to stop selling someone's data, so demanding one violates the CCPA's data-minimization rule and makes the opt-out harder than the law allows.

The agency called it the first decision against a data broker under the CCPA, and the first to arise under both the CCPA and the Delete Act. Our SB 361 fines guide breaks the $116,490 down line by line, and our DROP platform guide covers the third fine of the run, the $36,400 SalesIntel penalty issued September 1, so this page won't repeat those.

How a data broker registry fine is calculated

The number is built from a daily rate. The Delete Act of 2023 set the penalty for failing to register at $200 for each day a broker stays off the registry (the $100 figure still quoted in some summaries is the 2019 rate that the Delete Act replaced, and SB 361 in 2025 left the amount alone), and Cybba's $52,400 divides evenly into 262 days at that rate. The fine is a meter that runs from the registration deadline until the broker finally registers or the agency catches it, whichever comes first, which is why a company that ignores the January window for most of a year ends up with a five-figure bill even without any other violation.

There is a second meter that applies once a broker is registered: $200 per unprocessed deletion request per day, from the day the request should have been handled. Cybba's order plugs it into DROP, which means that meter now applies to it too. On September 3, CalPrivacy added a third exposure with Enforcement Advisory 2026-01: a broker whose registry entry contains incorrect information owes $200 for each day the bad information stays up. Registering is no longer enough; the entry has to be accurate.

How to check whether a data broker is registered

California's Data Broker Registry is public, searchable, and downloadable as a spreadsheet. That is the only practical way to answer "is this company a registered data broker" for a name you already have. We pull the full CSV periodically for our own removal work, and the September 1, 2026 copy shows what the Cybba order produced.

Cybba is on the list now, filed under its Boston address, and its entry answers yes to collecting consumers' precise geolocation. Two details in the entry are worth knowing if you ever want to exercise your rights against it. The field where a broker is supposed to give the web page explaining how Californians can exercise their privacy rights contains nothing more specific than https://cybba.com, the company's homepage. And of the 247 requests to opt out of sale or sharing it reported receiving in 2024, it denied 41. The registry's numbers are self-reported, which is what the September 3 advisory is aimed at, but they are the only public window into how a broker actually treats requests.

The registry has a harder limit, and it is the one that matters most for people-search exposure. It only lists companies that registered. When we compared our own opt-out targets against the September 1 file, Radaris and National Public Data had no entry at all, so a DROP request never reaches them and no registry fine applies until CalPrivacy gets to them the way it got to Cybba. New Jersey got to Radaris first, by a different route: a Daniel's Law default judgment on August 27, 2026 transferred the radaris.com domain to the plaintiff (what that seizure does and doesn't do). Meanwhile a single registration can cover many storefronts: Mississippi Tornado Alley, LLC registers ten sites on one entry, including FastPeopleSearch, USPhoneBook and PeopleSearchNow, each with its own database and its own opt-out form.

What the fines don't reach

A data broker registry fine punishes a company after the fact. It does not tell you which of the roughly 600 registered brokers hold your address, your phone number or a profile inferring what you are likely to buy, and it says nothing about the companies that never registered. Cybba sold Californians' data for most of 2025 without being on the list; anyone whose behavioral profile it built during that time got no notice and has no way to find out.

The people-search layer is where this becomes concrete. In our removal work, PeopleSearchNow shows current and past addresses, age and relatives on its free preview page before asking for anything, and its opt-out runs backwards from most sites: you give it your name and email before you see your record, and the removal form arrives as an emailed link that expires after 24 hours. FastPeopleSearch runs the same name-and-email-first pattern with the same 24-hour link, and both are Tornado Alley storefronts drawing on the same records. A registry entry and a DROP account do not change what those preview pages display to a stranger tomorrow.

What to do

If a company's name is in front of you (a breach notice, a marketing email you never signed up for, a people-search listing), search the registry first. A hit tells you the broker is inside DROP and that its request metrics are public; a miss tells you a direct opt-out is your only route, and that the broker is exactly the kind CalPrivacy has been fining.

If you live in California, file one DROP request and let the 45-day cycle do its work against every registered broker at once. Then handle the unregistered ones and the people-search sites directly; our data broker opt-out guide walks through them one at a time. Listings come back when brokers re-ingest public records, so plan on checking again rather than treating any of this as finished.

Delist My Data is being built for that layer: filing removals across the people-search sites, registered or not, and re-filing when a listing regenerates. We're in pre-launch; join the waitlist for founding-member access.

Sources

Find out which brokers are publishing your details.

No spam. One email when Delist My Data opens for your area.