SB 361 California Data Broker Fine: What the $200-a-Day Penalty Covers, and Where It Really Came From

California's data broker fines are the ones everyone quotes, and most of the pages explaining them get the history wrong. Search for the SB 361 California data broker fine and you'll find vendor blogs saying SB 361 doubled the registration penalty from $100 to $200 a day and invented a second fine for ignored deletion requests. Both fines are real, and both are $200 a day. They were written in 2023 by the Delete Act, and CalPrivacy was already collecting at that rate a year before SB 361 took effect. What SB 361 changed is narrower, and it still matters if you're trying to get delisted, because it's the version of the statute the current enforcement wave runs on.

What SB 361 actually changed

Governor Gavin Newsom signed SB 361, "Data brokers: data collection and deletion," on October 8, 2025. It is Chapter 466 of the Statutes of 2025 and took effect January 1, 2026. The bill text is worth reading against the law it amends. The Legislative Counsel's Digest says the bill "would make changes to the administrative fines and costs that apply to data brokers who fail to register." No new amounts. We put the 2023 and 2025 versions of Civil Code section 1798.99.82 side by side, and the only edit in the penalty subdivision is one clause. The 2023 text let the agency recover its investigation expenses "as the court deems appropriate." SB 361 swapped that for a flat entitlement to "reasonable expenses incurred by the California Privacy Protection Agency in the investigation and administration of the action." Every $200 figure survived untouched.

The parts of SB 361 that are genuinely new sit elsewhere in the statute. One is a deadline: a broker that denies a DROP deletion request has to process it as an opt-out of sale within 45 days of receiving it, and that 45-day clock on denials is SB 361's. The rest is disclosure.

SB 361 registration disclosures: what brokers file, and what CalPrivacy may not publish

Section 1798.99.82(b)(2) lists everything a registration has to contain. SB 361 added most of the list, and a companion edit to section 1798.99.84 tells the agency which answers to keep off the public registry. We checked that against the registry CSV on September 15, 2026: 77 columns, 603 broker rows, a column for every sharing and sensitive-category answer, and no column at all for the three withheld items.

Disclosure Subparagraph New in SB 361 Published on the registry
Name, addresses, prior-year request metrics, whether it collects minors' data, precise geolocation or reproductive health data (A), (B), (C), (M), (N) No Yes
Collects names, dates of birth, ZIP codes, email addresses or phone numbers (D) Yes No, withheld under 1798.99.84(b)
Collects account logins or numbers together with the code or password (E) Yes Yes
Collects government ID numbers (driver's license, Social Security, passport, tax ID, military ID) (F) Yes Yes
Collects mobile advertising IDs, connected TV IDs or VINs (G) Yes No, withheld under 1798.99.84(b)
Collects citizenship or immigration status, union membership, sexual orientation, gender identity, or biometric data (H) to (L) Yes Yes
Sold or shared data in the past year with a foreign actor, the federal government, another state, law enforcement (outside a subpoena or court order), or a generative AI developer (O) to (S) Yes Yes
One to three most common data types collected, if it collects none of (D) or (G) (T) Yes No, withheld under 1798.99.84(b)
Audit status (from 2029), a privacy-rights page without dark patterns, FCRA/GLBA/IIPPA/medical-privacy status (U), (V), (W) No Yes

The "New in SB 361" column follows the Legislative Counsel's Digest, which names the additions. The practical effect of the withholding is that the public registry cannot tell you whether a given people-search site holds your phone number or email address. The site's own search page still can, which is why our opt-out guides start there.

Where the $100 to $200 story comes from

The $100 was real. AB 1202, the 2019 law that created the registry under the Attorney General, set a civil penalty of $100 for each day a broker failed to register. SB 362, the Delete Act (Chapter 709, signed October 10, 2023), moved the registry to CalPrivacy, doubled that to $200, and wrote in the per-request deletion fine at the same time. The agency was charging the doubled rate well before SB 361 existed. In May 2025 it proposed a $46,000 fine against National Public Data for registering 230 days late, which is 230 days at $200. The doubling happened in 2023. A run of SB 361 summaries has been retelling it as a 2025 event.

How much is the California data broker fine under the Delete Act

The current section 1798.99.82 sets two fines. A broker that fails to register owes "$200 for each day the data broker fails to register," plus the registration fees it skipped, plus the agency's reasonable expenses. A broker that fails to act on deletion requests owes "$200 for each deletion request for each day the data broker fails to delete information," plus expenses again. Since August 1, 2026, every registered broker has had to check DROP at least once every 45 days and act on whatever is waiting. DROP is the Delete Request and Opt-Out Platform the California Privacy Protection Agency, now branded CalPrivacy, runs under the Delete Act.

One correction to a common misreading, including in some vendor summaries: the registration fine is a flat $200 a day per broker. It is the deletion fine that multiplies by the number of consumers involved. A broker can be fully registered and current on its paperwork and still be accruing fines because requests are sitting untouched.

There is a third way to run up a data broker registry penalty. On September 3, CalPrivacy issued Enforcement Advisory 2026-01, which reads the registration clause to cover accuracy: filing wrong information "violates the law, triggering a $200 fine for each day the incorrect information appears in the registry." A data broker registry violation, in the agency's view, includes a registration that is on file but wrong.

How the SB 361 California data broker fine adds up

Take a broker sitting on 500 unprocessed deletion requests, a modest backlog for a company that trades in bulk consumer data. At $200 per request per day, that is $100,000 a day in exposure. Leave it for 30 days, well inside a single 45-day DROP cycle, and the broker is looking at $3 million, before registration fees or investigative costs are added.

Run the numbers on a smaller broker and the math still stings. A backlog of 50 unresolved requests ignored for two weeks is $10,000 a day, or $140,000. A flat, one-time fine is a cost a company can budget around. A per-request, per-day fine grows every day the backlog exists, so the cheapest move for a broker is almost always to clear the queue.

Back fees and CalPrivacy's costs stack on top

The fines are not the whole bill. A broker found in violation also owes every registration fee it skipped during any unregistered period (the fee is $6,000 a year), plus CalPrivacy's "reasonable expenses for investigation and administration" of the case, the clause SB 361 tightened. So the $200-a-day figures are the starting line. A broker that strings together an unregistered period, a deletion backlog and an active investigation is stacking three categories of liability. Everything recovered goes into the Data Brokers' Registry Fund, which the statute says is meant to fully offset the agency's and the courts' costs.

Data broker registry fee and fine schedule

Item Amount Where it is set Since
Annual registration fee $6,000 for the 2026 cycle, plus a card-processing charge 1798.99.82(b)(1), set by CalPrivacy up to the cost of the registry and DROP $6,600 for the 2025 cycle, per the December 23, 2024 release
Failure to register $200 for each day unregistered 1798.99.82(c)(1) January 1, 2024 ($100 under AB 1202 from 2020)
Back fees Every fee that fell due while unregistered 1798.99.82(c)(2) January 1, 2024
Agency expenses "Reasonable expenses" of investigating and administering the action 1798.99.82(c)(3) and (d)(2) Flat entitlement since January 1, 2026 (SB 361)
Failure to delete $200 for each deletion request for each day 1798.99.82(d)(1) Enforceable since August 1, 2026
Incorrect registration information $200 for each day the wrong entry sits in the registry Advisory 2026-01's reading of (c)(1) September 3, 2026
Where the money goes Data Brokers' Registry Fund 1798.99.82(e) and 1798.99.81 Administered by CalPrivacy since 2024

The fee moves because the agency sets it, and it dropped $600 between the 2025 and 2026 cycles. The two $200 rates have no ceiling. The only cap in the title is the five-year limit on how far back a case can reach.

Data broker penalties 2026: who has paid a California data broker fine so far

Two brokers were fined within two weeks of the August 1 processing deadline, and a third on September 1. All three were registration failures rather than ignored DROP requests. LocateSmarter LLC, $116,490 on August 11 is an Iowa broker that missed the January 31, 2026 deadline, and its stipulated order also carries a $79,890 CCPA fine for demanding the last four digits of a Social Security number and a mailing address before it would process an opt-out, which CalPrivacy calls its first case combining the two laws. Cybba, Inc., $52,400 on August 13 is a Boston ad-tech broker that never registered by the 2025 deadline. SalesIntel Research, Inc., $36,400 on September 1 is a Virginia broker selling more than 200 million professional contacts, again for late registration.

Every CalPrivacy data broker enforcement action to date

The three summer cases sit at the end of a run that started with an investigative sweep announced October 30, 2024. The last column is the fine divided by $200. Where a release gives the unregistered window it matches to the day, with one exception.

Announced Company Amount Basis Days at $200
Nov 14, 2024 Growbots, Inc. $35,400 Unregistered Feb 1 to Jul 26, 2024 177
Nov 14, 2024 UpLead LLC $34,400 Unregistered Feb 1 to Jul 21, 2024 172
Dec 23, 2024 PayDae, Inc. (Infillion) $54,200 Unregistered Feb 1 to Nov 4, 2024 271
Dec 23, 2024 The Data Group, LLC $46,600 Unregistered Feb 1 to Sep 20, 2024 233
Jan 29, 2025 Key Marketing Advantage, LLC $55,800 Unregistered Feb 1 to Nov 5, 2024 279
Feb 27, 2025 Background Alert, Inc. Shut down through 2028, or $50,000 if it breaches Unregistered Feb 1 to Oct 8, 2024 n/a
May 8, 2025 National Public Data $46,000 Registered 230 days late, order entered by default 230
Jul 29, 2025 Accurate Append, Inc. $55,400 Missed the Jan 31, 2024 deadline 277
Nov 19, 2025 Data Broker Enforcement Strike Force none Dedicated unit inside the Enforcement Division n/a
Dec 3, 2025 ROR Partners LLC $56,600 in fines and past-due fees Sold custom audiences in 2024 unregistered Not split
Dec 17, 2025 Enforcement Advisory 2025-01 none Trade names and subsidiaries must be registered n/a
Jan 8, 2026 Rickenbacher Data LLC (Datamasters) $45,000, plus an order to stop selling Californians' data Resold health-condition and ethnicity lists unregistered 225
Jan 8, 2026 S&P Global, Inc. $62,600 Unregistered, called an administrative error 313
Aug 11, 2026 LocateSmarter LLC $116,490 Delete Act $30,600, CCPA opt-out gate $79,890, fee $6,000 153
Aug 13, 2026 Cybba, Inc. $52,400 Missed the 2025 deadline 262
Sep 1, 2026 SalesIntel Research, Inc. $36,400 Missed the 2025 deadline 182
Sep 3, 2026 Enforcement Advisory 2026-01 none Wrong registration data accrues the daily fine n/a

Fourteen companies, thirteen dollar amounts, $697,290 in fines and fees over 22 months, and every case includes a registration failure. The exception in the arithmetic is Infillion, where the release's window runs 278 days and the fine is 271 days' worth. The "more than a dozen" in the agency's releases is these fourteen names, and the releases place only one of them, Background Alert, in California.

What a broker actually pays: the 2026 cases worked

Every CalPrivacy fine divides evenly by $200, so each order can be rebuilt from the statute. The clock starts February 1, the day after the deadline, and runs until the broker files.

Case Days unregistered Times $200 Fee owed Added Total
LocateSmarter (Aug 11, 2026) 153 $30,600 $6,000 $79,890 CCPA fine $116,490
Cybba (Aug 13, 2026) 262 $52,400 None stated None $52,400
SalesIntel (Sep 1, 2026) 182 $36,400 None stated None $36,400

The January orders follow the same pattern (Datamasters 225 days, S&P Global 313), and every 2026 order adds non-monetary terms: publish request metrics, work DROP, and in Datamasters' case stop selling Californians' data at all. The same arithmetic prices a deletion backlog. Under subdivision (d), Cybba's 262 days with a single unprocessed DROP request would have cost the same $52,400, and a second request doubles it.

Each order also requires the company to post privacy-request metrics on its own site and to process future deletion requests through DROP. Cybba is on the list now. When we pulled the registry CSV on September 1, 2026, its entry reported 933,375 deletion requests received in 2024 with 117 denied, which gives some sense of the volume an ad-tech broker handles once it is inside the system it was fined for avoiding.

So no SB 361 California data broker fine to date has been a deletion fine. Every Delete Act fine published so far is for registration, and the one CCPA fine is for an opt-out flow. The per-request clause only became enforceable on August 1 and has not produced a published order yet. The agency said on August 25 that more than 500,000 Californians had signed up for DROP, that 654 brokers were in the system, and that roughly a quarter of them had reported processing deletion requests. The other three quarters are where the next round of penalties is likely to come from.

Why the deletion fine is the one that matters

Getting a broker's name on a list does not protect anyone's data. Getting that broker to act on deletion requests does. The registration fine has been on the books in some form since 2020 and brokers kept missing the deadline anyway. The deletion fine is priced per person, runs per day, and can hit a broker whose paperwork is spotless. SB 361 did not create it, but SB 361 is the statute in force on the day it became enforceable, which is how the bill number ended up attached to it.

Frequently asked questions about the California data broker fine

Who enforces the SB 361 California data broker fine

CalPrivacy's Enforcement Division, before the agency's own Board. Section 1798.99.82 makes both fines recoverable "in an administrative action brought by the California Privacy Protection Agency," so no court is involved unless a broker contests the order. The Attorney General ran the registry from 2020 through 2023. The December 2025 and January 2026 orders came from the Data Broker Enforcement Strike Force the division created on November 19, 2025.

Is there a cure period before the $200-a-day fine starts

No. Title 1.81.48 has no cure clause. Accurate Append registered only after the Enforcement Division contacted it and still paid $55,400, and National Public Data was ordered to pay for all 230 days on the same facts. The 30-day notice-and-cure window in section 1798.150 belongs to the CCPA's private data-breach action and does not carry over. The one time limit runs the other way: under 1798.99.89 the agency has five years from the violation to bring a case.

Can consumers sue a data broker under the Delete Act

Not under this title, which gives the enforcement power to CalPrivacy and nobody else. The CCPA's private right of action in section 1798.150 covers a data breach caused by a failure to keep reasonable security, which does not describe a broker ignoring a request. What you can do is file a complaint with the agency, the route its December 17, 2025 advisory release points consumers to for reporting an unregistered broker.

Does the fine money go to the people whose data was sold

No. Section 1798.99.82(e) sends every penalty, fine, fee and expense recovered into the Data Brokers' Registry Fund, and section 1798.99.81 limits that fund to running the registry website, running DROP, and covering the courts' and the agency's enforcement costs. A consumer whose request was ignored gets the deletion, if the order compels it, and nothing else.

What counts as a data broker under California law

Section 1798.99.80(c) defines one as "a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship," with four carve-outs: an entity to the extent it is covered by the Fair Credit Reporting Act, Gramm-Leach-Bliley, California's Insurance Information and Privacy Protection Act, or the medical-privacy exemption in section 1798.146. Because the carve-outs run "to the extent," a credit bureau's non-FCRA products can still qualify. The ROR Partners decision says "a sale is a sale" even when the data is bundled into an audience segment, and Background Alert was pursued for selling inferences drawn from public records.

When is the data broker registration window, and when does the clock start

Registration is due "on or before January 31 following each year in which a business meets the definition." The agency's portal takes filings from January 1 to 31, per its December 23, 2024 release. Every release that gives an unregistered window starts it on February 1, so a company that brokered data in 2025 and registers on March 15, 2026 owes 43 days, or $8,600, plus the $6,000 fee it paid late.

What it means if you're trying to get delisted

None of this changes the mechanics on your end. You still have to find the broker, still have to submit the request, and brokers still relist people who assume the job is done after one filing. What changes is the calculus on the broker's side. A registered broker deciding whether to process your request is now weighing an SB 361 California data broker fine that grows daily, a possible back-fee bill and the chance that CalPrivacy is already reading its DROP queue.

Two limits are worth knowing. The fine only reaches registered brokers: when we compared our own opt-out targets against the September 1 registry, Radaris and National Public Data had no entry, so no DROP request ever reaches them and no Delete Act deletion fine applies. (Radaris has since lost radaris.com to a New Jersey court order under Daniel's Law, but that protects only the officers in the case.) And the registry's metrics are self-reported. Mississippi Tornado Alley, LLC, which registers ten people-search sites on one entry (FastPeopleSearch, USPhoneBook, CyberBackgroundChecks and seven more, each with its own opt-out form), reports zero deletion requests received in 2024 across all of them, against 1,204,017 opt-out requests. Whitepages reports 5,879 deletion requests for the same year, 182 of them denied. Read the numbers as filings, not as audits.

One more bill is in the queue. SB 923, the Expanding Privacy Rights Act, passed the Legislature on August 28 and would widen the CCPA deletion right to data collected from third parties. As of September 14, 2026 it is with the Governor and unsigned, so nothing in it applies yet.

Delist My Data is still pre-launch. We're building the tooling to track requests like these across the registered brokers and the ones that never registered, so a request doesn't disappear into a queue nobody checks. If that's useful to you, join the waitlist for founding-member access.

Sources

Sources

Find out which brokers are publishing your details.

No spam. One email when Delist My Data opens for your area.