Anyone who contracts for internet or social-media-based advertising may have overlooked two recent actions by the California Privacy Protection Agency (CalPrivacy) and the proposed draft AI regulations from Colorado, but there are some important takeaways that should not be missed.
California fines data broker over $100,000 for broker and privacy law issues
California’s new data broker deletion requirements (known as the Delete Act) went into effect on August 1, 2026. On August 10, CalPrivacy announced an order against an Iowa data broker, LocateSmarter, LLC, alleging that the company violated both California’s data broker law and the California Consumer Privacy Act (CCPA). According to the order, LocateSmarter required consumers wishing to opt out of the sale or sharing of their personal data to submit not only their mailing addresses but also the last four digits of their Social Security numbers. The order found that this conduct violated CCPA because LocateSmarter:
- required consumers to provide verification information to opt out, which is contrary to CCPA;
- “unlawfully required consumers to provide more information than necessary to exercise their right to opt out of sale/sharing”; and
- “Requiring a Social Security number to submit a request to opt-out of sale/sharing could intimidate consumers from exercising their privacy rights. Any such intimidation would conflict with the CCPA’ s mandate that consumers be able to easily exercise their privacy rights.”
CalPrivacy fined the company over $30,000 for violating the Delete Act and nearly $80,000 for violating the CCPA. The order also required the company to pay the $6,000 broker registration fee.
California fines two unregistered data brokers
On August 13, CalPrivacy announced another order, this time against a Massachusetts data broker, Cybba Inc., alleging that the company failed to register as required under California’s data broker law. According to the order, in 2025, Cybba sold personal information—including geolocation data, identifiers, internet activity data, and inferences—to facilitate targeted advertising. Clients have described Cybba as helping “unlock [social media platform] advertising,” offering “retargeting campaigns,” helping “interpret our data,” and taking a “personalized approach to build and segment our [social media platform] campaign.” The order states that Cybba did not register as a data broker.
In addition to paying a $52,400 fine plus the data broker registration fee, the order requires Cybba to (1) post metrics about privacy rights on its website and (2) access CalPrivacy’s Delete Request and Opt-Out Platform (DROP) and process future consumer deletion requests through that system. On August 25, CalPrivacy reported that more than 500,000 California residents had filed such delete requests from data brokers.
On September 1, CalPrivacy announced a similar order signed on August 14 with Virginia-based data broker, SalesIntel Research Inc. (SRI). The company had been collecting consumer data since 2024, did not register as a data broker for 2025, but agreed to pay a fine of $36,400, which included the $6,600 registration fee for 2025. Like Cybba, SRI must post privacy rights metrics and access the DROP platform to process deletion requirements.
Colorado’s proposed AI regulations
As we have previously written, Colorado replaced its artificial intelligence law in May with a new AI Act that goes into effect on January 1, 2027. The new law defines “automated decision making technology” or “ADMT” as:
a technology that processes personal data and uses computation to generate output, including predictions, recommendations, classifications, rankings, scores, or other information that is used to make, guide, or assist a decision, judgment, or determination concerning an individual.
Similar to many states’ privacy laws, the new Colorado law and its proposed regulations focus on “consequential decisions,” which include decisions relating to a Colorado consumer’s education enrollment, employment, health care, insurance, financial services, and purchase or lease of residential real estate. Notably, under the new Colorado law and regulations, the definition of a Colorado consumer expressly includes employees.
If a Colorado consumer experiences an adverse consequential decision involving an ADMT that materially influenced the consequential decision., the new law gives consumers certain rights to request a response from a deployer. In those circumstances, a consumer has the right to:
- Access personal data used in the consequential decision involving the covered ADMT;
- Correct any factually incorrect or materially inaccurate personal data used in the consequential decision involving the covered ADMT;
- A meaningful human review (to the extent commercially reasonable) and reconsideration of the consequential decision.
On August 11, 2026, Colorado issued proposed regulations, with comments due on September 4, and a public hearing before the Attorney General scheduled for Monday, October 26. The proposed effective date of the regulations is the same as the new law: January 1, 2027. Under proposed Section 6.6 of the draft regulations, if a consumer requests additional information about the covered ADMT that made an adverse decision, the deployer must, under subsection B.(3), provide the following:
- The description of the sources of Personal Data considered by the covered ADMT and must identify each source by name.
- For example, specific data brokers, databases, courts, social media companies, schools, employers, and any other source of Personal Data for the covered ADMT must be identified by name.
- If the Deployer has obtained Personal Data from a third party, such as a data broker or aggregator, that obtains personal data from first-party or other third-party sources, the description shall include the original source of the information and any intermediary or vendor source(s) of the information.
Takeaways
These recent regulatory actions should prompt companies to ask several questions about their current vendor agreements, third-party due diligence program, and personal data sharing practices, especially in the context of advertising and marketing services that may implicate data broker requirements. You should ask yourself::
- Do your marketing agreements include an obligation on the vendor to comply with law, including having all necessary licenses (including data broker registrations)?
- Do your marketing agreements include an obligation for the vendor to notify you if the vendor becomes subject to a consent decree, order, complaint, or other regulatory action?
- Have you considered whether your company uses or licenses a covered ADMT and, if so, can you identify all data sources of personal data considered by a covered ADMT by name, which may be required if the Colorado AI regulations as currently drafted go into effect? Do you have a process to keep it current and make sure new data sources are not added overtime?
- Can you identify all the companies that receive personal data from you, which could have caused you to meet the definition of a “data broker”?
With respect to the last point, NT Analyzer is Norton Rose Fulbright’s proprietary, privacy forensics tool that it uses to assist clients with their mobile app/website/OTT compliance efforts and due diligence. NT Analyzer uses network traffic and runtime behaviors of your digital properties to provide precise, line-of-sight on what data is transmitted, to which third parties, and the root cause of such data transmissions.
If you would like to learn more about NT Analyzer, please contact:
Steven Roosa steven.roosa@nortonrosefulbright.com
Wenda Tang wenda.tang@nortonrosefulbright.com
Recent Comments