California has started enforcing one of the country's most ambitious data broker laws, and the early results are already showing where the industry is falling short. The state's Privacy Protection Agency has issued enforcement orders against data brokers that failed to register under the Delete Act, and one case in particular, involving a company called LocateSmarter, has pulled back the curtain on how registration failures can mask deeper problems with how consumers' opt-out and deletion requests are handled.
This wave of California data broker enforcement matters well beyond state lines. California often sets the tone for privacy regulation nationally, and how the CPPA handles these early cases will likely shape how data brokers behave in every state, not just the ones with their own privacy laws.
What California's Delete Act Requires of Data Brokers
The Delete Act was built around a simple idea: if a company buys, sells, or licenses personal information about Californians without a direct relationship with those individuals, it counts as a data broker and needs to register with the state. Registration isn't just paperwork. It's the foundation that lets consumers find out which companies hold their data in the first place, and it feeds into the broader deletion and opt-out infrastructure the law created.
According to the CPPA's enforcement actions, some data brokers simply didn't register at all, ignoring a core obligation of the law. That failure alone is enough to trigger enforcement, but as the LocateSmarter case shows, a registration violation can be the tip of the iceberg. Once regulators start looking at a company's registration status, they often find related compliance gaps in how that company actually handles consumer requests to opt out of data sales or delete their information entirely.
How the LocateSmarter Case Exposed Opt-Out Compliance Gaps
The LocateSmarter decision is notable because it goes beyond a simple "you didn't register" violation. The CPPA's review found that the company was requiring consumers to hand over excessive personal information just to submit an opt-out or deletion request. That's a significant problem: if a data broker demands more information than necessary to process a privacy request, it creates a barrier that discourages people from exercising rights the law is supposed to guarantee them.
This is the kind of friction that regulators are increasingly focused on. A data broker technically offering an opt-out mechanism isn't enough if that mechanism is designed, intentionally or not, to make the process harder than it should be. The LocateSmarter case signals that California regulators are willing to scrutinize not just whether a company registered, but how usable and good-faith its privacy tools actually are in practice.
What This Means for Your Data Deletion Rights Today
For consumers, this enforcement wave is a reminder that data broker compliance isn't automatic, and it isn't something you should simply assume is happening in the background. Companies that buy and sell personal data have had clear registration and opt-out obligations under the Delete Act, yet regulators are still finding brokers that either ignored the rules entirely or built opt-out processes that quietly discourage people from using them.
If you've submitted a deletion or opt-out request to a data broker and found the process confusing, overly demanding, or unresponsive, you're not imagining things. These are exactly the kinds of practices California regulators are now targeting. It's worth checking whether a company you've dealt with is registered as a data broker in California, and if a request feels excessive or obstructive, that friction itself may be a compliance red flag worth reporting.
How State-Level Privacy Enforcement Is Expanding Beyond California
California isn't alone in cracking down on companies that treat consumer data as a resource to monetize without meaningful transparency or consent. State attorneys general elsewhere have taken similar aim at companies accused of collecting or using personal data covertly. Texas, for example, has gone after major platforms over undisclosed data practices, including a lawsuit in which the Texas AG sued Netflix over secret user data collection, accusing the company of gathering and monetizing subscriber information without proper consent.
Taken together, these cases point to a broader trend: state regulators are no longer treating data broker registration and disclosure rules as a formality. They're actively testing whether companies' opt-out mechanisms, data collection practices, and consent processes hold up to scrutiny, and they're willing to bring enforcement actions when they don't.
Key Takeaways
California's Delete Act enforcement is still in its early stages, but the LocateSmarter case already shows that registration violations often uncover deeper opt-out and deletion problems. If you want to protect your own data, don't wait for regulators to catch every bad actor. Check whether companies handling your information are properly registered, exercise your opt-out and deletion rights directly, and push back if a company asks for more personal information than seems necessary just to process your request. As California data broker enforcement expands and other states follow with their own actions, staying proactive about your privacy rights remains the most reliable way to keep your personal data out of hands you never agreed to share it with.




