In the Matter of Cybba, Inc.
A practical analysis of CalPrivacy’s Cybba decision, addressing data broker registration under the Delete Act, targeted advertising and audience segmentation, and the growing importance of DROP in California’s data broker enforcement framework.
Key points: (1) Cybba failed to timely register as a data broker. Cybba operated as a data broker during 2024 but failed to register with CalPrivacy by the January 31, 2025 deadline. It registered only after the Enforcement Division contacted the company. (2) Digital advertising and audience-building activities can bring a company within California’s definition of a data broker. Cybba sold personal information—including geolocation data, internet activity data, inferences, identifiers, and commercial data—through products and services designed for digital marketing and custom audiences. (3) The Order provides a useful illustration of the data activities CalPrivacy may examine when determining whether a company is a data broker. Cybba’s services included behavioral, B2B, event, purchase, and custom audiences; look-alike and retargeting audiences; and measurement across the consumer’s path to purchase. (4) Cybba must pay a $52,400 administrative fine. The company had already paid its 2025 annual registration fee and timely registered in 2026 for its 2025 data broker activities. The Order concerns only its 2024 activities and corresponding failure to register in 2025. (5) Registration is only part of the compliance obligation. Cybba must timely register in future years in which it operates as a data broker, publish required CCPA request metrics in its privacy policy, and access CalPrivacy’s Delete Request and Opt-out Platform (DROP) to process deletion requests when required.
Background
Cybba, Inc. is a Delaware corporation with its principal place of business in Boston, Massachusetts that conducts business in California. According to the Order, Cybba sells personal information through products and services designed for integrated digital marketing of custom audiences.
The personal information sold through those services includes:
- geolocation data;
- internet activity data;
- inferences;
- identifiers; and
- commercial data.
Cybba’s services are designed to help clients identify and reach particular audiences. The Order notes that clients have described Cybba as helping to “unlock Facebook advertising,” provide “retargeting campaigns,” interpret client data, and build and segment LinkedIn campaigns.
The company provides several types of audiences for its clients, including behavioral audiences designed to reflect customer interests, B2B audiences designed to identify professionals, event audiences directed toward theater enthusiasts and ticket purchasers, purchase audiences targeting consumers with histories of purchasing within particular product categories, and custom audiences tailored to a client’s needs.
Cybba’s purchase audience category provides clients with inferences about potential customers through a service called “Action-based Segmentation.” According to the Order, the service organizes potential customers using “deterministic signals derived from their purchasing behaviors.” Cybba describes this category as useful for reconnecting with repeat customers or consumers with a high intent to purchase.
Cybba also markets social media advertising services that allow clients to target potential customers on Facebook, Instagram, LinkedIn, and YouTube. The Order specifically describes Cybba’s use of email lists and home addresses to build look-alike and retargeting audiences. The materials reproduced in the Order also describe granular targeting based on demographics, keywords, location, and behavior, as well as look-alike modeling based on users who have converted on a client’s website.
Cybba further promotes products designed to measure activity across the “full path to purchase,” covering the consumer journey from the first advertising impression through a verified transaction.
The Order also reproduces Cybba materials describing an identity framework connecting browsing data, devices, emails, media platforms, retail and point-of-sale data, and loyalty data to support attribution, audiences, and measurement.
Cybba sold Californians’ personal information through these products and services.
CalPrivacy’s position is that, under the CCPA, activities such as creating and providing behavioral, purchase, custom, look-alike, and retargeting audiences constitute a sale of personal information when they make consumers’ personal information—including identifiers, geolocation and internet activity data, commercial information, and inferences—available to third-party clients for commercial purposes.
Findings of violation
The Cybba Order is narrower than the LocateSmarter decision. It concerns only Cybba’s failure to timely register as a data broker under the Delete Act. The Order does not make a separate finding that the advertising or audience-segmentation practices described above independently violated the CCPA.
Importantly, the Order specifies that it does not release Cybba from liability for violations other than its violation of the Delete Act arising from the failure to register as a data broker between February 1 and October 20, 2025.
The Order finds that Cybba is a for-profit legal entity that:
collects consumers’ personal information;
- determines the purposes and means of processing that information; and
- annually buys, sells, or shares the personal information of 100,000 or more consumers or households.
During the 2024 calendar year, Cybba conducted business as a data broker by knowingly collecting and selling to third parties the personal information of consumers with whom the company did not have a direct relationship.
That last element is particularly important to the Order’s characterization of Cybba as a data broker. The company’s activities involved personal information about consumers with whom Cybba itself did not have a direct relationship.
Practice tip: Look beyond the label “data broker.” Businesses involved in digital advertising, audience segmentation, retargeting, identity resolution, or similar data-driven services should assess whether they knowingly collect and sell personal information about consumers with whom they do not have a direct relationship. The substance of the data activity—not simply how the company describes its business—matters when determining whether registration obligations apply.
Under the Delete Act, a business that meets the definition of a data broker must register with CalPrivacy on or before January 31 following each year in which it meets that definition.
Because Cybba conducted business as a data broker during 2024, it was required to register by January 31, 2025.
The Enforcement Division subsequently opened an investigation and contacted Cybba regarding its failure to register. Only after the Enforcement Division contacted the company did Cybba register as a data broker.
The Order also records Cybba’s subsequent compliance. Cybba timely registered with CalPrivacy in 2026 for its data broker activities during 2025. The Order therefore makes clear that the enforcement action concerns only Cybba’s 2024 data broker activities and its corresponding failure to register in 2025.
Practice tip: Calendar January 31—and do not wait for CalPrivacy to contact you. Data broker registration is an annual obligation. A business that operated as a data broker during a calendar year must register with CalPrivacy by January 31 of the following year. Registering after an enforcement inquiry does not erase the earlier failure to register.
Remedy and compliance obligations
The Order requires Cybba to pay a $52,400 administrative fine under Civil Code § 1798.99.82(c).
Cybba had already paid its 2025 annual registration fee. The administrative fine must be paid in full within 30 days of the Board’s Order of Decision.
The Order also imposes continuing compliance obligations.
Cybba must:
- timely register as a data broker in every future year in which it operates as one;
- notify CalPrivacy in writing before the registration deadline if it ceases operating as a data broker;
- disclose in its privacy policy the required metrics regarding the number of CCPA requests received, complied with, and denied during the previous calendar year, together with the time within which Cybba substantively responded to those requests;
- access DROP and process consumer deletion requests in accordance with Civil Code § 1798.99.86 during any year in which it operates as a data broker; and
- use reasonable efforts to notify the officers, directors, employees, agents, and contractors responsible for implementing the Order of its requirements.
Enforcement analysis
The Cybba decision is significant not because it announces a new substantive CCPA rule, but because it provides another concrete example of how CalPrivacy is enforcing California’s data broker registration regime.
Digital advertising companies should assess their data broker status
The factual findings devote substantial attention to how Cybba’s digital marketing products operate.
They describe behavioral audiences, B2B audiences, event audiences, purchase audiences, custom audiences, retargeting, look-alike modeling, geolocation-based advertising, purchasing-behavior signals, identity resolution, and measurement across the consumer journey.
Those descriptions provide useful context for the ultimate data broker finding: Cybba knowingly collected and sold to third parties personal information concerning consumers with whom it did not have a direct relationship.
For businesses operating in the advertising ecosystem, the practical question is therefore broader than whether the company considers itself a traditional “data broker.” Companies should examine the actual flows of personal information underlying their products and services.
Practice tip: Map the relationship as well as the data. When assessing data broker status, identify not only what personal information the company collects and sells, but also whether the consumers whose information is being sold have a direct relationship with the company. Cybba’s lack of a direct relationship with those consumers was central to the Order’s data broker finding.
Inferences are part of the data broker picture
The Order expressly identifies inferences among the categories of personal information Cybba sold.
It also provides a concrete example: Cybba’s “Action-based Segmentation” service used signals derived from purchasing behavior to organize potential customers, including consumers identified as repeat customers or as having a high intent to purchase.
The decision therefore illustrates that a data broker assessment should not focus only on conventional identifiers or raw consumer data. The information sold through an advertising or audience product may also include conclusions or predictions derived from consumer behavior.
Late registration does not eliminate the violation
Cybba eventually registered after being contacted by the Enforcement Division and subsequently registered timely for the following year.
Nevertheless, the Order imposes a $52,400 administrative fine for the earlier failure.
The Order specifies that the matter concerns Cybba’s failure to register between February 1, 2025 and October 20, 2025.
The practical lesson is straightforward: registration is deadline-driven. Correcting a missed registration after CalPrivacy initiates contact does not retroactively satisfy the January 31 obligation.
DROP is becoming part of the data broker compliance lifecycle
The remedy also extends beyond future registration.
Cybba must access CalPrivacy’s Delete Request and Opt-out Platform (DROP) and process consumer deletion requests in accordance with Civil Code § 1798.99.86 during any year in which it operates as a data broker.
CalPrivacy’s announcement describes DROP as a mechanism that allows a consumer to direct all data brokers to delete the consumer’s personal information through a single request. It also states that the annual registration fee helps fund both the Data Broker Registry and DROP.
As CalPrivacy’s head of enforcement stated in announcing the Cybba action, “Especially with the launch of DROP, businesses should take a close look at their activities.”
Practice tip: Treat registration and DROP as part of the same compliance program. Determining that a company is a data broker triggers more than an annual registration deadline. Businesses should also prepare for the operational requirements associated with DROP and the processing of consumer deletion requests.
Conclusion
In the Matter of Cybba, Inc. demonstrates that California’s data broker requirements can reach businesses operating in the digital advertising ecosystem. The critical fact was that Cybba knowingly collected and sold personal information about consumers with whom it did not have a direct relationship, making it subject to California’s data broker registration requirements.
The decision also shows that late registration does not eliminate liability: Cybba registered after CalPrivacy contacted the company but still must pay a $52,400 administrative fine. Registration is also only part of the compliance framework, which includes applicable reporting requirements and participation in DROP.
For digital advertising and audience businesses, the takeaway is clear: review your data practices, assess whether you have a direct relationship with the consumers whose information you sell, and treat registration and DROP readiness as ongoing compliance obligations.
Additional Resources
Cybba Enforcement Action
- Order of Decision and Stipulated Final Order — In the Matter of Cybba, Inc., Case No. ENF25-228-D-CY (Aug. 10, 2026). The CalPrivacy Order addressing Cybba’s failure to timely register as a data broker for its 2024 activities and imposing a $52,400 administrative fine together with continuing registration, reporting, and DROP obligations.
- CalPrivacy Announces Second Data Broker Enforcement Action in Less than a Week (Aug. 13, 2026). CalPrivacy’s newsroom announcement concerning the Cybba decision, the company’s targeted-advertising activities, and the Agency’s continuing data broker enforcement efforts.
Relevant Legal Provisions Identified in the Order
- Delete Act — Data Broker Registration, Privacy-Rights Metrics, & Delete Request and Opt-out Platform (DROP): Civil Code § 1798.99.82 (The provision underlying Cybba’s annual data broker registration obligation and the administrative fine imposed by the Order) & Civil Code § 1798.99.85 (The Order requires Cybba to disclose in its privacy policy required metrics concerning CCPA requests received, complied with, and denied, together with substantive response times.) Civil Code § 1798.99.86. (Cybba must access DROP and process consumer deletion requests through the platform during years in which it operates as a data broker.)
- CCPA Regs - Requirements for Businesses Collecting Large Amounts of Personal Information. Cal. Code Regs., tit. 11. § 7102. Establishes additional compliance requirements for businesses that process personal information at specified large-scale thresholds, including requirements relating to the compilation and disclosure of consumer-request metrics.
- California Consumer Privacy Act (CCPA) : Cal Civil Code § 1798.130. General Notice, Disclosure, Correction, and Deletion Requirements.
Related Reading from The de la Torre Review
- In the Matter of LocateSmarter, LLC — The de la Torre Review (Aug. 10, 2026). A related analysis of CalPrivacy’s enforcement action involving data broker registration under the Delete Act as well as separate CCPA violations involving data minimization and the right to opt out of sale or sharing.
