In the Matter of LocateSmarter, LLC
A practical analysis of CalPrivacy’s LocateSmarter decision, addressing data broker registration, the CCPA’s data minimization principle, and why businesses cannot require consumers to provide sensitive personal information to exercise the right to opt out of sale or sharing.
Key points: (1) LocateSmarter violated both the Delete Act and the CCPA. The company operated as a data broker during 2025 but failed to register with the California Privacy Protection Agency by the January 31, 2026 deadline. (2) Businesses cannot require consumers to verify their identity to opt out of sale or sharing. Unlike requests to know, delete, or correct, an opt-out request is not a verifiable consumer request. (3) Data minimization applies to consumer-rights request forms. A business may collect only the information necessary to process an opt-out request and, where it can comply without collecting additional information, it must do so. (4) Requiring part of a Social Security number to opt out violated the CCPA. LocateSmarter required consumers to provide their full name, mailing address, and the last four digits of their Social Security number. The Agency concluded that this required consumers to provide more information than necessary and effectively forced them to verify themselves with sensitive personal information. (5) The Order imposes $110,490 in administrative fines, plus a $6,000 data broker registration fee. LocateSmarter must also change its opt-out procedures, register as a data broker, participate in DROP when required, provide updated CCPA training, and comply with additional reporting and consumer-request requirements.
Background
LocateSmarter, LLC is an Iowa limited liability company based in Cedar Falls, Iowa that conducts business in California. According to the Order, the company provides “data solutions and analytics for clients in a variety of industries, with a focus on location and contact services, fraud identification and detection, and compliance products.”
LocateSmarter obtains personal information for these services from third-party sources, including data licensors, data analytics providers, data brokers, and other data suppliers that sell or license consumer personal information to the company.
LocateSmarter then sells consumers’ personal information to third parties through several types of products, including:
- batch data;
- Application Programming Interface (API) data;
- an online search platform; and
- data licensing products.
The personal information sold through these products includes names, dates of birth, Social Security numbers, physical addresses, telephone numbers, email addresses, business and employment information, driver’s license information, bankruptcy and litigation information, and information concerning military and deceased status.
For example, LocateSmarter’s “batch skip tracing products” provide clients access to information including Social Security numbers, phone numbers, email addresses, and physical addresses.
The company also provides inferences about consumers. Its “WebRecon Litigious Scrub” feature, for example, discloses an inference about whether a consumer is “litigious”—meaning whether that individual has filed lawsuits in the past.
By knowingly collecting and selling consumers’ personal information to third parties outside a direct relationship with those consumers, the Agency found that LocateSmarter operated as a data broker during the 2025 calendar year.
Findings of violation
The Order identifies two distinct sets of violations: (1) LocateSmarter’s failure to register timely as a data broker under the Delete Act and (2) its collection of unnecessary personal information from consumers seeking to exercise their CCPA right to opt out of sale or sharing.
(1) Failure to register as a data broker
Under the Delete Act, a business that meets the definition of a data broker must register with the California Privacy Protection Agency on or before January 31 following each year in which it operated as a data broker.
LocateSmarter conducted business as a data broker during 2025.
It therefore was required to register with the Agency by January 31, 2026.
LocateSmarter failed to do so.
The Order accordingly finds that LocateSmarter violated its data broker registration obligations under Civil Code § 1798.99.82.
Practice tip: Data broker registration is an annual obligation: Calendar the January 31 deadline. A business that operated as a data broker during a calendar year must register with CalPrivacy by January 31 of the following year. Failure to register timely is itself a violation of the Delete Act.
(2) Collection of Unnecessary Personal Information from Consumers Seeking to Exercise their CCPA right to opt out of sale or sharing.
Practice tip: Data brokers may also be CCPA “businesses”: Do not treat Delete Act compliance as a substitute for CCPA compliance. A company that qualifies as a California data broker may simultaneously qualify as a “business” under the CCPA. LocateSmarter was subject to both regimes because it operated as a data broker and independently satisfied the CCPA’s definition of a business. Data brokers should therefore assess their obligations under both laws, including whether their consumer-request procedures comply with the CCPA and its implementing regulations.
Businesses that sell or share personal information must provide consumers notice of their right to opt out of sale or sharing. When that notice is provided online, the business must provide an interactive form through which consumers can submit an online opt-out request.
But the rules for an opt-out request differ from those governing certain other CCPA rights.
A business may require a verifiable consumer request when a consumer exercises the right to delete, know, or correct. It may not require a verifiable consumer request to exercise the right to opt out of sale or sharing.
Practice tip: Match verification to the CCPA right: Do not use the same verification process for every consumer request. Requests to know, delete, and correct may require verification, but requests to opt out of sale or sharing may not. Design each consumer-rights workflow according to the verification requirements that apply to that specific right.
The Order explains why: the potential harm resulting from an imposter submitting an opt-out request is “minimal or nonexistent.”
In 2025, LocateSmarter provided consumers with an online form for submitting requests to opt out of sale or sharing. That form required consumers to provide:
- their full name;
- the last four digits of their Social Security number; and
- their mailing address.
In effect, the company required consumers to verify themselves using sensitive personal information even though the CCPA prohibits businesses from requiring verification for an opt-out request.
The Agency placed particular emphasis on the Social Security number requirement. A Social Security number, the Order explains, is “among the most sensitive personal information about a consumer” and can pose significant harm if accessed without authorization.
It was also more information than was minimally necessary to process an opt-out request.
Even if LocateSmarter needed additional information to complete a particular request, the Agency found that the company possessed other, non-sensitive data points that could have been used instead of a Social Security number.
Practice tip: Do not require sensitive information to opt out: Do not use sensitive personal information to verify an opt-out request. The CCPA prohibits requiring verification for requests to opt out of sale or sharing. If additional information is necessary to process a request, businesses should use non-sensitive data points and collect no more information than necessary.
The decision is particularly significant for its application of the CCPA’s data minimization principle to consumer privacy requests.
Civil Code § 1798.100(c) prohibits businesses from collecting personal information beyond what is “reasonably necessary and proportionate” to accomplish the purpose for which it is collected.
The Order explains that determining what is reasonably necessary and proportionate requires consideration of:
- the minimum personal information necessary to achieve the purpose of collection;
- the possible negative impacts to consumers arising from the collection; and
- the existence of additional safeguards capable of addressing those negative impacts.
Practice tip: Apply data minimization to privacy request forms: Consumer-rights workflows are themselves subject to the CCPA’s data minimization requirements. When designing an opt-out or other privacy request form, collect only the personal information that is reasonably necessary and proportionate to process the request, considering the minimum information needed, potential consumer harms, and available safeguards.
The Agency also considered the practical consequences of requiring consumers to disclose Social Security information before exercising a privacy right. The Order states that requiring a Social Security number to submit an opt-out request could intimidate consumers from exercising their privacy rights, which would conflict with the CCPA’s requirement that consumers be able to exercise those rights easily.
The Agency observed that only “a mere handful” of California’s population of nearly 40 million consumers submitted opt-out requests to LocateSmarter.
Based on the company’s requirement that consumers submit a partial Social Security number together with their full name and mailing address, the Agency found violations of Civil Code § 1798.100(c) and California Code of Regulations, title 11, §§ 7002(d) and 7026(d).
Remedy and compliance obligations
In total, the Order imposes $110,490 in administrative fines—$30,600 under the Delete Act and $79,890 under the CCPA—in addition to the $6,000 annual data broker registration fee.
LocateSmarter admitted the truth of the factual findings, agreed that the terms of the Order are fair, adequate, reasonable, and in the public interest, and waived its rights to hearings, reconsideration, appeal, and other review.
Delete Act obligations
LocateSmarter must:
- pay a $30,600 administrative fine under Civil Code § 1798.99.82(c) within 30 days of the Board’s Order of Decision;
- pay the $6,000 annual data broker registration fee and submit its registration within 14 days to effectuate its 2026 registration for its 2025 data broker activity;
- timely register in every future year in which it operates as a data broker;
- notify the Agency in writing before the registration deadline if it ceases operating as a data broker;
- disclose in its privacy policy the required metrics concerning CCPA requests received, complied with, and denied during the previous calendar year, as well as its substantive response times; and
- access DROP and process consumer deletion requests as required by Civil Code § 1798.99.86 during any year in which it operates as a data broker.
CCPA obligations
LocateSmarter must separately pay a $79,890 administrative fine under Civil Code § 1798.199.55 within 30 days.
It must also modify its procedures for requests to opt out of sale or sharing so that:
- consumers have methods to exercise the right that are easy and require minimal steps;
- the company does not request more information than necessary to complete an opt-out request;
- consumers are not required to submit verifiable consumer requests to opt out;
- consumers are never required to provide any portion of their Social Security number to exercise the right; and
- when a consumer submits an opt-out request, LocateSmarter must honor the request to the extent it is able to do so within the period required by the CCPA.
LocateSmarter must complete these changes within 60 days and confirm its compliance to the Enforcement Division in writing.
The company must also ensure that personnel responsible for handling CCPA requests understand the CCPA and implementing regulations applicable to their responsibilities. Within 60 days, it must confirm that updated CCPA training has been provided to all personnel handling CCPA requests.
Conclusion
In the Matter of LocateSmarter, LLC illustrates how California’s privacy requirements operate as an interconnected compliance framework rather than a series of isolated obligations. A company that qualifies as a data broker must comply with the Delete Act’s registration and DROP requirements, but data broker status does not displace the broader obligations that apply when the company also qualifies as a business under the CCPA.
The decision is particularly instructive for the design of consumer-rights workflows. Data minimization applies to compliance itself: information collected to process a privacy request must still be reasonably necessary and proportionate. Businesses also must distinguish among CCPA rights rather than applying a single verification process to every request. While requests to know, delete, and correct may require verification, requests to opt out of sale or sharing may not.
The right to opt out does not require verification. At most, a business may request information necessary to complete the opt-out request. And where a business can comply with an opt-out request without obtaining additional information, it must do so.
See Code Regs., tit. 11, §§ 7022(a), 7023(a), 7024(a)-(b), and 7026(d)
LocateSmarter’s use of a partial Social Security number demonstrates the risks of getting that distinction wrong. The Agency emphasized both the sensitivity of Social Security numbers and the availability of less sensitive alternatives, concluding that requiring this information could intimidate consumers from exercising their rights.
The broader compliance lesson is straightforward: registration, DROP participation, data minimization, and consumer-request design should be assessed together. Businesses subject to California privacy law should examine not only whether they provide mechanisms for exercising privacy rights, but also whether those mechanisms themselves comply with the CCPA.
Additional Resources
LocateSmarter Enforcement Action
- Order of Decision and Stipulated Final Order — In the Matter of LocateSmarter, LLC, Case No. ENF26-05-D-LO (Aug. 10, 2026). The CalPrivacy Order addressing LocateSmarter’s failure to register timely as a data broker and its CCPA violations involving data minimization and opt-out requests.
- CalPrivacy Brings First Action Against a Data Broker Under Both the CCPA and the Delete Act. (Aug. 11, 2026). CalPrivacy newsroom announcement discussing the LocateSmarter enforcement action and its significance as the Agency’s first action against a data broker under the CCPA and its first enforcement action arising under both the CCPA and Delete Act.
Regulations
- California Consumer Privacy Act (CCPA) — Cal. Civ. Code §§ 1798.100–1798.199.100. Relevant provisions include the CCPA’s data minimization requirements and consumers’ right to opt out of the sale or sharing of personal information.
- Delete Act data broker registration requirements — Cal. Civ. Code §§ 1798.99.80 et seq. See particularly § 1798.99.82 for data broker registration requirements and § 1798.99.86 for obligations relating to the Delete Request and Opt-out Platform (DROP).
- CCPA Regulations governing data minimization and opt-out requests — Cal. Code Regs., tit. 11. See particularly § 7002 (restrictions on the collection and use of personal information) and § 7026 (requests to opt out of sale/sharing).
CalPrivacy Enforcement Advisories and Announcements
- Applying Data Minimization To Consumer Requests, CalPrivacy Enforcement Advisory addressing the application of the CCPA’s data minimization principle when businesses collect personal information to process consumer requests.
- CalPrivacy Launches Data Broker Enforcement Strike Force (Nov. 19, 2025). CalPrivacy announcement concerning its dedicated enforcement initiative focused on compliance with California’s data broker requirements.
Related Reading from The de la Torre Review:
- The Delete Act: California’s New Framework for Data Broker Accountability The de la Torre Review (June 27, 2026). An overview of California’s Delete Act, the state’s data broker regulatory framework, registration requirements, and the role of DROP.
