Court Rules
All enforcement actions
Enforcement ActionLow RiskMultistate

State Agencies Target Businesses for Ignoring GPC Signals

Multiple businessesSeptember 9, 2025California Privacy Protection Agency

Summary

The California Privacy Protection Agency, together with the Attorneys General of California, Colorado, and Connecticut, announced an investigative sweep targeting businesses that fail to honor Global Privacy Control (GPC) signals, which automatically communicate consumers' opt-out requests. The coalition is contacting identified businesses and demanding immediate compliance with state privacy laws. This coordinated effort highlights the states' commitment to enforcing consumers' right to opt-out of the sale of their personal information.

Remedy

Businesses identified as non-compliant must immediately begin honoring GPC signals and processing opt-out requests as required by state privacy laws.

Corrective Notice

Contract Impact

In-house legal teams should review vendor, customer, and data processing agreements for clauses related to data sharing, consent mechanisms, and consumer rights requests. Specifically, examine provisions governing the 'sale' or 'sharing' of personal information, processes for honoring opt-out requests (including those communicated via automated signals like GPC), and requirements to update privacy policies. Contracts may need amendments to explicitly obligate the business to recognize and comply with GPC signals as a valid method for exercising opt-out rights under applicable state laws (CCPA, CPA, CTDPA). Teams should also assess breach notification and data retention clauses to ensure alignment with the broader privacy compliance framework enforced by this sweep.

Contract Search Terms

Global Privacy ControlGPC signalopt-out mechanismdo not sell requestdata sharing agreementprivacy preference signalbrowser setting complianceautomated signal processingconsumer right to opt-outstate privacy law compliance

Laws Cited

California Consumer Privacy Act (CCPA)Cal. Civ. Code 1798.100 et seq.

Violation Types

Entity Details

Entity

Multiple businesses

Also known as: Multiple Businesses

Industry

Other

Multistate Coalition

Official Sources

Related Enforcement Actions

CPPA

Data brokers (unspecified - advisory applies to all businesses registered with California's data broker registry)

CalPrivacy (the California Privacy Protection Agency) issued Enforcement Advisory 2026-01 warning data brokers that providing incorrect information in their annual registration with California's data broker registry carries liability of a $200 fine per day. The advisory observes that the Enforcement Division has already brought multiple enforcement actions over reporting errors, and emphasizes that accurate registry disclosures are what make the newly launched Delete Request and Opt-Out Platform (DROP) work for Californians. No specific company was named and no penalty was imposed by the advisory itself; it functions as forward-looking guidance.

CPPA

SalesIntel Research, Inc.

$36K

The California Privacy Protection Agency Board issued a Decision and Final Stipulated Order requiring Virginia-based data broker SalesIntel Research, Inc. to pay a $36,400 fine for operating as a data broker without registering by the 2025 deadline under the Delete Act. SalesIntel sells consumer personal information, including more than 200 million professional contacts and de-anonymized website traffic data, for targeted advertising. In addition to the fine, the company must post privacy rights metrics on its website, integrate with CalPrivacy's Delete Request and Opt-out Platform (DROP), and process future deletion requests through that system.

CPPA

Data brokers registered on California's DROP platform (654)

The California Privacy Protection Agency announced that more than 500,000 Californians have registered for the Delete Request and Opt-out Platform (DROP) since its January 1, 2026 launch. After the August 1, 2026 deadline for brokers to begin processing requests, 654 data brokers are in the system and approximately 25% have reported processing deletion requests, with tens of millions of records already deleted. No enforcement action has been announced yet; the agency warned that brokers who fail to delete eligible personal information face significant fines.

CPPA

Cybba, Inc.

$52K

The California Privacy Protection Agency Board issued an Order of Decision and Stipulated Final Order requiring Boston-based data broker Cybba, Inc. to pay a $52,400 fine for failing to register with the Agency's Data Broker Registry by the 2025 deadline, as required by the Delete Act. The order also requires Cybba to post metrics about privacy rights on its website, access the Agency's Delete Request and Opt-Out Platform (DROP), and process future deletion requests through that system. This is CalPrivacy's second data broker enforcement action announced in less than a week, following its action against LocateSmarter.

CPPA

LocateSmarter LLC

$116K

The California Privacy Protection Agency Board issued a decision and stipulated order requiring Iowa data broker LocateSmarter LLC to pay $116,490 and change its practices. The company failed to timely register as a data broker and unlawfully required Californians to provide the last four digits of their Social Security numbers before exercising opt-out rights, violating the CCPA's data minimization requirements. This is the first action against a data broker under both the CCPA and the Delete Act.

CPPA

California Privacy Protection Agency

The California Privacy Protection Agency announced that over 300,000 Californians have signed up for the Delete Request and Opt-out Platform (DROP) since its launch five months ago. The Data Broker Registry now includes 581 registered data brokers, the highest number since the registry was established in 2020. Beginning August 1, 2026, all data brokers will be required to access DROP and process deletion requests.