California Privacy Protection Agency warns data brokers of fines for inaccurate registration disclosures
On September 3, the California Privacy Protection Agency’s (CalPrivacy’s) Enforcement Division issued an enforcement advisory (2026-01) warning data brokers that providing inaccurate information in their annual Delete Act registration triggers a $200 fine for each day the incorrect information appears in the registry. The advisory noted that the Delete Act requires businesses that operated as data brokers in the prior year to register with the agency by January 31 each year, pay a registration fee, and disclose certain information, including the types of personal information collected and whether data was shared with certain categories of recipients such as the federal or state government, foreign actors, law enforcement, or developers of generative AI (GenAI) systems or models. The advisory stressed that the law does not distinguish between unintentional mistakes and intentional misrepresentation, and that the Enforcement Division has already brought multiple enforcement actions over reporting errors.
The advisory extends CalPrivacy’s enforcement focus beyond data brokers that fail to register entirely — an area in which the agency has brought more than a dozen actions — to the accuracy of the disclosures those brokers provide. Types of personal information subject to disclosure include data concerning minors, reproductive health, citizenship and immigration status, sexual orientation, gender identity and expression, biometric data, precise geolocation, and Social Security numbers. The advisory included hypothetical scenarios illustrating how data brokers should evaluate their disclosures, including whether clients qualify as foreign actors or developers of GenAI systems. As of January, data brokers must also establish an account with the agency’s “Delete Request and Opt-Out Platform” for purposes of processing consumer deletion requests.