Practical Lessons for All Businesses From a Recent CalPrivacy Action
by: Lael Bellamy
Summary: It’s easy to miss the CCPA lessons for all businesses if you assume LocateSmarter is just another data broker enforcement action[1]. CalPrivacy was explicit that LocateSmarter was both a data broker under the Delete Act and a business under the CCPA and that it could pursue violations under both statutes in a single action. LocateSmarter received fines of $79,890 under the CCPA for the issues listed below and $30,600 under the Delete Act (in addition to the $6,000 registration fee).
CCPA Lessons
1. Train personnel and document your policy in writing*
2. Minimize the data you require from consumers
3. Don’t verify opt-out requests, make them easy to submit, and act within 15 business days
4. Don’t assume low request volumes reduces your risk
Lesson One: Training personnel is required. The order, which also required LocateSmarter to confirm completion of updated CCPA training for all personnel who handle consumer requests, the CCPA[2] and the regulations all require training independently.
Under the CCPA regulations, “[a]ll individuals responsible for handling consumer inquiries about…information practices or…compliance with the CCPA shall be informed of all of the requirements in the CCPA and these regulations and how to direct consumers to exercise their rights….” Additionally, the regulations require a written training policy if the Business buys, receives, sells or shares for its commercial purposes the personal information of 10,000,000 or more consumers annually.*[3]
Lesson Two: Data Minimization Under CCPA: In response to an opt-out request under the CCPA, CalPrivacy found that LocateSmarter violated the CCPA’s data minimization obligations by requiring consumers to submit more information than reasonably necessary and proportionate to complete the request including their full name, the last four digits of their Social Security number and their mailing address.
The order states that “[a]lthough a business may require consumers to submit a verifiable consumer request to exercise their right to delete, right to know, and right to correct, a business may not require a verifiable consumer request for the right to opt-out…Requests to opt-out of sale/sharing are not verifiable because the potential harm to consumers resulting from an imposter submitting such a request is minimal or nonexistent.” The business may only ask for additional information that is necessary to complete the request for the opt-out of sale or sharing, and to the extent it can comply without additional information, it must do so.
CalPrivacy warned in 2024 that data minimization is a foundational CCPA principle and that data minimization applies to the processing of consumer requests.[4]
Lesson Three: Methods to opt-out of sale/sharing must:
be easy,
require minimal steps,
never require a verifiable consumer request or identity verification to exercise the right to opt-out of sale/sharing,
not require more information than necessary to complete the request, although the business may ask for information necessary to identify the consumer,
not require sensitive personal information, such as a Social Security number, where non-sensitive data points are available, and
result in the business ceasing sale/sharing as soon as feasibly possible and no later than 15 business days from receipt, and notifying the third parties to whom it sold or shared the information.
Lesson Four: Don’t assume low request volumes reduce your risk. CalPrivacy treated LocateSmarter's low opt-out volume as evidence that the excessive information requirement was itself the obstacle, observing that only a handful of California's nearly 40 million consumers ever submitted an opt-out request. Do not assume that few complaints or low opt-out numbers mean your process is sound. A regulator may read the same numbers as proof of unlawful friction.
If you need help reviewing and updating your consumer request process and training policy, please reach out to our team.
[1] Order of Decision and Stipulated Final Order, In re LocateSmarter, LLC (Cal. Priv. Prot. Agency Aug. 10, 2026), announced Aug. 11, 2026. https://privacy.ca.gov/wp-content/uploads/sites/357/2026/08/Order-of-Decision-and-Stipulated-Order_LocateSmarter-LLC-.pdf
[2] CCPA 1798.130(a)(6) Ensure that all individuals responsible for handling consumer inquiries about the business' privacy practices or the business' compliance with this title are informed of all requirements in Sections 1798.100, 1798.105, 1798.106, 1798.110, 1798.115, 1798.125, and this section, and how to direct consumers to exercise their rights under those sections.
[3] Cal. Code Regs. tit. 11, § 7100 (a) & (b) A business that knows or reasonably should know that it, alone or in combination, buys, receives for the business's commercial purposes, sells, or shares for commercial purposes the personal information of 10,000,000 or more consumers in a calendar year shall establish, document, and comply with a training policy to ensure that all individuals responsible for handling consumer requests made under the CCPA or the business's compliance with the CCPA are informed of all the requirements in these regulations and the CCPA.
[4] Cal. Priv. Prot. Agency, Enforcement Advisory No. 2024-01 (Apr. 2, 2024). https://cppa.ca.gov/pdf/enfadvisory202401.pdf
Originally published by InfoLawGroup LLP. If you would like to receive regular emails from us, in which we share updates and our take on current legal news, please subscribe to InfoLawGroup’s Insights HERE. This summary does not constitute legal advice.