Orrick, Herrington & Sutcliffe·PRIVACY / DATA SECURITY

California Privacy Agency Targets Inaccurate Data Broker Filings

An enforcement advisory warns data brokers that unintentional mistakes in annual registration disclosures will trigger a $200 daily fine for each incorrect entry.

The California Privacy Protection Agency’s (CPPA) Enforcement Division has expanded its focus from data brokers who fail to register to those who file inaccurate information. In a September 3 enforcement advisory, the agency warned that under the Delete Act, each incorrect disclosure in a data broker's annual registration triggers a $200 fine for every day the error remains uncorrected. The advisory emphasizes that the law does not distinguish between intentional misrepresentation and unintentional mistakes, putting the onus entirely on the filer to ensure accuracy. The CPPA noted it has already brought multiple enforcement actions over such reporting errors.

Sophisticated counsel should see this as a significant shift toward more granular compliance enforcement. The advisory provides hypothetical scenarios to guide brokers on complex disclosures, including whether data is shared with foreign actors or developers of generative AI systems. The warning covers a wide range of sensitive data types, such as information on minors, reproductive health, and biometric data. Data brokers and their advisors must now rigorously audit their annual registration disclosures and internal data-mapping processes to mitigate the risk of accumulating daily penalties.

data-brokercppacalifornia-delete-actprivacyenforcementregulatory-compliancefines-penalties
Read the original firm alert → Wednesday, September 16, 2026

Stay ahead

Join the digest.

One email when the daily AmLaw 100 briefing ships. No noise, no pitch decks — just the grade 4–5 signal.