The California Privacy Protection Agency publishes its enforcement decisions. This page tracks the ones involving data brokers and the registration requirement, with the figures as published and nothing added. There is no commentary here about the companies named: the point of the page is the arithmetic, which applies identically to any broker in the same position.
Published orders
| Respondent | Amount ordered | Stated basis |
|---|---|---|
| Growbots, Inc. | $35,400 | 177 days late, times $200 |
| UpLead LLC | $34,400 | 172 days late, times $200 |
| LocateSmarter LLC | $116,490 | Failure to register |
Each of these is a published CPPA enforcement action. The agency's site at cppa.ca.gov is the source, and it is the place to read the orders themselves rather than a summary of them. The registry the requirement attaches to is published separately at cppa.ca.gov/data_broker_registry.
For the first two, the published amount and the day count reconcile exactly against the daily figure. For LocateSmarter LLC, the signed order breaks $116,490 into a $30,600 Delete Act fine, a $79,890 CCPA fine, and the $6,000 annual registration fee, so the fines alone total $110,490.
The arithmetic
The Delete Act attaches an administrative fine to failing to register, and it is expressed as a daily figure: up to $200 per day for each day a broker fails to register. That structure is the whole story. It is not a fixed fine with a ceiling you approach slowly, and it is not assessed per consumer or per record. It counts days.
So the calculation any broker can run on themselves is a multiplication with two inputs: how many days late, and the daily figure. Growbots, Inc. shows the shape of it clearly. 177 days is under six months. The order is $35,400.
- Growbots, Inc.
- 177 days x $200 = $35,400
- UpLead LLC
- 172 days x $200 = $34,400
- LocateSmarter LLC
- $116,490 ordered
Two things follow from a per-day structure that are easy to miss. First, the exposure grows while nothing else changes. A broker who does not know they are a broker accrues the same days as one who knows and delays. Second, there is no cliff to watch for: every additional week of not registering is worth the same as the previous one, so the cheapest day to fix it is always today.
What the penalty is assessed for
In each of the actions above, the conduct at issue is failure to register as a data broker. Not a hashing error, not a missed deletion, not a late status file: the entity met the definition of a data broker in California and did not appear on the register when it should have.
That is worth stating plainly because it sets the order of operations for anyone reading this page and wondering whether it applies to them. Registration is the first obligation and the one with the published enforcement history. The processing obligations, including the 45-day cycle, follow it.
It also means the question that precedes all of this is definitional: does your business meet California's definition of a data broker at all? A business that knowingly collects and sells personal information about consumers with whom it has no direct relationship is in scope, and the phrase "no direct relationship" catches more businesses than people expect. If you are unsure, the five-question data broker check walks the definition.
The registration obligation itself
The requirement is annual. A data broker registers with the CPPA and pays the registration fee, and does so again each year by the deadline. The current deadline is January 31.
Registration and DROP now share one account. The Data Broker Portal at databroker.drop.privacy.ca.gov covers registration, fees and the API key in one place, and the agency's guidance on account creation, fees and annual registration is published at privacy.ca.gov. The agency approves a newly created account before it can be used, typically within two business days.
Reading the record honestly
A few notes on how to use the figures on this page, and how not to.
- These are published orders, not estimates. The amounts are what the agency ordered, and they are reproducible from the source. Nothing on this page is modelled or projected.
- The daily figure is a ceiling. The statute expresses a maximum, and an order is the outcome of a specific matter with specific facts. Treating the ceiling as an automatic assessment overstates it.
- Day counts are not comparable across matters. Two respondents with similar amounts did not necessarily do similar things. The only shared element is the day-count structure.
- Enforcement history is not a prediction. A published order tells you what happened in one matter. It does not tell you what will happen in yours.
- Watch for new orders rather than re-reading old ones. The agency publishes as matters conclude, and the enforcement log is where new entries land as they appear.
The reason a page like this belongs on a compliance product's site at all is not fear. It is that the numbers are checkable, and a checkable number is worth more than an adjective. Anyone reading can go to the agency's site, find the order, and do the multiplication themselves. That is the appropriate relationship to have with a penalty figure.
Figures on this page are reproduced from published CPPA enforcement actions. They are not legal advice, and they describe other companies' matters, not yours.
If you are already late
The structure of a per-day penalty means the only variable you still control is the day count. Registering does not undo the days already accrued, but it stops them accruing, and it is the single action with the largest effect on the arithmetic.
After registration comes the recurring obligation: access DROP at least once every 45 days, work the list, and file a status for every work item ID you were given. That is a different obligation with a different failure mode, and it is not what the orders above concern.