A Nevada marketing firm that never thought of itself as a data broker just found out California disagrees, and it cost the company $56,600. The California Privacy Protection Agency's new Data Broker Enforcement Strike Force brought the case against ROR Partners LLC for building consumer profiles from "billions of data points" and selling access to them without registering, and the decision it issued reads like a warning label for every advertising and marketing firm that touches Californians' data.

The strike force is new, the fine is the first one it has issued, and the reasoning behind it applies far beyond the one company that got caught. If your business collects information about people who are not your customers and sells any form of access to that data, this decision is worth reading closely.

CPPA announcement page confirming the $56,600 fine against ROR Partners LLC, the first enforcement action brought by the agency's Data Broker Enforcement Strike Force

Source: California Privacy Protection Agency, "CalPrivacy Fines Marketing Firm for Selling Custom Audiences Without Data Broker Registration", captured August 2026.

What happened

The CPPA announced its Data Broker Enforcement Strike Force in November 2025, a dedicated team inside the agency's Enforcement Division built to investigate data broker registration violations under California's Delete Act. Weeks later, the strike force brought its first case: a decision requiring ROR Partners LLC, a Nevada-based marketing firm serving fitness and wellness brands, to pay $56,600 in fines and past-due fees for operating as an unregistered data broker.

According to the CPPA's decision, ROR Partners used what the agency called a "rich repository" of demographic, socioeconomic, and behavioral data on more than 262 million Americans to build custom audience segments for its clients. The example the agency gave is a useful one: identify consumers who frequently attend health clubs, group them into a fitness-related audience segment, then sell that segment to health clubs for targeted advertising. ROR Partners did this in 2024 without ever registering in the California Data Broker Registry.

The CPPA's decision did not treat the packaging of that data as a defense. "A sale is a sale," the decision states. "A business cannot bypass the CCPA's and the Delete Act's requirements by selling personal information as part of a larger suite of products and services it offers." Michael Macko, the agency's head of enforcement, put it more bluntly in the agency's announcement: businesses that walk and talk like a data broker will get scrutinized whether they call themselves one or not.

What actually triggers data broker registration

California's Delete Act defines a data broker as a business that knowingly collects and sells the personal information of a consumer with whom it does not have a direct relationship. The ROR Partners case is a clean illustration of how broad that definition reaches in practice. The company was not selling raw lists of names and addresses. It was building inferred audience segments, fitness enthusiasts, likely health club members, and licensing access to those segments for advertising campaigns. The CPPA treated that as a sale of personal information regardless of the layer of analysis sitting on top of it.

That is the part of the decision advertising, adtech, and marketing analytics firms should sit with. If your business ingests data about people who never signed up for anything you offer, derives characteristics or behavioral predictions about them, and makes any part of that available to a client or partner for a fee, you are inside the definition the CPPA is now actively enforcing. Bundling that data access into a broader service, a dashboard, a targeting tool, a lookalike-audience feature, does not move you outside the registration requirement. The agency's own language rules that argument out directly.

CPPA Data Broker Enforcement Strike Force fines, first three cases 020k40k60k80k USD56.6kROR Partners45kDatamasters62.6kS&P Global

Figure: Fines from the CPPA's Data Broker Enforcement Strike Force since it began bringing cases in December 2025.

The ROR Partners fine was not an isolated action. Within weeks of that first decision, the strike force brought two more cases, a Texas-based data reseller and a New York-based financial information provider, each fined for the same underlying failure to register. The pattern across all three cases is consistent: the CPPA is not waiting for consumer complaints to find unregistered brokers, it is actively investigating businesses whose activities fit the statutory definition and pursuing fines and past-due registration fees once it finds one.

Registration is only the first obligation

Registering as a data broker is a compliance floor, not a finish line. Once a business is on the California Data Broker Registry, it takes on the ongoing obligations that came into force alongside the registry itself, including the deletion-request processing duties tied to the state's DROP platform. We covered that deadline and its $200-per-request, per-day penalty structure in detail in our post on California's DROP deletion deadline, which is worth reading alongside this one since both obligations flow from the same underlying registration status.

The throughline across both posts is the same: California is treating data broker status as a factual question about what a business actually does with personal information, not a label a business gets to choose for itself. A marketing firm that builds and sells audience segments is a data broker under the Delete Act whether or not "data broker" appears anywhere in its own description of its business.

What this means for your privacy policy

If your business collects information about people who are not your direct customers and makes any part of that information, or inferences drawn from it, available to others for compensation, your privacy policy needs to say so accurately. That includes disclosing the categories of personal information collected, the categories of third parties it is shared with or sold to, and whether your business is registered as a data broker under California law. A privacy policy that omits this, or that describes a narrower relationship with consumer data than the business actually has, is exactly the kind of gap the CPPA's strike force is now built to find.

Our Privacy Policy Generator builds CCPA-aligned data broker and third-party sale disclosures directly into your policy, so what you publish matches the data relationships your business actually maintains rather than a generic template that assumes you only handle your own customers' information.

The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.