Blog
CPPA Fines Two Data Brokers as Colorado Proposes ADMT and Chatbot Safety Rules
August 18, 2026
Do you want to receive these privacy recaps in your inbox each week? Subscribe here or follow us on LinkedIn.
The CPPA fined data brokers LocateSmarter and Cybba for failing to register under the Delete Act, with LocateSmarter also cited for requiring identity verification before opt-out requests under the California Consumer Privacy Act (CCPA). Colorado has released draft rules implementing its Automated Decision-Making Technology Act and Chatbot Safety Act, both operative January 1, 2027.
Keep reading to discover my analysis and takeaways.
United States
CPPA Fines Two Data Brokers Under the Delete Act / CCPA
In two separate orders within a 3-day period, the California Privacy Protection Agency (CPPA) fined Iowa data broker LocateSmarter and Boston-based data broker Cybba. Both entities were fined for failing to register as data brokers under the Delete Act.
The CPPA also found that LocateSmarter violated the CCPA because it required consumers to submit information to verify their identity before opting out of the sale or sharing of personal information.
Takeaway
Although the LocateSmarter decision is the first CPPA action we’ve seen combining both the CCPA and the Delete Act in the same Order, the actual claims in each order should not surprise businesses.
Including these actions, the CPPA has brought over a dozen enforcement actions against businesses for failing to register as data brokers under the Delete Act. Nothing about these entities falls outside the patterns we’ve seen so far, although the two actions together may refresh our memories regarding the breadth of what constitutes a data broker under the Delete Act.
LocateSmarter exemplifies the skip-tracing, identity, investigative-data end of the broker spectrum, and Cybba reinforces that audience segmentation, retargeting, and ad activation can constitute data brokering even when the company doesn’t look like a traditional database vendor.
LocateSmarter’s CCPA violation resurfaces an important distinction highlighted in the CPPA’s action against Ford Motor Company earlier this year. Under the CCPA, although a business may require a consumer to verify their information to exercise the right to delete, correct or know their personal information, businesses may not require verification to exercise the right to opt out. For opt-out requests, a business may ask for information necessary to identify the consumer but must not require extra steps or information to verify the consumer’s identity.
Companies might overlook this distinction when implementing consistent processes for consumer rights requests, but as this enforcement has made clear, it’s important to give opt-out rights the more immediate treatment required under the CCPA.
United States
Colorado Proposes Rules Implementing the ADMT Act and Chatbot Safety Act
The Colorado Department of Law’s Consumer Protection Section has released draft rules implementing the state’s reenacted Automated Decision-Making Technology Act (SB26-189) and its new Conversational Artificial Intelligence Services (“Chatbot Safety”) Act (HB26-1263).
Both sets of substantive requirements become operative January 1, 2027. The rules remain in the proposal stage and are not yet finalized. As drafted, they cover two distinct populations: (1) Developers, Midstream Developers (a newly defined intermediate category for parties that build Covered ADMT into their own product before passing it downstream), and Deployers of “Covered ADMT” used to make “Consequential Decisions” (the state’s version of significant decisions, including employment, housing, finance and lending, healthcare, education, and similar categories); and (2) Operators of conversational AI (“chatbot”) services, who face a separate set of obligations.
Takeaway
On the ADMT side, Colorado’s draft rules track the general shape of California’s ADMT regulations (adopted July 2025, with ADMT-specific compliance obligations required by January 1, 2027). They both include pre-use notice describing the ADMT’s purpose and the personal data that will affect the outcome, consumer opt-out rights where applicable, and, following an adverse outcome, a right to seek Meaningful Human Review, and developer-to-deployer documentation obligations.
But the Colorado rules go considerably further on mechanics, and not all of that is a surprise. The consumer’s right to “Meaningful Human Review” of an adverse ADMT-driven decision is itself statutory (SB26-189, §6-1-1701(15)). The underlying act already requires a reviewer with real authority to approve, modify, or override the decision, who considers the actual evidence and does not simply defer to the system’s output. What the draft rules add on top is more granular than the statute dictates but consistent with its direction; the reviewer must be shielded from retaliation and insulated from management steering, and the rules treat a full reversal of the original decision as evidence the review was meaningful.
California also requires substantive human review (a designated reviewer who must know how to interpret the ADMT’s output, consider the consumer’s submitted information, and have actual authority to change the decision under 11 CCR §7221(b)(1)), but does not prescribe reviewer independence, anti-retaliation protections, or the detailed review methodology Colorado proposes. Unlike Meaningful Human Review, however, “Midstream Developer” is not a statutorily defined term. SB26-189 defines only “Developer” and “Deployer.” The draft rules create the Midstream Developer subcategory to operationalize the Act’s developer-documentation obligations in multiparty supply chains, imposing a specific pass-through mechanism to obtain upstream Developer documentation and make it available to downstream parties. This structure is more granular than the simple two-party Developer/Deployer split that most ADMT frameworks, including California’s, use.
Colorado’s overall approach is also notably more developed than what other states’ comprehensive privacy laws that touch profiling offer. Maryland and Texas offer the most basic model, both limiting their profiling opt-outs to solely automated processing or decisions producing legal or similarly significant effects, with no profiling-specific correction or human-review mechanism attached. Maryland separately gives consumers a general, non-profiling-specific right to correct inaccurate personal data, and requires a recurring data-protection assessment for risky profiling, including, notably, an assessment for each algorithm used. Connecticut and Vermont go further, each giving consumers a right to question a profiling result, obtain the reason, and review the data used, with a correction or reevaluation right layered on top that is expressly limited to housing decisions specifically. Minnesota’s version is the most robust of the group. It extends the question-and-correct right to any decision type, with no domain limitation, and adds disclosure of what the consumer could do to secure a different result. Even Minnesota’s right, though, falls short of Colorado’s fully articulated, retaliation-proof “Meaningful Human Review” standard.
Bottom line: companies already built for CCPA ADMT compliance, or for the profiling opt-out rights under the comprehensive state privacy laws, should not expect Colorado’s rules to be a rubber stamp. The human-review mechanics are a foreseeable extension of the statute, and the Midstream Developer tier, while not itself a defined term in the Act, fills a documentation-flow gap the statute leaves open for multiparty ADMT supply chains.
A Little More Privacy, if You Please
- New Jersey Governor Signs Age Appropriate Design Code
- Dead-end data in retail: Why your conversions go missing (and what you can do about it)
A Little Privacy, Please weekly recaps are provided for general, informational purposes only, do not constitute legal advice, and should not be relied upon for legal decision-making. Please consult an attorney to determine how legal updates may impact you or your business.
Latest Blog Posts
CPPA Fines Two Data Brokers as Colorado Proposes ADMT and Chatbot Safety Rules
August 18, 2026CPPA fines two data brokers under the Delete Act...
FTC and States Sue Hims & Hers Over Health-Data Sharing; Vermont Releases Draft Age-Appropriate Design Code Rules
August 4, 2026FTC and states sue Hims & Hers over health-data...
New Jersey Signs Surveillance Pricing Law as South Korea Fines Apple and TikTok for Lacking a Legal Basis to Process Data
July 28, 2026New Jersey signs surveillance pricing law banning personal-data-based grocery...
Latest White Papers
Connecting Legal & Marketing Teams on Consent and Preferences
February 4, 2025Break down data silos and unlock better collaboration. Marketing...
Navigating Sensitive Data in the U.S.
February 4, 2025Download our comprehensive guide to learn how different states...
Enterprise Guide To Cookie management & Tracker List Curation
July 1, 2024How to review the tracking tech on your websites...