On August 14, SalesIntel's Vice President of Data signed a stipulated order with California's privacy regulator. The company agreed to pay $36,400.
The violation was not a breach, a leak or a dark pattern. It was a missed form.
SalesIntel sold personal information about people it had no direct relationship with. The order quotes its own marketing: more than 200 million professional contacts, 54 million mobile numbers, a product that "de-anonymizes your website traffic." Under California's Delete Act, that makes you a data broker, and a data broker must register with the state by January 31 each year.
SalesIntel missed the January 31, 2025 deadline, and the Enforcement Division opened an investigation. The order covers its failure to register from February 1 to June 29, 2025. That is 149 days.
Subtract the $6,600 registration fee from the fine and you get $29,800. Divide by 149. It comes to exactly $200 a day.
The graveyard is getting crowded
This is not one company having a bad year. It is the same death, over and over, with the same arithmetic on the headstone.
Cybba, Boston. Sold custom audiences built from geolocation, internet activity and purchase inferences. Missed the January 31, 2025 deadline and registered only after the Enforcement Division contacted it. Unregistered from February 1 to October 20, 2025: 262 days. Fine: $52,400. That is $200 a day, to the dollar.
National Public Data, Florida. Registered on September 18, 2024, 230 days late. Fine: $46,000. Again, $200 a day.
Accurate Append, Washington. Missed the January 31, 2024 deadline and registered only after the regulator reached out. Fine: $55,400.
The regulator has been saying this out loud for a while. In November 2025 it launched a Data Broker Enforcement Strike Force. By the end of this August, more than 500,000 Californians had filed deletion requests through its DROP platform, which registered brokers are now ordered to process.
So nobody can claim the rule is obscure. The deadline is the same date every year. The penalty is published. The enforcement is public and relentless.
And companies keep dying of it anyway.
What actually killed them
Read the orders closely and a pattern shows up that no fine can fix.
Look at how these companies describe themselves. SalesIntel calls itself the "Best Overall ZoomInfo Alternative." Cybba sells digital marketing. Their products describe themselves as sales tools, enrichment, audience finders, signal tracking.
The orders never say anyone chose the legal category. It reads like a side effect of what got shipped.
A feature that identifies anonymous website visitors. A signal product that tracks when a champion changes jobs. A lookalike audience built from home addresses. Each one is a reasonable roadmap item. Together, they quietly change what the company is in the eyes of the law.
That is the real cause of death: the business changed its identity, and nobody owned the question of what it had become.
In most companies like these, Sales owns the pipeline. Product owns the features. Legal owns the privacy policy. Finance owns the fees. The one question that connects them (does what we now do with data put us in a regulated category, and who files by January 31?) sits in the gap between four org charts.
This is why swapping in a sharper compliance hire does not change the outcome. The person was never the problem. The environment has no trigger that links a product launch to a legal classification, and no named owner for a date that comes around every single year.
A January deadline is especially cruel this way. It arrives right after the holidays, it concerns last year's activity, and it belongs to whoever remembers it. At $200 a day, nobody notices the meter running until the regulator reads it back to you.
If you lead data or governance, this is uncomfortably close to home. You are probably the only person who can see both sides: what the data actually does, and what the rules say that makes it. You also probably do not have the authority to make anyone act on that view.
The Monday move
You do not need a program. You need two sentences in writing.
First, pull the list of products and features that sell, share or enrich personal information about people your company has no direct relationship with. Visitor identification, enrichment, audience building, intent signals. If the list is not empty, write one sentence: "This activity may make us a registered data broker in California, and [name] decides whether it does."
Second, put January 31 on that named person's calendar as a standing commitment, with you copied. Not a reminder in a shared inbox. A person.
Then add one question to your product launch review: does this change what we are?
Nothing in these orders reads like recklessness. It reads like a question that belonged to nobody.
Who, by name, owns that question in your company today?
Sources
- Internet privacy updates: CalPrivacy fines data brokers, Colorado proposes new AI regulations, Data Protection Report
- In the Matter of SalesIntel Research, Inc., Stipulated Final Order (Case No. ENF25-221-D-SA), California Privacy Protection Agency
- In the Matter of Cybba, Inc., Stipulated Final Order (Case No. ENF25-228-D-CY), California Privacy Protection Agency