California Tightens Privacy Rules, Colorado, EU Prepare

CalPrivacy fined LocateSmarter more than $30,000 under the Delete Act and nearly $80,000 under the CCPA after the broker required consumers seeking to opt out of data sales or sharing to provide mailing addresses and the last four digits of their Social Security numbers. The agency said such a requirement could intimidate consumers from exercising their privacy rights.
CalPrivacy warned that inaccurate information in a data broker’s annual Delete Act registration can trigger a $200 fine for every day the error remains in the registry, regardless of whether the mistake was intentional. The agency has already brought multiple enforcement actions over reporting errors.
California’s Delete Act disclosures cover especially sensitive categories—including minors’ information, reproductive-health data, citizenship and immigration status, sexual orientation, gender identity, biometric data, precise geolocation and Social Security numbers—and require brokers to identify whether information was shared with government entities, foreign actors, law enforcement or generative-AI developers.
The EU child-safety panel proposed a developmental, age-tiered model: avoiding screens for children under 3, supervised and age-appropriate use from ages 3 to 12, and “evolving autonomous use” with mandatory safety features for ages 13 to 18. It also recommended restricting access for children under 13 until platforms demonstrate that their services are safe by design.
California’s proposed privacy-setting law would apply even when a change is not legally considered “material,” but it would allow businesses to discontinue services or privacy options when they maintain existing protections or increase privacy by reducing the collection, use, sharing or retention of personal information.
California regulators are cracking down hard on data brokers, imposing daily fines for sloppy registration and invasive opt-out practices. DW reports that Europe is simultaneously moving to restrict minors' access to social media, signaling a global shift toward treating privacy and child safety as default rights rather than paid add-ons.
CalPrivacy hit LocateSmarter with over $30,000 under the Delete Act and nearly $80,000 under the CCPA after the broker demanded mailing addresses and Social Security number fragments from people trying to opt out of data sales. The agency ruled such demands intimidate consumers from exercising their privacy rights.
Regulators warned that errors in a broker's annual registration can trigger $200-per-day fines, whether intentional or not. CalPrivacy has already launched multiple enforcement actions over reporting mistakes, making accuracy a costly compliance issue.
Proposed California legislation would prohibit apps and operating systems from weakening privacy settings without explicit user consent. The law allows changes only if they strengthen protections or are legally required—shifting the burden to companies to justify any reduction in privacy.
The Delete Act now requires brokers to disclose especially sensitive data categories: minors' information, reproductive health, citizenship status, sexual orientation, gender identity, biometrics, precise location, and Social Security numbers. Brokers must also reveal if this data went to government agencies, foreign actors, law enforcement, or AI developers.
DW reports that the EU child-safety panel proposed a developmental model: no screens for children under 3, supervised use ages 3-12, and "evolving autonomous use" with safety features for ages 13-18. The panel recommended blocking access for children under 13 until platforms prove their services are safe by design.
Similar initiatives are underway in Australia, the UK, and U.S. states. These moves reflect growing recognition that platforms must redesign themselves around child safety rather than asking parents to police addictive features like infinite scrolling.
Proposed Colorado AI regulations and California's emerging rules signal a wider effort to govern how businesses collect, use, and process personal information—including data used by generative-AI developers. The fight hinges on a fundamental question: Is privacy a right everyone gets, or a premium feature you pay for?
If California and Europe succeed, the default will shift. Companies will no longer be able to harvest data unless users actively consent. For ad-supported platforms, that means reckoning with a future where targeted advertising requires explicit permission rather than buried opt-outs.
Publishers
16
Articles
16
Reach
32