California Privacy Agency Fines Datamasters for Selling Sensitive Health Data Without Registration

Listen to this Post

Featured Image

Introduction: A Warning Shot for the Data Brokerage Industry

California’s privacy regulators have delivered one of their clearest messages yet to the data brokerage industry: operating in the shadows is no longer an option. In a landmark enforcement action, the California Privacy Protection Agency (CalPrivacy) fined a marketing firm for secretly trading in highly sensitive personal and health data—without registering as required by state law. The case exposes how deeply personal information is still being commodified and signals that California’s expanding privacy framework is beginning to show real teeth.

Regulatory Action Against an Unregistered Data Broker

The California Privacy Protection Agency has taken formal enforcement action against Rickenbacher Data LLC, which operates under the name Datamasters. The Texas-based marketing firm was found to be buying and selling the personal and medical data of millions of individuals without registering as a data broker in California, as mandated by law.

Requirements Under the California Delete Act

Under the California Delete Act, any business that buys or sells consumer information must register its data brokerage activities by January 31 of each year. This registry is designed to bring transparency to an industry that has historically operated with limited oversight.

DROP Platform and Consumer Control

Beginning in 2026, the Delete Act introduces a centralized system known as the Delete Request and Opt-out Platform (DROP). This online platform will allow consumers to submit a single request requiring all registered data brokers to delete their personal data, significantly lowering the barrier for individuals to reclaim control over their information.

Datamasters Fined and Restricted

CalPrivacy imposed a $45,000 fine on Datamasters for failing to register on time. Beyond the financial penalty, regulators took the stronger step of prohibiting the company from selling any personal information related to California residents due to ongoing and severe violations.

Sale of Sensitive Medical Information

According to CalPrivacy’s final order, Datamasters purchased and resold personal data related to individuals suffering from serious medical conditions. These included Alzheimer’s disease, drug addiction, and bladder incontinence—information that most consumers would never expect to be used for advertising purposes.

Profiling Based on Race, Age, and Beliefs

The agency further revealed that Datamasters marketed lists categorized by age and perceived race, such as “Senior Lists” and “Hispanic Lists.” The company also trafficked in data sets built around political views, grocery shopping habits, banking activity, and health-related purchases.

Scale of the Data Collection

The scope of the operation was vast. Regulators found that Datamasters handled hundreds of millions of records, containing names, email addresses, physical addresses, and phone numbers—forming a comprehensive profile of millions of individuals.

Resistance and Misrepresentation

An aggravating factor in the case was Datamasters’ repeated resistance to regulatory oversight. The company initially claimed it did not conduct business in California or process data belonging to Californians. When confronted with evidence to the contrary, it reversed its position and asserted that it manually screened data—an explanation regulators found unconvincing.

Continued Non-Compliance

Despite multiple attempts by CalPrivacy to bring the firm into compliance, Datamasters continued operating as an unregistered data broker. This persistent defiance played a significant role in the severity of the enforcement action.

Mandatory Data Deletion Orders

As part of the final decision, signed on December 12, Datamasters was ordered to delete all personal data belonging to Californians by the end of December. The ruling also requires the company to delete any Californian data it may receive in the future within 24 hours.

Long-Term Oversight Measures

CalPrivacy imposed additional compliance obligations lasting five years. Datamasters must implement ongoing privacy controls and submit a detailed report outlining its data handling practices one year after the order.

S&P Global Also Fined for Registration Failure

In a separate but related enforcement action, CalPrivacy fined S&P Global Inc. $62,600 for failing to register as a data broker for 2024 by the January 31, 2025 deadline.

Administrative Error but Real Consequences

Unlike Datamasters, S&P Global’s violation stemmed from an administrative error rather than deliberate resistance. Still, regulators emphasized that the company remained unregistered for 313 days, justifying the fine despite its swift corrective actions once the mistake was identified.

Enforcement Momentum Builds

Together, these cases demonstrate a shift from theoretical privacy protections to active enforcement, with regulators signaling that registration failures—intentional or not—will carry tangible consequences.

What Undercode Say:

A Turning Point for Data Brokerage Accountability

This enforcement action marks a critical inflection point in California’s privacy regime. For years, data brokers have operated largely unseen, trading in sensitive personal information with minimal accountability. CalPrivacy’s move against Datamasters shows that the era of plausible deniability is ending.

Health Data as a Red Line

The sale of medical-condition-based lists highlights one of the most disturbing aspects of modern data brokerage. Health data is not just personal—it is deeply intimate. Using such information for targeted advertising crosses ethical boundaries that regulators are now willing to enforce with real penalties.

Registration as a Gatekeeping Mechanism

Mandatory registration may seem like a bureaucratic step, but it serves as the foundation for enforcement. Without knowing who the data brokers are, regulators cannot audit, fine, or restrict them. Datamasters’ failure to register effectively placed it outside the system, making its activities even more concerning.

DROP Could Reshape Consumer Power

The upcoming DROP platform could become one of the most powerful consumer privacy tools in the U.S. By centralizing deletion requests, California is removing the friction that previously discouraged individuals from exercising their rights.

The Illusion of Geographic Avoidance

Datamasters’ claim that it did not do business in California reflects a common misconception in the data economy. In a digital marketplace, geographic boundaries are porous. Regulators are making it clear that handling Californian data—anywhere in the world—triggers legal obligations.

Escalation Beyond Fines

The prohibition on selling Californian data is arguably more impactful than the monetary penalty. It cuts directly into the company’s business model, signaling that non-compliance can threaten a firm’s ability to operate at all.

Lessons for Large Corporations

The S&P Global fine demonstrates that size and reputation do not exempt companies from compliance. Even administrative oversights can result in significant penalties, reinforcing the need for internal governance around privacy obligations.

A Blueprint for Other States

California’s approach may serve as a template for other states considering similar legislation. As privacy laws proliferate, data brokers will face a patchwork of requirements that increasingly demand transparency and accountability.

Long-Term Compliance as the New Normal

The five-year oversight requirement imposed on Datamasters underscores a broader shift: regulators are no longer satisfied with one-time corrections. Continuous compliance, documentation, and reporting are becoming standard expectations.

Industry-Wide Ripple Effects

This case will likely reverberate across the data brokerage ecosystem. Firms that have delayed registration or underestimated enforcement risk may now reconsider their exposure, particularly those handling sensitive data categories.

Privacy Enforcement Enters a New Phase

Ultimately, this action reflects a maturation of privacy regulation. Laws are no longer symbolic. They are being enforced, tested, and refined through real-world cases that redefine acceptable behavior in the data economy.

Fact Checker Results

Verification of Key Claims

CalPrivacy’s fines and enforcement actions are officially documented and publicly disclosed. ✅

Datamasters’ sale of health, demographic, and behavioral data is supported by regulatory findings. ✅

The DROP platform timeline aligns with the provisions of the California Delete Act. ❌

Prediction

What Comes Next for Data Brokers

Increased audits and enforcement actions against unregistered brokers are likely. 🔍

Health and demographic data sales will face tighter scrutiny and possible outright bans. ⚠️

Other states may accelerate similar registry and deletion platforms inspired by California. 📈

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: www.bleepingcomputer.com
Extra Source Hub (Possible Sources for article):
https://www.digitaltrends.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon