l0grisk intelligence · english

// analysis

Personal data trade: the cost of enforcement

Illustration for the analysis: Personal data trade: the cost of enforcement

Mobilewalla, Avast, Mobius and DROP: an investigation into fines, restricted uses and the continuing cost of oversight in the personal data trade.

dated revision: September 19, 2026French originalprimary sourcesno tracker

The trade in our traces · Sixth and final part of a six-part investigation.

Enforcement can take cash out of a business, close a market or require a dataset to be deleted. It can also become a clause in a merger agreement. From Mobilewalla and Avast to France’s CNIL and California’s DROP platform, the final instalment follows privacy rules into the economics of the data trade.

On 29 May 2026, Mobilewalla Holdco and SPACSphere signed a business combination agreement. Section 4.14(m) addresses the Federal Trade Commission’s order against Mobilewalla: the company represents that it complies with the order. Section 4.14(b) makes its data-processing rights subject to the order’s restrictions. S01

The enforcement case has entered the commitments exchanged by the parties to a financial transaction. After the life of copies beyond the contract, this final instalment examines the revenue still available, the datasets requiring attention and the cost of continuing oversight.

Four economic effects

The most visible effect is a cash outflow. The Avast settlement requires $16.5 million for consumer redress. The CNIL imposed a €1 million administrative fine on Mobius. The currencies, legal bases and destinations of the money differ. S09 S07

Restrictions can also affect future earnings. Losing the right to reuse a source may require a business to find another supplier, secure additional consent or discontinue a use. Any economic loss depends on the margins that use would have generated and the available alternatives.

Accumulated data presents a separate issue. The Avast order covers Jumpshot data and certain models, algorithms and software developed from it. The Gravy order provides several possible treatments for historical data, subject to conditions. Enforcement can therefore reach both the input and the products built from it. S09 S13

Continuing oversight consumes resources too: identifying suppliers, examining their practices, tracking deletion requests and testing restrictions. Gravy must assess its suppliers initially and then annually; Avast must obtain independent assessments of its privacy programme. S13 S09

These effects provide an economic framework. Quantifying them would require incremental costs, the margins of the affected uses and a comparison with the business’s likely path without intervention. Adding announced amounts alone risks double counting, particularly where an activity had already ended.

Four economic effectsQualitative framework. Cash: fine or redress. Earnings: restricted uses. Data: datasets and derived products to address. Oversight: recurring assessments. No total cost calculated.Four economic effectsOrders and penalties · 2024–2025CashFine or consumer redressEarningsRestricted usesDataDatasets and derived productsOversightRecurring assessments
Economic reading of the Mobilewalla, Avast and Gravy–Venntel remedies. Requirements differ by case; costs are neither added together nor estimated. S04 S09 S13

Mobius: a disclosed fine and redacted revenue

The Mobius decision, adopted on 11 December 2025 and announced on 19 December, concerns retention after the contract ended, processing beyond the client’s instructions and the absence of a processing register. The CNIL found breaches of GDPR Articles 28, 29 and 30. S06 S07

The applicable ceiling was the higher of €10 million or 2% of total worldwide annual turnover in the preceding financial year. The frequently cited GDPR ceiling of 4% applies to other categories of infringement. S06 S08

Mobius’s 2023 and 2024 revenue figures and the losses it cited are redacted in the published decision. The document therefore leaves the fine’s size relative to revenue or the benefit of the disputed reuse unquantifiable. Dividing the fine by the number of affected people would yield an amount per person, with no measure of the file’s profitability. S06

Timing matters as well. Mobius reported deleting its copy on 1 October 2023, before the December 2025 fine. The sequence separates reported deletion from the later penalty, while leaving the respective effects of the incident, the investigation and the client’s requests unresolved. S06

Restrictions reshape permitted uses

The Gravy Analytics–Venntel order, issued on 13 January 2025 and published on 14 January, contains no monetary payment requirement. It nevertheless restricts the use and supply of sensitive location data and imposes continuing controls. S13 S14

Its scope rests on precise definitions. The sensitive locations covered are in the United States. The definition of Location Data excludes specified security uses, national-security purposes conducted by federal bodies, and a federal law-enforcement response to an imminent risk of death or serious bodily harm. Activities may therefore remain permitted depending on their purpose and conditions. S13

The order also allows conversion into data that is no longer sensitive or falls outside its definition of Location Data. Another exception covers a service directly requested by a consumer with whom the business has a direct relationship and from whom it has obtained the required consent. These exceptions belong to this order and operate alongside other applicable rules. S13

At Mobilewalla, Section II targets sourcing. It prohibits acquiring or retaining covered information accessed through online advertising auctions for any purpose other than participating in those auctions. Data received to assess an advertising opportunity consequently loses one route to reuse. S04 S05

The commercial effect lies in uses removed from the catalogue or made more expensive. Measuring it would require comparing sources before and after intervention, replacement contracts and the margins of the affected products. A business can continue operating while losing some of its opportunities to exploit data.

Mobilewalla brings compliance into the transaction

The May 2026 agreement provides for notification to the FTC within fourteen days of closing, as required by the order. The proposed transaction thus accommodates continuing obligations after a change in corporate structure. S01

The companies’ announcement states a $250 million pre-money equity valuation and $13.9 million of annual recurring revenue as of 30 April 2026, or ARR. ARR annualises a recurring revenue base; it differs from accounting revenue recognised over a year. The valuation describes the proposed transaction’s terms. S03

A further step appears in the 12 August 2026 filing: the parties announced submission of a Form S-4 registration statement containing a preliminary prospectus and proxy statement. That filing still describes a proposed combination subject to conditions. S23

The contractual representations have a specific role. SPACSphere’s filing explains that they allocate risk between the parties, may be qualified by confidential disclosures and use materiality standards particular to the agreement. Publication reveals negotiated commitments; details of the acquirer’s diligence remain outside these documents. S02

For a buyer, the economic question is whether expected revenue rests on sufficiently secure usage rights. A dataset’s value also depends on the uses a future owner can continue and the cost of maintaining those rights. The Mobilewalla documents bring that issue into the transaction’s clauses, without isolating a dollar amount attributable to the FTC’s intervention.

Avast: from Jumpshot’s closure to consumer payments

Avast says it closed Jumpshot and ended its collection operation in January 2020. The company disputes the FTC’s characterisation of the facts. The final settlement followed on 26 June 2024, more than four years after the closure. S11 S12

On 2 December 2025, the FTC announced that it was sending nearly $15.3 million to 103,152 customers who had filed valid claims. That figure concerns payments sent through the methods selected by recipients. The $16.5 million required under the settlement and the money distributed to claimants represent different stages. S10 S09

This sequence places Jumpshot’s 2020 closure before the 2024 settlement. The agreement adds its own requirements: restrictions on future uses, treatment of data and certain derived products, a privacy programme and financial redress. Previously distributed files, examined in the preceding instalment, follow another process. S09

From closure to paymentsJanuary 2020: Jumpshot closure reported by Avast. 26 June 2024: final settlement requires a 16.5 million dollar payment. 2 December 2025: the FTC announces nearly 15.3 million dollars being sent to 103,152 customers. Event spacing is not proportional to elapsed time.From closure to paymentsAvast / Jumpshot · 2020–2025January 2020Jumpshot closed, Avast says26 June 2024$16.5m required by settlement2 December 2025Nearly $15.3m sent103,152 customer recipients
Events spaced for readability. Nominal US dollars: money due under the settlement and payments announced as sent to customers with valid claims. S09 S10 S11 S12

Oversight becomes a recurring expense

The Avast order requires an initial assessment covering the first 180 days, followed by independent assessments for successive two-year periods over twenty years. They must include technical testing and examine gaps in the programme. Findings must be grounded in the assessor’s work, including its methods, documents and results. Annual certifications by senior officers are required separately, with publication in the investor section of the website. S09

This framework requires time, expertise and access to systems. The European Data Protection Board takes a comparable approach to checking processors’ safeguards: contractual commitments need to be accompanied by examination of their implementation, calibrated to the risks. S22

Each case has its own timetable. The Kochava court order, signed on 25 June 2026 and published by the FTC on 26 June, gives Collective Data Solutions 90 days to establish its sensitive-location programme. It requires a compliance report after one year and runs for ten years. As of 19 September 2026, the first 90-day deadline has yet to expire. S15 S16

Assessing these arrangements means matching each obligation to its deadline, the systems covered and the recipient of the reports. The documents examined here set out the requirements while offering limited access to the detailed findings of internal and independent reviews.

DROP makes deletion an ongoing process

California’s Delete Request and Opt-out Platform, or DROP, centralises residents’ requests to data brokers covered by the law. Since 1 August 2026, those businesses have been required to download requests at least every 45 days. S17 S20

A broker prepares its identifiers, matches them against downloaded lists, deletes non-exempt information and returns a status. Information covered includes inferences: characteristics derived from other data. Processing obligations also extend to instructions for the relevant service providers and contractors. S18

The request persists. Brokers retain the minimum identifiers needed to honour it and compare them against newly collected records before sale or sharing. This exclusion mechanism serves the purpose of a suppression list, discussed in the previous instalment. It is designed to prevent the next purchased file from rebuilding a deleted profile. S18

The 2026 annual registration fee is $6,000, with an additional processing fee for electronic payments. CalPrivacy lists a potential penalty of $200 per day per request for failure to delete information as legally required. This is statutory exposure, distinct from a penalty already imposed. S20

Integration and repeated processing generate costs for brokers. A common platform may also simplify the receipt of requests previously arriving through separate channels. The net effect on expenses, let alone market concentration, would require business-level data absent from the documents examined here.

Two indicators with different denominators

CalPrivacy’s 25 August 2026 update reports more than 500,000 registered consumers and 654 brokers in the system. Approximately 25% of brokers reported processing requests. According to the agency, 99.9% of consumers had their profile deleted by at least one broker. S19

The first rate counts businesses; the second counts people. A consumer may obtain deletion from one broker while awaiting responses from others. The 99.9% figure describes that initial coverage, using a threshold of at least one deletion. The update relies on outcomes reported by brokers and does not measure the overall share of data erased.

DROP: two populations99.9% of consumers have a profile deletion reported by at least one broker. Approximately 25% of the 654 brokers reported processing requests. More than 500,000 consumers registered. The rates have different denominators.DROP: two populationsCalPrivacy update · 25 August 202699.9%of consumersat least one broker deletedtheir profile, the agency reports≈ 25%of the 654 brokersreported processing requests
Two denominators: consumers in the system and registered brokers. More than 500,000 consumers at that date. Outcomes reported by brokers; no overall data-erasure rate is calculated. S19

Downloading and processing requests have separate deadlines. CalPrivacy describes downloads at least every 45 days, followed by processing and a response within 45 days of receipt. The first status may consequently take up to 90 days. Responses distinguish deleted data, exempt information, no match and certain cases of opting out of sale or sharing. S18 S21

The law requires independent audits from 1 January 2028, then every three years, alongside the authority’s enforcement powers. The first August 2026 results precede that audit cycle. Their date, population and reliance on broker reports remain essential to interpreting each indicator. S17

Value follows the right to use data

The six instalments have followed information from collection to buyers, derived products and residual copies. Enforcement intervenes at several points along this chain: access, permitted uses, historical holdings and the organisation of oversight.

A fine has a currency and a date. A restriction defines the services that remain permissible. A deletion requirement must be followed through datasets and their recipients. Reading these together gives a more precise account of a decision’s commercial effects than the headline amount alone.

Data’s value also depends on the right to keep using it. Rules can change that utility, require a different source or make exploitation more demanding. Evaluating their effectiveness still requires the margins of discontinued uses, compliance costs and sustained deletion outcomes. Public access to those detailed results varies across the cases examined here.

Read the six instalments

  1. The economics of collection
  2. The chain of intermediaries
  3. Turning traces into saleable profiles
  4. Buyers and their contracts
  5. The life of copies after the contract
  6. The cost of enforcement, this final instalment.

Sources and method

Research cut-off: 19 September 2026. CNIL decisions, US settlement orders, companies’ contractual representations and CalPrivacy updates are attributed according to their nature. US settlements contain their own provisions on admissions of allegations. The Mobius decision was consulted through Légifrance.

This analysis uses the cited public documents. It includes no access to company databases, DROP request campaign, interviews or audits conducted by l0g. The diagrams present possible economic effects of the remedies, a chronology and two published indicators. Mobilewalla’s revenue and valuation figures are attributed to the companies.

  1. S01 · Mobilewalla–SPACSphere: business combination agreementSPACSphere / SEC EDGAR · agreement dated 2026-05-29, filed 2026-06-01. §§ 4.05(b)(ii), 4.14(b), 4.14(m). Accessed 2026-09-19.
  2. S02 · SPACSphere: transaction filingSPACSphere / SEC EDGAR · filed 2026-06-01. Item 1.01; role of representations and warranties, p. 4. Accessed 2026-09-19.
  3. S03 · Mobilewalla–SPACSphere: transaction announcementMobilewalla / SPACSphere / SEC EDGAR · 2026-06-01. Company-reported figures; ARR as of 2026-04-30; Transaction Overview. Accessed 2026-09-19.
  4. S04 · Mobilewalla: final orderFTC · issued 2025-01-13, published 2025-01-14. §§ II and XV.B. Accessed 2026-09-19.
  5. S05 · Mobilewalla: publication of the orderFTC · 2025-01-14. Publication of the final order. Accessed 2026-09-19.
  6. S06 · Mobius: decision SAN-2025-014CNIL / Légifrance · decision dated 2025-12-11, published 2025-12-19. §§ 64–67, 104–110; operative provisions. French source. Accessed 2026-09-19.
  7. S07 · CNIL: announcement of the Mobius fineCNIL · 2025-12-19. Articles 28, 29 and 30; amount of the fine. French source. Accessed 2026-09-19.
  8. S08 · GDPR: Article 83 and administrative fine ceilingsEuropean Union / CNIL · Article 83(2), (4) and (5). French source. Accessed 2026-09-19.
  9. S09 · Avast: complaint and final orderFTC · 2024-06-26. Order III, VI–IX; PDF pp. 18–24. Accessed 2026-09-19.
  10. S10 · FTC: payments to Avast customersFTC · 2025-12-02. Payments sent and customers with valid claims. Accessed 2026-09-19.
  11. S11 · Avast: Jumpshot settlement FAQAvast · company statement. Introduction: January 2020 closure and end of collection; position on settlement. Accessed 2026-09-19.
  12. S12 · Avast: official case timelineFTC · entries dated 2024-06-26 and 2025-12-02. Accessed 2026-09-19.
  13. S13 · Gravy–Venntel: complaint and final orderFTC · issued 2025-01-13, published 2025-01-14. Definitions G–L; §§ II, III, VII and XIII. Accessed 2026-09-19.
  14. S14 · Gravy–Venntel: official case timelineFTC · entry dated 2025-01-14. Accessed 2026-09-19.
  15. S15 · Kochava: signed court orderU.S. District Court for the District of Idaho / FTC · signed and filed 2026-06-25, published by FTC 2026-06-26. Document 138; §§ II–III, XV and XVIII. Accessed 2026-09-19.
  16. S16 · Kochava: official case timelineFTC · entries dated 2026-05-04 and 2026-06-26. Accessed 2026-09-19.
  17. S17 · California: Civil Code § 1798.99.86California Legislature · SB 361 version effective 2026-01-01. Subdivisions c, d and e. Accessed 2026-09-19.
  18. S18 · DROP: processing and following up requestsCalPrivacy · matching, statuses, 45-day cycle, continuing requests and service providers. Accessed 2026-09-19.
  19. S19 · DROP: 25 August 2026 updateCalPrivacy · 2026-08-25. Registrations, brokers and broker-reported outcomes. Accessed 2026-09-19.
  20. S20 · DROP: registration, fees and penaltiesCalPrivacy · 2026 registration fee and potential penalties. Accessed 2026-09-19.
  21. S21 · DROP: implementing regulationsCalPrivacy · regulations effective 2026-01-01. §§ 7610–7614, including access, matching and statuses. Accessed 2026-09-19.
  22. S22 · EDPB: Opinion 22/2024 on processorsEuropean Data Protection Board · adopted 2024-10-07. Paragraphs 31–32 and 69–71. Accessed 2026-09-19.
  23. S23 · Mobilewalla–SPACSphere: preliminary prospectus filingMobilewalla / SPACSphere / SEC EDGAR · 2026-08-12. Item 8.01: S-4 submission and preliminary status. Accessed 2026-09-19.

This analysis is not investment advice.

// cite this analysis

l0g, “Personal data trade: the cost of enforcement”, l0g.fr, published September 19, 2026, updated September 19, 2026, https://l0g.fr/en/analysis/personal-data-trade-cost-of-enforcement/


$ cd ../analysis