// analysis
Personal data trade: the cost of enforcement

Mobilewalla, Avast, Mobius and DROP: an investigation into fines, restricted uses and the continuing cost of oversight in the personal data trade.
The trade in our traces · Sixth and final part of a six-part investigation.
Enforcement can take cash out of a business, close a market or require a dataset to be deleted. It can also become a clause in a merger agreement. From Mobilewalla and Avast to France’s CNIL and California’s DROP platform, the final instalment follows privacy rules into the economics of the data trade.
On 29 May 2026, Mobilewalla Holdco and SPACSphere signed a business combination agreement. Section 4.14(m) addresses the Federal Trade Commission’s order against Mobilewalla: the company represents that it complies with the order. Section 4.14(b) makes its data-processing rights subject to the order’s restrictions. S01
The enforcement case has entered the commitments exchanged by the parties to a financial transaction. After the life of copies beyond the contract, this final instalment examines the revenue still available, the datasets requiring attention and the cost of continuing oversight.
Four economic effects
The most visible effect is a cash outflow. The Avast settlement requires $16.5 million for consumer redress. The CNIL imposed a €1 million administrative fine on Mobius. The currencies, legal bases and destinations of the money differ. S09 S07
Restrictions can also affect future earnings. Losing the right to reuse a source may require a business to find another supplier, secure additional consent or discontinue a use. Any economic loss depends on the margins that use would have generated and the available alternatives.
Accumulated data presents a separate issue. The Avast order covers Jumpshot data and certain models, algorithms and software developed from it. The Gravy order provides several possible treatments for historical data, subject to conditions. Enforcement can therefore reach both the input and the products built from it. S09 S13
Continuing oversight consumes resources too: identifying suppliers, examining their practices, tracking deletion requests and testing restrictions. Gravy must assess its suppliers initially and then annually; Avast must obtain independent assessments of its privacy programme. S13 S09
These effects provide an economic framework. Quantifying them would require incremental costs, the margins of the affected uses and a comparison with the business’s likely path without intervention. Adding announced amounts alone risks double counting, particularly where an activity had already ended.
Mobius: a disclosed fine and redacted revenue
The Mobius decision, adopted on 11 December 2025 and announced on 19 December, concerns retention after the contract ended, processing beyond the client’s instructions and the absence of a processing register. The CNIL found breaches of GDPR Articles 28, 29 and 30. S06 S07
The applicable ceiling was the higher of €10 million or 2% of total worldwide annual turnover in the preceding financial year. The frequently cited GDPR ceiling of 4% applies to other categories of infringement. S06 S08
Mobius’s 2023 and 2024 revenue figures and the losses it cited are redacted in the published decision. The document therefore leaves the fine’s size relative to revenue or the benefit of the disputed reuse unquantifiable. Dividing the fine by the number of affected people would yield an amount per person, with no measure of the file’s profitability. S06
Timing matters as well. Mobius reported deleting its copy on 1 October 2023, before the December 2025 fine. The sequence separates reported deletion from the later penalty, while leaving the respective effects of the incident, the investigation and the client’s requests unresolved. S06
Restrictions reshape permitted uses
The Gravy Analytics–Venntel order, issued on 13 January 2025 and published on 14 January, contains no monetary payment requirement. It nevertheless restricts the use and supply of sensitive location data and imposes continuing controls. S13 S14
Its scope rests on precise definitions. The sensitive locations covered are in the United States. The definition of Location Data excludes specified security uses, national-security purposes conducted by federal bodies, and a federal law-enforcement response to an imminent risk of death or serious bodily harm. Activities may therefore remain permitted depending on their purpose and conditions. S13
The order also allows conversion into data that is no longer sensitive or falls outside its definition of Location Data. Another exception covers a service directly requested by a consumer with whom the business has a direct relationship and from whom it has obtained the required consent. These exceptions belong to this order and operate alongside other applicable rules. S13
At Mobilewalla, Section II targets sourcing. It prohibits acquiring or retaining covered information accessed through online advertising auctions for any purpose other than participating in those auctions. Data received to assess an advertising opportunity consequently loses one route to reuse. S04 S05
The commercial effect lies in uses removed from the catalogue or made more expensive. Measuring it would require comparing sources before and after intervention, replacement contracts and the margins of the affected products. A business can continue operating while losing some of its opportunities to exploit data.
Mobilewalla brings compliance into the transaction
The May 2026 agreement provides for notification to the FTC within fourteen days of closing, as required by the order. The proposed transaction thus accommodates continuing obligations after a change in corporate structure. S01
The companies’ announcement states a $250 million pre-money equity valuation and $13.9 million of annual recurring revenue as of 30 April 2026, or ARR. ARR annualises a recurring revenue base; it differs from accounting revenue recognised over a year. The valuation describes the proposed transaction’s terms. S03
A further step appears in the 12 August 2026 filing: the parties announced submission of a Form S-4 registration statement containing a preliminary prospectus and proxy statement. That filing still describes a proposed combination subject to conditions. S23
The contractual representations have a specific role. SPACSphere’s filing explains that they allocate risk between the parties, may be qualified by confidential disclosures and use materiality standards particular to the agreement. Publication reveals negotiated commitments; details of the acquirer’s diligence remain outside these documents. S02
For a buyer, the economic question is whether expected revenue rests on sufficiently secure usage rights. A dataset’s value also depends on the uses a future owner can continue and the cost of maintaining those rights. The Mobilewalla documents bring that issue into the transaction’s clauses, without isolating a dollar amount attributable to the FTC’s intervention.
Avast: from Jumpshot’s closure to consumer payments
Avast says it closed Jumpshot and ended its collection operation in January 2020. The company disputes the FTC’s characterisation of the facts. The final settlement followed on 26 June 2024, more than four years after the closure. S11 S12
On 2 December 2025, the FTC announced that it was sending nearly $15.3 million to 103,152 customers who had filed valid claims. That figure concerns payments sent through the methods selected by recipients. The $16.5 million required under the settlement and the money distributed to claimants represent different stages. S10 S09
This sequence places Jumpshot’s 2020 closure before the 2024 settlement. The agreement adds its own requirements: restrictions on future uses, treatment of data and certain derived products, a privacy programme and financial redress. Previously distributed files, examined in the preceding instalment, follow another process. S09
Oversight becomes a recurring expense
The Avast order requires an initial assessment covering the first 180 days, followed by independent assessments for successive two-year periods over twenty years. They must include technical testing and examine gaps in the programme. Findings must be grounded in the assessor’s work, including its methods, documents and results. Annual certifications by senior officers are required separately, with publication in the investor section of the website. S09
This framework requires time, expertise and access to systems. The European Data Protection Board takes a comparable approach to checking processors’ safeguards: contractual commitments need to be accompanied by examination of their implementation, calibrated to the risks. S22
Each case has its own timetable. The Kochava court order, signed on 25 June 2026 and published by the FTC on 26 June, gives Collective Data Solutions 90 days to establish its sensitive-location programme. It requires a compliance report after one year and runs for ten years. As of 19 September 2026, the first 90-day deadline has yet to expire. S15 S16
Assessing these arrangements means matching each obligation to its deadline, the systems covered and the recipient of the reports. The documents examined here set out the requirements while offering limited access to the detailed findings of internal and independent reviews.
DROP makes deletion an ongoing process
California’s Delete Request and Opt-out Platform, or DROP, centralises residents’ requests to data brokers covered by the law. Since 1 August 2026, those businesses have been required to download requests at least every 45 days. S17 S20
A broker prepares its identifiers, matches them against downloaded lists, deletes non-exempt information and returns a status. Information covered includes inferences: characteristics derived from other data. Processing obligations also extend to instructions for the relevant service providers and contractors. S18
The request persists. Brokers retain the minimum identifiers needed to honour it and compare them against newly collected records before sale or sharing. This exclusion mechanism serves the purpose of a suppression list, discussed in the previous instalment. It is designed to prevent the next purchased file from rebuilding a deleted profile. S18
The 2026 annual registration fee is $6,000, with an additional processing fee for electronic payments. CalPrivacy lists a potential penalty of $200 per day per request for failure to delete information as legally required. This is statutory exposure, distinct from a penalty already imposed. S20
Integration and repeated processing generate costs for brokers. A common platform may also simplify the receipt of requests previously arriving through separate channels. The net effect on expenses, let alone market concentration, would require business-level data absent from the documents examined here.
Two indicators with different denominators
CalPrivacy’s 25 August 2026 update reports more than 500,000 registered consumers and 654 brokers in the system. Approximately 25% of brokers reported processing requests. According to the agency, 99.9% of consumers had their profile deleted by at least one broker. S19
The first rate counts businesses; the second counts people. A consumer may obtain deletion from one broker while awaiting responses from others. The 99.9% figure describes that initial coverage, using a threshold of at least one deletion. The update relies on outcomes reported by brokers and does not measure the overall share of data erased.
Downloading and processing requests have separate deadlines. CalPrivacy describes downloads at least every 45 days, followed by processing and a response within 45 days of receipt. The first status may consequently take up to 90 days. Responses distinguish deleted data, exempt information, no match and certain cases of opting out of sale or sharing. S18 S21
The law requires independent audits from 1 January 2028, then every three years, alongside the authority’s enforcement powers. The first August 2026 results precede that audit cycle. Their date, population and reliance on broker reports remain essential to interpreting each indicator. S17
Value follows the right to use data
The six instalments have followed information from collection to buyers, derived products and residual copies. Enforcement intervenes at several points along this chain: access, permitted uses, historical holdings and the organisation of oversight.
A fine has a currency and a date. A restriction defines the services that remain permissible. A deletion requirement must be followed through datasets and their recipients. Reading these together gives a more precise account of a decision’s commercial effects than the headline amount alone.
Data’s value also depends on the right to keep using it. Rules can change that utility, require a different source or make exploitation more demanding. Evaluating their effectiveness still requires the margins of discontinued uses, compliance costs and sustained deletion outcomes. Public access to those detailed results varies across the cases examined here.
Read the six instalments
- The economics of collection
- The chain of intermediaries
- Turning traces into saleable profiles
- Buyers and their contracts
- The life of copies after the contract
- The cost of enforcement, this final instalment.
Sources and method
Research cut-off: 19 September 2026. CNIL decisions, US settlement orders, companies’ contractual representations and CalPrivacy updates are attributed according to their nature. US settlements contain their own provisions on admissions of allegations. The Mobius decision was consulted through Légifrance.
This analysis uses the cited public documents. It includes no access to company databases, DROP request campaign, interviews or audits conducted by l0g. The diagrams present possible economic effects of the remedies, a chronology and two published indicators. Mobilewalla’s revenue and valuation figures are attributed to the companies.
- S01 · Mobilewalla–SPACSphere: business combination agreement
- S02 · SPACSphere: transaction filing
- S03 · Mobilewalla–SPACSphere: transaction announcement
- S04 · Mobilewalla: final order
- S05 · Mobilewalla: publication of the order
- S06 · Mobius: decision SAN-2025-014
- S07 · CNIL: announcement of the Mobius fine
- S08 · GDPR: Article 83 and administrative fine ceilings
- S09 · Avast: complaint and final order
- S10 · FTC: payments to Avast customers
- S11 · Avast: Jumpshot settlement FAQ
- S12 · Avast: official case timeline
- S13 · Gravy–Venntel: complaint and final order
- S14 · Gravy–Venntel: official case timeline
- S15 · Kochava: signed court order
- S16 · Kochava: official case timeline
- S17 · California: Civil Code § 1798.99.86
- S18 · DROP: processing and following up requests
- S19 · DROP: 25 August 2026 update
- S20 · DROP: registration, fees and penalties
- S21 · DROP: implementing regulations
- S22 · EDPB: Opinion 22/2024 on processors
- S23 · Mobilewalla–SPACSphere: preliminary prospectus filing
This analysis is not investment advice.
// cite this analysis
l0g, “Personal data trade: the cost of enforcement”, l0g.fr, published September 19, 2026, updated September 19, 2026, https://l0g.fr/en/analysis/personal-data-trade-cost-of-enforcement/
$ cd ../analysis