Out of curiosity, does anyone know how this is enforceable for a company not based in California? Can CA fine a data broker that is based in another state but that is selling CA residents' information?
The company would have to not have any interstate presence at all. If you are a business based in the united states that has customers in California, you are easily reachable under California law.
[dead]
Yes; the nexus for legal purposes is generally the location of the user, not the broker