California has entered a new phase of data privacy regulation. On August 1, 2026, the principal processing obligations under the California Delete Act became operational. Covered data brokers must now retrieve and process consumer requests submitted through the state’s Delete Request and Opt-Out Platform, commonly known as “DROP.”
The California Privacy Protection Agency recently reported that DROP has accumulated more than 345,000 active consumer requests and that over 600 data brokers are required to access the platform. These figures demonstrate why California Delete Act compliance should be treated as an immediate operational priority—not merely another privacy-policy update.
Businesses that buy, aggregate, analyze, license, exchange, or monetize personal information should determine whether they qualify as data brokers and whether their privacy infrastructure can satisfy the law’s recurring requirements.


