California has entered a new phase of data privacy regulation. On August 1, 2026, the principal processing obligations under the California Delete Act became operational. Covered data brokers must now retrieve and process consumer requests submitted through the state’s Delete Request and Opt-Out Platform, commonly known as “DROP.”
The California Privacy Protection Agency recently reported that DROP has accumulated more than 345,000 active consumer requests and that over 600 data brokers are required to access the platform. These figures demonstrate why California Delete Act compliance should be treated as an immediate operational priority—not merely another privacy-policy update.
Businesses that buy, aggregate, analyze, license, exchange, or monetize personal information should determine whether they qualify as data brokers and whether their privacy infrastructure can satisfy the law’s recurring requirements.
What Is the California Delete Act?
The California Delete Act, enacted through Senate Bill 362, expanded California’s regulation of data brokers. Its centerpiece is DROP, a centralized platform through which a verified California resident can submit a single request directing registered data brokers to delete applicable personal information.
Before DROP, consumers generally had to identify and contact data brokers individually. DROP consolidates that process and allows a consumer to submit a request to all active data brokers or selectively exclude particular brokers.
The platform opened to California consumers on January 1, 2026. Beginning August 1, 2026, data brokers became responsible for accessing DROP and processing the requests assigned to them.
The Delete Act operates alongside the California Consumer Privacy Act and California Privacy Rights Act. It does not replace the rights and obligations established by those laws.
Which Businesses Qualify as Data Brokers?
Under California Civil Code Section 1798.99.80, a data broker generally means a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship.
This category is not necessarily limited to traditional people-search websites or companies that sell mailing lists. Depending on their practices, advertising-technology companies, lead generators, analytics providers, identity-resolution services, location-data providers, and artificial-intelligence companies may qualify.
California’s regulations provide that a direct relationship ordinarily requires an intentional interaction in which the consumer accesses, purchases, uses, requests, or obtains information about the business’s products or services. Merely collecting information directly from an individual does not necessarily establish a direct relationship if the individual did not intend to interact with that business.
A company may also have a direct relationship with a consumer for one purpose while operating as a data broker with respect to information obtained outside that first-party interaction. Businesses should therefore examine their information sources and downstream disclosures rather than relying exclusively on their general business classification.
Certain entities or activities governed by laws such as the Fair Credit Reporting Act, Gramm-Leach-Bliley Act, California Insurance Information and Privacy Protection Act, or specified healthcare privacy laws may be excluded to the extent provided by statute. These exclusions may apply only to particular information or activities rather than the entire organization.
Registration and DROP Account Requirements
A business that operated as a data broker during the preceding calendar year generally must register with the California Privacy Protection Agency during the January 1–31 registration period. Registration requires submitting specified information, paying the applicable fee, and maintaining a DROP account.
A business beginning data-broker operations after the annual registration period must create its DROP account before commencing covered operations. It must begin accessing DROP within 45 calendar days after commencing operations and pay the applicable first-time access fee unless it already paid the annual registration fee for that year. It must then complete annual registration during the following January registration period.
Registration disclosures address numerous information practices, including whether the broker collects identifiers, precise geolocation, biometric information, reproductive healthcare data, information about minors, mobile advertising identifiers, or other sensitive information. Brokers may also need to disclose specified relationships involving government agencies, law enforcement, foreign actors, and generative-AI developers.
The 45-Day DROP Compliance Cycle
A covered data broker must access DROP at least once every 45 calendar days. “Access” means retrieving the appropriate consumer deletion lists—not simply signing into the account.
The regulations permit manual or automated access. However, if the broker cannot timely retrieve its lists through an automated connection for any reason, it must manually download them through its DROP account. If an automated connection fails for reasons that are not the broker’s fault, the broker must also notify the agency as prescribed by the regulations.
After retrieving the appropriate list, the broker must compare the hashed consumer identifiers supplied through DROP with corresponding information in its records. The regulations contain detailed standardization requirements concerning names, dates of birth, ZIP Codes, telephone numbers, email addresses, and hashing procedures.
When an identifier matches, the broker generally must delete all covered personal information associated with it, including qualifying inferences generated from information obtained from third parties or outside a first-party relationship. The broker must also direct its service providers and contractors to delete covered information in their possession.
If a request cannot be verified because, for example, an identifier corresponds to multiple consumers, the broker generally must process the request as an opt-out of the sale or sharing of the associated information. A broker may not contact the consumer to verify a DROP request.
The broker must report the status of requests through DROP using the appropriate response designation, including “record deleted,” “record opted out of sale,” “record exempted,” or “record not found.”
Deletion Is an Ongoing Obligation
The Delete Act does not contemplate a one-time database purge. After honoring a request, the broker generally must ensure that covered information remains deleted and must not sell or share newly acquired personal information concerning that consumer unless the consumer changes the request or a legal exemption applies.
Even when no matching record is initially found, the broker must maintain the relevant deletion information for the limited purpose of comparing it against information acquired later. This suppression procedure is intended to prevent deleted information from being reacquired and returned to commercial circulation.
Compliance should therefore extend across active systems, archived information, data warehouses, vendors, contractors, analytics tools, and other relevant environments. A procedure addressing only a customer-facing database will probably be insufficient.
Exemptions Must Be Applied Carefully
The law recognizes circumstances in which information need not be deleted, including specified exceptions incorporated from the California Consumer Privacy Act. The regulations also distinguish certain information collected directly through a first-party interaction.
However, information retained under an exemption generally may be used only for the purpose supporting the exemption and not for unrelated purposes such as marketing. Businesses should document the legal and factual basis for each exemption.
Information contained in archived or backup systems may, under specified circumstances, remain until the system is restored or accessed for a sale, disclosure, or other commercial purpose. Backup-restoration procedures should account for this limitation.
Penalties and Audit Requirements
Noncompliance can create substantial financial exposure. A data broker that fails to satisfy the deletion requirements may face an administrative fine of $200 for each deletion request for each day the broker fails to delete the information, along with reasonable investigation and administrative expenses.
Failure to register may result in a separate $200-per-day administrative fine, unpaid registration fees, and enforcement costs. Because DROP transmits requests at scale, even a short operational failure could generate substantial potential penalties.
Beginning January 1, 2028, data brokers must undergo an independent third-party compliance audit every three years. Audit reports and related materials must be retained for at least six years and provided to the agency within five business days after a written request.
Practical California Delete Act Compliance Steps
Potentially covered businesses should:
- Determine whether their practices satisfy California’s data-broker definition.
- Map personal information acquired outside direct consumer relationships.
- Confirm their registration and DROP-account status.
- Assign responsibility for the recurring 45-day access cycle.
- Test identifier standardization, hashing, matching, deletion, and reporting.
- Update service-provider and contractor procedures.
- Establish a documented suppression process for future information.
- Preserve compliance records in anticipation of enforcement or audit review.
- Maintain manual backup procedures for automated-access failures.
- Review claimed exemptions with qualified privacy counsel.
California’s Delete Act transforms consumer deletion from an isolated response function into a recurring data-governance obligation. Businesses that may qualify as data brokers should promptly assess their status, implement reliable DROP procedures, and reduce the risk of accumulating administrative penalties.
Internet Lawyer Blog

