5 min read

California continues to be on the forefront of data privacy in the U.S., with its Data Broker Requests and Opt-out Platform (DROP), which launched January 1, 2026. Part of the Delete Act, DROP has brought profound new operational challenges to businesses while simultaneously making it easier than ever for individuals to exercise their data rights.
Passed in late 2023, California’s Delete Act imposed new regulatory requirements on data brokers, including:
The DROP platform is the latest and arguably most important addition to the Delete Act, acting as one of the main data privacy drivers of 2026. But in many ways, this represents a new paradigm much bigger than privacy alone, pushing Compliance teams to work side-by-side with Engineering and Data teams more than ever.
In a world where tech stacks and data infrastructure need to always be right about which data can be used for which situations, regulation that both empowers consumers more than ever and creates hundreds of thousands of additional data requests for organizations will serve as a critical stress test for data infrastructure at-large.
For every organization rushing to be able to clearly answer the question “Can I use this data?”, DROP will show which data infrastructure set-ups can match any level of scale and complexity and which set-ups are underutilizing data and opening the organization up to risk.
The Data Broker Requests and Opt-Out Platform is a centralized system developed and enforced by the California Privacy Protection Agency (recently rebranded as CalPrivacy).
Designed to simplify how consumers exercise their data rights, DROP enables Californians to submit a single centralized request to all registered data brokers to delete their personal information and opt out of the sale or sharing of that information.
The platform went live to the public on January 1, 2026, with over 300,000 people and counting signed up as of early June. Given that tremendous volume, the regulation has been staggered for data brokers, with the deadline to begin processing requests submitted through DROP set at August 1, 2026.
DROP significantly broadens consumer control over their personal information by streamlining the deletion request process.
Where previously an individual would need to send requests to dozens if not hundreds of companies, they can now authenticate their identity once within the platform to send out deletion and opt-out requests to all registered data brokers. This allows individuals to practice their data rights quickly and easily, marking a significant step forward for the consumer-friendliness of data privacy within the U.S.
A DROP request acts as both a deletion and an opt-out, so even if a data broker cannot verify the deletion request, they must treat the request as a Do Not Sell or Share opt-out.
Consumers receive a DROP ID to check the status of their requests and see the final result from each data broker (e.g., Deleted, Opted Out, Exempted, or Record Not Found).
Compliance with the Delete Act and mandatory participation in DROP is required for any business that qualifies as a data broker under California law.
A data broker is defined as “a business that knowingly collects and sells third-party consumers' personal information without having a direct relationship with them.”
As of January 2026, nearly 600 companies had registered as a data broker with CalPrivacy, with that number expected to continue growing.
While data brokers will be directly responsible for checking and processing all consumer requests coming through the DROP system, the new platform will have a wider impact on business as well.
Data brokers will need to disseminate requests to their third-party systems, meaning a wide range of companies–particularly B2C–are in line to see a significant increase in the number of user data requests they receive throughout 2026 and beyond.
Data brokers must prepare their systems for two main obligations: annual registration and processing DROP requests.
1. Annual Registration
2. Processing DROP Requests
Data brokers must have an active DROP account and be prepared to process requests starting August 1, 2026, pulling new rolls from the system at least every 45 days.
To help facilitate the work, CalPrivacy released the full API spec and opened a sandbox environment in April 2026. Once data brokers receive the DROP requests, they must:
Failure to process deletion requests starting August 1, 2026, may incur financial penalties of $200 per request per day (stacked on top of a potential $200 per day fine for failing to register as a data broker). Since the Delete Act has no cure period, enforcement can be swift if CalPrivacy detects noncompliance.
The scope and scale of DROP are massive, likely posing as one of the largest data initiatives many teams have ever worked on. While data brokers are used to receiving thousands of requests per month, DROP will likely see that number up to double, with the initial August 1 deadline bringing a tsunami of hundreds of thousands of requests.
For organizations that still have manual processes or limited legacy solutions in place to complete data subject requests, here are the technical steps to take to prevent the DROP-related increase in requests from becoming an all-encompassing responsibility or breaking data infrastructure..
While these steps could be challenging for any organization without dedicated privacy engineering, steps 2 and 7 are heavy lifts in particular given they require new infrastructure to connect the DROP API to the organization's technical solution.
The above roadmap for technical readiness might be challenging without a proven data privacy platform, but Transcend automates those tasks and limits risk from data brokers’ DROP compliance thanks to our unique technical capabilities:
Managing user requests at-scale is about efficiency and proper data infrastructure. Only Transcend has the integrations and capability to stand up to the scale of DROP, proven by the platform saving organizations thousands of hours a year, from data brokers like ZoomInfo to customer-facing financial organizations like GoCardless.
With data brokers now just weeks away from the August 1 processing deadline, and the quantity of requests and stakes to process them higher than ever in 2026, preparing for this fundamental change in data decisioning is vital for success.
Interested in seeing how Transcend can help with DROP compliance? Let's talk
Interested in seeing how Transcend can help with DROP compliance? Let’s talk
Contact usBy James Grieco
Senior Product Marketing Manager I