5 min read

On August 1, 2026, the California Delete Act stopped being a registration formality and became an enforcement deadline. Data brokers are now required to log into the state's Delete Request and Opt-Out Platform, known as DROP, at least every 45 days, match consumer identifiers against their own systems, delete what matches, and report back to the California Privacy Protection Agency (CalPrivacy) on the outcome of every request. Every registered broker now has to produce, for any single request, proof of exactly what was deleted, when, and where.
DROP is built to test that kind of proof directly.
DROP lets a Californian file one verifiable request that reaches every registered data broker at once, instead of contacting each broker separately. Each request functions as both a deletion request and an opt-out, so even a data broker that can't verify someone's identity still has to opt that person out of having their data sold or shared. Consumers get a DROP ID to track the outcome for each broker: Deleted, Opted Out, Exempted, or Record Not Found.
The platform opened to consumers on January 1, 2026. By early August, more than 345,000 deletion requests had already been submitted, and that number climbs with every 45-day cycle brokers are required to pull from the system.
The Delete Act defines a data broker as a business that knowingly collects and sells third-party consumers' personal information without a direct relationship with them. As of this year, more than 600 companies had registered with CalPrivacy under that definition.
The obligation doesn't stop at the registered broker. Every data broker must direct its own third-party service providers and contractors to delete matched data too, which means the practical reach of DROP extends well beyond the 600 companies that filed paperwork. A B2C company that has never registered as a data broker can still receive a deletion instruction indirectly, through a broker it sends data to.
Registration happens every January, and the cost of it just went up. CalPrivacy's 2027 registration fee rises to $9,500, an increase of $3,500 over 2026. Missing the January 31 registration deadline carries its own administrative penalty, separate from the deletion-processing fines below.
SB 361, signed into law in late 2025, raised the stakes further. It doubled the daily fine for failing to process a deletion request to $200 per request, per day, and added new disclosure obligations: data brokers must now tell CalPrivacy whether they collect sensitive categories such as biometric data, immigration status, or government identifiers, and whether they've shared consumer data with foreign actors, government entities, law enforcement, or generative AI developers.
There's no cure period built into any of this. If CalPrivacy finds a data broker hasn't processed requests on schedule, the fines start accruing immediately, and they stack for every day and every request left unresolved.
The next governance layer is already forming. CalPrivacy's board met on August 7 to begin the formal rulemaking process for DROP compliance audit regulations, which are set to take effect January 1, 2028. When they do, a written record of intent won't be what auditors ask for. They'll ask for evidence: which identifiers were checked, which systems were queried, what each request's final determination was, and when it happened.
Regulators are moving from asking whether a policy exists to asking whether a system enforced it, record by record, and California isn't the only place this is happening. A privacy policy that describes your deletion process is a starting point. Proving that a specific consumer's data was actually deleted from a specific system on a specific date is a different task entirely, and it's the one the incoming audit regime is built to demand.
See how privacy, legal, and risk teams are preparing for DROP audits at Transcend for Privacy, Legal & Risk →
Privacy & Legal leadersFor teams still running this process manually, DROP is likely one of the largest data initiatives they've taken on. Two steps below are the heaviest lifts, since both require new infrastructure rather than a policy update.
See how engineering and product teams automate deletion and opt-out at scale at Transcend for Engineering & Product →
Engineering & Product TeamsTranscend automates the roadmap above rather than leaving it to a manual build:
Data brokers including ZoomInfo and financial platforms like GoCardless have used Transcend to move deletion and opt-out processing from a manual, days-long task to a system that runs on its own schedule.
Enforcement is now the operating reality for every registered data broker, and the audit regime coming in 2028 raises the bar further. The organizations that treat DROP as a one-time compliance project will be rebuilding this process again in two years. The ones that treat it as infrastructure won't have to.
Talk to us about DROP compliance
Contact usJuly 17, 2026