CalPrivacy's DROP platform: A legal and engineering roadmap for DROP compliance

5 min read

The image showcases the dome of a government building against a blue sky, with an American flag flying. Text on the left reads, "A legal and engineering roadmap for DROP readiness," along with a button labeled "Privacy Law."

You documented the California Delete Act. Can you prove it held?

On August 1, 2026, the California Delete Act stopped being a registration formality and became an enforcement deadline. Data brokers are now required to log into the state's Delete Request and Opt-Out Platform, known as DROP, at least every 45 days, match consumer identifiers against their own systems, delete what matches, and report back to the California Privacy Protection Agency (CalPrivacy) on the outcome of every request. Every registered broker now has to produce, for any single request, proof of exactly what was deleted, when, and where.

DROP is built to test that kind of proof directly.

What the California Delete Act and DROP actually require

DROP lets a Californian file one verifiable request that reaches every registered data broker at once, instead of contacting each broker separately. Each request functions as both a deletion request and an opt-out, so even a data broker that can't verify someone's identity still has to opt that person out of having their data sold or shared. Consumers get a DROP ID to track the outcome for each broker: Deleted, Opted Out, Exempted, or Record Not Found.

The platform opened to consumers on January 1, 2026. By early August, more than 345,000 deletion requests had already been submitted, and that number climbs with every 45-day cycle brokers are required to pull from the system.

Are you a data broker under the Delete Act?

The Delete Act defines a data broker as a business that knowingly collects and sells third-party consumers' personal information without a direct relationship with them. As of this year, more than 600 companies had registered with CalPrivacy under that definition.

The obligation doesn't stop at the registered broker. Every data broker must direct its own third-party service providers and contractors to delete matched data too, which means the practical reach of DROP extends well beyond the 600 companies that filed paperwork. A B2C company that has never registered as a data broker can still receive a deletion instruction indirectly, through a broker it sends data to.

The deadlines and fines already in motion

Registration happens every January, and the cost of it just went up. CalPrivacy's 2027 registration fee rises to $9,500, an increase of $3,500 over 2026. Missing the January 31 registration deadline carries its own administrative penalty, separate from the deletion-processing fines below.

SB 361, signed into law in late 2025, raised the stakes further. It doubled the daily fine for failing to process a deletion request to $200 per request, per day, and added new disclosure obligations: data brokers must now tell CalPrivacy whether they collect sensitive categories such as biometric data, immigration status, or government identifiers, and whether they've shared consumer data with foreign actors, government entities, law enforcement, or generative AI developers.

There's no cure period built into any of this. If CalPrivacy finds a data broker hasn't processed requests on schedule, the fines start accruing immediately, and they stack for every day and every request left unresolved.

The next governance layer is already forming. CalPrivacy's board met on August 7 to begin the formal rulemaking process for DROP compliance audit regulations, which are set to take effect January 1, 2028. When they do, a written record of intent won't be what auditors ask for. They'll ask for evidence: which identifiers were checked, which systems were queried, what each request's final determination was, and when it happened.

Why documentation alone won't survive an audit

Regulators are moving from asking whether a policy exists to asking whether a system enforced it, record by record, and California isn't the only place this is happening. A privacy policy that describes your deletion process is a starting point. Proving that a specific consumer's data was actually deleted from a specific system on a specific date is a different task entirely, and it's the one the incoming audit regime is built to demand.

See how privacy, legal, and risk teams are preparing for DROP audits at Transcend for Privacy, Legal & Risk →

Privacy & Legal leaders

An engineering roadmap for DROP readiness

For teams still running this process manually, DROP is likely one of the largest data initiatives they've taken on. Two steps below are the heaviest lifts, since both require new infrastructure rather than a policy update.

  1. Connect to CalPrivacy's API sandbox, live since April 2026. Manually downloading lists doesn't hold up at this volume.
  2. Set up a scheduled job to pull the latest batch of consumer deletion lists from DROP at least every 45 days.
  3. Inventory your identifiers. Know which identifier types, such as email or phone, your organization actually holds before you try to match against them.
  4. Standardize identifier formatting before matching. CalPrivacy's own hashing process expects specific formats, dates as eight-digit strings, phone numbers as the last 10 digits with no dashes, so a mismatch in formatting looks like a mismatch in identity. Map each identifier to every other identifier your systems associate with the same person.
  5. Query every system that holds consumer data, from databases and warehouses to SaaS tools, and forward matched deletions downstream to any third-party processor that also holds the data.
  6. Build a suppression list. Even unverified requests require an opt-out from sale and sharing, so identifiers need to be blocked from future use regardless of whether deletion could be confirmed.
  7. Automate status reporting back to DROP. This is the other heavy lift: a live feedback loop, not a quarterly export.
  8. Keep timestamped audit logs of which identifiers were checked, which systems were queried, and what each request's final determination was.

See how engineering and product teams automate deletion and opt-out at scale at Transcend for Engineering & Product →

Engineering & Product Teams

How Transcend closes the gap between policy and proof

Transcend automates the roadmap above rather than leaving it to a manual build:

  • Automated ingestion pulls raw DROP registry files directly, on schedule, without a person downloading anything
  • Identifier matching runs automatically across the identifier types DROP requires, without manual verification for every record
  • Deep deletion and opt-out propagates each determination through connected systems and downstream providers, not just the system where the request first landed
  • Audit-ready logs retain the determination, timestamp, and systems touched for every request, so the evidence already exists before an auditor asks for it

Data brokers including ZoomInfo and financial platforms like GoCardless have used Transcend to move deletion and opt-out processing from a manual, days-long task to a system that runs on its own schedule.

Enforcement is now the operating reality for every registered data broker, and the audit regime coming in 2028 raises the bar further. The organizations that treat DROP as a one-time compliance project will be rebuilding this process again in two years. The ones that treat it as infrastructure won't have to.

Talk to us about DROP compliance

Contact us

A blue circular pattern with a solid dot at the center surrounded by evenly spaced, curved lines radiating outward.

By Transcend Team

July 17, 2026

Share this article