The 60-second summary
California’s Delete Request and Opt-out Platform (DROP) has moved into production processing. Since 1 August 2026, covered data brokers must access DROP at least once every 45 calendar days, download their selected consumer deletion lists, standardise and hash relevant identifiers, match requests against their records, process deletion or opt-out outcomes, and report request status. A matched request reaches personal information associated with the identifier—including relevant inferences—and must also be carried through to service providers and contractors, subject to statutory exceptions. Brokers must preserve deletion preferences for future collections and prevent renewed sale or sharing unless the consumer changes the request or an exception applies. CalPrivacy states that production access is now available and warns that failure to delete can attract a $200-per-request-per-day administrative fine, plus costs.
Timeline that matters
10 October 2023
Delete Act enacted
California enacted SB 362, requiring a statewide accessible deletion mechanism for registered data brokers.
6 November 2025
Final regulations approved
The Office of Administrative Law approved the DROP regulations and filed them with the Secretary of State.
1 January 2026
Rules and consumer requests begin
The regulations took effect and California residents could begin submitting DROP requests.
1 August 2026
Broker processing duty begins
Covered data brokers must access DROP at least once every 45 days and process applicable requests.
Every 45 calendar days
Recurring operating cycle
Brokers retrieve new or amended requests, process them, maintain suppression and report statuses through DROP.
1 January 2028
Independent audit cycle begins
Data brokers must undergo an independent compliance audit every three years and retain supporting reports and materials for at least six years.
What changed
The Delete Act and implementing regulations were already final, but the operational phase is now live. Consumer requests have been available since January 2026; from 1 August 2026, data brokers must actually retrieve and process them through DROP. The final rules turn the obligation into a repeatable technical workflow: retrieve lists at least every 45 days, standardise and hash broker-held identifiers using the supplied algorithm, match records, delete covered data or apply the required opt-out treatment, direct service providers and contractors, retain the minimum information needed for continuing suppression, and return a prescribed status code at the next access session. Logging into DROP without retrieving a deletion list does not count as access.
Who should pay attention?
Registered California data brokers
Production processing is active. Access must include retrieving the relevant deletion lists, not merely signing in.
New data brokers
A business beginning data-broker operations after 1 August 2026 must create its DROP account before operating and begin access within the applicable timeframe.
Engineering and data operations
The rules prescribe standardisation, hashing, matching, deletion, suppression and status-reporting steps that need tested production workflows.
Service providers and contractors
Covered brokers must direct associated providers and contractors to delete matched personal information and support ongoing compliance.
Global vendors with California data
Location outside California does not by itself answer scope. Teams should assess whether their activities meet the statutory data-broker definition and whether exclusions apply.
What the guidance clarifies
- 45-day recurring access
- A data broker must download its selected consumer deletion lists at least once every 45 calendar days; a sign-in without retrieval is not sufficient.
- Matching workflow
- Relevant identifiers in broker records must be standardised and hashed using the algorithm supplied with the consumer list before comparison.
- Deletion scope
- For a matched identifier, covered personal information includes relevant inferences. Statutory exemptions and first-party data distinctions require careful application.
- No-match is not the end
- Deletion lists for unmatched requests must be retained for the limited purpose of checking newly collected records before personal information is sold or shared.
- Status reporting
- At each later access session, brokers report outcomes for requests from the previous session using prescribed response codes.
Global relevance — scope depends on your data activities
Why this matters for global organisations
Analytics, lead-generation, identity, advertising, enrichment, fraud-prevention, people-data and data-resale providers may handle information about individuals in a regulated market or support a covered organisation. Applicability depends on the relevant statutory definitions, exclusions, business thresholds, customer relationships and processing activities—not simply the provider’s location.
- Map personal information associated with the regulated market and determine whether it was collected outside a direct customer relationship.
- Treat deletion readiness as both a legal and technical control: matching, deletion, suppression, vendor propagation and evidence must work together.
- Review global vendor contracts so downstream processors can meet deletion and evidence requirements within the applicable operating cycle.
- Do not assume existing privacy workflows automatically satisfy another regime’s identifiers, response codes, recurring suppression or platform-access requirements.
- Even organisations outside direct regulatory scope may benefit from stronger deletion orchestration and supplier assurance.
12 actions to start now
- Confirm whether each relevant entity and business line meets California’s statutory data-broker definition; document exclusions and the direct-relationship analysis.
- Verify DROP account approval, registration status, fee payment and the selected consumer deletion lists for every covered entity.
- Assign an accountable owner and calendar the recurring cycle so list retrieval never exceeds 45 calendar days.
- Implement both automated and manual download procedures; document the fallback when an automated connection fails.
- Map every system, dataset, archive, backup, inference store, service provider and contractor that may contain personal information associated with a matched identifier.
- Build and test the prescribed identifier standardisation and hashing process, including multi-identifier combinations and collision or multiple-consumer scenarios.
- Define outcome logic for deletion, opt-out, exemption and record-not-found cases; require legal review for exemption rules and first-party distinctions.
- Propagate deletion and opt-out instructions to service providers and contractors, with completion evidence and escalation deadlines.
- Maintain the minimum restricted-use information needed to honour future suppression and check newly collected records before sale or sharing.
- Upload accurate status codes during the next DROP access session and reconcile transaction identifiers to internal case records.
- Test permanent deletion across active, archived and backup environments, including the rule governing delayed deletion when backups are restored or commercially accessed.
- Update vendor contracts, privacy procedures, incident response and audit readiness for the 2028 independent-audit requirement.
Evidence worth retaining
- Documented entity-by-entity data-broker scope assessment, including exclusions and direct-relationship reasoning.
- DROP account, registration and fee records, plus the selected-list configuration.
- Timestamped retrieval logs proving access at least every 45 calendar days.
- Version-controlled standardisation, hashing and matching specifications with test results.
- Per-request audit trail linking transaction ID, match result, action, exception basis, status code and completion time.
- Deletion proof across databases, inference stores, archives and backup-restoration workflows.
- Service-provider and contractor instructions, acknowledgements and completion confirmations.
- Suppression controls and restricted-purpose retention records for matched and unmatched requests.
- Automated-connection monitoring, failure notices to CalPrivacy and manual-download fallback logs.
- Copies of status uploads and reconciliation reports from each DROP cycle.
- Policies, training records and incident/escalation logs.
- Independent-audit preparation files and the eventual audit report retention schedule.
Questions to take to counsel or your conformity team
These are discussion prompts, not legal advice or conclusions.
- Which legal entity is the data broker, and do any products combine first-party and brokered data in ways that need separate treatment?
- Which statutory exemptions apply, and is the retained information limited to the permitted purpose?
- Can the matching method meet the regulations without creating avoidable identity-matching or security risk?
- How will multiple consumers tied to one identifier be handled under the required opt-out path?
- Do deletion instructions contractually and technically reach every service provider, contractor, subprocessor, archive and inference store?
- How will unmatched identifiers be retained securely and checked against newly collected data without reuse for another purpose?
- Does the backup process prevent restored data from re-entering sale, sharing or other commercial use before deletion?
- Who certifies each status response, and what evidence can be retrieved quickly for a CalPrivacy investigation or audit?
- Do cross-border data flows or distributed operations affect where matching, deletion and evidence are performed, while leaving California scope unchanged?
Official sources
- CalPrivacy — DROP for data brokers (production processing now available)
- California Privacy Protection Agency — Information for data brokers
- California Privacy Protection Agency — Final DROP regulations and rulemaking record
- California Privacy Protection Agency — Final text of DROP regulations
- California Legislature — SB 362 (Delete Act), Chapter 709
PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.
PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.