AI & Privacy · guide
The California Delete Act and the DROP Platform: Data Broker Duties Explained
Updated
California's Delete Act (SB 362, signed in 2023) turned a modest data broker registry into a full compliance regime. Brokers must register every year, process consumer deletion requests through a single state-run platform, and submit to periodic independent audits. The California Privacy Protection Agency (CPPA) enforces it and has been doing so steadily. This guide walks through the statute, Civil Code section 1798.99.80 and following, and the platform it created. Details are current at time of writing (September 2026).
Who is a data broker
Under Civil Code 1798.99.80, a data broker is a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship. Entities already regulated by the Fair Credit Reporting Act, the Gramm-Leach-Bliley Act, California's Insurance Information and Privacy Protection Act, and certain health-data provisions are excluded. The definition catches many companies that do not think of themselves as brokers, including marketing-data resellers, people-search sites and analytics vendors, which is why several enforcement actions have involved firms that simply never registered.
Annual registration
Section 1798.99.82 requires a data broker to register with the CPPA on or before January 31 of each year following a year in which it met the definition. Registration includes paying a fee set by the agency and disclosing information about the broker's practices, such as whether it collects data on minors, precise geolocation or reproductive health, and how consumers can exercise their rights. The registry is public at privacy.ca.gov.
Failure to register carries an administrative fine of 200 dollars for each day the broker is unregistered, plus the unpaid fees and the agency's investigation costs.
DROP: the Delete Request and Opt-out Platform
The centerpiece of the law is section 1798.99.86. It required the CPPA to build an accessible deletion mechanism by January 1, 2026, through which a Californian can submit a single request that reaches every registered broker. The agency launched DROP on that date, and says a request currently reaches more than 600 registered brokers.
| Date | Broker obligation |
|---|---|
| January 1, 2026 | Consumers can submit deletion requests through DROP |
| August 1, 2026 | Brokers must begin accessing DROP and processing requests |
| Every 45 days thereafter | Brokers must check DROP and delete the personal information of each requesting consumer within 45 days |
| November 2026 | By this point every registered broker should have completed a first upload and download cycle, per the CPPA |
Deletion is not one-time. The statute treats a DROP request as a standing instruction: after the initial deletion, the broker must continue to delete data about that consumer at least every 45 days and must not sell or share new data about them, unless the consumer withdraws the request. Where a broker cannot verify a request, the request is treated as an opt-out of sale.
Failure to delete carries an administrative fine of 200 dollars for each deletion request for each day the broker fails to delete, again with fees and costs on top. For a broker with thousands of pending requests, the exposure compounds quickly.
Audits and record-keeping
Beginning January 1, 2028 and every three years after, a data broker must undergo an audit by an independent third party to determine compliance with the deletion and opt-out duties. The broker must keep the audit report and supporting materials for at least six years and provide them to the CPPA on request within a short statutory window.
Enforcement so far
The CPPA began bringing registration cases in late 2024 and has continued at a steady pace. Examples from the agency's own announcements:
- January 8, 2026: fines of 45,000 dollars against Rickenbacher Data (Datamasters) and 62,600 dollars against S&P Global for failing to register, per the CPPA announcement.
- August 2026: an action against LocateSmarter, described by the agency as its first brought under both the CCPA and the Delete Act, followed within days by a 52,400 dollar fine against Cybba for missing the 2025 registration deadline, per the CPPA announcement.
- September 1, 2026: a 36,400 dollar fine against SalesIntel Research, per the CPPA announcement.
The agency's enforcement division operates a Data Broker Enforcement Strike Force, and its settlement orders now routinely require the broker to access DROP and process deletion requests, not only to register. With the August 1, 2026 processing deadline now past, expect the next wave of actions to target brokers that registered but are not deleting.
Compliance checklist
- Decide whether you meet the definition; if the answer is close, get counsel's view in writing.
- Register by January 31 and diarize it annually.
- Build a workflow to download the DROP list every 45 days, match records, delete, and log the outcome.
- Suppress re-acquisition of data about consumers who have submitted DROP requests.
- Plan for the first independent audit in 2028 and keep records for six years.
RegPing's AI and privacy bot posts CPPA data broker enforcement announcements like these into Discord as they are published.
Where to verify
- Civil Code 1798.99.80 to 1798.99.89, Delete Act text
- SB 362 bill history and text
- CPPA DROP platform
- About DROP and the Delete Act
- Data broker registration regulations
- CPPA news and enforcement announcements
This guide is general information, not legal advice. Verify against the primary source and consult counsel before acting.
Questions people ask
When must data brokers start processing DROP requests?
Beginning August 1, 2026, registered data brokers must access DROP at least once every 45 days and delete the personal information of each requesting consumer within 45 days. Consumers have been able to submit requests since January 1, 2026.
What is the penalty for not registering as a data broker in California?
An administrative fine of 200 dollars for each day the broker fails to register, plus unpaid registration fees and the CPPA's investigation costs. Recent settlements have ranged from roughly 36,000 to 63,000 dollars.
When do Delete Act audits begin?
Beginning January 1, 2028 and every three years after, brokers must obtain an independent third-party audit of their deletion compliance and retain the report for at least six years.