California's Delete Act Deletion Mandate Takes Effect: Data Brokers Must Now Process DROP Requests Every 45 Days

California's Delete Act Deletion Mandate Takes Effect: Data Brokers Must Now Process DROP Requests Every 45 Days
As of August 1, 2026, California data brokers face a new operational duty under the Delete Act (SB 362): they must log into the state's DROP platform at least once every 45 days, retrieve consumer deletion requests, and report back the status of each one, under Cal. Civ. Code sec. 1798.99.80 et seq.
Information last verified on August 5, 2026. This is a developing story; we update it as the record changes.
Jurisdiction scope: This obligation applies in California, to data brokers that collect and sell personal information of California residents. For background on the underlying registration regime, see our US data broker registration laws and Delete Act overview.
What Happened
August 1, 2026 is the compliance date on which registered data brokers must start actively working the DROP queue rather than simply existing on the registry. Under the Delete Act, data brokers are required to access DROP at least every 45 days, retrieve any consumer deletion requests that have accumulated since their last visit, and process the matches against their own records, according to the California Privacy Protection Agency's data broker guidance page.
The consumer-facing side of DROP has already been running for seven months. California residents gained the ability to submit one deletion request through DROP, addressed to every active, registered data broker at once, starting January 1, 2026, per the CPPA. Requests filed since then have been sitting in the platform waiting for brokers to retrieve them; August 1 is the date brokers are required to start pulling that queue on a recurring schedule.
When a broker finds a match between a DROP request and its own held data, the statute requires it to delete all of that consumer's associated personal information, including inferences the broker has generated from the raw data, unless a specific statutory exemption applies. The broker must then report the status of that request back into DROP within 45 days of having retrieved it, and, per the CPPA's guidance, must continue to honor that deletion so the consumer's information stays deleted going forward rather than reappearing the next time the broker refreshes its data.
DROP itself is a CPPA-built platform, separate from (but linked to) the CPPA's pre-existing Data Broker Registry, on which every business that meets the statutory definition of "data broker" is already required to register annually between January 1 and January 31 and pay a registration fee. SB 362 (Chapter 709, Statutes of 2023) is the bill that created both the Delete Act's deletion mandate and directed the CPPA to build DROP; it is codified starting at Cal. Civ. Code sec. 1798.99.80.

What the Law Actually Says
The Delete Act adds a distinct layer on top of two things that already existed in California data-broker law: the annual registration requirement, and each consumer's individual right to request deletion of their own data under the CCPA/CPRA. DROP does not replace either. It is a third mechanism, a single, government-run point where a consumer can trigger deletion across every registered broker at once instead of filing a separate request with each one, our guide to opting out of data brokers covers the manual, per-broker alternative that still exists.
The statute treats two different failures with two different, specifically numbered penalties, and reporting on the Delete Act should not conflate them:
- Failure to register. A data broker that misses the January 31 annual registration deadline can face an administrative fine, plus the CPPA's costs of investigation, in an action under Civil Code section 1798.99.82(d). CPPA enforcement communications describe that registration fine as $200 per day the broker remains unregistered, and the agency has already settled multiple registration-based enforcement actions on that basis.
- Failure to process a deletion request. Separately, Civil Code section 1798.99.82 authorizes an administrative fine of $200 per deletion request for each day a data broker fails to delete a consumer's information as the statute requires, once that broker has retrieved the request through DROP. That is the penalty that becomes operative now that the August 1 processing duty is live, since it attaches to a broker actually failing to act on a request sitting in its DROP queue rather than to the registration step.
Both figures come from the same statute and the same enforcing agency, but they attach to different conduct, and neither should be quoted as a blanket, flat "$200 per day" without saying which obligation it penalizes. The CPPA is the agency that both administers DROP and brings these enforcement actions; it has already brought settlement actions against multiple brokers over registration failures ahead of this deletion-processing deadline, according to the CPPA's own enforcement announcements.
Analysis: Why This Matters
The following is analysis from the Recording Law Editorial Team.
DROP is California's first state-run, universal opt-out-style deletion mechanism for data brokers, and it changes what "compliance" requires of a broker in a structural way. Registration was always a paperwork exercise: file a form once a year, pay a fee, appear on a public list. The deletion-processing duty that started August 1 is an operational one. A broker now has to build a recurring workflow, someone or something logging into DROP on a schedule no longer than 45 days, matching incoming requests against internal records, executing deletions that reach derived inferences and not just raw fields, reporting status back into the platform, and then repeating the deletion on the same interval so it does not silently expire. That is a materially different compliance posture than filing an annual registration, and it is the kind of ongoing technical obligation that is easier to miss than a once-a-year deadline.
It is also worth being precise about what DROP is not. It is not a new individual right; California consumers already had a right to request deletion from any single business under the CCPA/CPRA. What DROP adds is aggregation and a government-hosted front door, one request instead of one request per broker. Whether that materially increases the rate at which brokers actually complete deletions, as opposed to simply registering, is not something the record supports predicting yet; the processing requirement is only days old as of this article and the CPPA has not yet published data-broker-specific enforcement outcomes tied to the deletion duty itself, as distinct from the registration duty it has already enforced.
How This Affects You
For California consumers, the practical takeaway is that DROP is now live on both ends: a request submitted since January 1, 2026 should, as of August 1, begin actually reaching the data brokers it names, rather than sitting unprocessed. DROP is a way to reach every registered broker at once; it is not a substitute for other, separate privacy tools such as a credit freeze with the credit bureaus or opting out of a specific data broker directly, and it only reaches brokers that are registered with the CPPA in the first place.
For businesses that meet the statutory definition of "data broker," the relevant question is not just whether the business is registered, it is whether it has an actual internal process, someone assigned, a recurring calendar reminder, a system integration, that logs into DROP at least every 45 days, retrieves and matches requests, executes deletions including derived inferences, and reports status back inside that same window. A business unsure whether it meets the data broker definition, or whether specific data it holds falls under a statutory exemption from deletion, should consult a qualified California privacy attorney; nothing here is legal advice on how the exemptions apply to a particular business's data.
This is general legal information, not legal advice. Laws change, and how a statute applies can depend on specific facts. Consult a licensed California attorney for advice about a particular situation. (California; verified August 5, 2026.)
Related articles
- US Data Broker Registration Laws & the Delete Act
- How to Opt Out of Data Brokers
- California Data Privacy Laws
- CCPA Opt-Out Rights
Last updated: 2026-08-05. This is a developing story; details verified as of 2026-08-05.
Frequently Asked Questions
What is the California Delete Act?
The Delete Act is SB 362 (Chapter 709, Statutes of 2023), codified starting at Cal. Civ. Code sec. 1798.99.80. It requires the California Privacy Protection Agency to build and run DROP, a single platform where a California consumer can submit one request to have their personal information deleted by every registered data broker.
What changed on August 1, 2026?
Registered data brokers became required to access DROP at least once every 45 days to retrieve consumer deletion requests, process matching deletions (including deleting inferences, absent an exemption), and report the status of each request in DROP within 45 days of retrieving it.
How does DROP work for consumers?
A California consumer creates one account on DROP and submits a single deletion request that is addressed to every active, registered data broker at once, rather than filing a separate request with each broker individually. Consumers have been able to do this since January 1, 2026, according to the CPPA.
Who has to comply with the DROP deletion mandate?
Any business that meets the Delete Act's statutory definition of a data broker and is registered with the CPPA's Data Broker Registry must comply. The definition generally covers businesses that knowingly collect and sell the personal information of consumers with whom they have no direct relationship.
What are the penalties for noncompliance?
Civil Code section 1798.99.82 authorizes an administrative fine of $200 per deletion request for each day a broker fails to process a required deletion, separate from a $200-per-day fine the same section authorizes for a broker that fails to register by the January 31 annual deadline. The CPPA can also recover its investigation costs in either type of action.
Is DROP the same as a CCPA deletion request?
No. The CCPA/CPRA already gives California consumers an individual right to request deletion from any single business. DROP is a separate, additional mechanism built specifically for data brokers that lets one consumer request reach every registered broker at once, rather than requiring a separate request to each one.
Does DROP reach every data broker operating in California?
DROP reaches data brokers that have registered with the CPPA. A business that meets the statutory definition of data broker but has failed to register is itself out of compliance and subject to separate administrative fines for that failure.
Sources and References
- CPPA, Information for Data Brokers (DROP 45-day access and processing requirement)(cppa.ca.gov).gov
- CPPA, Delete Request and Opt-out Platform (DROP) System Requirements(cppa.ca.gov).gov
- Data Broker Registry / Delete Act statute (Cal. Civ. Code sec. 1798.99.80 et seq., eff. 1/1/2026)(cppa.ca.gov).gov
- CPPA, Data Broker Registry(cppa.ca.gov).gov
- CPPA, Enforcement Advisory 2025-01: Data Broker Registration (registration fine basis)(cppa.ca.gov).gov
- CPPA, California Approves Delete Act Regulations (Nov. 13, 2025 announcement)(cppa.ca.gov).gov
- CPPA, CalPrivacy Issues Enforcement Advisory Highlighting Data Broker Registration(cppa.ca.gov).gov