Clym Logo

California DROP Is Now Enforceable. Are Data Brokers Ready?

Published
AS
AuthorAdam Safar
8 min read

California DROP Enforcement Explained

California's DROP became enforceable August 1, 2026. Data brokers must access it every 45 days, process deletions, and prepare for 2028 audits.

Summarize full article with:

On August 1, 2026, California's Delete Request and Opt-out Platform, known as DROP, became fully enforceable for the state's registered data brokers. Brokers are now required to log into the platform at least once 45 days and act on the deletion requests it delivers.

The early numbers are notable. At its August 2026 board meeting, the California Privacy Protection Agency (CPPA) reported that only about 30% of registered data brokers had begun processing DROP requests during the platform's first week of enforceability, even as consumers had already submitted roughly 450,000 deletion requests through the system, according to IAPP's coverage of the meeting.

Key takeaways
  • California's DROP system became enforceable for data brokers on August 1, 2026.

  • Only about 30% of registered data brokers were processing DROP requests in week one.

  • Consumers had submitted roughly 450,000 deletion requests through DROP by August 2026.

  • Data brokers must access DROP at least once every 45 days and act on requests.

  • Noncompliance penalties can reach $200 per day per violation, with no cure period.

  • Independent third-party DROP audits begin January 1, 2028, on a three-year cycle.  

What is California's DROP system?

California's Delete Request and Opt-out Platform (DROP) is a free, state-run tool that lets California residents submit one verified request to delete their personal information from every registered data broker at once.

It was created under the California Delete Act (Senate Bill 362), which added an accessible deletion mechanism requirement to the state's privacy framework. Instead of contacting each broker separately, a consumer verifies their identity once, and the CPPA distributes that single request to every broker on its registry.

Through DROP, California consumers can create a verified profile, submit a deletion or opt-out request to every registered broker simultaneously, and track the status of that request over time. For a full walkthrough of how consumers use the platform, including each response category a broker can return, see our guide to the DROP platform.

DROP applies specifically to registered data brokers, currently more than 600 companies. Certain entities or processing activities covered by laws such as the Fair Credit Reporting Act, Gramm-Leach-Bliley Act, and specified health-information exemptions may fall outside the data broker definition to the extent provided by California law.

Does California DROP apply to my business?

DROP applies to businesses that meet California’s definition of a data broker and are required to register with the CPPA. California generally defines a data broker as a business that knowingly collects and sells to third parties personal information about consumers with whom it does not have a direct relationship, subject to statutory exclusions.

What changed on August 1, 2026?

The Delete Act has been in effect in some form since 2024, and DROP itself launched on January 1, 2026. What changed on August 1 is narrower and more specific: it is the date the operational obligation to act on DROP requests became enforceable against data brokers.

Obligation

Status as of August 2026

Annual registration with the CPPA (window: January 1 to January 31 each year)

Already required since 2024; unrelated to the August 1 date

CPPA builds and operates the DROP platform

CPPA's own obligation; platform launched January 1, 2026

Access DROP at least once every 45 days

Enforceable against brokers since August 1, 2026

Process deletion and opt-out requests retrieved from DROP

Enforceable against brokers since August 1, 2026

Public reporting of consumer request metrics

Recurring annual obligation; first reports due the following July 1

Independent third-party compliance audits

Not yet enforceable; begins January 1, 2028

One clarification worth knowing: a separate amendment, SB 361, resolved an ambiguity in the original Delete Act by specifying that when a broker cannot verify a deletion request, it must still be treated as a valid opt-out request, with a 45-day window to comply, rather than being ignored outright, per Hintze Law's summary of the amendment.

How often must a data broker check DROP?

At least once every 45 days. Registered brokers must log into DROP, retrieve the deletion and opt-out requests waiting for them, and begin acting on that batch, on a recurring cycle that has been enforceable since August 1, 2026, according to the CPPA's data broker guidance.

How quickly must a deletion request be processed?

Data brokers must process DROP requests at least once every 45 days and report the status of each request in DROP within 45 days of receiving it. Because a request may wait until the broker’s next 45-day processing cycle before that period begins, consumers may wait up to roughly 90 days to see the request reflected as processed in DROP.

What data has to be deleted?

The personal information a broker has collected about the consumer, along with a stop to any ongoing sale or sharing of that information going forward. Brokers match the identifiers a consumer provides, such as name and date of birth, against the records they hold to determine which accounts are affected.

Are there exceptions?

Yes. Certain entities or processing activities may fall outside the data broker definition to the extent provided by California law. If a deletion request cannot be verified through DROP, the broker must instead process it as an opt-out of the sale or sharing of personal information within 45 days.

What records should data brokers keep?

Enough to demonstrate that the 45-day access cycle was followed, and what happened to each request: deleted, exempted, opted out, or not found. Brokers must also publicly report aggregate request metrics annually, with the first reports due the following July 1. These are close to the exact records the CPPA's planned 2028 audits are expected to review, covered further down.

What happens after a request is processed?

The broker updates the request's status in DROP, which the consumer can see in their own account. Brokers are not permitted to contact consumers directly to verify a deletion request outside of DROP's own identity verification process, and they should retain evidence supporting whatever outcome they recorded.

Only 30% of data brokers were processing DROP requests in week one

At its August 2026 board meeting, the CPPA reported that roughly 30% of registered data brokers had begun processing DROP requests during the platform's first week of enforceability, against a backdrop of about 450,000 consumer deletion requests already submitted through the platform.

A number like that invites a simple conclusion: most data brokers are ignoring the law. The evidence available so far does not support that reading. There is a real difference between a company choosing not to comply and a company still building the infrastructure to comply reliably, and the more plausible explanation for slow early adoption is operational rather than intentional.

A few factors that plausibly explain the gap:

  • Operational readiness: Connecting DROP with existing privacy workflows and internal systems requires technical work that some brokers may not have completed before August 1.

  • Data discovery and identity matching: Brokers need to match requests accurately and locate personal information across databases, vendors, and legacy systems.

  • Resources and ownership: DROP requires ongoing coordination across privacy, legal, engineering, and potentially third parties, creating both operational and staffing demands.

None of this excuses noncompliance once the enforcement date has passed. But it does explain why a 70% gap in week one looks more like a rollout problem than a mass act of defiance, and why the CPPA's next few board meetings, along with its planned audits, are likely to matter more than the initial week-one number.

Why DROP compliance is an operational challenge

The legal requirement is short: access DROP every 45 days, process what it delivers. Meeting that requirement reliably is a different kind of problem, closer to a data engineering project than a legal one.

  • Match requests accurately against existing records.
  • Locate personal information across relevant systems and vendors.
  • Route requests to the teams and third parties responsible for the data.
  • Apply and document exceptions where appropriate.
  • Verify completion and maintain records showing how each request was handled.

What are the penalties for DROP noncompliance?

A data broker that fails to register with the CPPA can face administrative fines of $200 per day of noncompliance. The CPPA has already brought enforcement actions over data broker registration failures, demonstrating that these requirements are being actively enforced.

Failing to delete information as required under the Delete Act can result in a separate penalty of $200 per request, per day the request remains unprocessed. The Delete Act provision does not provide a statutory cure period for this violation.

Enforcement authority sits with the CPPA rather than individual consumers. The Delete Act does not create a private right of action for DROP violations, though the agency can pursue administrative enforcement and recover certain costs.

For more on how the CPPA has enforced data broker obligations in practice, see our earlier coverage of California data broker enforcement and DROP.

California DROP audits are coming in 2028

Starting January 1, 2028, registered data brokers must undergo an independent third-party audit at least once every three years to verify Delete Act compliance, per the CPPA's own guidance for data brokers.

That trigger date and the three-year cycle are set in the underlying statute, which makes them a finalized requirement rather than a proposal. What is still being developed is the how. The CPPA has opened formal rulemaking on the mechanics of these audits and has not yet adopted final rules on auditor qualifications, audit methodology, or exactly what a compliant audit report must contain, according to Freshfields' review of the rulemaking process.

Based on the questions the CPPA has posed to stakeholders so far, the audits are expected to examine:

  • Internal policies and procedures governing deletion request handling

  • System logs documenting the 45-day access and processing cycle

  • Matching methodologies used to identify affected consumer records

  • Deletion records and suppression lists

  • Reporting activity, including the annual public metrics brokers must file

Treat that list as directionally accurate rather than final. The CPPA is still taking stakeholder input on auditor independence standards and what documentation audits will require, so the exact scope could shift before rules are adopted.

What is unlikely to change is the underlying expectation: by 2028, "we deleted it" will need to be something a broker can demonstrate, not just assert.

How should data brokers prepare for DROP audits?

You do not need to wait for the final audit rules to start building toward them. Most of the following is good operational practice regardless of what the finalized audit regulation ends up requiring.

  1. Test workflows end to end.
  2. Document how requests move through systems.
  3. Maintain timestamped logs and evidence of outcomes.
  4. Assign ownership and review third-party dependencies.
  5. Track exceptions and periodically test the process.

Tools built for consent and request management, including Clym's platform, can help centralize this kind of documentation so it exists in one place rather than scattered across ticketing systems and inboxes.

Treat that as a starting point for organizing the work, not a substitute for reviewing your own process against the CPPA's final audit rules once they are adopted.

What DROP means for privacy teams beyond California

DROP is California-specific, and other states may not adopt the same centralized model. But organizations operating across multiple states are already managing a growing mix of deletion, opt-out, registration, and reporting requirements. Building scalable privacy workflows is more durable than creating a new manual process each time another requirement takes effect.

Conclusion

California DROP is now enforceable, but the early 30% processing rate shows that implementation is still catching up with the law. For data brokers, the priority is straightforward: retrieve requests on schedule, process them within the required timeframe, and maintain records showing what happened.

With independent audits beginning in 2028, building a documented and repeatable process now will be easier than trying to reconstruct one later.

Frequently asked questions

DROP, the Delete Request and Opt-out Platform, is a free tool built by the California Privacy Protection Agency that lets California residents submit one verified request to delete their personal information from every registered data broker at once, instead of contacting each broker separately.

DROP applies to businesses that meet California’s definition of a data broker and are required to register with the CPPA. Certain entities or processing activities covered by laws such as the FCRA, GLBA, and specified health-information exemptions may be excluded to the extent provided by California law.

DROP launched on January 1, 2026, but the requirement for data brokers to access the platform and process deletion requests became enforceable on August 1, 2026.

At least once every 45 days. Registered brokers must log in, retrieve pending requests, and act on them during that recurring cycle.

Data brokers must process DROP requests at least once every 45 days and report the status of each request within 45 days of receiving it. As a result, consumers may wait up to about 90 days to see an updated status in DROP.

Registration violations can carry fines of $200 per day. Failing to process a verified deletion request can carry a separate penalty of $200 per request, per day, with no cure period.

Independent third-party audits become required starting January 1, 2028, on a three-year cycle. The audit trigger date is finalized in statute, while the CPPA is still finalizing the detailed procedural rules through active rulemaking.

Start now by testing your deletion workflow end to end, documenting how requests move through your systems, keeping clean logs, and tracking every exception you apply. Demonstrable process matters more than a verbal assurance that requests are being handled.

Adam Safar

Head of Digital Marketing

Adam is the Head of Digital Marketing at Clym, where he leverages his diverse expertise in marketing to support businesses with their compliance needs and drive awareness about data privacy and web accessibility. As one of the company’s original team members, Adam has been instrumental in shaping its journey from the very beginning. When he’s not diving into marketing strategies, Adam can be found cheering on his favorite sports teams or enjoying fishing.

Find out more about Adam