California DROP Enforcement Explained
California's DROP became enforceable August 1, 2026. Data brokers must access it every 45 days, process deletions, and prepare for 2028 audits.
California's DROP became enforceable August 1, 2026. Data brokers must access it every 45 days, process deletions, and prepare for 2028 audits.
On August 1, 2026, California's Delete Request and Opt-out Platform, known as DROP, became fully enforceable for the state's registered data brokers. Brokers are now required to log into the platform at least once 45 days and act on the deletion requests it delivers.
The early numbers are notable. At its August 2026 board meeting, the California Privacy Protection Agency (CPPA) reported that only about 30% of registered data brokers had begun processing DROP requests during the platform's first week of enforceability, even as consumers had already submitted roughly 450,000 deletion requests through the system, according to IAPP's coverage of the meeting.
California's DROP system became enforceable for data brokers on August 1, 2026.
Only about 30% of registered data brokers were processing DROP requests in week one.
Consumers had submitted roughly 450,000 deletion requests through DROP by August 2026.
Data brokers must access DROP at least once every 45 days and act on requests.
Noncompliance penalties can reach $200 per day per violation, with no cure period.
Independent third-party DROP audits begin January 1, 2028, on a three-year cycle.
California's Delete Request and Opt-out Platform (DROP) is a free, state-run tool that lets California residents submit one verified request to delete their personal information from every registered data broker at once.
It was created under the California Delete Act (Senate Bill 362), which added an accessible deletion mechanism requirement to the state's privacy framework. Instead of contacting each broker separately, a consumer verifies their identity once, and the CPPA distributes that single request to every broker on its registry.
Through DROP, California consumers can create a verified profile, submit a deletion or opt-out request to every registered broker simultaneously, and track the status of that request over time. For a full walkthrough of how consumers use the platform, including each response category a broker can return, see our guide to the DROP platform.
DROP applies specifically to registered data brokers, currently more than 600 companies. Certain entities or processing activities covered by laws such as the Fair Credit Reporting Act, Gramm-Leach-Bliley Act, and specified health-information exemptions may fall outside the data broker definition to the extent provided by California law.
DROP applies to businesses that meet California’s definition of a data broker and are required to register with the CPPA. California generally defines a data broker as a business that knowingly collects and sells to third parties personal information about consumers with whom it does not have a direct relationship, subject to statutory exclusions.
The Delete Act has been in effect in some form since 2024, and DROP itself launched on January 1, 2026. What changed on August 1 is narrower and more specific: it is the date the operational obligation to act on DROP requests became enforceable against data brokers.
Obligation | Status as of August 2026 |
|---|---|
Annual registration with the CPPA (window: January 1 to January 31 each year) | Already required since 2024; unrelated to the August 1 date |
CPPA builds and operates the DROP platform | CPPA's own obligation; platform launched January 1, 2026 |
Access DROP at least once every 45 days | Enforceable against brokers since August 1, 2026 |
Process deletion and opt-out requests retrieved from DROP | Enforceable against brokers since August 1, 2026 |
Public reporting of consumer request metrics | Recurring annual obligation; first reports due the following July 1 |
Independent third-party compliance audits | Not yet enforceable; begins January 1, 2028 |
One clarification worth knowing: a separate amendment, SB 361, resolved an ambiguity in the original Delete Act by specifying that when a broker cannot verify a deletion request, it must still be treated as a valid opt-out request, with a 45-day window to comply, rather than being ignored outright, per Hintze Law's summary of the amendment.
At least once every 45 days. Registered brokers must log into DROP, retrieve the deletion and opt-out requests waiting for them, and begin acting on that batch, on a recurring cycle that has been enforceable since August 1, 2026, according to the CPPA's data broker guidance.
Data brokers must process DROP requests at least once every 45 days and report the status of each request in DROP within 45 days of receiving it. Because a request may wait until the broker’s next 45-day processing cycle before that period begins, consumers may wait up to roughly 90 days to see the request reflected as processed in DROP.
The personal information a broker has collected about the consumer, along with a stop to any ongoing sale or sharing of that information going forward. Brokers match the identifiers a consumer provides, such as name and date of birth, against the records they hold to determine which accounts are affected.
Yes. Certain entities or processing activities may fall outside the data broker definition to the extent provided by California law. If a deletion request cannot be verified through DROP, the broker must instead process it as an opt-out of the sale or sharing of personal information within 45 days.
Enough to demonstrate that the 45-day access cycle was followed, and what happened to each request: deleted, exempted, opted out, or not found. Brokers must also publicly report aggregate request metrics annually, with the first reports due the following July 1. These are close to the exact records the CPPA's planned 2028 audits are expected to review, covered further down.
The broker updates the request's status in DROP, which the consumer can see in their own account. Brokers are not permitted to contact consumers directly to verify a deletion request outside of DROP's own identity verification process, and they should retain evidence supporting whatever outcome they recorded.
At its August 2026 board meeting, the CPPA reported that roughly 30% of registered data brokers had begun processing DROP requests during the platform's first week of enforceability, against a backdrop of about 450,000 consumer deletion requests already submitted through the platform.
A number like that invites a simple conclusion: most data brokers are ignoring the law. The evidence available so far does not support that reading. There is a real difference between a company choosing not to comply and a company still building the infrastructure to comply reliably, and the more plausible explanation for slow early adoption is operational rather than intentional.
A few factors that plausibly explain the gap:
Operational readiness: Connecting DROP with existing privacy workflows and internal systems requires technical work that some brokers may not have completed before August 1.
Data discovery and identity matching: Brokers need to match requests accurately and locate personal information across databases, vendors, and legacy systems.
Resources and ownership: DROP requires ongoing coordination across privacy, legal, engineering, and potentially third parties, creating both operational and staffing demands.
None of this excuses noncompliance once the enforcement date has passed. But it does explain why a 70% gap in week one looks more like a rollout problem than a mass act of defiance, and why the CPPA's next few board meetings, along with its planned audits, are likely to matter more than the initial week-one number.
The legal requirement is short: access DROP every 45 days, process what it delivers. Meeting that requirement reliably is a different kind of problem, closer to a data engineering project than a legal one.
A data broker that fails to register with the CPPA can face administrative fines of $200 per day of noncompliance. The CPPA has already brought enforcement actions over data broker registration failures, demonstrating that these requirements are being actively enforced.
Failing to delete information as required under the Delete Act can result in a separate penalty of $200 per request, per day the request remains unprocessed. The Delete Act provision does not provide a statutory cure period for this violation.
Enforcement authority sits with the CPPA rather than individual consumers. The Delete Act does not create a private right of action for DROP violations, though the agency can pursue administrative enforcement and recover certain costs.
For more on how the CPPA has enforced data broker obligations in practice, see our earlier coverage of California data broker enforcement and DROP.
Starting January 1, 2028, registered data brokers must undergo an independent third-party audit at least once every three years to verify Delete Act compliance, per the CPPA's own guidance for data brokers.
That trigger date and the three-year cycle are set in the underlying statute, which makes them a finalized requirement rather than a proposal. What is still being developed is the how. The CPPA has opened formal rulemaking on the mechanics of these audits and has not yet adopted final rules on auditor qualifications, audit methodology, or exactly what a compliant audit report must contain, according to Freshfields' review of the rulemaking process.
Based on the questions the CPPA has posed to stakeholders so far, the audits are expected to examine:
Internal policies and procedures governing deletion request handling
System logs documenting the 45-day access and processing cycle
Matching methodologies used to identify affected consumer records
Deletion records and suppression lists
Reporting activity, including the annual public metrics brokers must file
Treat that list as directionally accurate rather than final. The CPPA is still taking stakeholder input on auditor independence standards and what documentation audits will require, so the exact scope could shift before rules are adopted.
What is unlikely to change is the underlying expectation: by 2028, "we deleted it" will need to be something a broker can demonstrate, not just assert.
You do not need to wait for the final audit rules to start building toward them. Most of the following is good operational practice regardless of what the finalized audit regulation ends up requiring.
Tools built for consent and request management, including Clym's platform, can help centralize this kind of documentation so it exists in one place rather than scattered across ticketing systems and inboxes.
Treat that as a starting point for organizing the work, not a substitute for reviewing your own process against the CPPA's final audit rules once they are adopted.
DROP is California-specific, and other states may not adopt the same centralized model. But organizations operating across multiple states are already managing a growing mix of deletion, opt-out, registration, and reporting requirements. Building scalable privacy workflows is more durable than creating a new manual process each time another requirement takes effect.
California DROP is now enforceable, but the early 30% processing rate shows that implementation is still catching up with the law. For data brokers, the priority is straightforward: retrieve requests on schedule, process them within the required timeframe, and maintain records showing what happened.
With independent audits beginning in 2028, building a documented and repeatable process now will be easier than trying to reconstruct one later.
DROP, the Delete Request and Opt-out Platform, is a free tool built by the California Privacy Protection Agency that lets California residents submit one verified request to delete their personal information from every registered data broker at once, instead of contacting each broker separately.
DROP applies to businesses that meet California’s definition of a data broker and are required to register with the CPPA. Certain entities or processing activities covered by laws such as the FCRA, GLBA, and specified health-information exemptions may be excluded to the extent provided by California law.
DROP launched on January 1, 2026, but the requirement for data brokers to access the platform and process deletion requests became enforceable on August 1, 2026.
At least once every 45 days. Registered brokers must log in, retrieve pending requests, and act on them during that recurring cycle.
Data brokers must process DROP requests at least once every 45 days and report the status of each request within 45 days of receiving it. As a result, consumers may wait up to about 90 days to see an updated status in DROP.
Registration violations can carry fines of $200 per day. Failing to process a verified deletion request can carry a separate penalty of $200 per request, per day, with no cure period.
Independent third-party audits become required starting January 1, 2028, on a three-year cycle. The audit trigger date is finalized in statute, while the CPPA is still finalizing the detailed procedural rules through active rulemaking.
Start now by testing your deletion workflow end to end, documenting how requests move through your systems, keeping clean logs, and tracking every exception you apply. Demonstrable process matters more than a verbal assurance that requests are being handled.