California's Delete Act Deletion Mandate Takes Effect: Data Brokers Must Now Process DROP Requests Every 45 Days

Independently fact-checkedBy Recording Law Editorial Team7 min read

Independently fact-checked against primary sources (last audited August 5, 2026). · 7 primary sources cited on this page. How we verify our legal content

California's Delete Act Deletion Mandate Takes Effect: Data Brokers Must Now Process DROP Requests Every 45 Days

Frequently Asked Questions

What is the California Delete Act?

The Delete Act is SB 362 (Chapter 709, Statutes of 2023), codified starting at Cal. Civ. Code sec. 1798.99.80. It requires the California Privacy Protection Agency to build and run DROP, a single platform where a California consumer can submit one request to have their personal information deleted by every registered data broker.

What changed on August 1, 2026?

Registered data brokers became required to access DROP at least once every 45 days to retrieve consumer deletion requests, process matching deletions (including deleting inferences, absent an exemption), and report the status of each request in DROP within 45 days of retrieving it.

How does DROP work for consumers?

A California consumer creates one account on DROP and submits a single deletion request that is addressed to every active, registered data broker at once, rather than filing a separate request with each broker individually. Consumers have been able to do this since January 1, 2026, according to the CPPA.

Who has to comply with the DROP deletion mandate?

Any business that meets the Delete Act's statutory definition of a data broker and is registered with the CPPA's Data Broker Registry must comply. The definition generally covers businesses that knowingly collect and sell the personal information of consumers with whom they have no direct relationship.

What are the penalties for noncompliance?

Civil Code section 1798.99.82 authorizes an administrative fine of $200 per deletion request for each day a broker fails to process a required deletion, separate from a $200-per-day fine the same section authorizes for a broker that fails to register by the January 31 annual deadline. The CPPA can also recover its investigation costs in either type of action.

Is DROP the same as a CCPA deletion request?

No. The CCPA/CPRA already gives California consumers an individual right to request deletion from any single business. DROP is a separate, additional mechanism built specifically for data brokers that lets one consumer request reach every registered broker at once, rather than requiring a separate request to each one.

Does DROP reach every data broker operating in California?

DROP reaches data brokers that have registered with the CPPA. A business that meets the statutory definition of data broker but has failed to register is itself out of compliance and subject to separate administrative fines for that failure.

Updates

Independently fact-checked against the cited primary sources

Sources and References

  1. CPPA, Information for Data Brokers (DROP 45-day access and processing requirement)(cppa.ca.gov).gov
  2. CPPA, Delete Request and Opt-out Platform (DROP) System Requirements(cppa.ca.gov).gov
  3. Data Broker Registry / Delete Act statute (Cal. Civ. Code sec. 1798.99.80 et seq., eff. 1/1/2026)(cppa.ca.gov).gov
  4. CPPA, Data Broker Registry(cppa.ca.gov).gov
  5. CPPA, Enforcement Advisory 2025-01: Data Broker Registration (registration fine basis)(cppa.ca.gov).gov
  6. CPPA, California Approves Delete Act Regulations (Nov. 13, 2025 announcement)(cppa.ca.gov).gov
  7. CPPA, CalPrivacy Issues Enforcement Advisory Highlighting Data Broker Registration(cppa.ca.gov).gov
Share: