California's Delete Act DROP Deadline Just Landed

For seven years the California Consumer Privacy Act gave residents a right to delete their data one company at a time. You found the business, you filed the request, you waited. Starting today that changes. As of August 1, 2026, a single request on the state's Delete Request and Opt-Out Platform reaches every data broker registered in California at once, and the businesses on the receiving end now have a hard clock and a steep fine attached to it.

What Just Changed

CalPrivacy (the California Privacy Protection Agency) built DROP under the Delete Act, the 2023 law that extends the CCPA deletion right across the entire data-broker industry. The platform opened to consumers on January 1, 2026, and more than 300,000 Californians have already queued deletion requests through it. Today is the day the other side of the transaction switches on. Every business registered as a data broker must now log into DROP at least once every 45 days, pull the list of people who asked to be forgotten, and erase their records.

Skip a cycle and the math turns ugly fast. The penalty runs $200 for each deletion request, for each day a broker fails to act. A backlog of even a few thousand ignored requests becomes six-figure exposure inside a week, which is exactly the pressure the statute was written to create.

Why This Reaches Businesses That Don't Feel Like Brokers

Here's the part that catches companies off guard: you might be a data broker without ever thinking of yourself as one. California defines the term broadly. It covers any business that knowingly sells the personal information of people it has no direct relationship with, and "sharing" data for cross-context behavioral advertising counts as selling. Plenty of ad-tech-heavy sites and lead-generation operations land inside that line without a storefront that looks anything like a data broker.

If you might qualify, a few deadlines matter now. Registration with CalPrivacy runs every January and carries a $6,000 annual fee, so a broker that missed the window is already accruing $200 a day. Deletion processing through DROP is the obligation that started today. And beginning January 1, 2028, registered brokers face triennial independent audits of how they handle all of it. The first thing to settle isn't your DROP workflow; it's whether you count as a broker at all.

How Privisy Helps

Privisy won't file your DROP deletions. That runs through your own data systems, and no external scan can reach it. What Privisy will tell you is whether your website is quietly behaving like a data broker in the first place.

If your site is sending personal information to third parties you never inventoried, you want to know that before a 45-day clock starts on requests you didn't realize you had to answer. See the CCPA enforcement actions tracker for the full record of California privacy actions to date.

Find Out What Your Site Is Really Sharing

Before a deletion request forces the question, map your own data flows. Privisy scans your site for the trackers and disclosure gaps that decide whether you're acting like a data broker.

Run a Free Scan