For seven years the California Consumer Privacy Act gave residents a right to delete their data one company at a time. You found the business, you filed the request, you waited. Starting today that changes. As of August 1, 2026, a single request on the state's Delete Request and Opt-Out Platform reaches every data broker registered in California at once, and the businesses on the receiving end now have a hard clock and a steep fine attached to it.
What Just Changed
CalPrivacy (the California Privacy Protection Agency) built DROP under the Delete Act, the 2023 law that extends the CCPA deletion right across the entire data-broker industry. The platform opened to consumers on January 1, 2026, and more than 300,000 Californians have already queued deletion requests through it. Today is the day the other side of the transaction switches on. Every business registered as a data broker must now log into DROP at least once every 45 days, pull the list of people who asked to be forgotten, and erase their records.
Skip a cycle and the math turns ugly fast. The penalty runs $200 for each deletion request, for each day a broker fails to act. A backlog of even a few thousand ignored requests becomes six-figure exposure inside a week, which is exactly the pressure the statute was written to create.
Why This Reaches Businesses That Don't Feel Like Brokers
Here's the part that catches companies off guard: you might be a data broker without ever thinking of yourself as one. California defines the term broadly. It covers any business that knowingly sells the personal information of people it has no direct relationship with, and "sharing" data for cross-context behavioral advertising counts as selling. Plenty of ad-tech-heavy sites and lead-generation operations land inside that line without a storefront that looks anything like a data broker.
If you might qualify, a few deadlines matter now. Registration with CalPrivacy runs every January and carries a $6,000 annual fee, so a broker that missed the window is already accruing $200 a day. Deletion processing through DROP is the obligation that started today. And beginning January 1, 2028, registered brokers face triennial independent audits of how they handle all of it. The first thing to settle isn't your DROP workflow; it's whether you count as a broker at all.
How Privisy Helps
Privisy won't file your DROP deletions. That runs through your own data systems, and no external scan can reach it. What Privisy will tell you is whether your website is quietly behaving like a data broker in the first place.
- Full tracker detection: a scan intercepts every outbound request as your pages load, surfacing the ad-tech and analytics vendors receiving visitor data — the same "sharing" that can pull you under the Delete Act's definition.
- Consumer-rights mechanisms: Privisy checks whether your Do Not Sell or Share control is actually present and working, the prominence failures that already cost Ford and Disney.
- Privacy policy analysis: the scanner cross-checks what your policy claims against the trackers firing on the page, so you find the gap between what you disclose and where the data really goes.
If your site is sending personal information to third parties you never inventoried, you want to know that before a 45-day clock starts on requests you didn't realize you had to answer. See the CCPA enforcement actions tracker for the full record of California privacy actions to date.
Find Out What Your Site Is Really Sharing
Before a deletion request forces the question, map your own data flows. Privisy scans your site for the trackers and disclosure gaps that decide whether you're acting like a data broker.
Run a Free Scan