Salta al contenuto principale

California's Delete Act Deletion Deadline Arrives August 1, 2026: What Data Brokers and Small Businesses Must Do About DROP

5 minuti di letturaMike ThriftMike Thrift
California's Delete Act Deletion Deadline Arrives August 1, 2026: What Data Brokers and Small Businesses Must Do About DROP

On January 1, 2026, California launched DROP — the Delete Request and Opt-Out Platform — and on August 1, 2026, it becomes mandatory. From that date, every registered data broker in California must access DROP at least every 45 days, retrieve centralized deletion requests, determine whether deletion is required within 90 days, and report back. By 2028, every broker must undergo an independent Delete Act audit at least every three years and submit the report to the California Privacy Protection Agency (CPPA).

If you are a data broker, a business that sells personal information, or a small business that buys data from brokers, the deadline matters — not because you will file the deletion yourself, but because the data supply you rely on is about to be filtered by consumer requests at scale, every 45 days, forever.

What DROP Is — and Why It Changes the Workflow

Before the Delete Act (SB 362, 2023), a Californian who wanted to delete personal information held by data brokers had to find each broker and opt out individually — a tedious, manual process across 500+ registered brokers. DROP centralizes that: a Californian verifies residency once through the CPPA's platform, submits a single deletion request, and the request is transmitted to every current and future registered broker. The consumer may selectively exclude specific brokers from the request and verify status.

For brokers, the operational shift is from reactive, one-off requests to a recurring, platform-driven queue:

  • Access DROP at least every 45 days. The broker must retrieve all applicable delete requests at least that often — not when it has time, but on a 45-day cycle.
  • Determine within 90 days. For each request, the broker has 90 days to determine whether deletion is required, to delete (including telling service providers and contractors to delete), and to report the determination to the consumer via DROP.
  • Continuing obligation. If the consumer has opted out, the broker must delete any information it later collects about that individual at least every 45 days — not just once, but on an ongoing basis.

Brokers must also disclose at registration whether they collect precise geolocation data or information about minors — expanded registration details that did not exist before SB 362 — and they must have registered annually with the CPPA since January 2024.

Who Is a Data Broker

The Delete Act applies to businesses that knowingly collect and sell the personal information of consumers with whom they do not have a direct relationship. If your revenue depends on aggregating, combining, and trading personal information — people search, marketing data, risk, lead lists — you are in scope. A small business that occasionally sells a customer list is not the target, but a business whose model is data brokerage, even at modest scale, is.

If you buy data from brokers for marketing, risk scoring, or lead generation, you are not directly subject to Delete Act deletion duties, but you will feel it downstream: the broker pool you buy from will be thinned every 45 days by deletions. A lead list purchased in July may be 10–15% smaller after the August DROP sweep, with refresh requirements.

The Operational Checklist Before August 1

If you are a broker:

  • Confirm CPPA registration is current and the DROP integration is tested — automated retrieval, not manual portal checks
  • Build the 45-day retrieval calendar with an on-call owner so a vacation does not break the cadence
  • Implement the 90-day determination and deletion workflow with contractor/service-provider notification — your downstream obligation does not end when you delete locally
  • Log every determination with the DROP ticket ID, the deletion date, and the service-provider confirmations — that log is the 2028 audit exhibit
  • Schedule the independent audit for 2028 now; auditors are already booking, and the first audit must be filed at least every three years

If you are a small business that is not a data broker but handles personal information, the Delete Act does not directly impose deletion duties on you, but it signals the CPPA's direction: centralized, consumer-initiated deletion at scale. Aligning your own privacy request workflow — notice, verification, 45-day deletion cadence — with the broker standard reduces the gap you will need to close when broader CCPA obligations reach you.

Simplify Your Financial Management

Data you cannot keep, sell, or reuse has no asset value — and deletion compliance has a cost that belongs in the ledger. Beancount.io keeps compliance costs, data handling expenses, and any broker fees in plain-text, version-controlled accounting — so your next DROP cycle is budgeted and traceable, not just a privacy page update. Get started for free and keep your data handling as auditable as your financials.

Condividi questo articolo