Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

California Delete Act explained

California Delete Act: The Complete Guide to DROP in 2026

The California Delete Act — Senate Bill 362 of 2023, codified at Civil Code sections 1798.99.80 to 1798.99.89 — is the law that turned California’s data broker registry into an enforcement machine and built the Delete Request and Opt-out Platform, DROP, through which a Californian submits one deletion request that every registered data broker must honour. Consumers have been able to sign up since 1 January 2026; brokers have been required to access the platform at least every 45 days and process requests since 1 August 2026; more than 500,000 Californians had registered by 25 August 2026 and brokers had reported deleting tens of millions of records. The fines are per day: $200 a day for failing to register, and $200 per deletion request per day for failing to delete. This guide sets out who is a data broker, the registration duty and its $6,000 fee, how DROP works on the consumer and broker sides, the 45-day cycle and the re-deletion duty, the independent audit from 2028, the fines and the enforcement record through September 2026, and what a company that is not sure whether it is a broker should do first.

California Delete Act: the DROP obligations and dates
Register by 31 January each year, $6,000 fee · consumers on DROP from 1 Jan 2026 · brokers access DROP every 45 days and process requests from 1 Aug 2026 · re-delete every 45 days · independent audit from 1 Jan 2028, every 3 years · $200/day fines.

Who the California Delete Act treats as a data broker

Section 1798.99.80 defines a data broker as “a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship”, with exclusions for entities covered by the Fair Credit Reporting Act, the Gramm-Leach-Bliley Act, the Insurance Information and Privacy Protection Act and certain health information. The test is the absence of a direct relationship, not the business model’s name: the Agency’s 2025–26 enforcement actions reached a marketing firm building custom audiences (ROR Partners, $56,600 in December 2025), a B2B contact-data vendor (SalesIntel, $36,400 in September 2026) and an ad-tech signals company (Cybba, $52,400 in August 2026), none of which called itself a data broker. Our guide to CCPA compliance covers how the Delete Act sits beside the CCPA’s own obligations.

Registration under the California Delete Act

Under section 1798.99.82 a business that met the data broker definition in a year must register with the California Privacy Protection Agency on or before 31 January of the following year, pay a registration fee — $6,000 under the Agency’s regulations, plus a card-processing fee of up to 2.99% — and disclose a growing list of information: contact details, the categories of personal information collected, whether it collects minors’ data, precise geolocation or reproductive health data, its handling of deletion requests, and, from 1 January 2029, whether it has undergone the section 1798.99.86 audit. The registry is public. A broker that fails to register owes $200 for each day of failure, the fees that were due, and the Agency’s investigation costs — the arithmetic behind fines of $36,000 to $116,000 for late registration.

How DROP works

Side What happens Rule
Consumer Verifies California residency with the Agency, then submits one deletion request covering all registered brokers, optionally excluding named brokers; may alter the request after 45 days; may use an authorised agent after residency verification Section 1798.99.86(a)–(b); DROP regulations sections 7620–7622
Broker — intake Accesses DROP at least once every 45 days and matches the request list against its records Section 1798.99.86(c)(1), from 1 August 2026
Broker — deletion Within 45 days of receiving a request, deletes all personal information relating to the consumer, subject to the CCPA exceptions in sections 1798.145 and 1798.146, and directs its service providers and contractors to do the same Section 1798.99.86(c)
Broker — where the request cannot be verified Processes the request as an opt-out of sale and sharing within 45 days instead, and directs service providers and contractors to do the same; deletion is also not required where the information is reasonably necessary for a section 1798.105(d) purpose or a 1798.145 or 1798.146 exception applies Section 1798.99.86(c)(1)(B)–(D), (c)(2)
Broker — ongoing After deleting, re-deletes the consumer’s personal information at least every 45 days and does not sell or share new personal information about them unless the consumer asks otherwise or an exception applies Section 1798.99.86(d), from 1 August 2026
Broker — reporting Compiles metrics on requests received and processed and provides them at registration, including the number of requests where deletion was not required and under which exception Sections 1798.99.82(b) and 1798.99.85

The re-deletion duty in subdivision (d) is the operational surprise. A DROP request is not a one-off: once a broker has deleted, it must keep deleting whatever it re-acquires about that consumer every 45 days, indefinitely, unless the consumer withdraws. A broker whose ingestion pipelines keep pulling the same people from the same sources needs a suppression list that runs at ingestion, not a quarterly clean-up.

The audit from 2028

The California Delete Act adds an audit. Section 1798.99.86(e) requires every data broker, beginning 1 January 2028 and every three years thereafter, to undergo an audit by an independent third party to determine compliance with the section, and to submit the report and related materials to the Agency on request; from 2029 the registry discloses whether a broker has been audited and the year of its last report. The audit is the Delete Act’s equivalent of the CCPA cybersecurity audit — external, periodic, and disclosed — and a broker that has not built a DROP processing log by then will have nothing to audit.

California Delete Act fines and the enforcement record

Failure Fine Source
Not registering $200 per day, plus the unpaid fees, plus the Agency’s investigation and administration expenses Section 1798.99.82(c)
Not deleting as required under section 1798.99.86 $200 per deletion request per day, plus expenses Section 1798.99.82(d)
CCPA violations found alongside Up to $2,663 per violation, or $7,988 for intentional violations and those involving consumers under 16 Civil Code section 1798.155 as adjusted

The Agency’s Enforcement Division created a Data Broker Enforcement Strike Force in November 2025, and the record since shows the pattern: registration failures first, then combined actions. LocateSmarter, an Iowa broker, was ordered in August 2026 to pay $116,490 in the first decision brought under both the CCPA and the Delete Act, for registering late and for demanding partial Social Security numbers before honouring opt-outs; Cybba followed days later at $52,400, and SalesIntel in September at $36,400, both ordered to access DROP and process requests through it. The Agency’s September 2026 enforcement advisory targeted incorrect information in registrations. Our guide to CCPA penalties sets these against the CCPA’s own amounts.

What the California Delete Act means for non-brokers

A business with a direct relationship to its consumers is not a data broker and does not process DROP requests — but its service providers and contractors may be brokers in other lines of business, and its own consumers’ deletion rights under the CCPA are unchanged. Two things still land on it: the Agency’s public statements that the Delete Act “works” are drawing consumers to the general right to delete, and the August 2026 legislative push to strengthen deletion rights suggests the mechanism will widen. A company that sells or shares personal information without a direct relationship in even one product line — a lookalike-audience service, a contact-enrichment feed — should test itself against the definition before the Agency does.

What to do first

  1. Test every revenue line against the California Delete Act definition — knowingly collect, sell to third parties, no direct relationship — and record the conclusion.
  2. If any line qualifies, register now rather than in January; the $200-a-day clock runs from the missed deadline.
  3. Build the DROP workflow: a 45-day access schedule, a matching process, deletion with exception coding, a suppression list at ingestion, and a log that the 2028 auditor can read.
  4. Flow the duty to service providers and contractors, because the statute makes the broker responsible for directing them.
  5. Fix the opt-out route. LocateSmarter’s fine turned on demanding excessive verification for an opt-out — a CCPA violation the Delete Act investigation surfaced.

Frequently asked questions

What is the California Delete Act?
Senate Bill 362 of 2023, Civil Code sections 1798.99.80 to 1798.99.89: it requires data brokers to register annually with the California Privacy Protection Agency, created the Delete Request and Opt-out Platform through which a consumer submits one deletion request to every registered broker, and imposes per-day fines for failing to register or delete.

When did DROP obligations start?
Consumers could register from 1 January 2026; brokers have had to access DROP at least every 45 days and process deletion requests within 45 days since 1 August 2026, and to re-delete every 45 days thereafter.

What does registration cost?
$6,000 a year under the Agency’s regulations, plus a card-processing fee of up to 2.99%, due by 31 January.

What are the fines?
$200 per day for failing to register plus unpaid fees and costs; $200 per deletion request per day for failing to delete. Decisions in 2025–26 ranged from $36,400 to $116,490, the latter combined with CCPA violations.

Is there an audit?
Yes. From 1 January 2028 and every three years, an independent third-party audit of compliance with section 1798.99.86, reportable to the Agency on request and disclosed on the registry from 2029.

Where this leaves you

Treat the California Delete Act as a live operational duty with a daily meter: decide whether any part of the business is a data broker, register on time, run the 45-day DROP cycle with suppression at ingestion, flow it to your processors, and keep the log the 2028 audit will read. Half a million Californians have already asked; the Agency has shown it will fine the brokers that did not answer.

References

More on the CCPA

The Right to Delete Fulfillment Procedure, the Right to Opt-Out of Sale/Sharing Procedure, the Authorized Agent Verification Procedure, the Consumer Request Tracking Log and the Data Processing Inventory are in the CCPA-CPRA Compliance Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.