← BLOG  |  NEWS

California Launches DROP Data Broker Deletion Tool

California’s Delete Act (Senate Bill 362) required CalPrivacy to launch a state-run deletion tool by January 1, 2026. That tool is now live as Delete Request and Opt-Out Platforms (DROP), which allows California residents to submit a single deletion and opt-out request to registered data brokers.

Consumers can submit requests now, but data brokers are not required to begin processing them until August 1, 2026. In-scope businesses should prepare in advance of that date.

This update applies to businesses that qualify as “data brokers” under California’s Delete Act (SB 362). It covers DROP deletion and opt-out requests submitted on or after January 1, 2026, with mandatory broker processing beginning August 1, 2026.

What Employers Need to Do

1) Determine Whether Your Organization is a “Data Broker” Under the Delete Act: CalPrivacy explains that a data broker is a business that knowingly collects and sells a consumer’s personal information to third parties without a direct relationship with the consumer, subject to specified exceptions.

2) If in Scope, Ensure Registration is Completed and Maintained: CalPrivacy instructs that data brokers must register annually (during January) through the DROP system and warns that failure to register by January 31 may result in administrative fines and costs.

3) Prepare Operationally for the August 1, 2026, DROP Processing Obligations: CalPrivacy states that, beginning August 1, 2026, data brokers must access DROP at least every 45 days to retrieve requests and process deletion requests, including deleting associated personal information (including inferences) unless an exception applies, and maintain a suppression list to help ensure the data is not re-collected or resold.

4) Update Request-handling Workflows To Support DROP Status Reporting and Timing: CalPrivacy’s regulations summary notes that brokers must report request status in DROP and describes ongoing operational requirements tied to the platform (including periodic retrieval and processing).

5) Monitor Enforcement Activity and Budget for Potential Exposure: CalPrivacy has already issued enforcement decisions for failure to register (including fines against Datamasters and S&P Global) and is signaling active oversight through its Data Broker Enforcement Strike Force.

Overview

1) What DROP is and Why It Exists

  • DROP is a state-run platform that allows Californians to tell registered data brokers to delete their personal information and not sell it through a single request.
  • The Governor’s office describes DROP as a first-in-the-nation tool enabled by SB 362 (the Delete Act) to make it easier for Californians to exercise deletion rights across many brokers.

2) What California Residents Can Do Now

  • Californians can use DROP to verify eligibility, create a profile, and submit a single request that is sent to 500+ registered data brokers.
  • DROP also allows consumers to return later to check status and update profile information.

3) Eligibility and Verification (How Consumers Authenticate)

  • To submit a deletion request, a user must be a California resident and verify via the California Identity Gateway (or use Login.gov as an option).
  • CalPrivacy states that users do not need to create an Identity Gateway account and that verification information is handled through the State’s verification pathway.

4) Key Compliance Timeline for Data Brokers:

  • January 1, 2026: Consumers can submit DROP requests.
  • August 1, 2026: Data brokers must begin processing deletion requests and must retrieve requests at least every 45 days and complete required deletion steps.

5) Notable Exclusions/Carve-outs (high level): Certain regulated activities may fall outside the data broker definition, including those governed by the Fair Credit Reporting Act (FCRA), the Gramm‑Leach‑Bliley Act (GLBA), or HIPAA, depending on the specific activity involved.

6) Enforcement Signals (Registration and Early Actions): CalPrivacy reports enforcement actions for failure to register, including fines against Datamasters and S&P Global, and notes the role of its Data Broker Enforcement Strike Force.

Why This Matters

DROP changes the practical reality of consumer deletion rights by enabling a single verified request to reach hundreds of registered data brokers. This increases the likelihood and volume of deletion and opt-out requests that data brokers must operationalize beginning August 1, 2026.

For businesses that qualify as data brokers (including organizations that may not self-identify that way), this creates near-term compliance priorities around registration, integration, and request-handling readiness—backed by active enforcement for registration failures.

Key Risks for Employers

  • Misclassification risk: Some companies may meet the definition of a data broker based on their data-sharing practices, even if they do not view themselves as brokers.
  • Operational Readiness Risk for August 1, 2026: Data brokers must retrieve requests at least every 45 days and implement processing and reporting workflows tied to DROP.
  • Enforcement/Penalty Exposure: CalPrivacy has already imposed fines for failure to register and is actively enforcing the data broker regime through its strike force.
  • Downstream Impact for Non-brokers: Even organizations not in scope may see indirect effects as brokers begin processing deletion requests that implicate shared/vendor-sourced datasets and partner relationships.

Source Reference

Need help understanding how changes to employment laws will affect your business?

Learn more about how Vensure's California PEO services can help you navigate complex employment laws and keep your business compliant.


This communication is intended solely for the purpose of conveying information. The present post might incorporate hyperlinks directing readers to websites managed by third-party entities. The inclusion of any links within this communication is meant to serve as points of reference and could encompass opinion articles from various law firms, articles from HR associations, official websites, news releases, and documents of government agencies, and other relevant third-party sources. Vensure has no authority over these external websites and bears no responsibility for their content. Furthermore, Vensure does not endorse the materials present on these websites. The contents of this communication should not be interpreted as legal advice or as a legal standpoint concerning specific facts or scenarios. Nor should it be deemed an exhaustive compilation of facts potentially pertinent to federal, state, or local laws. It is strongly advised that employers solicit legal guidance from an employment attorney when undertaking actions in response to any legal updates provided. This is due to the possibility of future alterations occurring in federal, state, and local laws, regulations, as well as the directives and guidelines issued by governing agencies. These changes may transpire at any given time, potentially rendering certain portions of the content within this update void or inaccurate.

Compliant Lorem Ipsum Heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua.

Lorem Ipsum Headline Here​

Subheader lorem ipsum

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

Amazing!

You're all set.

Thanks for subscribing. Be on the look out for the Legal HR updates in your email.