Skip to content

California Delete Act DROP: what data brokers must do now

Filip LuchianencoUpdated 6 min read

Last updated: 2026-10-02

On August 1, 2026, the California Delete Act (SB 362, Chapter 709, Statutes of 2023) began requiring data brokers to "access the accessible deletion mechanism established pursuant to subdivision (a) at least once every 45 days" and process the deletion requests submitted through it (Civ. Code § 1798.99.86(c)(1)). That mechanism is the Delete Request and Opt-out Platform (DROP), run by the California Privacy Protection Agency (CalPrivacy): a California resident submits one request, and every registered data broker must process it. A broker that fails to delete is liable for "two hundred dollars ($200) for each deletion request for each day" (§ 1798.99.82(d)(1)). CalPrivacy reported on August 25, 2026 that more than 500,000 Californians had registered for DROP.

What must data brokers do under the Delete Act DROP rules?

Section 1798.99.86(c) also requires a broker to:

  • process every deletion request within 45 days of receiving it and delete "all personal information related to the consumers making the requests";
  • treat a request it cannot verify as an opt-out of the sale or sharing of that consumer's personal information, also within 45 days;
  • direct its service providers and contractors to delete, or to process the opt-out.

After a deletion, the duty repeats. Under § 1798.99.86(d), the broker "shall delete all personal information of the consumer at least once every 45 days" and "shall not sell or share new personal information of the consumer", subject to the statutory exemptions.

How does DROP matching work?

Under the DROP regulations, a consumer deletion list contains identifiers "(e.g., email address, phone number, or combination of name, date of birth, and zip code)" in hashed form, with a transaction identifier and the hashing algorithm used (§ 7601(c)). The broker downloads its lists at least "once every 45 calendar days" (§ 7612(a)), standardizes and hashes the same fields in its own records and compares them (§ 7613(a)).

A consumer may add "pseudonymous identifiers, such as a Mobile Ad Identifier ('MAID')" to a request (§ 7620(b)). On a match, the broker deletes all personal information associated with the identifier, "including inferences based in whole or in part on personal information collected from third parties" (§ 7613(b)(1)); data it "collected directly from the consumer as a 'first party'" is outside that duty (§ 7613(b)(1)(A)). The broker keeps an unmatched request on file and checks it against newly collected records before it sells or shares new personal information (§ 7613(c)).

Who counts as a data broker under the California Delete Act?

A data broker is "a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship" (§ 1798.99.80(c)). Entities are excluded to the extent the FCRA, the Gramm-Leach-Bliley Act, California's insurance privacy act or the § 1798.146 health exemption covers them.

From the regulations' definition of "direct relationship": "A business does not have a 'direct relationship' with a consumer simply because it collects personal information directly from the consumer; the consumer must intend to interact with the business" (§ 7601(d)).

What does Delete Act registration require?

A broker registers by January 31 each year after a year in which it met the definition (§ 1798.99.82(a)). The 2026 fee is "$6,000 plus an associated third-party fee" (§ 7600(a)). A business that starts brokering mid-year begins accessing DROP within 45 days and pays a first-time access fee, $6,000 in January down to $500 in December (§ 7611).

Since January 1, 2026 (SB 361), the registration form also asks whether the broker collects mobile advertising IDs or biometric data, and whether it sold or shared data with a foreign actor, law enforcement or a GenAI developer (§ 1798.99.82(b)(2)). The answers on names and contact data, advertising IDs and the "most common types" of data are withheld from the public registry (§ 1798.99.84(b)). The questions on minors and precise geolocation predate SB 361, and both answers are public.

The registry download on October 2, 2026 lists 603 brokers that registered for 2025 activity; 115 answered "Yes" to collecting precise geolocation and 18 to collecting personal information of minors.

Duty Source When
Register and pay the annual fee ($6,000 in 2026) § 1798.99.82(a), reg. § 7600 By January 31 each year
Access DROP and download deletion lists § 1798.99.86(c)(1), reg. § 7612(a) From August 1, 2026, at least every 45 days
Independent compliance audit § 1798.99.86(e) From January 1, 2028, every three years

Fines under § 1798.99.82: $200 per day of failure to register, plus the unpaid fees and CalPrivacy's expenses (subdivision (c)); $200 per deletion request per day of failure to delete, plus expenses (subdivision (d)). CalPrivacy's data broker page cites subdivision (d) for the registration fine; the current text and the 2026 orders below use (c).

What has CalPrivacy enforced since DROP went live?

Between August 11 and September 3, 2026, CalPrivacy announced three broker decisions and one advisory:

  • LocateSmarter LLC, August 11, 2026: the Iowa company pays $116,490 under a stipulated order: a $30,600 Delete Act fine under § 1798.99.82(c), the $6,000 annual fee and a $79,890 CCPA fine. CalPrivacy's release states the company failed to register on time and "allegedly required Californians to provide unnecessary data, including the last four digits of their Social Security number" before they could opt out, and calls the decision "the first to arise under both the CCPA and the Delete Act."
  • Cybba, Inc., August 13, 2026: a $52,400 fine for missing the 2025 registration deadline. CalPrivacy's release describes the Boston company as selling personal information, "including geolocation data, internet activity data, and inferences", for targeted advertising.
  • SalesIntel Research, Inc., September 1, 2026: a $36,400 fine, of which $6,600 reflects the 2025 registration fee; the Enforcement Division alleged the Virginia company operated as a data broker without registering by the 2025 deadline (release). Michael Macko, CalPrivacy's head of enforcement: "If you're operating in the AdTech ecosystem, these recent enforcement actions are reminders to review whether you engaged in data broker activity and properly registered."
  • Enforcement Advisory 2026-01, September 3, 2026: incorrect registration information triggers "a $200 fine for each day the incorrect information appears in the registry."

Each order requires the company to "access the Agency's Delete Request and Opt-out Platform ('DROP') and process consumer deletion requests" for any year it operates as a data broker.

What changes in 2027?

AB 883, approved on September 27, 2026 (Chapter 507), changes each 45-day period in § 1798.99.86(c) and (d) to 30 days. The bill's only operative date, July 1, 2027, is in subdivision (i) of the new § 1798.99.86.5 on elected officials and judges, and the bill status page lists AB 883 as non-urgency. Under Article IV, § 8(c)(1) of the California Constitution, a regular-session statute takes effect "on January 1 next following a 90-day period from the date of enactment", which puts the 30-day cycle at January 1, 2027; Venable's September 2026 summary gives the same date. Regulation § 7612(a) still sets 45 calendar days as of October 2, 2026.

SB 923, approved the same day (Chapter 482), extends the CCPA right to delete in § 1798.105(a) to personal information "collected from or about the consumer"; its findings state that "Many businesses regularly collect personal information from third parties." It takes effect on January 1, 2027.

Connecticut's act banning the sale of precise geolocation data also requires data brokers to register with its Department of Consumer Protection by January 1, 2027 (see the post on Connecticut SB 4).

What does an app's network traffic show about data brokers?

DROP accepts the advertising ID, and CalPrivacy's page on unique identifiers says a MAID "allows data brokers to track a user's activity within apps and across different platforms for targeted advertising purposes." In captured app traffic, the advertising ID appears as a field in requests to ad and attribution SDK hosts, recorded with the request's IP address and, where the app has location permission and the SDK sends them, coordinates. Related: the posts on ad SDKs and precise location and the FTC's Kochava order.

Some SDK publishers are registered brokers. The 2026 registry download, which covers businesses that "operated as data brokers in 2025", lists AppLovin Corporation, Ogury Ltd, and Chartboost, LLC (doing business as Chartboost and LoopMe), among others. A capture of an advertising ID sent to one of their hosts shows disclosure to a registered California data broker. Whether that company sold the data, received it as the app's service provider, or keeps it in records a DROP deletion covers turns on contracts, SDK terms and discovery.

When I scan an app, the report lists the SDKs found in the binary, the permissions and consent flow, and the requests recorded on the test device: host, the identifiers in each request (advertising ID, IP address, coordinates, hashed email), and whether each was sent before or after consent. Every static finding cites its file and line; every traffic finding cites its capture. SDK presence in a binary shows the code is there; only a capture shows an identifier was sent. The methodology page sets out what a scan checks and its limits.

I run these investigations for lawyers and the researchers working with them, on one app or on a list of apps in bulk. Sign up for a CanITrustThat account to run your own research, let us run an investigation for you, or browse the scanned apps.

App privacy law, applied to real apps.

Posts on new laws, fines and studies, and teardowns of the apps those laws apply to.

How we use your address: privacy notice. Prefer a feed reader? Use the RSS feed.