Obtainer
Use case

California Delete Act Compliance: DROP Deletion Requests for Data Brokers

On August 1, 2026 the California Delete Act stops being a registration formality and becomes an operating requirement. Every registered data broker has to pull deletion requests out of the state's DROP platform at least once every 45 days, match them against its records, delete what matches, tell its service providers to do the same, and then keep re-deleting that consumer every 45 days for as long as it holds data. Obtainer handles the part that actually takes the time: finding where each person's data lives across your systems, compiling a reviewable manifest, keeping the clocks, and leaving an evidence trail you can hand a regulator.

See how it works
Discovery across your systems Human redaction gate Helps you comply, not legal advice
Request Studio
Requester
Compiled the manifest and drafted the response - illustrative sample request
0
records found
0
systems scanned
Data manifest
Response draft

Assembling the cover letter from the template...

You approve what is disclosed before anything ships

Helps you comply, not legal advice

In short

The California Delete Act (Senate Bill 362, 2023) moved the state data broker registry to the California Privacy Protection Agency and required the agency to build a single deletion mechanism, the Delete Request and Opt-out Platform, known as DROP. A data broker is a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship, subject to statutory exemptions. If that describes you, you must register with the agency every year between January 1 and January 31. The 2026 registration fee is $6,000 plus a third-party processing fee for electronic payment, up from the $400 the old attorney general registry charged, because the statute makes registration fees pay for DROP itself. Registration is not just a name and address. You disclose whether you collect the personal information of minors, precise geolocation, or reproductive healthcare data, your regulatory status under the FCRA, GLBA, HIPAA and state insurance and medical privacy laws, a link to a page explaining how consumers exercise their rights, metrics on how many CCPA and Delete Act deletion requests you received, complied with in whole or in part, and denied, and, under the 2026 registration cycle, whether personal information was shared with foreign actors, law enforcement, or developers of generative AI systems. DROP opened to California consumers on January 1, 2026, and a resident submits one request that reaches every registered data broker at once. The operational clock starts August 1, 2026. From that date, Civil Code section 1798.99.86 requires a data broker to access the deletion mechanism at least once every 45 days, and for every consumer whose request matches its records, delete all personal information related to that consumer, direct all service providers and contractors to delete the personal information in their possession, and finish its determinations within 90 days of retrieving the batch. The part teams miss is subdivision (d): the obligation does not end with the first deletion. You must delete that consumer's personal information at least once every 45 days going forward, and you may not sell or share new personal information about that consumer. Deletion can be declined only where an exemption applies, principally the retention purposes in Civil Code section 1798.105(d) and the carve-outs in sections 1798.145 and 1798.146. Failing to register carries administrative fines of $200 per day plus the agency's investigation costs, and failing to process a deletion request carries $200 per request per day, which compounds fast when a single unprocessed batch holds thousands of consumers. Beginning January 1, 2028 you must also undergo an independent third-party audit every three years, with audit compliance reported at registration from January 1, 2029. Obtainer covers the operational half of this. Once you have retrieved a DROP batch, it finds where each person's data actually sits across your source systems, compiles one reviewable manifest that shows which downstream recipients need a deletion instruction, tracks the 45-day and 90-day clocks, and keeps a timestamped record of what was searched, found, deleted, and declined. Nothing is erased automatically. A human reviews and approves. Obtainer helps you comply. It is not legal advice, so scope and exemption calls stay with your team. Self-serve from $49/mo.

// THE FIT

Why it fits

Registered California data brokers preparing for the August 1, 2026 DROP deadline, people-search and identity-verification businesses, marketing and audience data providers, lead-generation and enrichment vendors, adtech and location data companies, and any business that has just worked out it meets the no-direct-relationship definition and needs a repeatable deletion process before its first batch lands.

August 1, 2026 starts a permanent 45-day cycle, not a one-time cleanup

Most compliance projects have an end. This one does not. The statute requires you to access DROP at least once every 45 days, and once a consumer has been matched and deleted, subdivision (d) of Civil Code section 1798.99.86 requires you to delete that consumer's personal information again at least once every 45 days for as long as you operate, and forbids you from selling or sharing new personal information about them. That turns a deletion request into a standing suppression obligation. A spreadsheet and a quarterly SQL script will pass the first cycle and quietly fail the eighth, because new data about a previously deleted consumer keeps arriving through the same feeds that brought it the first time. What you need is a repeatable pass that re-runs discovery against every source, proves it ran, and shows what it found.

Deletion has to reach your service providers and contractors, not just your database

Subdivision (c)(1)(C) requires you to direct all service providers and contractors associated with your business to delete the personal information in their possession. You cannot issue that instruction if you cannot name the recipients, and most brokers cannot, because data left through an enrichment partner, a hosted append service, a cloud warehouse share, or a reseller agreement that predates the current team. Obtainer's discovery pass reports the source system behind every record it surfaces, which converts the downstream instruction list from a guess into a document you can produce and evidence later.

The registration form asks for numbers you have to be able to produce

California requires registered data brokers to report the metrics for their consumer requests: how many they received, how many they complied with in whole or in part, and how many they denied. Those figures are a public, sworn statement of how your process performed, filed in the same month every year. If your requests arrive in a shared inbox and get resolved by whoever is free, you will be estimating a regulated disclosure. Running requests through one system of record means the January filing is a report you export rather than a reconstruction you attempt.

The agency is counting days, not harms

On January 8, 2026 the California Privacy Protection Agency announced two data broker actions on the same day: Rickenbacher Data LLC, which does business as Datamasters, agreed to a $42,000 fine for failing to register, and S&P Global, Inc. agreed to $62,000 after remaining unregistered for 313 days. Neither case turned on a consumer being harmed. They turned on arithmetic: a per-day penalty multiplied by the number of days out of compliance. The same arithmetic applies to deletion requests at $200 per request per day, which is why an unprocessed batch is a materially different kind of risk from a late individual response.

// FAQ

Questions

Common questions about this

What is the California Delete Act?

The Delete Act is California Senate Bill 362, signed in 2023. It moved the state data broker registry from the Attorney General to the California Privacy Protection Agency, expanded what brokers must disclose when they register, and required the agency to build a single mechanism through which a California resident can send one deletion request to every registered data broker at once. That mechanism is DROP, the Delete Request and Opt-out Platform. It also added a recurring deletion duty and a third-party audit requirement.

Am I a data broker under the California Delete Act?

You are if you knowingly collect and sell to third parties the personal information of consumers with whom you do not have a direct relationship, unless a statutory exemption applies. The test is the relationship, not your self-description or your industry label. Entities regulated as consumer reporting agencies under the FCRA, financial institutions under the GLBA, and covered entities under HIPAA and California medical privacy law have carve-outs to the extent the data is covered there. Many enrichment, audience, and lead vendors qualify without ever using the phrase.

When do data brokers have to start processing DROP deletion requests?

August 1, 2026. California consumers have been able to submit requests through DROP since January 1, 2026, and those requests have been queuing against more than 600 registered data brokers since then. From August 1 you must access the deletion mechanism at least once every 45 days, and you have 45 days from that first access to work through your first batch, with determinations completed within 90 days of retrieval.

How often do data brokers have to check DROP?

At least once every 45 days, beginning August 1, 2026. This is a floor, not a schedule you can negotiate down in a light quarter. Each time you retrieve requests you have to match them against your records, delete all personal information related to matching consumers, and instruct your service providers and contractors to delete their copies. Determinations must be complete within 90 days of retrieval, which means the retrieval and processing windows overlap rather than run one after the other.

Do I have to delete a consumer's data only once, or repeatedly?

Repeatedly. Civil Code section 1798.99.86(d) requires that once a consumer has submitted a deletion request through the mechanism, the data broker delete all personal information of that consumer at least once every 45 days, and it prohibits selling or sharing new personal information about that consumer. In practice a DROP request creates a permanent suppression obligation, because your ordinary data feeds will keep re-acquiring records about people you already deleted.

What are the penalties for failing to comply with the Delete Act?

Failing to register by January 31 carries administrative fines of $200 for each day you are not registered, plus the agency's expenses in the investigation and administrative action. Failing to delete carries $200 per deletion request per day. Because the second figure multiplies by the number of requests, a single batch left unprocessed produces a far larger number than a late registration does. The California Privacy Protection Agency enforces both.

When do the Delete Act audit requirements start?

Beginning January 1, 2028, a data broker must undergo an audit by an independent third party every three years to determine compliance with the Delete Act, and must submit the audit report to the agency on request. From January 1, 2029, registration must include information about that audit compliance. Auditors will look for evidence that each cycle ran, so the records you keep in 2026 are the material the 2028 audit will examine.

Run a data subject access request end to end

Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.