What is the California DROP (Delete Request and Opt-out Platform)?
The DROP is California's Delete Request and Opt-out Platform, built by CalPrivacy under the Delete Act. Since August 1, 2026, every registered data broker must check it at least once every 45 days and delete the personal information of consumers who filed a request, subject to limited exceptions.
Applies to: Businesses that meet California's data broker definition, meaning they knowingly collect and sell to third parties the personal information of consumers with whom they have no direct relationship, and are therefore required to register with CalPrivacy and process deletion requests through the DROP.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanThe Delete Act gave California consumers something no other state has: one request that reaches every registered data broker at once. For brokers, that single request became an operating obligation on August 1, 2026.
Where the DROP came from
In 2023 the Legislature passed the Delete Act, Senate Bill 362, Chapter 709, Statutes of 2023. It requires the Agency to establish an accessible deletion mechanism that lets consumers request, from registered data brokers, deletion of all non-exempt personal information related to the consumer through a single deletion request to the Agency.
CalPrivacy built that mechanism as a web application called the Delete Request and Opt-out Platform, the DROP. The Agency adopted regulations on the accessible deletion mechanism on September 26, 2025. The Office of Administrative Law approved them on November 6, 2025 and they were filed with the Secretary of State. Their effective date is January 1, 2026.
The obligation that started on August 1, 2026
This is the date that matters operationally. Under Cal. Civ. Code section 1798.99.86(c), beginning August 1, 2026 data brokers must access the accessible deletion mechanism at least once every 45 days and process consumer deletion requests, subject to limited exceptions.
The reach is deliberately wide. The mechanism allows a consumer, through a single verifiable request, to direct every data broker that maintains any personal information related to that consumer, held by the data broker or their service provider or contractor, to delete that information.
Two practical consequences follow. First, 45 days is a ceiling, not a target, and it runs continuously rather than being triggered by anything a consumer sends you directly. Second, deletion has to cover data held on your behalf by service providers and contractors, not only the records in your own systems. If a consumer's information matches your records, the associated personal data, including inferences, comes out unless a legal exemption applies, and you report the status of the request back in the DROP.
Who counts as a data broker
The definition sits in Cal. Civ. Code section 1798.99.80(c), which leans on the definition of "business" in Cal. Civ. Code section 1798.140(d), and on the adopted regulations. To fall inside it, a business must knowingly collect and sell to third parties the personal information of a consumer with whom the business does not have a direct relationship. The definition of personal information is in Cal. Civ. Code section 1798.140(v).
The direct-relationship test is the one most companies get wrong. Selling data about your own customers does not make you a data broker. Selling data about people who have never dealt with you is what does.
Registration, and what failing it costs
The Delete Act requires a business to register annually starting the year after it began brokering the data of California residents. Registration and payment run between January 1 and January 31 through the DROP. The 2026 fee is $6,000 plus an associated third-party processing fee for electronic payments.
A data broker that fails to register by January 31 may be liable for administrative fines and costs in an administrative action or investigation brought by the Agency, under Cal. Civ. Code section 1798.99.82(d).
The disclosures SB 361 added
California expanded broker transparency again with SB 361 in 2025. Beyond basic business information, brokers must now disclose whether they collect additional sensitive data types such as sexual orientation, union membership, or citizenship status. They must state what categories of personal information they collect, such as mobile advertising identification numbers, basic identification information like name, email, and phone number, and login or account information. SB 361 also requires disclosure of selling and sharing practices, including whether data has been shared with foreign actors, law enforcement, or developers of generative AI systems.
Separately, by July 1 following the first year a business meets the data broker definition, brokers must compile and publish in their online privacy policy the number of consumer requests received, complied with in whole or in part, and denied in the previous calendar year, across deletion, know and access, know what is sold or shared and to whom, opt-out of sale or sharing, and limit use of sensitive personal information, together with the median and mean number of days taken to respond substantively.
Audits are already on the calendar
Beginning January 1, 2028, and every three years after that, data brokers must undergo an audit by an independent third party to determine compliance with the law, and must submit the audit report to the Agency on the Agency's written request. Beginning January 1, 2029, a broker registering with the Agency must also disclose whether it has undergone that audit and, if so, the most recent year it submitted a report and any related materials.
Three years is not long to build an auditable record. The evidence an auditor will want, dated DROP access logs, match results, deletion confirmations, and exemption decisions, is evidence you have to be generating now.
Next step
Most companies that worry about the DROP are not data brokers, and most that are have other California obligations running alongside it. The free 2-minute Obligation Scan tells you which US state privacy laws and GDPR apply to your business and what each one requires. If registration rather than deletion is your question, the California data broker registration page covers the annual filing, and the CCPA right to delete page covers the consumer deletion right that applies to businesses generally.
Compliance checklist
- Confirm whether you meet the data broker definition in Cal. Civ. Code section 1798.99.80(c), which turns on knowingly collecting and selling to third parties the personal information of consumers you have no direct relationship with.
- Create your DROP account and complete registration between January 1 and January 31 each year, and budget for the annual fee.
- Put a recurring job on the calendar to access the DROP at least once every 45 days, and record the date of every access so you can evidence the cycle.
- Match retrieved requests against your records and delete all associated personal information, including inferences, unless a legal exemption applies, then report the status of each request back in the DROP.
- Publish your annual request metrics in your privacy policy by July 1, covering deletion, know and access, know sale or sharing, opt-out, and limit-sensitive-information requests, plus the median and mean days you took to respond.
- Plan for the independent third-party audit that begins January 1, 2028 and repeats every three years, and for the audit disclosure that registration requires from January 1, 2029.
Sources
- Information for Data Brokers, California Privacy Protection Agency (CalPrivacy)
- Accessible Deletion Mechanism, Delete Request and Opt-out Platform (DROP) System Requirements, California Privacy Protection Agency
Last verified: 2026-08-20
Informational, not legal advice.