Back to the hub

What is the CA DROP law?

The DROP is California's Delete Request and Opt-out Platform, built by CalPrivacy under the Delete Act. Since August 1, 2026, every registered data broker must check it at least once every 45 days and delete the personal information of consumers who filed a request, subject to limited exceptions.

Applies to: Businesses that meet California's data broker definition, meaning they knowingly collect and sell to third parties the personal information of consumers with whom they have no direct relationship, and are therefore required to register with CalPrivacy and process deletion requests through the DROP.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

The Delete Act gave California consumers something no other state has: one request that reaches every registered data broker at once. For brokers, that single request became an operating obligation on August 1, 2026.

Is it the "DROP Act"?

Worth clearing up the name first, because the search term and the statute do not match. There is no California statute called the "DROP Act." The law is the Delete Act, Senate Bill 362 (2023). The DROP is the platform that the Delete Act directed the California Privacy Protection Agency to build. If someone points you at the "DROP Act," they mean the Delete Act obligations described below.

Where the DROP came from

In 2023 the Legislature passed the Delete Act, Senate Bill 362, Chapter 709, Statutes of 2023. It requires the Agency to establish an accessible deletion mechanism that lets consumers request, from registered data brokers, deletion of all non-exempt personal information related to the consumer through a single deletion request to the Agency.

CalPrivacy built that mechanism as a web application called the Delete Request and Opt-out Platform, the DROP. The Agency adopted regulations on the accessible deletion mechanism on September 26, 2025. The Office of Administrative Law approved them on November 6, 2025 and they were filed with the Secretary of State. Their effective date is January 1, 2026.

The obligation that started on August 1, 2026

This is the date that matters operationally. Under Cal. Civ. Code section 1798.99.86(c), beginning August 1, 2026 data brokers must access the accessible deletion mechanism at least once every 45 days and process consumer deletion requests, subject to limited exceptions.

The reach is deliberately wide. The mechanism allows a consumer, through a single verifiable request, to direct every data broker that maintains any personal information related to that consumer, held by the data broker or their service provider or contractor, to delete that information.

Two practical consequences follow. First, 45 days is a ceiling, not a target, and it runs continuously rather than being triggered by anything a consumer sends you directly. Second, deletion has to cover data held on your behalf by service providers and contractors, not only the records in your own systems. If a consumer's information matches your records, the associated personal data, including inferences, comes out unless a legal exemption applies, and you report the status of the request back in the DROP.

Who counts as a data broker

The definition sits in Cal. Civ. Code section 1798.99.80(c), which leans on the definition of "business" in Cal. Civ. Code section 1798.140(d), and on the adopted regulations. To fall inside it, a business must knowingly collect and sell to third parties the personal information of a consumer with whom the business does not have a direct relationship. The definition of personal information is in Cal. Civ. Code section 1798.140(v).

The direct-relationship test is the one most companies get wrong. Selling data about your own customers does not make you a data broker. Selling data about people who have never dealt with you is what does.

Registration, and what failing it costs

The Delete Act requires a business to register annually starting the year after it began brokering the data of California residents. Registration and payment run between January 1 and January 31 through the DROP. The 2026 fee is $6,000 plus an associated third-party processing fee for electronic payments.

A data broker that fails to register by January 31 may be liable for administrative fines and costs in an administrative action or investigation brought by the Agency, under Cal. Civ. Code section 1798.99.82(d).

The disclosures SB 361 added

California expanded broker transparency again with SB 361 in 2025. Beyond basic business information, brokers must now disclose whether they collect additional sensitive data types such as sexual orientation, union membership, or citizenship status. They must state what categories of personal information they collect, such as mobile advertising identification numbers, basic identification information like name, email, and phone number, and login or account information. SB 361 also requires disclosure of selling and sharing practices, including whether data has been shared with foreign actors, law enforcement, or developers of generative AI systems.

Separately, by July 1 following the first year a business meets the data broker definition, brokers must compile and publish in their online privacy policy the number of consumer requests received, complied with in whole or in part, and denied in the previous calendar year, across deletion, know and access, know what is sold or shared and to whom, opt-out of sale or sharing, and limit use of sensitive personal information, together with the median and mean number of days taken to respond substantively.

Audits are already on the calendar

Beginning January 1, 2028, and every three years after that, data brokers must undergo an audit by an independent third party to determine compliance with the law, and must submit the audit report to the Agency on the Agency's written request. Beginning January 1, 2029, a broker registering with the Agency must also disclose whether it has undergone that audit and, if so, the most recent year it submitted a report and any related materials.

Three years is not long to build an auditable record. The evidence an auditor will want, dated DROP access logs, match results, deletion confirmations, and exemption decisions, is evidence you have to be generating now.

The DROP timeline CalPrivacy publishes

The California Privacy Protection Agency, which now operates publicly as CalPrivacy, publishes a four-stage timeline for DROP. It is worth reading alongside the statute, because it tells you what the regulator expects to see and when.

January 1, 2026: DROP launches and Californians can start submitting requests.

August 1, 2026: data brokers begin processing requests. CalPrivacy warns consumers it could take up to 90 days before a status update appears in DROP, and that timing varies by data broker.

November 2026: by this point, all data brokers in DROP should have completed their initial download and upload cycle. From then on the obligation is steady state, and brokers must delete data every 45 days.

The consumer-facing platform sends a single request to more than 600 registered data brokers, and eligibility is limited to California residents, verified through the California Identity Gateway.

What the statute requires, section by section

Civil Code 1798.99.86(c)(1) is the operative obligation: "Beginning August 1, 2026, a data broker shall access the accessible deletion mechanism established pursuant to subdivision (a) at least once every 45 days" and do four things.

Subparagraph (A): within 45 days after receiving a request, process all deletion requests and delete all personal information related to the consumers making them.

Subparagraph (B): where the broker denies a deletion request because it cannot be verified, process the request instead as an opt-out of the sale or sharing of that consumer's personal information under Section 1798.120, as limited by Sections 1798.105, 1798.145 and 1798.146, within 45 days of receipt. An unverifiable request is not a dead request.

Subparagraphs (C) and (D): direct all associated service providers and contractors to delete the same data, and to process an unverifiable request as an opt-out on the same terms.

Section 1798.99.86(c)(2) supplies the only two exceptions. A broker need not delete where it is reasonably necessary to maintain the information for a purpose described in Civil Code 1798.105(d), or where deletion is not required under Section 1798.145 or 1798.146. Section 1798.99.86(c)(3) then confines any information retained under that paragraph to those purposes alone.

The consumer-side mechanics that shape broker workload

Section 1798.99.86(a) sets what the mechanism itself must do, and two of its requirements drive broker volume. Paragraph (2) lets a consumer, through a single verifiable consumer request, reach every data broker holding their information. Paragraph (3) lets a consumer selectively exclude specific brokers from that request, so a broker cannot assume every California consumer is in scope. Paragraph (4) lets a consumer alter a previous request once at least 45 days have passed since the last one.

That 45-day cadence appears three times in the section: the consumer's re-request interval, the broker's polling interval, and the broker's processing deadline. Aligning your internal cycle to it is the practical implementation.

Next step

Most companies that worry about the DROP are not data brokers, and most that are have other California obligations running alongside it. The free 2-minute Obligation Scan tells you which US state privacy laws and GDPR apply to your business and what each one requires. If registration rather than deletion is your question, the California data broker registration page covers the annual filing, and the CCPA right to delete page covers the consumer deletion right that applies to businesses generally.

Compliance checklist

  • Confirm whether you meet the data broker definition in Cal. Civ. Code section 1798.99.80(c), which turns on knowingly collecting and selling to third parties the personal information of consumers you have no direct relationship with.
  • Create your DROP account and complete registration between January 1 and January 31 each year, and budget for the annual fee.
  • Put a recurring job on the calendar to access the DROP at least once every 45 days, and record the date of every access so you can evidence the cycle.
  • Match retrieved requests against your records and delete all associated personal information, including inferences, unless a legal exemption applies, then report the status of each request back in the DROP.
  • Publish your annual request metrics in your privacy policy by July 1, covering deletion, know and access, know sale or sharing, opt-out, and limit-sensitive-information requests, plus the median and mean days you took to respond.
  • Plan for the independent third-party audit that begins January 1, 2028 and repeats every three years, and for the audit disclosure that registration requires from January 1, 2029.

Sources

Last verified: 2026-09-07

Informational, not legal advice.