California’s Delete Act has moved from statute to enforcement. Starting August 1, 2026, more than 600 registered data brokers must begin systematically processing consumer deletion requests through DROP, the state’s new centralized deletion platform, or face financial penalties. Here’s what DROP actually requires, who it applies to, and how brokers can get ahead of it.
What is DROP?
DROP, short for the Delete Request and Opt-Out Platform, is a centralized tool operated by the California Privacy Protection Agency (CPPA). It lets a California resident submit a single deletion request that reaches every data broker registered with the state, rather than filing separate requests with each company individually.
The platform opened to consumers on January 1, 2026. As of this spring, more than 300,000 Californians had already submitted deletion requests through it, all of which are now queued for processing ahead of the August 1 deadline.
Any company that meets California’s legal definition of a data broker must create a DROP account, register annually with the CPPA, and follow the deletion process the Delete Act lays out.
Who does this apply to, and why does it matter?
DROP access is limited to registered data brokers themselves. Third-party platforms, including consent and privacy management vendors, are not permitted to access DROP directly on a broker’s behalf.
For the data brokers that are subject to it, the obligation is not optional. Beginning August 1, 2026, brokers must access DROP at least every 45 days, and the Delete Act attaches real financial penalties to noncompliance: a recent amendment, SB 361, doubled the daily administrative fine for failing to register on California’s data broker registry from $100 to $200 per consumer, per day.
How the DROP process works
At a high level, the law expects data brokers to download deletion lists from DROP, search their own records for matches, delete what they find, and report back on what happened. The full cycle breaks down into five steps:
- Consumer submits a request. A California resident files a deletion request directly through DROP. The CPPA verifies the person’s identity and residency before anything moves forward.
- DROP compiles and distributes the verified list. Once verified, the request is added to a consolidated deletion list, built on hashed identifiers like email and phone number, that’s made available to every registered broker.
- Brokers download the list and take action. Brokers must check DROP at least every 45 days (via CSV download or API), match the list against their own records, and delete any personal information they find. Processing must be completed within 45 days of receipt. If a consumer’s data can’t be located or deleted, the broker must instead opt that consumer out of the sale or sharing of their information.
- Brokers report the outcome back to DROP. For each request, brokers report what happened: record deleted, record not found, consumer not in the database, or information incomplete.
- DROP handles all consumer communication. The platform, not the broker, follows up with the consumer. Brokers are prohibited from contacting consumers directly to verify or discuss a deletion request.
What SB 361 adds to the picture
SB 361, signed into law in late 2025, expands the Delete Act’s disclosure and enforcement provisions. Data brokers must now disclose to the CPPA whether they collect sensitive categories of data, such as biometric information, immigration status, or government identifiers, and whether they’ve sold or shared consumer data with foreign actors, government entities, law enforcement, or generative AI developers. The CPPA is restricted from making certain of those disclosures public.
SB 361 also sets a firm 45-day deadline for brokers to treat any denied or unverifiable deletion request as an opt-out of data sale and sharing, and it’s the amendment responsible for doubling the daily noncompliance fine to $200. Registration filings reflecting these new disclosure requirements came due at the start of 2026, well ahead of the August 1 processing deadline.
How TrustArc supports DROP compliance
For data brokers navigating this process, TrustArc’s Individual Rights Manager is built to be the source of truth for individual rights and deletion requests, DROP included.
Individual Rights Manager supports the operational core of the DROP cycle: brokers can export a deletion list from DROP and submit it into Individual Rights Manager as a single, auditable request. Because verification and consumer communication are handled by DROP and the CPPA, Individual Rights Manager supports bulk request handling without duplicating that verification step. From there, Individual Rights Manager can be paired with TrustArc’s integrations to search and delete matching records across downstream systems, and its existing status-reporting tools help brokers assemble the outcomes they need to report back to DROP.
TrustArc also tracks the regulatory side of this closely. Ask Arc and Nymity Research provide ongoing guidance on Delete Act and DROP obligations, along with updates on enforcement activity and emerging requirements like those introduced by SB 361, so compliance teams aren’t left tracking deadlines and rule changes on their own.
Getting ready for August 1
The August 1, 2026 deadline is fixed, the penalties are real, and the volume of requests already queued in DROP means brokers have no ramp-up period once enforcement begins. Companies that fall under the Delete Act’s data broker definition should confirm their DROP registration is current, map out how deletion requests will flow into their internal systems, and put a reporting process in place now, not in the weeks before the deadline.
See Individual Rights Manager handle a DROP request end to end
Bring us a sample deletion list and we’ll walk your team through intake, search and delete across connected systems, and status reporting back to the CPPA, all inside Individual Rights Manager.
Request a DROP readiness walkthrough