How California's DROP tool lets you erase your data from every broker at once
DROP lets Californians send one deletion request to hundreds of data brokers. Brokers that ignore it face fines of $200 per request per day.

Californians who want their personal information out of the hands of data brokers used to have to find each broker, figure out its opt-out process, and repeat that work company by company. The Delete Act changed that. It created a state-run tool called the Delete Request and Opt-Out Platform, or DROP, that lets a resident submit one deletion request that reaches every broker registered with the state at once.
DROP opened to consumers on January 1, 2026. The compliance clock for data brokers started on August 1, 2026, when they became legally required to check the platform and act on the requests sitting in it. For California tech companies that buy, sell or handle third-party consumer data, understanding how DROP's request cycle and penalty structure work is now a practical compliance question, not a future one.
What DROP actually does
DROP is a web application built by California's Privacy Protection Agency, the state's dedicated privacy regulator, sometimes referred to by its newer public-facing name, CalPrivacy. It serves as the accessible deletion mechanism required under the Delete Act, formally Senate Bill 362, which Governor Gavin Newsom signed in October 2023.
To use it, a consumer goes to Privacy.ca.gov, registers with an email address, verifies California residency, and can optionally add identifiers such as a phone number, date of birth or name variations to help brokers match records. The consumer then submits a single deletion request, which is transmitted to every active data broker registered with the state rather than requiring separate contact with each one. The agency describes it as the first system of its kind in the country: one request reaching more than 500 registered data brokers.
As of mid-August 2026, more than 475,000 Californians had submitted a deletion request through the platform, according to the Governor's office. Consumers can amend or cancel a submitted request, but not sooner than 45 days after they filed it.
How data brokers are required to respond
Registration with the state comes first. Any business that meets the legal definition of a data broker, one that knowingly collects and sells the personal information of consumers with whom it has no direct relationship, must register annually with the CPPA by January 31, paying a $6,000 fee plus processing costs. That definition applies broadly, with no revenue threshold or carve-out for partial data sales, and can sweep in retailers that sell audience segments, lead generators that resell third-party data, adtech and analytics platforms, and business intelligence firms, even ones that don't think of themselves as data brokers.
Processing obligations follow a separate, later deadline. Beginning August 1, 2026, registered brokers must access DROP at least once every 45 days to download the current deletion list, and they must report an outcome for each request within 45 days of receiving it. Regulators require brokers to report one of four standardized outcomes for each request: deleted, opted out of sale, exempted, or not found. If a request can't be verified, the broker must still process it as an opt-out of future sale or sharing rather than simply setting it aside, and brokers are barred from contacting consumers directly to verify a request.
The deletion duty is also broader than under the state's general privacy law. It covers personal information a data broker holds itself as well as information held by its service providers and contractors, and it extends to inferences a broker has built from data it collected about a consumer from third parties.
To help brokers get ready, the agency opened a DROP Sandbox testing environment in March 2026 and rolled out programmatic API access that spring, so brokers with large volumes could automate matching and reporting rather than downloading lists by hand ahead of the August deadline.
What noncompliance costs
The Delete Act sets two separate fine tracks, both run through the CPPA's administrative enforcement process rather than private lawsuits. A broker that fails to register by the January 31 deadline faces an administrative fine of $200 for each day it remains unregistered, plus any unpaid fees and the agency's investigation costs.
A broker that fails to process deletion requests once the August 1 obligation applies faces a fine of $200 for each deletion request for each day it remains unresolved, also plus investigation costs. Because that fine multiplies by both the number of unprocessed requests and the number of days they sit unresolved, the total can escalate quickly for a broker handling a large volume of requests that falls behind. Under the regulations the agency adopted, there is no grace period once a violation is found: registration and processing failures are enforceable as soon as the relevant deadline passes.
The Delete Act also requires brokers to undergo independent third-party audits starting January 1, 2028 and every three years after that, with the first audit results due to the agency by January 1, 2029, and to publish metrics on the deletion requests they've received and processed on their privacy policies every July 1.
“Because that fine multiplies by both the number of unprocessed requests and the number of days they sit unresolved, the total can escalate quickly.”
A pattern of enforcement before and after the August deadline
The CPPA's enforcement arm was already active against unregistered brokers well before the August 2026 processing deadline took effect. On January 8, 2026, the agency announced a $42,000 fine against Rickenbacher Data LLC for failing to register and a $62,000 fine against S&P Global, Inc., which had gone unregistered for 313 days. Earlier cases brought registration-failure fines against Accurate Append, for $55,400, and National Public Data, for $46,000, while a separate case against Background Alert carried a $50,000 penalty or an operational suspension running until 2028. The agency has now brought more than a dozen enforcement actions against data brokers in total.
In August 2026, the agency announced actions against two companies, including its first case combining violations under the California Consumer Privacy Act and the Delete Act. LocateSmarter LLC, an Iowa-based broker that sells names, dates of birth, Social Security numbers, addresses, phone numbers, employment information and driver's license and bankruptcy records, had failed to register for the 2025 calendar year and required consumers to submit their full name, mailing address and the last four digits of their Social Security number just to opt out, a practice the agency found violated the CCPA's data-minimization rules. LocateSmarter agreed to pay $116,490, combining a $79,890 CCPA fine, a $30,600 Delete Act fine and its outstanding $6,000 registration fee, and to strip the Social Security number requirement from its opt-out process, simplify the procedure, retrain staff and register within 14 days.
Cybba, Inc., a Boston-based firm that sells geolocation data, internet activity information and other identifiers to marketers, agreed to pay $52,400 after failing to register for its 2024 data-broker activity; it only registered after the agency opened an investigation. Both companies were also ordered to begin accessing and processing requests through DROP and to publish annual metrics on the consumer privacy requests they receive.
Michael Macko, the CPPA's head of enforcement, said the LocateSmarter case showed the agency evaluates broker conduct "through the lens of multiple laws to find the best fit to protect Californians."
What it means for businesses handling consumer data
For a company that qualifies as a data broker under the statute's broad definition, the practical checklist now runs on two clocks: register by January 31 each year, and, since August 1, 2026, check DROP and clear the request queue at least every 45 days. Missing either deadline exposes a company to the CPPA's administrative fine schedule described above, and the agency's recent cases show it treating registration lapses and consumer-rights violations as parts of the same enforcement action rather than separate matters.
Law firms tracking the enforcement pattern have pointed to the opt-out process itself as a recurring problem: cases against LocateSmarter and others centered on brokers requiring more identifying information, such as partial Social Security numbers, than necessary to verify a request, which regulators treated as a data-minimization violation layered on top of the registration failure. A low volume of opt-out requests relative to a company's data holdings has also been flagged as a signal that a broker's process may itself be creating unlawful friction.
For companies that buy consumer data from brokers rather than sell it, the Delete Act's registration and processing duties fall on the broker side of the transaction. But the requirement that brokers direct their own service providers and contractors to honor deletion and opt-out requests means the obligation can reach further down a data supply chain than a company's own registration status might suggest.
Related coverage: What your California privacy rights actually let you do; What the CCPA and CPRA actually require of a business.

