The Delete Request and Opt-out Platform — DROP — has been available to Californians since the start of the year. Since 1 August 2026 it has been mandatory for the other side.

From that date, every one of the 500-plus registered data brokers in California must:

  • Access DROP at least once every 45 days to collect pending requests
  • Process every request within 45 days of receipt
  • Delete all associated personal information where a consumer’s record matches — including inferences derived from it — unless a statutory exemption applies
  • Cease selling or sharing that consumer’s information going forward

And the number that makes it real: a broker that fails to process a deletion request faces a fine of $200 per deletion request, per day, for as long as the information remains undeleted.

Why the Structure Is Unusual

Almost every privacy right in the world is exercised one company at a time. Under the GDPR, the CCPA as originally written, or any of the newer state laws, you have a right to deletion — and you exercise it by identifying the controller, finding its request form, verifying your identity, waiting, and repeating. Against an industry of thousands of brokers, most of whom you cannot name, that right is theoretical.

DROP inverts it. One verified request at the state platform reaches every registered broker. The consumer does the work once. The obligation to find and act on the request sits with the broker, on a clock, with a per-day penalty attached.

That design decision — a centralised registry plus a centralised request channel plus a per-day accrual penalty — is the reason this is the most consequential consumer privacy mechanism operating anywhere in the United States, and it is worth understanding why each piece is load-bearing:

  • The registry (and the fines for skipping it) makes the population of brokers knowable.
  • DROP makes the request routable without the consumer knowing who is on the list.
  • The 45-day polling duty removes the excuse of not having seen it.
  • The $200-per-day accrual means non-compliance gets more expensive the longer it lasts, rather than resolving into a one-off settlement that can be budgeted.

We covered the launch in DROP going live for brokers. What has changed since is that the deletion duty has actually attached, and the agency has started building the machinery to check.

The Audits Are Coming

On 7 August 2026, the CalPrivacy board met to discuss proposed DROP compliance audit regulations. The Delete Act’s audit requirements take effect 1 January 2028, and the agency has begun formal rulemaking to define what an audit of a broker’s DROP compliance looks like — scope, methodology, evidence, auditor independence, and what gets reported to the agency.

Eighteen months of lead time on an audit regime sounds generous. It is not, and brokers should read it as the warning it is.

A deletion obligation is only as good as the evidence that it was performed. The hard question is not “did you delete the record you matched?” — it is “can you demonstrate what you had, what you matched, what you did not match, and why?” A broker that quietly under-matches requests, by using a narrow identity resolution threshold on the way in and a broad one on the way out, would look compliant on every individual request while deleting almost nothing. Audit regulations are how that gets caught.

The Number Nobody Is Talking About

By early August, over 345,000 deletion requests had been submitted through DROP.

Set that against a California adult population in the tens of millions, and it is small. Set it against the number of people who have ever successfully deleted themselves from the data broker industry by any other means, and it is enormous — it is very likely more than every individually-filed broker deletion request in American history combined.

The gap between those two readings is the entire story of privacy rights: the mechanism works, and almost nobody knows it exists.

What Deletion Does and Does Not Reach

Be clear-eyed about the limits, because the exemptions are real:

  • Registered brokers only. A company that has never registered is not polling DROP. That is why the registration enforcement actions matter more than their dollar amounts suggest.
  • Statutory exemptions apply. Data governed by the FCRA, GLBA, HIPAA and similar regimes is carved out. Credit bureaus and much financial and health data are not reachable this way.
  • It does not reach first parties. DROP addresses brokers — companies selling data about people they have no direct relationship with. Your bank, your retailer and your employer are unaffected.
  • It does not undo prior sales. Data already sold to a downstream buyer who is not itself a registered broker stays sold.
  • Re-collection is possible. Deletion is not a permanent exile. Brokers must stop selling and sharing your data, but the ecosystem regenerates from new sources, which is why the 45-day cycle exists rather than a one-time purge.

What To Do

  1. If you live in California, submit a DROP request today. It is at the state’s data broker portal via privacy.ca.gov. It takes minutes, it is free, it requires one verification, and it reaches all 500-plus registered brokers at once. There is no higher-leverage privacy action available to any American right now.
  2. Do it even if you did it in January. The consumer-side platform opened before the broker-side obligation attached on 1 August. A request submitted now lands in a system where non-compliance costs $200 a day.
  3. Refuse over-verification. If a broker contacts you demanding an SSN fragment or an ID scan to honour a DROP request, that is very likely unlawful — CalPrivacy has already fined a broker on exactly that theory. Report it.
  4. Check the registry for your own employer. The definition of “data broker” is broader than most companies think, and unregistered brokers are the leak in the system. The public registry is at privacy.ca.gov.
  5. If you are outside California, use this as your argument. Washington’s AG has recommended a registry of its own. The counterargument to state broker registries has always been that they are unworkable. California now has 345,000 processed requests and a per-day penalty schedule saying otherwise.