US State Law California, USA

California Delete Act: SB 362 and the DROP Explained

The Delete Act's one-stop deletion mechanism for data brokers: registration, the DROP platform, 2026 deadlines, audit duties, and CPPA enforcement.

Regulation

California Delete Act (SB 362, 2023), Civ. Code 1798.99.80 et seq.

Max Penalty

$200 per day for failure to register; $200 per deletion request per day for failing to honor DROP requests

Enforcing Authority

California Privacy Protection Agency (CPPA)

Official Source

cppa.ca.gov

Executive Summary

  • The Delete Act (SB 362, signed October 2023) moved California's data broker registry to the CPPA and created the DROP: a single mechanism through which consumers request deletion from every registered broker at once.
  • Data brokers are businesses that knowingly collect and sell personal information about consumers with whom they have no direct relationship; registration is annual with escalating disclosure duties.
  • The deletion mechanism launched for consumers via DROP; from August 1, 2026, brokers must check the DROP list at least every 45 days and delete matched consumers' data, then keep them deleted (treating subsequent data as opted out).
  • Penalties are per-day: $200/day for unregistered brokering and $200 per deletion request per day for non-compliance after the deadline; the CPPA has already fined late registrants through enforcement sweeps.
  • From 2028, brokers must undergo independent compliance audits every three years, making the Delete Act the most operationally demanding broker law in the US.

The Delete Act attacks the data-broker economy at its weakest point: the asymmetry between how easily brokers acquire data and how hard deletion used to be, one request per broker, hundreds of brokers, no directory. SB 362 inverts that with the DROP: one consumer request, binding on every registered broker, forever. For the roughly 500 registered California brokers, the August 2026 deadline converts privacy compliance from a request-handling function into a data-pipeline architecture requirement.

LawDelete Act (SB 362, 2023), Civ. Code 1798.99.80 et seq.
Key datesRegistry live (CPPA); broker deletion duty from 1 August 2026; audits from 2028
Penalties$200/day unregistered; $200 per request per day for DROP non-compliance
RegulatorCPPA
StatuteSB 362 text

The compliance build

Classify honestly. The definition turns on selling data about people you have no direct relationship with. First-party businesses that also license enriched audiences frequently qualify for that slice of their activity. Getting this wrong is expensive in both directions: unregistered brokering accrues $200/day, while unnecessary registration puts you in a public registry and the DROP’s scope.

Register and disclose. Annual CPPA registration with the expanded disclosure set (minors, geolocation, reproductive health data flags). The CPPA’s sweep practice shows it cross-references registries, marketing claims, and industry lists to find non-registrants.

Engineer the suppression pipeline before mid-2026. The 45-day DROP polling cycle, identity matching against your entity graph, deletion cascades to service providers, and permanent intake filtering. Matching is the hard part: DROP requests arrive as consumer identifiers, and over-matching deletes sellable inventory while under-matching accrues per-request daily penalties.

Prepare for the audit era. From January 2028, an independent third-party audit every three years, with reports retainable and producible to the CPPA. Design the suppression system with audit evidence as an output: logs of list pulls, match rates, deletion confirmations, and vendor attestations.

The Delete Act sits on top of ordinary CCPA obligations, brokers still owe notices, DSARs, and opt-outs, and parallels the registration regimes in other states. To understand which third parties receive data from your own properties (and whether any are brokers you should paper or drop), run a free scan.

Frequently Asked Questions

Are we a data broker under this law?

You are if you knowingly collect and sell to third parties the personal information of consumers with whom you have no direct relationship. That covers list brokers, identity-graph vendors, people-search sites, and many ad-tech data suppliers, but also surprises companies whose secondary revenue includes licensing enriched contact data. Exemptions track entities covered by FCRA, GLBA, and specified insurance codes for that regulated activity.

What does registration require?

Annual registration with the CPPA including fees and disclosures: categories of data collected, whether minors' data, precise geolocation, or reproductive health data is involved, metrics on consumer requests, and a link to your deletion process. The registry is public. The CPPA's enforcement division has fined brokers roughly $200 per day for late registration in published sweep actions.

How does the DROP actually work?

Consumers (or their authorized agents) submit a single verified deletion request through the CPPA's Delete Request and Opt-out Platform. Registered brokers must access the list every 45 days, match it against their holdings, delete matched records, direct their service providers to do the same, and thereafter treat the consumer as opted out of sale, meaning newly acquired data about them must also be suppressed, continuously.

What is the continuous-deletion problem?

Broker datasets regenerate: feeds re-import the same person from new sources. The act anticipates this by requiring ongoing suppression after a DROP match, so compliance is not a one-time purge but a standing suppression list wired into every ingestion pipeline. Architecturally, that means hashing DROP identifiers into your match keys and filtering at intake, which is why 2026 readiness work needs to start in engineering, not legal.

How does this interact with other broker laws?

Vermont pioneered broker registration (2018); Texas and Oregon added registries with their 2023-2024 laws; California's is the only one with a centralized deletion mechanism and audit mandate. A national broker compliance program registers in all four, but engineers to California: its suppression-list architecture satisfies the others' individual deletion duties as a byproduct.

Regulatory Crosswalk

CCPAVermont/Texas/Oregon broker registries

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.