California’s Delete Act Reaches Enforcement Stage as Data Brokers Begin Processing Requests

by Lawrence J. Tjan | Aug 04, 2026
Close-up of hands holding a smartphone displaying a red warning alert on the screen. Photo Source: Adobe Stock Image

California’s Delete Act entered a major new phase on August 1, requiring registered data brokers to begin processing residents’ requests to erase personal information collected about them.

The law created the Delete Request and Opt-out Platform, known as DROP, which allows a California resident to send one deletion request to more than 600 registered data brokers. Consumers previously had to locate and contact companies individually, often through different forms and verification systems.

DROP opened to consumers on January 1, seven months before brokers became responsible for acting on the requests. More than 300,000 Californians had signed up by early June, according to the California Privacy Protection Agency, which administers the platform and enforces the Delete Act.

The August 1 deadline does not mean every request will be completed immediately. Data brokers must check DROP at least once every 45 days. After retrieving a request, a broker generally has another 45 days to match the consumer’s information, delete covered records, and report the result. A request can therefore remain pending for up to 90 days.

The California Legislature passed Senate Bill 362 in 2023, and Gov. Gavin Newsom signed it on October 10 of that year. The measure expanded California’s existing data broker registration law and directed the state privacy agency to build a single, free deletion system by January 1, 2026.

Under the statute, a data broker is generally a business that knowingly collects and sells personal information about consumers with whom it has no direct relationship. The definition covers companies that assemble information from online activity, commercial records and other sources before selling or sharing it with advertisers, marketers, background-screening services and other customers.

Information held by brokers can include names, email addresses, telephone numbers, browsing history, interests, health-related information, precise location data and assumptions drawn from a person’s activities. The law requires a broker that finds a matching record to delete the consumer’s associated personal information, including sensitive information and inferences generated from the underlying data.

California residents begin the DROP process by confirming their eligibility through the state’s identity-verification system. They then create a profile containing information that brokers can compare against their records.

A consumer needs only a name, date of birth, and ZIP code to submit a request. Email addresses and telephone numbers can also be included, along with optional identifiers such as a mobile advertising ID, a connected television ID, or a vehicle identification number. Providing more identifiers can increase the likelihood that a broker will locate the correct record.

The request applies to all current and future brokers registered with the agency unless the consumer chooses to exclude particular companies. Parents, authorized agents, and certain family members can also submit requests on behalf of another California resident in qualifying circumstances.

Once a broker processes the request, DROP can show several possible results. A “deleted” status means the company found a match and removed the information it was legally required to erase. “Record not found” means the company reported that it did not locate matching information.

An “exempted” status means the broker retained information that the law allows it to keep. An “opted-out” status means the broker could not verify an exact match but must stop selling or sharing the consumer’s information.

That fallback protection is an important part of the law. If a broker denies deletion because it cannot verify the request, it must still treat the submission as a request to opt out of the sale or sharing of personal information.

The Delete Act also addresses what happens after a company removes a consumer’s information. A broker generally must continue to check for and delete newly acquired information about that person every 45 days. It also cannot resume selling or sharing newly obtained information unless the consumer asks it to do so or a legal exception applies.

The law does not erase every record held by every company. DROP applies to registered data brokers, not necessarily a company with which the consumer has a direct relationship. Information obtained directly by a retailer, bank, streaming service or other business is not automatically removed through the broker portal.

The statute also contains exemptions for information that must be retained for certain legal or operational purposes. Publicly available records and some information governed by federal financial, credit-reporting, insurance or health privacy laws may fall outside the deletion requirement. A broker that keeps exempt information may use it only for the purpose supporting the exemption and cannot repurpose it for marketing.

Enforcement rests primarily with the California Privacy Protection Agency. A broker that fails to process a covered request can face an administrative fine of $200 for each request for every day the violation continues, along with the state’s investigation and enforcement costs. Failure to register can carry a separate $200-per-day penalty.

The Delete Act does not provide consumers with a separate private right of action to sue a broker for violating its DROP obligations. Instead, the agency can bring administrative enforcement actions. Beginning in 2028, brokers must also undergo independent compliance audits every three years.

The new system is designed to address a persistent weakness in consumer privacy laws: legal rights can offer little practical protection when exercising them requires contacting hundreds of unfamiliar companies.

A May 2026 study of 522 registered California data brokers found that only 9% fully complied with the transparency requirements examined by the researchers. In a separate review of 250 brokers’ consumer-request procedures, the researchers reported that 43% made it impossible to exercise every privacy right and 64% introduced at least one significant source of friction.

DROP replaces much of that company-by-company process with a state-managed request. Whether it succeeds will now depend on the accuracy of the matching system, the willingness of brokers to follow the recurring deletion rules, and the state’s ability to identify and penalize companies that do not comply.

For California residents, the Delete Act has moved beyond a promise written into a statute. As of August 1, its central deletion requirements are in operation, and the first wave of requests is moving through the data broker industry.

Share This Article

If you found this article insightful, consider sharing it with your network.

Lawrence J. Tjan
Lawrence is an attorney with experience in corporate and general business law, complemented by a background in law practice management. His litigation expertise spans complex issues such as antitrust, bad faith, and medical malpractice. On the transactional side, Lawrence has handled buy-sell agreements, Reg D disclosures, and stock option plans, bringing a practical and informed approach to each matter. Lawrence is the founder and CEO of Law Commentary.

Related Articles

A row of airplanes parked on a runway with mountains in the background.
Airlines Under Fire for Selling Customer Travel Records to Federal Authorities

A data broker owned by major U.S. airlines, including Delta, American Airlines, and United, collected and sold domestic flight information of American travelers to Customs and Border Protection (CBP), according to internal agency documents obtained by 404 Media. The records include passengers' names, full travel itineraries, and financial information. The... Read More »