California’s First-of-Its-Kind Data Deletion Platform Goes Live: What Businesses Should Know

This is Part 1 of Manatt’s series on developments in data broker law in 2026.

On August 1, California’s Delete Request and Opt-out Platform (DROP) went live, marking a new era for all manner of businesses that rely on information services. Mandated by , DROP is a first-of-its-kind platform that allows California residents to submit a single request to delete, or otherwise opt-out from the sales of, their personal information to any business that meets the definition of “data broker” in California.

At the recent board meetings of the California Privacy Protection Agency (CalPrivacy), the agency emphasized there will be a review of brokers’ activity and processing outcomes from the first 90 days of the DROP, tightening of audit standards and requirements, and significantly, an increase in registration fees, from $6,000 to $9,500, starting in January 2027.

What is a “data broker”?

The Delete Act required any company conducting business in California that meets the definition of “data broker” to register with CalPrivacy by January 31, 2026. But what is a “data broker,” exactly?

In California, a “data broker” is defined as any “business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship,” and excludes certain limited regulated businesses. The definition is relational in nature, such that a company may qualify as a data broker as to personal information that was collected outside of any “direct relationship” it may have with a consumer. To have a “direct relationship,” the consumer must have intentionally interacted with a company to access, request, or obtain information about the company’s products or services.

What does DROP require of in-scope businesses?

Data brokers are now required to access DROP at least once every 45 days to retrieve the consumer deletion list and process requests. The system uses specified consumer identifiers for every consumer who submitted a deletion request, which the broker must match to its own standardized consumer data.

Any matches must result in deletion of all personal information associated with the matched consumer identifier, including inferences. Many exceptions may apply, including to personal information that the broker collected as a “first party” and to preexisting exceptions under the CCPA’s deletion requirements. In addition, like the CCPA, personal information subject to DROP does not include any publicly available information. 

If multiple consumers are associated with a single matched identifier, the broker must instead opt each associated consumer out of the sale or sharing of their personal information. Notably, the broker may not contact a consumer to verify a deletion request submitted through the DROP.

In-scope brokers must also report the statuses of requests to CalPrivacy, corresponding to one of four response codes: record deleted, record opted out of sale, record exempted and record not found. Other reporting obligations include providing the types and numbers of consumer requests received, processed and denied, as well as the types of personal information collected, all of which appear in the public Data Broker Registry on the CalPrivacy website. Brokers must also conduct audits starting January 1, 2028 and every three years thereafter and provide audit reports to CalPrivacy upon demand. Fines for failure to register are set at $200 per day while fines for failure to process requests are set at $200 per day per consumer, not including enforcement costs.

California consumers have been able to sign up through the DROP starting January 2026. According to CalPrivacy, as of approximately August, there have been over 450,000 consumers that have submitted deletion requests, with the number expected to grow as the agency continues its public outreach efforts.

What will enforcement look like?

Enforcement has already begun. A sizable amount of CalPrivacy’s enforcement actions to date have dealt with data broker registration compliance, with the agency requiring businesses to pay up to tens of thousands of dollars for failing to register as a data broker, even if the failure was due to an administrative error.

In December 2025, CalPrivacy fined a New York-based company for failing to register. Though it promptly completed registration when notified, they were fined $200 per day for the 313 days that they were unregistered. In total, there have been at least ten other publicized enforcement actions against data brokers for failure to register. Monetary penalties have ranged from $34,400 to $62,600, the higher fines passing the $46,000 statutory maximum penalty for failure to register due to other non-compliant conduct, such as failing to pay past-due registration fees. Some brokers have been required to cease operations instead of monetary penalties, while others have been subject to both operational restrictions and fines.

What’s next?

California’s DROP system is in effect now. With state regulators keen to enforce compliance, businesses that believe they are potentially in-scope for data broker registration should evaluate whether the law applies to them and implement immediate measures to comply with DROP. And the regulatory environment for data brokers does not stop in California: Recent developments in New Jersey, Connecticut and Vermont all demand further attention for data brokers and other companies that handle personal data collected from sources other than the direct data subject. Private litigants are also increasingly pursuing creative theories targeting data brokers. Stay tuned for future editions in our series on data broker laws in the United States for more on these developments.

We will continue to track developments as states refine and expand privacy regulations, and will provide further guidance as more updates arise. More information about Manatt’s Privacy and Data Security practice can be found .