trustifo

Privacy reference

California DELETE Act Audit Requirements for Data Brokers

What California's DELETE Act requires from data broker audits, including timing, scope, independence, report delivery, retention, and open rulemaking questions.

California’s DELETE Act requires a covered data broker, beginning January 1, 2028 and every three years thereafter, to undergo an independent third-party audit of its compliance with Civil Code section 1798.99.86.

The audit requirement is part of the DELETE Act, enacted as SB 362. It is not the name of the deletion platform. DROP means the Data broker Requests and Opt-out Platform, the mechanism through which California consumers submit centralized deletion requests. The DELETE Act and DROP overview explains how the statute and platform fit together.

The statutory audit requirements at a glance

The current law states a short set of express requirements. It does not yet supply a complete audit standard, mandatory report template, or prescribed testing methodology.

IssueCurrent requirementImportant limit
Start and frequencyBeginning January 1, 2028, a data broker must undergo an audit every three years under section 1798.99.86(e)(1).The section does not state one calendar date by which every broker must finish its first audit.
AuditorThe audit must be performed by an independent third party under section 1798.99.86(e)(1).The statute does not name a required credential, certification, or professional standard.
ScopeThe audit determines compliance with section 1798.99.86, according to the statutory scope clause.It is not worded as a general audit of every privacy obligation the business may have.
Agency deliveryThe broker must provide the audit report and related materials within five business days after a written CalPrivacy request under section 1798.99.86(e)(2).The current text does not require routine automatic filing of every completed report.
RetentionThe broker must keep the report and related materials for at least six years under section 1798.99.86(e)(3).“Related materials” is not exhaustively defined in the statute.
Registration disclosureBeginning January 1, 2029, the registration must state whether an audit occurred and, if so, the most recent year the broker submitted the report and related materials to CalPrivacy, under section 1798.99.82(b)(2)(U).This disclosure is not a substitute for the audit report itself.

Who is subject to the audit duty

The duty attaches to a “data broker” as that term is defined in the California statute. In general terms, the definition covers a business that knowingly collects and sells to third parties personal information about a consumer with whom it has no direct relationship, while specifying exclusions for certain regulated entities or processing. The exact language and exclusions in Civil Code section 1798.99.80 control.

A registry listing is strong operational evidence that a business has represented itself as a data broker, but the legal definition remains the starting point for coverage. The broader data broker explainer is useful background; it does not decide whether a specific entity or activity falls within a statutory exclusion.

The audit requirement should also be separated from a consumer’s use of DROP. A consumer submits a specialized consumer request through the platform. The broker’s audit is a later accountability mechanism directed at the broker’s compliance system. Under section 1798.99.86, consumers do not conduct the audit, choose the auditor, or need to wait for an audit cycle before submitting a DROP request.

What the audit is meant to examine

The statutory phrase “compliance with this section” points to section 1798.99.86 as the audit’s subject. That section requires brokers to access the deletion mechanism on a recurring cycle, process received requests, take the required deletion or opt-out action, direct service providers and contractors, respect applicable exceptions, and continue honoring requests when new information is collected. Those duties appear in subsections (c) and (d) of the current code. SB 361 amended the section effective January 1, 2026, including an express 45-day period for processing an unverifiable deletion request as an opt-out.

The effective DROP regulations provide the operational rules against which those systems can be examined. Among other things, they address:

  • selection and retrieval of the consumer deletion lists that correspond to identifiers in the broker’s records;
  • standardization and hashing before comparison with DROP identifiers;
  • treatment of matches, ambiguous matches, nonmatches, exemptions, and personal information associated with a matched identifier;
  • maintenance of the minimum information needed for continuing compliance and limits on using that information for another purpose;
  • reporting an accurate response code for each transaction; and
  • account controls, restricted use of DROP-supplied information, and reasonable security measures.

These obligations are set out in California Code of Regulations, title 11, sections 7610–7616. CalPrivacy’s official processing summary describes the same download, standardization, hashing, matching, action, reporting, and continuing-compliance cycle in operational terms.

An audit limited to confirming that a broker logged into DROP would therefore miss material parts of the stated compliance scope. The regulations define access as retrieval of a consumer deletion list, not merely signing into an account, and require subsequent processing and status reporting. The effective regulations also allow a broker to ask CalPrivacy for a complete list when needed to reconcile records or complete the statutory audit.

What remains unresolved as of September 4, 2026

CalPrivacy has begun considering more detailed audit rules, but it has not converted its preliminary questions into binding audit standards. The Agency’s DROP audits page says the preliminary comment period is closed and describes the topic as one it is exploring. Its laws and regulations page states that preliminary topics have not advanced to formal rulemaking and, as of this article’s publication date, lists no proposed regulation packages.

The distinction matters. In its invitation for preliminary comments, CalPrivacy asked stakeholders about auditor credentials and independence, evidence of standardization and hashing, matching, deletion, permitted retention, suppression-list use, audit methods and tools, AI-assisted processing, identifiers, and materials that might accompany a report. These are questions for potential rulemaking, not adopted requirements.

Accordingly, the current official sources do not establish:

  • a named certification that every auditor must hold;
  • a required audit framework or assurance level;
  • a fixed lookback period or sampling formula;
  • a mandatory report structure;
  • an automatic filing date for every audit report; or
  • a rule that an existing security or financial audit satisfies the DELETE Act duty.

A broker should not treat a public comment, an Agency question, or a familiar audit label as law. New regulations could define these points before the first audit cycle, so the CalPrivacy rulemaking page remains the appropriate source for status changes.

Report delivery, retention, and registration are separate duties

Completing an audit does not end the record-handling obligation. If CalPrivacy sends a written request, the broker has five business days to submit both the resulting report and any related materials. It must retain those items for at least six years, under section 1798.99.86(e)(2)–(3). A process that stores the final report but discards the supporting materials may therefore be incomplete.

Annual registration is a different process. Beginning January 1, 2029, a broker must disclose whether it has undergone the required audit and, if it has, the most recent year in which it submitted the report and related materials to the Agency. That wording appears in section 1798.99.82(b)(2)(U). It does not say that the full report must be attached to every annual registration.

Practical audit-readiness checklist

The following list is a preparation framework, not a substitute for a future regulation or advice about a particular business. It follows the current compliance duties and the evidence categories CalPrivacy identified during preliminary rulemaking.

  1. Define the legal and system boundary. Map the entities, data stores, products, service providers, contractors, and DROP account activity relevant to section 1798.99.86.
  2. Document auditor independence. Record financial, management, implementation, and other relationships that could affect the third party’s independence, while recognizing that the current CalPrivacy rulemaking status does not supply a credential rule.
  3. Preserve cycle evidence. Retain dated proof of list retrieval, processing, response-code submission, amendments, connection failures, and required notices in a form that can be reconciled with the DROP regulations.
  4. Test matching logic. Verify that list selection, normalization, hashing, combined identifiers, and matching operate as required by the effective DROP regulations.
  5. Trace each outcome. Make it possible to distinguish the defined DROP outcomes without exposing more consumer information than the review requires.
  6. Check downstream action. Preserve evidence that service providers and contractors received and carried out the directions required by section 1798.99.86(c).
  7. Review continuing controls. Test whether later-acquired records are screened and whether information retained solely to maintain a request is restricted to that purpose under the DROP regulations.
  8. Plan for production and retention. Keep the final report and related materials together, protect their contents, track the six-year minimum, and establish a route for responding to a written Agency request within five business days under section 1798.99.86(e).

This checklist does not create duties beyond the statute and effective regulations. It identifies records that may help demonstrate whether the existing duties operated in practice. The final audit design should be checked against any rules CalPrivacy adopts before the engagement begins.

What the audit does and does not establish for consumers

The audit requirement adds an independent review to the DELETE Act framework, but it does not promise that every consumer identifier will match a broker record or that every item must be erased. Section 1798.99.86 preserves specified deletion exceptions and requires an unverifiable request to be handled as an opt-out within the statutory limits. The broader California privacy-law guide explains why deletion, access, correction, and opt-out remain distinct rights.

The current statute also directs audit reports to CalPrivacy upon written request; it does not give an individual consumer a direct right to receive the report. A consumer should interpret a DROP status as the broker’s reported result for that request, not as a public audit opinion about the broker’s entire data environment.

In short, the California DELETE Act audit requirements establish a recurring independent review, a five-business-day production duty after a written Agency request, and a six-year retention period. The operational subject is compliance with section 1798.99.86, while detailed auditor qualifications and methods remain open as of September 4, 2026. This article provides general information, not legal advice.

Frequently asked questions

When do California DELETE Act audits begin?

Civil Code section 1798.99.86 says data brokers must undergo an independent third-party compliance audit beginning January 1, 2028, and every three years thereafter.

What does a DELETE Act audit examine?

The statutory audit determines compliance with Civil Code section 1798.99.86, which governs DROP access, request processing, deletion, opt-out treatment, downstream directions, and ongoing controls.

Must every audit report be filed automatically with CalPrivacy?

No automatic filing schedule appears in the current statute. A data broker must provide the report and related materials within five business days after a written CalPrivacy request.

How long must a data broker keep its audit materials?

The statute requires the data broker to maintain the audit report and related materials for at least six years.

Has CalPrivacy finalized detailed DELETE Act audit standards?

As of September 4, 2026, CalPrivacy describes data broker audits as a preliminary rulemaking activity and has not listed a formal proposed audit regulation package.

Primary sources

This article provides general information, not legal advice.