trustifo

Privacy reference

California DELETE Act and CCPA: Key Differences

A source-linked comparison of the California DELETE Act and CCPA, including coverage, deletion rights, DROP requests, verification, timing, and limits.

The California DELETE Act is not a replacement for the CCPA. It adds a data-broker-specific, centralized deletion system, while the CCPA remains the broader law governing privacy rights and duties for covered businesses.

How the two laws fit together

The California Consumer Privacy Act (CCPA) is the state’s general consumer privacy framework for entities meeting its definition of a business. Its rights include knowing, deleting, correcting, opting out of sale or sharing, limiting certain uses of sensitive personal information, and receiving equal treatment for exercising those rights, as summarized by the California Privacy Protection Agency. The CCPA was amended by the California Privacy Rights Act, but the amended framework is still commonly called the CCPA.

The DELETE Act is the law enacted through SB 362. It amended California’s separate data-broker registration title and required the Agency to establish an accessible deletion mechanism. That mechanism is DROP, the Data broker Requests and Opt-out Platform. The DELETE Act is the statute; DROP is the platform. The broader DELETE Act and DROP overview explains their relationship.

The laws are connected rather than isolated. The data-broker title generally imports definitions from CCPA Civil Code section 1798.140, while adding its own definition of a data broker and broker-specific obligations in Civil Code sections 1798.99.80–1798.99.89. A request may therefore involve both bodies of law, but their coverage, channels, and effects should not be treated as interchangeable.

California DELETE Act and CCPA differences at a glance

IssueCCPADELETE Act and DROP
Regulated entityApplies to an entity that meets the CCPA definition of a “business,” including the statutory criteria and covered affiliates described in Civil Code section 1798.140(d).Applies to a “data broker”: a business that knowingly collects and sells to third parties personal information about a consumer with whom it lacks a direct relationship, subject to listed exclusions in section 1798.99.80.
Rights involvedProvides a set of rights, including know, delete, correct, opt out of sale or sharing, limit, and nondiscrimination, subject to the CCPA’s terms and exceptions.Creates a centralized deletion request for covered broker data and requires an opt-out of sale or sharing when a request cannot be verified in the circumstances stated in section 1798.99.86(c).
Request destinationThe consumer ordinarily uses methods designated by the particular business under CCPA regulation 7020.The consumer submits one request through the Agency-operated DROP service for participating data brokers, with the ability to exclude selected brokers under section 1798.99.86.
Data relationshipThe statutory deletion right concerns personal information the business collected from the consumer, subject to exceptions in section 1798.105.DROP regulations cover broker information associated with a match that was collected from third parties or from the consumer outside a first-party interaction; first-party information is excluded from that DROP deletion rule under regulation 7613.
VerificationThe receiving business applies the CCPA verification rules to direct requests to delete, correct, or know and may deny deletion if identity cannot be verified under regulation 7022.The Agency verifies California residency before DROP submission, and a broker may not contact the consumer to verify that request under regulations 7616 and 7620.
Continuing effectA direct deletion request is processed by the recipient business according to the CCPA deletion rules, including notices to service providers, contractors, and certain third parties under regulation 7022.After covered data is deleted, the broker must perform recurring deletion and generally must not sell or share newly obtained personal information, subject to the conditions and exceptions in section 1798.99.86(d).

The CCPA and DELETE Act do not divide the market into ordinary businesses on one side and data brokers on the other. A legal entity can satisfy both definitions. It can also be a CCPA business without being a data broker, because the data-broker definition requires the specified collection, sale, and absence of a direct relationship. The controlling definitions appear in CCPA section 1798.140(d) and data-broker section 1798.99.80.

This distinction is why a directory description or industry label cannot settle coverage. The legal definition is narrower than the everyday concept discussed in what a data broker is, and section 1798.99.80 lists exclusions for specified regulated entities or activities. Coverage may also differ by activity within the same organization.

First-party and broker-held data follow different routes

The source and context of collection matter. Under the DROP regulations, information associated with a matched identifier includes personal information obtained outside a first-party interaction and inferences based on that information. The DROP deletion rule does not require deletion of information the broker collected directly in a first-party capacity.

That exclusion does not establish that first-party information may always be retained. A direct CCPA deletion request may address personal information collected from the consumer under Civil Code section 1798.105, if the entity and data are covered and no exception applies. The practical question is therefore not simply “Which law is stronger?” but “Which entity holds which information, from what relationship, and which right addresses it?”

DROP is a deletion mechanism, not a full CCPA request center

A direct CCPA consumer request can seek different outcomes. The official CCPA rights summary distinguishes the rights to know, correct, delete, opt out, limit, and receive equal treatment. A consumer seeking copies of information, categories of sources, correction of an inaccurate record, or limits on sensitive-information use should not assume that a DROP submission makes those separate requests.

DROP has a more focused function. Civil Code section 1798.99.86 requires one verifiable request capable of reaching every data broker that maintains covered personal information, while allowing the consumer to exclude selected brokers. The DROP regulations then govern identifier matching and reported outcomes. If one identifier maps to multiple consumers, the prescribed result is an opt-out of sale or sharing for the associated consumers rather than deletion based on an ambiguous match.

Neither route guarantees erasure of every record. The CCPA deletion section contains retention purposes, and the DELETE Act carries forward specified CCPA exceptions through section 1798.99.86(c)(2). DROP status can also reflect that a record was exempted or not found under regulation 7614.

Request channels, timing, and status are different

For direct requests to delete, correct, or know, CCPA regulation 7020 specifies business-provided submission methods. Regulation 7021 requires confirmation within 10 business days and a substantive response within 45 calendar days, with one additional 45-day period when necessary and when notice and an explanation are provided.

DROP uses a state-operated channel. Beginning August 1, 2026, section 1798.99.86(c) requires a data broker to access the mechanism at least once every 45 days and process received requests within 45 days. Because access and reporting occur in cycles, CalPrivacy’s consumer workflow cautions that a status update can take up to 90 days. These are not two descriptions of the same response clock.

The continuing obligation is another material difference. Section 1798.99.86(d) requires recurring deletion at least every 45 days after a covered deletion and restricts later sale or sharing unless the consumer requests otherwise or a statutory provision permits it. The DROP processing regulations also require brokers to retain the minimum information needed to compare newly collected records, while limiting that retention to compliance purposes.

Practical checklist for choosing the correct route

  1. Define the desired result. Use the official CCPA rights list to distinguish access, correction, deletion, sale or sharing opt-out, and limitation of sensitive-information use.
  2. Identify the legal entity and relationship. Determine whether the information arose through an intentional first-party interaction or appears to have been obtained elsewhere. Apply the statutory data-broker definition and exclusions, not only a brand description.
  3. Use DROP for its defined purpose. A California resident may use DROP for a centralized request concerning covered broker data; the current official DROP workflow controls the live submission and status process.
  4. Use a direct CCPA channel for a distinct CCPA right. Business-provided methods remain relevant for access, correction, first-party deletion, and other applicable rights under the current CCPA regulations.
  5. Do not treat one submission as proof of the other. DROP and direct CCPA requests have different recipients, verification structures, and legal effects under their separate regulations.
  6. Keep neutral records. Save the request confirmation, scope, identifiers supplied, and response or DROP status. Under regulation 7614, a DROP status describes a broker’s reported matching outcome; it does not determine whether every related entity or dataset was covered.

The broader California privacy-law guide provides context for direct CCPA rights. This article provides general information, not legal advice. Coverage and the correct request route depend on the current law, the entity, the data relationship, applicable exceptions, and the facts of the request.

Frequently asked questions

Is the California DELETE Act the same law as the CCPA?

No. The CCPA is California's broader consumer privacy framework. The DELETE Act adds registration and centralized deletion duties directed specifically at covered data brokers.

Is DROP another name for the California DELETE Act?

No. The DELETE Act is the statute enacted through SB 362. DROP is the Data broker Requests and Opt-out Platform created to implement its centralized request mechanism.

Does a DROP request exercise every right available under the CCPA?

No. DROP is designed for deletion from covered data brokers and an opt-out result in specified matching circumstances. Direct CCPA requests remain relevant for rights such as access, correction, and limiting sensitive-information use.

Can a company be covered by both the CCPA and the DELETE Act?

Yes. The legal definitions overlap, and a company may be both a CCPA business and a data broker. Coverage depends on the current statutory definitions, exclusions, and facts.

Does using DROP guarantee that every record about a consumer will be deleted?

No. Results depend on broker coverage, identifier matching, the information held, and statutory exceptions. DROP may report outcomes including deleted, exempted, opted out, or record not found.

Primary sources

This article provides general information, not legal advice.