trustifo

Privacy reference

California DELETE Act Duties for Registered Data Brokers

A source-linked explanation of registration, DROP request processing, matching, deletion, reporting, ongoing controls, audits, and enforcement.

Registered California data brokers must register annually, use DROP beginning August 1, 2026, process deletion requests on the required cycle, report outcomes, maintain requests against later-collected data, direct vendors, protect DROP data, and prepare for audits under the current Civil Code.

The DELETE Act and DROP have different roles

The DELETE Act is the statute enacted through SB 362. DROP is the Data broker Requests and Opt-out Platform, the state-operated mechanism used to implement the centralized request system. The current duties come from the California Civil Code, the effective CPPA regulations, and later amendments including SB 361. The separate California DELETE Act overview explains the consumer-facing system.

Coverage comes first. Civil Code section 1798.99.80 defines a data broker as a business that knowingly collects and sells to third parties personal information about a consumer with whom it lacks a direct relationship, subject to specified exclusions. The current statutory definition and exclusions control; the broader everyday meaning of data broker is not enough to decide whether a business must register.

Registration and DROP access are related but distinct. Registration reports prior-year activity during the annual registration period. DROP access is the operational duty to retrieve and act on centralized deletion requests. A business that begins brokering data outside the registration period may still have account, access-fee, and processing duties before its first annual registration, as the effective regulations and CalPrivacy account guidance explain.

Duty map for a registered broker

DutyOperative timingRequired result
Annual registrationBy January 31 after each year in which the business met the statutory definitionRegister with CalPrivacy, pay the set fee, and provide the required business, data-practice, request, and rights information under Civil Code section 1798.99.82.
DROP accessBeginning August 1, 2026, at least once every 45 daysRetrieve every applicable consumer deletion list through the manual or supported automated method described in the DROP regulations.
Matching and actionWithin 45 days after receiving a requestStandardize and hash comparable identifiers, perform the required match, then delete, opt out, exempt, or report no match as applicable under the statute and agency workflow.
Status reportingDuring the next required access cycle after processingReturn an accurate response code for each transaction through DROP under title 11, section 7614.
Continuing complianceAfter a request, unless the consumer changes it or an exception appliesScreen later-collected records, repeat required deletion, and prevent prohibited later sale or sharing under section 1798.99.86(d).
Independent auditBeginning January 1, 2028, then every three yearsObtain an independent compliance audit, retain the materials for at least six years, and provide them after a qualifying agency request as specified by section 1798.99.86(e).

Annual registration and public-facing disclosures

A broker must register by January 31 following each year in which it met the statutory definition. The registration includes the broker’s identifying and contact information, the fee, request metrics, disclosures about specified categories of personal information and recipients, and a link to a page explaining how consumers may exercise listed privacy rights. The current, expanded fields appear in Civil Code section 1798.99.82; they should be reviewed directly rather than replaced with an older registration checklist.

Separate metrics duties apply by July 1 after a covered year. Section 1798.99.85 requires compilation of request counts and response-time measures, disclosure of those metrics through the broker’s privacy policy, and additional breakdowns for DROP requests denied in whole or in part. The current code text identifies the request types and denial categories that belong in those disclosures.

These duties do not make every submitted registration field public. Section 1798.99.84 excludes specified fields from the public registry. A compliance record should therefore distinguish information submitted to the Agency from information displayed publicly, using the current statutory publication rule rather than assuming that the registry reproduces the entire filing.

Processing DROP requests

Select, normalize, and compare the right lists

The regulations organize requests into consumer deletion lists containing hashed identifiers. A broker must select the lists containing identifiers that correspond to personal information in its records; a narrower selection is permitted only in the circumstance defined by the regulations. The broker then standardizes comparable fields and applies the prescribed hashing process before comparison. CalPrivacy’s processing instructions summarize the lists, matching sequence, and recurring access cycle, while the regulatory text supplies the controlling technical requirements.

The broker must perform the comparison even when it expects few or no matches. CalPrivacy states that a broker that does not collect, maintain, or sell information contained in any available list must still select at least one list and report “record not found” after completing the prescribed comparison. That position appears in the Agency’s DROP help for data brokers.

Apply the result to associated personal information

When a valid identifier match exists, the duty is not limited to deleting the matched field. The regulations require deletion of all personal information associated with the matched identifier, including covered inferences, subject to statutory exceptions. If one matched identifier is associated with multiple consumers, the broker must instead opt the associated consumers out of sale or sharing and direct its service providers and contractors to do the same. These outcomes are defined in sections 7613 and 7614 of the effective regulations.

Deletion is subject to the exceptions incorporated by section 1798.99.86. Information retained because an exception applies may be used only for the permitted purpose and not for another purpose such as marketing. The current statute points to the relevant CCPA provisions. The broader California privacy-law page provides context, but it does not determine whether an exception applies to a specific record.

Direct vendors and report an accurate status

A broker must direct associated service providers and contractors to delete covered information for a verified match or apply the required opt-out for an ambiguous match. After processing, the broker reports the transaction identifier and the applicable response code: record deleted, record opted out, record exempted, or record not found. The Agency’s official processing workflow explains when each result is used and requires later status updates when a previously unmatched request becomes a match.

The response code is a compliance record, not a substitute for the underlying work. Internal evidence should support which lists were retrieved, how identifiers were standardized, what match occurred, what information and systems were addressed, which vendors were directed, which exception was used, and when DROP was updated. This is a practical control inferred from the reporting and audit obligations, not a separate statutory form.

Ongoing use, security, and no direct verification contact

A DROP request has continuing effect. For both matched and unmatched requests, brokers must retain the minimum information needed to screen newly collected records and maintain compliance; the information cannot be repurposed. The regulations and Agency guidance describe this limited compliance list and the duty to compare later-acquired records before a prohibited sale or sharing.

DROP data is also restricted at the point of receipt. Section 7616 permits use of personal information supplied by the Agency only for compliance with section 1798.99.86, prohibits its sale or sharing, requires reasonable security appropriate to the information, and bars a broker from contacting a consumer to verify a DROP request. Those requirements appear in the effective DROP regulations. A DROP request is therefore a specialized consumer request, not permission to enrich a profile or start a separate authentication exchange.

Audits and administrative exposure

Starting January 1, 2028, a broker must undergo an independent third-party audit every three years to determine compliance with section 1798.99.86. The broker must keep the report and related materials for at least six years and submit them within five business days after a written CPPA request. These dates and retention duties come directly from section 1798.99.86(e).

Failure to register may result in a $200 administrative fine for each day of nonregistration, unpaid fees, and investigation or administrative costs. Failure to delete as required may result in a $200 administrative fine for each deletion request for each day of failure, plus reasonable investigation and administration expenses. The enacted DELETE Act enforcement provisions and current code should be consulted before assessing exposure in a particular matter.

Practical compliance checklist

  1. Document why each legal entity is or is not within the current data-broker definition and exclusions.
  2. Assign ownership for annual registration, July metrics, fee payment, public disclosures, and registry updates.
  3. Create the entity’s DROP account and map every held identifier category to the applicable deletion lists.
  4. Test standardization, hashing, matching, deletion, ambiguous-match opt-out, and status reporting against the effective specifications.
  5. Map personal information to active systems, archives, service providers, and contractors before requests arrive.
  6. Keep exception decisions narrow, source-linked, and separated from data used for marketing or another incompatible purpose.
  7. Maintain only the identifiers needed for continuing compliance and restrict their use and access.
  8. Preserve evidence for status corrections, recurring 45-day access, vendor directions, security controls, and the independent audit.

This checklist organizes duties stated in the current law, effective regulations, and CalPrivacy broker guidance. It is general information, not legal advice or a conclusion that the DELETE Act covers a particular business, record, or processing activity.

Frequently asked questions

When do registered data brokers have to begin processing DROP requests?

The statutory processing duty begins August 1, 2026. Brokers must access DROP at least once every 45 days and process received requests within the governing cycle.

Does a data broker delete only the identifier that matched?

No. A valid match requires action on the non-exempt personal information associated with the matched consumer, not merely removal of the submitted identifier.

What happens when one identifier is associated with multiple consumers?

The DROP regulations require the broker to opt the associated consumers out of sale or sharing rather than treating the ambiguous identifier as a verified deletion match.

Can a registered data broker contact a consumer to verify a DROP request?

The effective DROP regulations state that a data broker must not contact a consumer to verify a deletion request submitted through DROP.

When do the independent audit duties begin?

Beginning January 1, 2028, a data broker must undergo an independent third-party compliance audit and repeat the audit every three years under the statute.

Primary sources

This article provides general information, not legal advice.