trustifo

Privacy reference

California DELETE Act Enforcement Powers Explained

How California DELETE Act enforcement works: CPPA administrative actions, per-day and per-request fines, DROP evidence, audits, settlements, and legal limits.

The California DELETE Act gives the California Privacy Protection Agency (CPPA) power to bring administrative actions against covered data brokers, impose specified fines for registration and deletion failures, demand audit materials, and issue implementing regulations. Consumers do not calculate or impose those penalties.

The enforcement structure in one view

The DELETE Act is the law enacted through SB 362. DROP is the Data broker Requests and Opt-out Platform created to implement the centralized request mechanism. DROP carries requests and broker-reported results; it is not the enforcement agency. The California DELETE Act overview explains the broader relationship between the statute and platform.

The current Civil Code sections 1798.99.80–1798.99.89 place the specified administrative actions with the CPPA. The Agency’s authority is directed at a legally covered data broker, not every organization that stores or transfers information. Section 1798.99.80 supplies the controlling definition and exclusions; an everyday description of a data broker cannot determine coverage by itself.

Enforcement toolStatutory trigger or functionStated consequenceImportant limit
Registration actionFailure to register as required by section 1798.99.82$200 for each day of nonregistration, unpaid fees, and reasonable investigation and administration expensesCoverage and the period of nonregistration must be established
DROP deletion actionFailure by a broker required to register to delete information as required by section 1798.99.86$200 for each deletion request for each day of failure, plus reasonable investigation and administration expensesThe formula is tied to failure to delete; exemptions and matching facts matter
Independent-audit demandWritten CPPA request for a completed statutory auditBroker must submit the report and related materials within five business daysThe audit is performed by an independent third party, not automatically by the CPPA
RulemakingImplementation and administration of the data-broker titleCPPA may adopt regulations under the Administrative Procedure Act, with a stated exception for fee regulationsRegulations cannot be treated as separate from their statutory authority
Limitations periodAdministrative action alleging a violation of the titleAction generally must begin within five years after the violationThe provision sets a filing limit; it does not shorten a broker’s underlying operational duties

These categories come from the current statutory text. They should not be collapsed into a single generic “privacy fine.”

Who can bring a DELETE Act action

Sections 1798.99.82(c) and (d) identify an administrative action brought by the CPPA. A consumer may submit information to the Agency, but the consumer does not become the prosecutor and cannot direct the amount of an administrative fine. The CPPA’s official complaint form says complaint information may be used to monitor compliance or inform enforcement; submission is not itself a finding that a violation occurred.

The law also does not make a DROP status an adjudication. Under the effective DROP regulations, brokers report standardized outcomes such as record deleted, opted out of sale, exempted, or not found. Those codes create an operational record of what the broker reported. Whether the broker correctly matched data, applied an exception, completed deletion, or remained covered can still require evidence and legal analysis.

The enforcement sections do not create an express private damages action for failure to register or process DROP deletion requests. The same title also says it does not supersede or interfere with the California Consumer Privacy Act (CCPA). Accordingly, a possible claim or remedy under another law is a separate question; the broader California privacy-law guide should not be read as converting every DROP dispute into a private lawsuit.

How the two fine formulas work

Failure to register

A covered broker that fails to register is liable under section 1798.99.82(c) for an administrative fine of $200 for each day it fails to register, an amount equal to the fees due during that period, and reasonable expenses incurred by the CPPA in investigating and administering the action. The daily count therefore depends on when the registration obligation arose and when the failure ended.

The Agency has used this authority in practice. Its Enforcement Advisory 2025-01 explains the registration consequences and warns that separately organized entities must assess their own status rather than assume a parent’s filing covers them. An advisory communicates the Enforcement Division’s position; the statute and effective regulations remain controlling.

Failure to delete through DROP

For noncompliance with section 1798.99.86, section 1798.99.82(d) states a $200 administrative fine for each deletion request for each day the broker fails to delete information as required, plus reasonable investigation and administration expenses. Because both requests and days are multipliers, there is no single aggregate number in the statute that applies to every case.

The wording matters. It does not say that every technical mistake automatically generates $200 for every request and every day. The quoted monetary formula is attached to a failure to delete information as required. A sound assessment must identify the covered broker, request, match, required deletion, applicable exception, relevant dates, and evidence of what remained. It must also account for the statute’s rules on service providers, contractors, later-collected data, and permitted retention, all stated in section 1798.99.86.

How DROP supports oversight

Beginning August 1, 2026, the statute requires brokers to access the mechanism at least once every 45 days, process requests within the governing cycle, and take the required action. The effective regulations add standardized list selection, hashing and matching, deletion, continuing-compliance, and status-reporting rules. A broker must report a response code that accurately describes its action for each transaction identifier.

This structure can make compliance more reviewable: DROP records when request lists and status reports move through the platform, while the broker’s systems should show matching, deletion, exception decisions, vendor directions, and controls over later-acquired information. That is an inference about the evidentiary value of the required records, not a statement that the platform automatically proves liability. A reported “record deleted” result is not conclusive proof that every non-exempt copy was handled correctly, and “record exempted” does not by itself establish that an exception was valid.

A DROP submission is a specialized consumer request. It should remain distinct from a direct access, correction, or deletion request sent to one business under another provision of California law.

Audits, regulations, and the five-year period

Starting January 1, 2028, and every three years afterward, section 1798.99.86(e) requires a data broker to undergo an independent third-party audit of compliance with that section. The broker must retain the report and related materials for at least six years and provide them within five business days after a written CPPA request. These are future recurring duties stated in the current law; they should not be described as a present annual CPPA inspection.

Section 1798.99.87 authorizes the Agency to adopt regulations to implement and administer the title. The existing DROP regulations are therefore part of the compliance framework, including rules on account security, access, matching, response codes, restricted use of request data, and broker security practices.

Section 1798.99.89 generally bars commencement of an administrative action more than five years after the violation. That is a limitations rule for the action, not permission to discard audit material early: the separate six-year audit-retention requirement still applies on its own terms under section 1798.99.86(e).

Administrative orders may include corrective terms

The statutory schedules state the baseline fines and recoverable expenses. Resolutions can also contain agreed forward-looking terms. In the CPPA’s Datamasters stipulated final order, the Board adopted a settlement containing a fine together with cessation, deletion, written-policy, recordkeeping, and reporting provisions. Those provisions arose from that settlement and its facts; they are not automatic remedies in every DELETE Act matter.

Settlement is not the only possible disposition. The CPPA has also reported a registration action completed by default after the respondent did not challenge the allegations, with the Board ordering the statutory fine. The Agency’s National Public Data announcement describes that outcome. These examples show administrative enforcement in operation, but neither decides how the Agency would prove a future DROP deletion case.

Practical record checklist for a consumer

If a consumer believes a broker has not complied, preserve information that distinguishes a platform result from a legal conclusion:

  1. Save the DROP ID, submission date, broker name, transaction status, and dates on which the status changed.
  2. Confirm the broker’s legal entity in the official registry; do not rely only on a product or website name.
  3. Record the identifiers supplied for matching without publishing them or sending extra sensitive information through an unofficial channel.
  4. Preserve the exact status and any explanation of an exemption rather than summarizing it from memory.
  5. Separate a DROP deletion issue from a direct CCPA access, correction, or first-party deletion request.
  6. If reporting the matter, use the CPPA’s official complaint form and state observable facts without assigning a penalty amount.
  7. Keep evidence securely and avoid assuming that a complaint guarantees an investigation, order, fine, or individual payment.

The DELETE Act gives the CPPA substantial administrative tools, but their application depends on statutory coverage, the specific duty, the evidence, exemptions, and procedure. This article provides general information, not legal advice. For an assessment of a particular broker, request, investigation, or possible claim, consult the current official materials and a qualified legal professional.

Frequently asked questions

Who enforces the California DELETE Act?

The California Privacy Protection Agency brings the administrative actions specified by the DELETE Act against covered data brokers for registration and DROP deletion failures.

What is the fine for failing to delete after a DROP request?

The statute specifies $200 for each deletion request for each day the broker fails to delete information as required, plus reasonable investigation and administration expenses.

Is there one maximum DELETE Act fine for a data broker?

The statute does not state one aggregate cap for deletion failures. Exposure depends on proven requests, days of failure, coverage, exceptions, and the administrative action.

Can a consumer sue for damages under the DELETE Act itself?

The DELETE Act enforcement provisions do not create an express private damages action for registration or DROP-processing violations; possible rights under other laws are separate.

Can the CPPA obtain a data broker's independent audit report?

Yes. Starting in 2028, covered brokers must undergo an independent audit every three years and submit the report and related materials within five business days after a written CPPA request.

Primary sources

This article provides general information, not legal advice.