Truyo recognized in Gartner® Magic Quadrant™ for AI Governance Platforms | Download Report
CalPrivacy DROP
Privacy Enforcement, U.S. Laws & Regulations

This Just DROP-ed: What California’s New Deletion Requirements Mean for Privacy Compliance

Since August 1, 2026, registered data brokers have been required to access the California Privacy Protection Agency’s Delete Request and Opt-out Platform (DROP) at least once every 45 days and process consumer requests within 45 days. Through a single request, California residents can direct registered data brokers to delete eligible personal information held about them. The objective is straightforward. Implementing it, however, may be anything but.

The challenges in compliance to DROP do not necessarily indicate indifference towards consumer privacy but reflect the complexity of modern data environments and the difficulty of converting a legal requirement into a reliable process. Therefore, let us discuss DROP in detail and understand how businesses must prepare ahead.

Is Your Business In Scope?

DROP applies to businesses that qualify as “data brokers” under the California Delete Act. A data broker is generally a business that knowingly collects and sells to third parties the personal information of consumers with whom it does not have a direct relationship. “Sale” is interpreted broadly under California privacy law and may include exchanging personal information for monetary or other valuable consideration.

The definition can cover more than businesses traditionally described as data brokers. Advertising technology providers, lead-generation companies, audience and data-enrichment platforms, analytics providers and even consumer-facing businesses may fall within scope when they obtain personal information outside a direct consumer relationship and sell it to third parties.

The law contains limited exclusions for certain activities regulated by laws including the Fair Credit Reporting Act, Gramm-Leach-Bliley Act, California’s Insurance Information and Privacy Protection Act and specified health-information laws. These exclusions generally apply only to the extent that the relevant activity or information is covered.

More Than a One-Time Delete

The California Delete Act, under which DROP was created, requires more than responding to individual requests. It introduces continuing obligations that businesses must support through clear responsibilities, documented procedures and appropriate technical controls. Data brokers have reportedly already started processing DROP requests.

  • The 45-day deadline. Beginning August 1, 2026, a data broker must access DROP at least once every 45 days. Within 45 days after receiving a request, it must process that request and delete the consumer’s matching personal information, subject to limited statutory exemptions.
  • Exercising the right: DROP permits a single verifiable request to be made across registered data brokers. Although the consumer may selectively exclude particular brokers.
  • Deletion beyond the broker’s database: The obligation requires the broker to also direct associated service providers and contractors to delete personal information in their possession relating to the requesting consumer. The practical perimeter may therefore include enrichment vendors, cloud environments, marketing platforms, analytics stores, archives and other systems into which data has travelled.
  • Unverifiable deletion request: Where a broker cannot verify a request sufficiently to delete the information, the Delete Act generally requires it to process the request as an opt-out of sale or sharing.
  • Deletion is designed to persist. After deleting a consumer’s information pursuant to DROP, the broker must continue deleting personal information about that consumer at least once every 45 days, unless the consumer requests otherwise or an exemption applies. The broker also may not resume selling or sharing newly acquired information about that consumer if it re-entered the system through another source.
  • Financial liability: A broker that fails to comply with DROP’s deletion requirements may face an administrative fine of $200 for each deletion request for each day the violation continues, as well as reasonable enforcement expenses.

Building a DROP-Ready Business

Consumer information often exists across legacy systems, vendor platforms, archived records and datasets maintained by different teams. Identifying the correct records, applying statutory exceptions, coordinating deletion with service providers and preventing deleted information from re-entering commercial workflows can require significant operational coordination. Here’s how businesses can prepare.

  • Determine Data Scope: Assess, and document, the data related to personal information about the customers that is collected and processed. Examine actual data flows and revenue arrangements and review the statutory exclusions carefully.
  • Confirm registration and DROP access immediately: Verify that the correct legal entity is registered, that the registration is current and accurate, that the required fees have been paid and that more than one trained person can access the platform.
  • Build a controlled request-ingestion process. Establish a schedule comfortably inside the statutory 45-day limit. Log when request lists are retrieved, which systems receive them, who owns processing, when each stage is completed and how exceptions or errors are escalated. Internal targets should leave time for matching failures, vendor delays and quality assurance.
  • Engineer matching with privacy and accuracy in mind: DROP uses privacy-protective hashed identifiers. Brokers therefore need consistent normalization and hashing procedures for their own records. Test variations involving names, email addresses, telephone numbers, postal addresses and optional identifiers. Measure false negatives and ambiguous matches.
  • Map deletion across the entire data estate: Inventory source systems, derived datasets, audience segments, model inputs, activation platforms, file transfers, backups and downstream recipients. Specify what “delete” means in each environment and how completion is verified. If some information must be retained, segregate it where feasible and restrict its use to the legally permitted purpose.
  • Create durable suppression controls: Establish controls that recognize the consumer when data is reacquired and prevent prohibited sale or sharing. Ensure the suppression record contains only what is reasonably necessary to honour the request and is itself protected against unrelated use.
  • Review contractors and third parties: Asses the contractor agreements for deletion duties, response times, evidence requirements, audit rights and escalation procedures. Test the communication pathway rather than assuming a contract clause performs deletions by telepathy. The broker remains responsible for directing its downstream partners; a vendor’s silence does not stop the statutory clock.

To operationalize the DROP obligations in a way that is sustainable rather than reactive, organizations typically need a structured compliance workflow supported by purpose-built tooling. Truyo Privacy helps centralize and automate the steps required for request intake, identity matching, workflow routing, deletion orchestration and audit logging across complex data environments.

Clarity Is the Best Compliance Strategy

Businesses are not indifferent to consumer privacy. In practice, most organizations subject to these rules are not resisting deletion requests out of intent or disregard but more practical limitations. Compliance with DROP therefore requires translating the intent into processes that ensure consumer privacy and trust. For businesses the most constructive response is clarity regarding data flows, responsible data processing, and internal mechanisms. With that foundation in place, compliance becomes not a reactive scramble, but a managed and predictable function of modern data governance.


Author

Dan Clarke
Dan Clarke
President, Truyo
August 12, 2026

Let Truyo Be Your Guide Towards Safer AI Adoption

Connect with us today