California residents can now ask hundreds of data brokers to delete their personal information through a single request. The Delete Request and Opt-out Platform (DROP) replaces the need to contact each registered broker separately.
Consumer access to the platform launched in January 2026, and data brokers have been obligated to pull and fulfill DROP requests starting August 1, 2026.
What is the California Delete Act?
The California Delete Act was introduced through Senate Bill 362 and is set out in California Civil Code §§ 1798.99.80 to 1798.99.89. It builds on the California Consumer Privacy Act (CCPA) by making it easier for California residents to exercise deletion rights against data brokers.
Its main feature is DROP, a free platform operated by the California Privacy Protection Agency (CPPA), also known as CalPrivacy. A consumer can use DROP to send one deletion request to all active data brokers or exclude specific brokers from the request.
The Delete Act California does not replace existing CCPA rights. Consumers can still contact individual businesses directly to request access, correction, deletion, or an opt-out from the sale or sharing of their personal information.
Does your website serve Californians?
Give visitors a clear way to opt out of data sale or sharing with a CookieYes banner built to support CCPA compliance.
Create an opt-out banner- 14-day free trial
- Cancel anytime
Who is a data broker under the Delete Act California?
A data broker is a business that knowingly collects and sells personal information about consumers with whom it does not have a direct relationship.
For example, a company may be a data broker if it collects information about people from several sources and sells it to other companies, even though those people have never dealt with it directly.
A retailer collecting information from its own customers is not a data broker merely because it holds personal information. However, a business may still fall within the definition if it also runs a separate data-broker activity.
Limited exemptions
The definition excludes entities to the extent that they are covered by certain sector-specific laws, including:
- The Fair Credit Reporting Act
- The Gramm-Leach-Bliley Act
- California's Insurance Information and Privacy Protection Act
- Certain processing covered by healthcare privacy exemptions under the CCPA
These are not necessarily blanket exemptions. A business must consider whether the relevant law covers the particular entity or processing activity.
Important Delete Act deadlines
| Date | Requirement |
|---|---|
| January 31 each year | A business must register with the CPPA if it met the data-broker definition during the previous year. |
| July 1 each year | A data broker must compile and publish required request-handling metrics for the previous calendar year. |
| January 1, 2026 | DROP became available for consumers to submit requests. |
| August 1, 2026 | Data brokers had to begin accessing DROP and processing requests at least once every 45 days. |
| January 1, 2028 | Independent compliance audits begin and repeat every three years. |
| January 1, 2029 | Annual registrations must state whether the broker has undergone the required audit and provide certain audit details. |
In 2025, SB 361 expanded the information data brokers must provide when registering. The current requirements include disclosures about certain sensitive identifiers and whether data has been sold or shared with governments, law enforcement, foreign actors, or developers of generative AI systems.
About DROP and Delete Act: How does it work ?
DROP is available only to California residents. The consumer process is relatively simple:
- Verify California residency: DROP uses the California Identity Gateway to confirm eligibility. A person does not need to create an account with the gateway, and the information used for the check is not retained by DROP.
- Create a profile: The consumer provides basic details that data brokers can use to find matching records. Name, date of birth, and ZIP code are required. Other details, such as email addresses, phone numbers, and certain device or vehicle identifiers, are optional.
- Submit one request: The request applies to all active data brokers unless the consumer chooses to exclude particular brokers.
- Track its status. The consumer receives a DROP ID that can be used to check how brokers have handled the request.
Consumers may also use an authorised agent in supported circumstances. They can update a previous request after at least 45 days.
What must data brokers do with a DROP request?
Beginning August 1, 2026, registered data brokers must access DROP at least once every 45 days. They must then:
- process each request and delete matching, non-exempt personal information within the required period;
- instruct their service providers and contractors to delete the consumer's personal information;
- update the request status in DROP;
- continue checking for and deleting newly acquired matching information at least once every 45 days; and
- stop selling or sharing new personal information about that consumer, unless the consumer later requests otherwise or an exemption applies.
If a deletion request cannot be verified, the broker must generally treat it as a request to opt out of the sale or sharing of personal information.
The CPPA explains that it may take up to 90 days for a consumer to see an updated status. This reflects the time allowed for brokers to retrieve a request and then process and report it. It does not mean a broker receives 90 days from the point at which it accesses the request.
Are there exceptions to deletion under the California Delete Act?
Yes. A data broker may retain information where a CCPA exception applies. This can include information reasonably needed for certain purposes listed in the CCPA, such as security, fraud prevention, or compliance with a legal obligation.
Information kept under an exception may be used only for the permitted purpose. It cannot be reused or disclosed for an unrelated purpose such as marketing.
How is DROP different from a CCPA deletion request?
Both routes remain available, but they work differently:
| CCPA request | DROP request |
|---|---|
| The consumer contacts a particular business. | The consumer sends one request to active data brokers. |
| It may apply to any business covered by the CCPA. | It applies specifically to data brokers. |
| It is handled through the business's own request process. | It is submitted and tracked through a state-run platform. |
| It concerns information held by the business receiving the request, subject to exceptions. | It creates an ongoing duty for brokers to check for and delete new matching information, subject to exceptions. |
A business that deals directly with consumers may therefore need a normal CCPA request process even if it is not a data broker. A company that acts as both a consumer-facing business and a data broker may need to support both routes.
Penalties for non-compliance
A data broker that fails to process a DROP request as required may face an administrative fine of $200 for each deletion request for each day of non-compliance, plus the CPPA's reasonable investigation and administrative costs.
Failure to register can lead to a separate fine of $200 for each day the broker remains unregistered, the unpaid registration fees and the CPPA's reasonable costs.
These are administrative penalties enforced by the CPPA. The law gives the agency five years from the date of a violation to begin an administrative action.
California Delete Act checklist: What should businesses do?
- Register with the CPPA by the applicable deadline and keep registration disclosures accurate.
- Create a DROP account and establish a process for checking it at least once every 45 days.
- Map where personal information is stored so matching records can be found and deleted.
- Ensure service providers and contractors can act on deletion and opt-out instructions.
- Keep a suppression process so deleted information is not later sold or shared again.
- Track request outcomes and response times for the annual metrics disclosure.
- Prepare for independent audits beginning in 2028 and retain audit materials for at least six years.
Businesses that do not meet the data-broker definition are not directly subject to DROP merely because they use advertising, analytics, or marketing providers. They should still understand where website data goes and comply with their separate obligations under the CCPA and other privacy laws.
A cookie scanner can help identify third-party cookies on a website. However, a scan cannot decide whether a company is legally a data broker. That requires a review of how personal information is collected, the relationship with the consumer, and whether the information is sold to third parties.
Similarly, a cookie consent solution can support website consent and opt-out processes, but it does not replace a data broker's DROP workflow.
Does your site offer an opt-out?
Add an opt-out cookie banner to help meet CCPA requirements
Get started for free- 14-day free trial
- Cancel anytime
Frequently asked questions
What is the California Delete Me Act?
The California Delete Act is a law that allows California residents to send one deletion request to active data brokers through DROP. It also sets registration, reporting, processing and audit duties for data brokers.
Is DROP available now?
Yes. Consumers have been able to submit requests since January 2026. Data brokers were required to begin retrieving and processing those requests on August 1, 2026.
Who can submit a DROP request?
California residents can submit a request for themselves. The platform also supports requests made on behalf of another resident in certain circumstances, such as a parent acting for a child.
Does a DROP request delete every piece of information?
Not always. Data brokers may keep information covered by a legal exception. Any retained information may be used only for the permitted purpose and not for unrelated purposes such as marketing.
Does the Delete Act California replace the CCPA?
No. DROP adds a central request route for data brokers. The rights and business obligations under the CCPA continue to apply.
Is California a right-to-delete state?
Yes. The CCPA gives California residents the right to ask covered businesses to delete personal information collected about them. Some information may be kept where a legal exception applies, such as for security, legal compliance or completing a transaction.
Can I ask a company to delete my data in the US?
You can ask, but whether the company must comply depends on where you live, which privacy law applies and whether an exception covers the information. Several US states provide deletion rights, but there is no single general federal law giving everyone the same right across the country.
What are the GDPR and CCPA?
The General Data Protection Regulation (GDPR) is the European Union’s main data protection law. It regulates how organisations process personal data and gives individuals rights such as access, correction, and erasure.
The CCPA is California’s main consumer privacy law. It gives California residents consumer privacy rights over their personal information, including the rights to know, delete, correct, and opt out of its sale or sharing.




