California's 'Delete Act' Goes Live, Forcing Data Brokers to Process Consumer Deletion Requests
After a seven-month grace period, California's centralized deletion platform is now legally enforceable, requiring over 500 data brokers to systematically erase the personal information of hundreds of thousands of residents.
By Tariq Nasser
- Privacy Advocates
- View the law as a necessary correction to an exploitative industry.
- Data Broker Industry
- Argues the mandate imposes severe technical burdens and risks deleting essential verification data.
- State Regulators
- Focus on strict enforcement and establishing a national precedent.
What everyone gets wrong about California’s Delete Act is the assumption that the state simply flipped a switch on January 1, instantly wiping millions of consumer profiles from the internet. The reality is far more bureaucratic, yet ultimately far more effective. While the consumer-facing portal—the Delete Request and Opt-Out Platform, or DROP—launched at the start of the year, the actual mandate forcing the data broker industry to process those requests only went live on August 1, 2026.[1][2]
For seven months, residents who submitted requests were essentially taking a number and standing in a digital queue. That queue is now moving. As of this month, the more than 500 data brokers registered in California are legally required to begin systematically processing the backlog of over 475,000 deletion requests that accumulated during the first half of the year.[1]
The gap between the platform's launch and the enforcement date was not an oversight by lawmakers. It was a deliberate grace period designed to give an entirely unregulated industry time to build the necessary API connections to the state's centralized system. Now that the grace period has expired, the law's financial teeth are fully exposed, and the technical mechanisms are actively running.[1]
The mechanism driving this mass deletion is surprisingly straightforward, relying on cryptographic matching rather than manual oversight. Under the regulations drafted by the California Privacy Protection Agency (CPPA), data brokers must log into the DROP system at least once every 45 days.[1][2]
Once logged in, brokers download a list of hashed identifiers—cryptographically scrambled versions of consumers' emails, phone numbers, and names. The brokers must then apply the exact same hashing algorithm to their own databases and compare the results. If a hash from the state's list matches a hash in the broker's system, the broker possesses that consumer's data and must delete it entirely.[2]
Once logged in, brokers download a list of hashed identifiers—cryptographically scrambled versions of consumers' emails, phone numbers, and names.
This deletion mandate includes not just the raw data, but any inferences or behavioral profiles drawn from that information. To prevent brokers from using formatting discrepancies as a loophole—such as claiming a phone number with dashes didn't match a number without them—the state mandated strict standardization rules before the hashing process occurs. Dates must be formatted as eight-digit strings, and phone numbers must be reduced to their last ten digits.[2]
This standardization is the quiet engine of the Delete Act, stripping away the technical excuses that data brokers have historically used to ignore individual opt-out requests. Furthermore, the deletion obligation is continuous. Because brokers must check the DROP registry every 45 days, any personal information they inadvertently re-acquire about a consumer who has opted out must be deleted again in the next cycle.
The definition of a data broker under California law is intentionally broad, capturing any business that knowingly collects and sells the personal information of a consumer with whom it does not have a direct relationship. This casts a wide net, ensnaring not just traditional background-check services and marketing aggregators, but also consumer brands that supplement their first-party data by purchasing and reselling third-party profiles.[1]
There is no revenue threshold for compliance, meaning even niche operators must register and connect to DROP. Enforcement has already begun, signaling that the CPPA intends to police the registry aggressively. With the passage of a recent amendment, SB 361, the administrative fine for failing to register has doubled to $200 per consumer, per day, creating a catastrophic liability for companies that attempt to fly under the radar.[1]
The CPPA recently issued decisions against LocateSmarter LLC and Cybba, Inc. for failing to register with the state by the required deadlines and for unlawfully demanding sensitive information—such as partial Social Security numbers—before processing opt-outs. These early actions serve as a warning shot to the rest of the industry that the agency is actively monitoring compliance.[1]
Despite the robust framework, significant uncertainties remain regarding the law's ultimate efficacy. The Delete Act includes several legal exemptions; brokers can decline a deletion request if the data is required for legal compliance, security purposes, or specific credit reporting functions. While brokers must report any denied requests to the state, privacy advocates worry that the CPPA may lack the auditing bandwidth to verify whether these exemptions are being applied legitimately across hundreds of companies.[2]
There is also the question of national spillover. Because data brokers operate across state lines, segregating California residents' data from the rest of a national database is technically complex. Some industry analysts predict that major brokers will simply apply the DROP deletion lists nationwide to avoid the compliance overhead of maintaining separate state-by-state architectures, potentially making California's platform a de facto national privacy standard.[2]
What to know
- California's Delete Act mandate went into effect on August 1, 2026, requiring data brokers to process consumer deletion requests.
- Over 500 registered data brokers must access the state's DROP platform every 45 days to download and process hashed deletion lists.
- More than 475,000 Californians have already submitted requests through the centralized portal since it opened in January.
- Brokers face fines of $200 per consumer, per day for failing to register or comply with the deletion mandates.
- The law requires continuous compliance, meaning brokers must re-delete any newly acquired data for opted-out consumers in subsequent cycles.
Key terms
- Data Broker
- A business that knowingly collects and sells the personal information of consumers with whom it does not have a direct relationship.
- DROP
- The Delete Request and Opt-Out Platform, California's centralized portal where residents can submit a single request to delete their data across all registered brokers.
- Cryptographic Hashing
- A process that scrambles personal identifiers (like an email address) into a fixed string of characters, allowing companies to match records without exposing the underlying plain-text data.
- CPPA
- The California Privacy Protection Agency, the state regulatory body tasked with implementing and enforcing the Delete Act.
Reader questions
Who can use the DROP platform?
The platform is available for free to all verified residents of California.
How long does it take for my data to be deleted?
Once a broker retrieves your request from the DROP system, they have 45 days to process the deletion and erase your data from their records.
Can a data broker refuse to delete my information?
Yes, but only under specific legal exemptions, such as if the data is required for legal compliance, security investigations, or certain credit reporting functions. They must report any denials to the state.
Do I need to submit a request more than once?
No. A single request remains active indefinitely. Brokers are required to check the list every 45 days and delete any new information they may have acquired about you.
Sources
[1]California Privacy Protection AgencyState RegulatorsDelete Request and Opt-Out Platform (DROP)
Read on California Privacy Protection Agency →
[2]Factlen Editorial TeamSynthesis by Factlen editorial team
Read on Factlen Editorial Team →
Comments
Every angle. Every day.
Get technology stories with full source coverage and perspective breakdowns delivered to your inbox.

