How to Comply with the California Delete Act and DROP System
A technical roadmap for data brokers to automate deletion requests and mitigate $200/day per-request fines.
The operational launch of California’s Data Broker Deletion Request and Opt-Out Platform (DROP) has transformed data privacy from a reactive legal obligation into a mandatory technical pipeline. As of August 1, 2026, the California Privacy Protection Agency (CPPA) has activated the centralized mechanism that allows consumers to delete their personal information across all registered data brokers with a single request. For organizations categorized as data brokers, the grace period for manual processing has ended.
Failure to comply is no longer a matter of simple administrative friction. Under the California Delete Act (SB 362), the CPPA is authorized to levy fines of $200 per consumer request, per day, for every day the deletion remains unprocessed (https://www.iapp.org/news/a/calprivacy-discusses-drop-enforcement-data-broker-fee-hike/). For a broker managing thousands of requests, these compounding penalties can mathematically reach millions of dollars in exposure within a single 45-day cycle. This guide outlines the specific steps required to align your data infrastructure with the DROP system.
1. Determining Your Status Under SB 362
The first step in compliance is confirming whether your entity meets the statutory definition of a "data broker." California defines a data broker as a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship. This excludes entities covered by the Fair Credit Reporting Act (FCRA) or the Gramm-Leach-Bliley Act (GLBA) in specific contexts.
If your organization aggregates datasets for AI training or secondary market licensing, you likely fall within this scope. Understanding what you can legally sell under GDPR and CCPA frameworks is critical before registering with the CPPA, as the act of registration itself triggers the requirement to interface with the DROP system.
2. The 45-Day Synchronization Mandate
The core of the Delete Act is the requirement for brokers to query the DROP platform at least once every 45 days. This is not a suggestion; it is a disclosed statutory deadline (https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240SB362). Your technical team must implement an automated process to:
- Connect to the CPPA’s API to retrieve the latest batch of deletion requests.
- Cross-reference the identifiers provided (names, emails, hashed IDs) against your internal production and backup databases.
- Execute the deletion of all personal information associated with those consumers.
- Ensure that the data is not re-collected or re-associated with the consumer in future ingestion cycles.
Crucially, if a broker cannot verify a consumer's identity through the DROP-provided data, they must still treat the request as an opt-out of the sale or sharing of that consumer's information, as per CPPA enforcement guidelines.
3. Handling the 'No Re-Identification' Paradox
A significant challenge in DROP compliance is the prohibition against re-identifying consumers. The law mandates that brokers must not use the information provided in a deletion request for any purpose other than to facilitate the deletion. This requires a "clean room" approach to request processing: the data sent by the state must be used to trigger a purge and then be discarded or siloed, rather than being added to a "suppression list" that inadvertently creates a new profile of the consumer.
4. Mandatory Triennial Audits
Beyond the 45-day sync, data brokers must undergo an independent audit every three years. This audit must verify compliance with the deletion requirements and the results must be submitted to the CPPA upon request. The estimated cost for these audits can range from $15,000 to over $50,000 depending on the complexity of the data architecture (https://www.iapp.org/news/a/calprivacy-discusses-drop-enforcement-data-broker-fee-hike/). Documentation of every deletion event, including the timestamp of the DROP query and the confirmation of the purge, is essential for a successful audit trail.
5. Financial and Operational Risk Management
The fiscal impact of the Delete Act extends beyond fines. The CPPA has recently discussed fee hikes for data broker registration to fund the maintenance of the DROP system, with proposed annual fees reaching significant disclosed amounts to cover administrative overhead (https://www.iapp.org/news/a/calprivacy-discusses-drop-enforcement-data-broker-fee-hike/).
For data buyers, the Delete Act introduces a new layer of due diligence. When acquiring or licensing a dataset, you must verify that the seller has a verified DROP-compliant pipeline. If a dataset contains "zombie data"—information that should have been deleted under a DROP request—the buyer may face secondary liability or find their AI models compromised by the need to retrain without the illicit data.
What this means for you
For data owners, compliance is the prerequisite for liquidity. A dataset that cannot be audited for DROP compliance is a toxic asset in the 2026 market. Conversely, organizations that can demonstrate a robust, automated deletion pipeline will see higher valuations from institutional buyers who prioritize regulatory safety. Whether you are looking to monetize your internal assets or browse our dataset catalogue for high-quality, compliant training data, understanding the technical nuances of the Delete Act is no longer optional—it is a core requirement of the data economy.
Data Academy
Go deeper with our guides
From the marketplace
Explore live data opportunities
Cleanpower — Search & Query Logs Dataset Opportunity
View opportunity →mobilityHartmann International — API-Accessible Dataset Opportunity
View opportunity →otherListenfield — Search & Query Logs Dataset Opportunity
View opportunity →d-nvest turns the data assets behind these deals into scored, actionable opportunities.
Explore the pipeline →