Data Brokers

The California Delete Act: Registration, DROP, and the Deadlines Written Into SB 362

Compliance date August 1, 2026 Registered data brokers must access DROP at least once every 45 days and process deletion requests within 45 days, under Civ. Code § 1798.99.86(c) and Cal. Code Regs. tit. 11, § 7612 Applies to: Businesses registered as data brokers with the California Privacy Protection Agency

Key Takeaways

  • SB 362 (Stats. 2023, ch. 709) moved data broker registration from the Attorney General to the CPPA and added the accessible deletion mechanism, effective January 1, 2024
  • DROP opened to consumers on January 1, 2026; from August 1, 2026 registered brokers must access it at least once every 45 days and process each request within 45 days
  • Registration costs $6,000 a year under Cal. Code Regs. tit. 11, § 7600, is non-prorated and nonrefundable, and is due between January 1 and 31 each year
  • Failure to register carries $200 for each day, plus the fees that were due and the agency's investigation expenses — the arithmetic behind both 2026 orders
  • SB 361 added disclosures effective January 1, 2026 covering sales to foreign actors, to federal, state and law enforcement agencies, and to developers of generative AI systems

What SB 362 Changed

California has had a data broker registry since AB 1202 in 2019. Senate Bill 362 (Becker), chaptered as Stats. 2023, ch. 709 and approved by the Governor on October 10, 2023, kept the registry and changed almost everything around it. The Legislative Counsel's Digest describes the two structural moves precisely: the bill "would require a data broker to register with, pay a registration fee to, and provide information to, the agency instead of the Attorney General and would require the agency to maintain the informational internet website," and it directed the agency to build a deletion mechanism the registry had never had.

The result is a two-part statute at Civil Code sections 1798.99.80 through 1798.99.89. One part is a list of who is in the business. The other is a channel through which a consumer's single deletion request reaches everyone on the list. Section 1798.99.88 preserves the boundary with the main privacy statute: nothing in the title "shall be construed to supersede or interfere with the operation of the California Consumer Privacy Act of 2018."

Senate Bill 361, chaptered as Stats. 2025, ch. 466 and approved October 8, 2025, amended sections 1798.99.82, 1798.99.84 and 1798.99.86 effective January 1, 2026.

Who Counts as a Data Broker

Section 1798.99.80(c) defines a data broker as "a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship." Every term in that sentence is doing work — knowledge, sale, third parties, and the absence of a direct relationship — and subsection (a) imports the CCPA's own definitions from section 1798.140 for the rest.

Four exclusions follow, and each is phrased as a partial carve-out rather than an entity-level exemption. An entity is outside the definition "to the extent that it is" covered by the federal Fair Credit Reporting Act, by the Gramm-Leach-Bliley Act and its implementing regulations, or by the Insurance Information and Privacy Protection Act; and a covered entity or business associate is outside it to the extent its processing is exempt under section 1798.146, the CCPA's HIPAA carve-out. A company whose activities straddle the line is inside the definition for the part that is not covered.

Registration and the Public Registry

Section 1798.99.82(a) sets the window: registration is due "on or before January 31 following each year in which a business meets the definition of data broker." The fee is set by regulation rather than statute — Cal. Code Regs. tit. 11, § 7600(a) fixes "the annual fee to register as a data broker" at "$6,000 plus an associated third-party fee for processing electronic payments not to exceed 2.99%," payable by credit card unless the agency authorises another method, and subsection (d) states that it "cannot be prorated and is nonrefundable."

What the registration form asks for is enumerated in section 1798.99.82(b)(2), and the list grew under SB 361. Alongside the name and addresses and the request metrics, a registrant discloses whether it collects minors' personal information, government identification numbers, mobile advertising and connected television identifiers, citizenship and immigration status, union membership, sexual orientation, gender identity and expression, biometric data, precise geolocation and reproductive health care data. The 2026 additions ask whether the broker has, in the past year, shared or sold consumer data to a foreign actor, to the federal government, to other state governments, to law enforcement other than under subpoena or court order, or "to a developer of a GenAI system or model." "Foreign actor" is defined by reference to the "covered nation" list in 10 U.S.C. § 4872. From January 1, 2029, subparagraph (U) also asks whether the broker has undergone the audit described below.

Not all of it is public. Section 1798.99.84(b) withholds the answers to subparagraphs (D), (G) and (T) from the agency's public website. The rest is published: the agency's registry file for 2025 lists 543 registrants, and the DROP consumer page describes a single request reaching "over 600 registered data brokers."

Section 1798.99.85 adds an annual disclosure that lives on the broker's own site rather than the registry. By July 1 following each year, a broker compiles the number of CCPA and deletion requests it received, complied with in whole or part, and denied, plus the median and mean days to substantive response, and publishes those metrics in its privacy policy. Denials have to be broken out by reason — not verifiable, not made by a consumer, information exempt from deletion, or other grounds — and by the specific provision of section 1798.145 or 1798.146 relied on.

The Deletion Request Mechanism

Section 1798.99.86(a) required the agency to establish an accessible deletion mechanism by January 1, 2026 that lets a consumer, "through a single verifiable consumer request," ask every data broker holding their personal information to delete it, while allowing the consumer to exclude specific brokers. The platform the agency built is DROP, the Delete Request and Opt-out Platform. The statute requires it to be free to consumers, available in any language spoken by a consumer whose information brokers have collected, usable by consumers with disabilities, open to authorized agents, and capable of showing a requester the status of their request.

It also constrains what brokers learn. Subsection (b)(3) requires the mechanism to let a registered broker determine whether an individual has submitted a deletion request while not allowing "the disclosure of any additional personal information when the data broker accesses the accessible deletion mechanism." The deletion channel is not a new source of data about the person asking.

The implementing regulations, effective January 1, 2026, describe the mechanics in more detail than the statute does. Section 7620 requires the agency to verify a consumer's California residency before a request can be submitted, and allows a consumer to amend or cancel a request "no sooner than 45 calendar days after submission." Section 7612 requires a broker to download its consumer deletion list at least once every 45 calendar days, manually if an automated connection fails, and to notify the agency in writing of a connection failure within 45 days of its last access. After the first download, subsequent lists carry only new or amended requests.

Section 7613 goes as far as string formatting. Before comparing a deletion list against its own records, a broker standardises its data: lowercase throughout, extraneous and special characters removed, non-English characters converted to the closest English equivalent — the regulation's own example is that "Björn O'Connor-López shall be formatted as bjornoconnorlopez" — dates of birth as an eight-digit year-month-day string, zip codes truncated to five characters, phone numbers as the last ten digits without dashes or country code. Section 7614 then requires the broker to report a response code for each transaction identifier at its next access session, using values such as "record deleted" and "record not found," and to report a status change if a later collection produces a match that an earlier comparison missed.

Accessible Deletion Deadlines

The obligations phase in on dates written into section 1798.99.86 itself.

DateWhat attaches to itProvision
January 1, 2024SB 362 takes effect; registration moves to the CPPAStats. 2023, ch. 709
January 1, 2026DROP established and open to consumer requests; SB 361 amendments and the DROP regulations take effect§ 1798.99.86(a)
August 1, 2026Brokers access DROP at least every 45 days and process requests within 45 days of receipt§ 1798.99.86(c)(1)
August 1, 2026Ongoing duty to re-delete every 45 days, and not to sell or share new personal information about a requester§ 1798.99.86(d)
January 1, 2028First triennial audit by an independent third party for compliance with the deletion duties§ 1798.99.86(e)(1)
January 1, 2029Registration begins disclosing whether the broker has been audited§ 1798.99.82(b)(2)(U)

Two features of the August 2026 duties are easy to miss. A deletion request that a broker cannot verify does not simply fail: section 1798.99.86(c)(1)(B) requires it to be processed instead as an opt-out of sale or sharing under section 1798.120, within the same 45 days, and the broker must direct its service providers and contractors to do the same. And the duty does not end when the records are deleted — subsection (d) requires the broker to keep deleting that consumer's personal information every 45 days and to refrain from selling or sharing newly acquired information about them, unless the consumer asks otherwise or an exemption applies.

The audit obligation beginning January 1, 2028 runs every three years, and the resulting report and related materials go to the agency within five business days of a written request. Brokers retain them for at least six years.

Penalties for Non-Registration

Section 1798.99.82(c) makes a broker that fails to register liable in an administrative action for "[a]n administrative fine of two hundred dollars ($200) for each day" it fails to register, plus "an amount equal to the fees that were due during the period it failed to register" and the agency's reasonable investigation and administration expenses. Subsection (d) applies the same $200 figure per deletion request per day where a registered broker fails to delete as section 1798.99.86 requires. Recoveries go to the Data Brokers' Registry Fund. Section 1798.99.89 bars any administrative action commenced more than five years after the violation occurred.

The daily structure is what makes the fines calculable, and the 2026 orders show the arithmetic on their face. The order against LocateSmarter LLC, Case No. ENF26-05-D-LO, imposes "thirty thousand, six-hundred dollars ($30,600.00) in accordance with section 1798.99.82(c)" — 153 days at $200 — and separately requires the company to pay "the six-thousand dollar ($6,000.00) annual fee set forth in the Code of Regulations, title 11, § 7600(a)" and to file its registration within fourteen days. The order against Cybba, Inc., Case No. ENF25-228-D-CY, imposes $52,400, or 262 days, "having previously paid the 2025 annual registration fee," and requires the company to post its privacy rights metrics, access DROP and process future deletion requests through it.

LocateSmarter is also the first action the agency has brought under the Delete Act and the CCPA together. Its second component, $79,890 under Civil Code section 1798.199.55, concerns requiring a full name, the last four digits of a Social Security number and a mailing address to submit an opt-out — which the order treats as exceeding the minimum personal information the request needed.

How This Differs From Registration-Only States

A registry on its own produces a published list and a filing deadline. What a consumer does with the list is left to them: find the brokers, approach each one, and use whatever rights another statute supplies. Several states operate registries on that model, and the comparison between them is a separate subject from this one.

The Delete Act keeps the list and adds four things that do not follow from registration: a single request that fans out to every registrant, a recurring 45-day cycle in which brokers must return to the platform, a standing obligation not to re-acquire and sell the requester's data afterwards, and an independent audit of whether any of it happened. The registry becomes the addressing system for a deletion right rather than the end product. The enforcement hook follows the same logic — the $200-a-day fine for not registering is what keeps the address book complete, and the parallel $200-per-request-per-day fine is what backs the deletion duty itself.

Background

For the underlying law rather than this development: California privacy law.

Frequently Asked Questions

When did DROP open, and when do brokers have to start using it?
Civil Code section 1798.99.86(a) required the agency to establish the mechanism by January 1, 2026, and consumers could submit requests from that date. Subsections (c) and (d) attach the broker-side duties to August 1, 2026: accessing the platform at least once every 45 days, processing each request within 45 days of receipt, and continuing to delete every 45 days thereafter.
What does it cost to register as a data broker in California?
Cal. Code Regs. tit. 11, § 7600(a) sets the annual fee at $6,000 plus a payment-processing fee not exceeding 2.99%. The fee cannot be prorated and is nonrefundable, and registration is due on or before January 31 following each year in which the business met the definition.
What happens to a deletion request the broker cannot verify?
Section 1798.99.86(c)(1)(B) provides that where a broker denies a deletion request because it cannot be verified, it must process the request as an opt-out of the sale or sharing of that consumer's personal information under section 1798.120 within 45 days of receiving it, and direct its service providers and contractors to do the same.
Does the Delete Act reach a company already regulated under GLBA or the FCRA?
Only in part. Section 1798.99.80(c) phrases each exclusion as applying "to the extent that" an entity is covered by the Fair Credit Reporting Act, the Gramm-Leach-Bliley Act, or the Insurance Information and Privacy Protection Act, and "to the extent" processing is exempt under section 1798.146. Activity outside the covered scope remains within the definition.
What did SB 361 add to the registration disclosures?
Effective January 1, 2026, section 1798.99.82(b)(2) asks whether the broker has in the past year shared or sold consumer data to a foreign actor, to the federal government, to other state governments, to law enforcement other than under subpoena or court order, and to a developer of a generative AI system or model. It also requires disclosure, from January 1, 2029, of whether the broker has undergone the triennial audit.

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.