Key Takeaways
- California’s Delete Request and Opt-out Platform (DROP) is the state-run system created by the California Delete Act (Senate Bill 362). Data brokers must start processing DROP deletion requests by August 1, 2026.
- Covered data brokers must log in to DROP at least once every 45 days to download new consumer deletion lists, match records, delete or opt out as required, and report a status for every request.
- DROP compliance is an ongoing suppression obligation. Brokers must maintain hashed identifiers to prevent future sale or sharing of data for consumers who have submitted requests.
- Penalties can reach $200 per day for failure to register and $200 per day per unprocessed deletion request, plus investigation and administrative costs.
- UnsubCentral serves as infrastructure to centralize consumer identifiers, automate matching and suppression across systems, orchestrate downstream actions, and create an auditable trail of DROP compliance activity.
Meta Title: California DROP & Delete Act Compliance Guide for Data Brokers (2026 Update)
Meta Description: Learn what California’s Delete Request and Opt-out Platform (DROP) requires from data brokers by August 1, 2026, how to manage 45-day deletion cycles, and how to operationalize ongoing suppression with UnsubCentral.
Disclaimer: This article is for educational purposes only and does not constitute legal advice. Readers should consult qualified counsel for interpretations of the California Delete Act and related regulations. Information is based primarily on official California Privacy Protection Agency resources, with source URLs cited throughout.
What Is California DROP and How Does It Relate to the Delete Act?
DROP stands for Delete Request and Opt-out Platform. It is operated by the California Privacy Protection Agency (CalPrivacy) and became available to California consumers on January 1, 2026. DROP launches as a free, centralized portal where California residents can submit a single request asking all registered data brokers to delete their personal information and opt out of the sale or sharing of that data.
The California Delete Act, formally known as Senate Bill 362 (Chapter 709, Statutes of 2023, as amended by SB 361 in 2025), is the California law that directed CalPrivacy to build DROP. Some people informally say “California DROP Act,” but the correct legal name is the California Delete Act, and DROP is the platform created under that law.
The law’s core objectives are to strengthen California’s data broker framework, require annual registration and disclosures, and give residents a simple way to exercise deletion and opt-out rights across hundreds of data brokers at once. The DROP platform aims to simplify the process for consumers requesting data deletion, making it less burdensome. DROP ensures consumers can significantly reduce exposure to identity theft and spam, and it reduces unwanted texts, calls, and emails for users. When a consumer submits a delete request through DROP, it functions as both a deletion request and a “Do Not Sell or Share” opt out, processed by every registered data broker holding that consumer’s non-exempt personal information. As of July 2026, over 325,000 consumers have submitted DROP requests to more than 600 active registered data brokers.
Who Qualifies as a Data Broker Under California’s Delete Act?
Under Civ. Code § 1798.99.80(c), a data broker is generally a business that knowingly collects and sells to third parties the personal information of consumers with whom the business does not have a direct relationship. The Delete Act defines a data broker broadly without revenue thresholds. “Sale” and “sharing” incorporate the California Consumer Privacy Act (CCPA/CPRA) definitions, which may include exchanges of personal information for monetary or other valuable consideration and for cross-context behavioral advertising.
Organizations that may fall in scope include:
- List brokers and marketing data cooperatives
- People-search sites
- Third-party lead aggregators
- Identity and risk data vendors
- Analytics providers that resell third-party consumer data
Some consumer-facing brands might still qualify if they sell or share personal information collected in one context into unrelated downstream uses. For example, a company collecting emails for one service but selling that data to unrelated parties could meet the definition. Whether a specific company is a data broker is a fact-specific legal determination. Companies should review their data collection and sale activities with counsel to evaluate whether they fall within the Delete Act’s scope.
Certain entities and data processing activities may be excluded, including those covered by the Fair Credit Reporting Act, the Gramm-Leach-Bliley Act, and certain health-related exemptions under § 1798.146.
Key DROP Compliance Dates, Registration Duties, and Penalties
| Date | Milestone |
|---|---|
| 2018 | CCPA passed |
| 2019 | AB 1202 created the original data broker registry |
| November 2020 | Voters approved creation of CalPrivacy |
| October 2023 | The Delete Act was signed into law |
| 2025 | SB 361 amendments adopted |
| January 1, 2026 | Users can submit deletion requests; DROP opens to consumers |
| August 1, 2026 | Data brokers must process requests starting this date |
| January 1, 2028 | First independent audit required |
Businesses meeting the data broker definition must create a DROP account if they operated as data brokers in 2025, began brokering California residents’ data between January and August 2026, or plan to begin after August 1, 2026. Data brokers must register annually with CalPrivacy by January 31, complete the registration form, disclose categories of identifiers they collect, and pay the current registration fee of $6,000 plus applicable payment processing fees.
Starting August 1, 2026, data brokers must delete data within 90 days and must access DROP at least once every 45 calendar days to retrieve new consumer deletion lists, process requests, and report outcomes.
Penalties for non-compliance with the Delete Act can reach $200 per violation per day: $200 per day for failure to register, and $200 per day per consumer deletion request for failure to delete information as required, plus CalPrivacy’s investigation and administrative costs. The Delete Act does not provide a cure period before enforcement can begin.

How DROP Deletion Requests and Lists Work (Including the 45-Day Cycle)
The end-to-end flow works like this: California consumers authenticate via the California Identity Gateway, start submitting requests through DROP, and CalPrivacy makes standardized deletion lists available to all registered data brokers. DROP allows California residents to submit a single request to delete their personal data. DROP helps limit data brokers’ collection of personal information going forward by requiring ongoing suppression.
Beginning August 1, 2026, data brokers must at least once every 45 days log into DROP or connect via the DROP API to select and download consumer deletion lists. Data brokers must process deletion requests within 45 days, and data brokers delete data every 45 days after processing requests.
The Six DROP Consumer Deletion Lists
- First name, last name, date of birth, and ZIP code
- Email address
- Phone number
- Mobile advertising ID (MAID)
- First name, last name, and vehicle identification number (VIN)
- Connected TV identifier
After the initial download, subsequent downloads contain only new or amended DROP requests. Consumers do not need to resubmit. A single DROP request continues to apply, and data brokers must use standardized and hashed identifiers to match new data they acquire against historic lists.
From Download to Status Report: What Data Brokers Must Do Every 45 Days
Every 45-day cycle follows five required steps. Here is the operational walkthrough:
Step 1 – Download. Log into the DROP portal or use the official API to download all relevant consumer deletion lists. Follow file formats and security practices described in CalPrivacy’s technical specifications (Version 1.2.0, last updated July 2026).
Step 2 – Standardize and hash identifiers. Transform your own records to match standardized formats (normalize casing, trim whitespace, format phone numbers and dates consistently), then apply the prescribed SHA-256 hashing method with Base64 encoding before comparison.
Step 3 – Match and classify. Compare your hashed identifiers to the hashed values from DROP lists. Determine matches and verify whether any exemptions under California law apply to specific records.
Step 4 – Execute actions. For matched requests, delete all non-exempt personal information. Direct applicable service providers and contractors to delete corresponding data. Where a single identifier maps to multiple individuals and an exact person match is not possible, opt all associated consumers out of sale and sharing.
Step 5 – Report status. Report the correct outcome for each request back through the platform within 45 days:
| Status Code | Meaning |
|---|---|
| Deleted | Non-exempt personal information was deleted |
| Opted Out | Consumer opted out of sale/sharing (ambiguous match) |
| Exempted | Data retained under a legal exception |
| Not Found | No matching record identified |
Update statuses within 45 days if circumstances change. If an automated DROP connection fails, notify CalPrivacy through your DROP account within 45 days.
Ongoing Suppression Obligations and Operational Challenges
CalPrivacy’s guidance emphasizes that data brokers must retain the minimum necessary hashed identifiers from DROP requests as suppression lists. This screening layer ensures newly acquired or generated data is not sold or shared for consumers who have already submitted a deletion and opt-out request. DROP enhances security against identity theft and data leaks by enforcing this ongoing obligation.
Even when a record is “Not Found,” brokers must keep enough information – for example, a hashed email or phone number – to block future inclusion of that consumer in sales, sharing, or other regulated disclosures.
Spreadsheets, ad hoc scripts, or one-off SQL jobs do not scale once DROP requests arrive continuously. Common risk factors include:
- Inconsistent hashing across CRMs, data warehouses, and marketing platforms
- Missed 45-day cycles due to manual tracking
- Misaligned deletion and opt-out logic across teams
- Gaps in data privacy controls between marketing, product, and data engineering
- Inability to verify compliance during a regulatory inquiry or violation investigation
Robust audit trails showing when lists were downloaded, how records were matched, which identifiers were suppressed, and how outcomes were reported will be critical to demonstrate good-faith compliance.
How UnsubCentral Helps Operationalize DROP and Data Privacy Suppression
The California Delete Act introduces requirements that extend beyond traditional marketing opt-outs. Beginning August 1, 2026, registered data brokers must regularly retrieve DROP requests, match them against their records, delete applicable personal information, communicate required actions to service providers and contractors, and report processing outcomes through DROP.
UnsubCentral’s current suppression-management capabilities can support an important part of this process. Organizations can use UnsubCentral to maintain applicable consumer identifiers as centralized privacy suppression or opt-out records, helping prevent suppressed individuals from being reintroduced into marketing, sale, or sharing workflows. These records can also provide timestamps, history, and other operational evidence supporting an organization’s privacy procedures.
A suppression record should not, by itself, be treated as proof that a DROP deletion request has been fully processed. Under the Delete Act, matched records generally must be deleted unless an exemption applies. If a request cannot be verified, it must instead be processed as an opt-out of the sale or sharing of the consumer’s personal information. The law also requires data brokers to direct associated service providers and contractors to take the corresponding action. The Delete Act requirements explain this distinction.
UnsubCentral is developing expanded capabilities intended to help operationalize more of the DROP workflow, including request intake, matching and processing coordination, downstream suppression or deletion instructions, status tracking, and auditable reporting. These additional capabilities are coming soon and are being designed to complement—not replace—a company’s legal, privacy, and data-governance processes.
California’s DROP program may also provide a model for future privacy initiatives elsewhere. As other states consider similar centralized deletion and data-broker requirements, UnsubCentral is preparing its privacy-suppression framework to help organizations manage these obligations across jurisdictions through a more consistent and scalable process.
UnsubCentral is not operated by, certified by, or endorsed by the California Privacy Protection Agency. No technology platform independently guarantees legal compliance; each organization remains responsible for determining its obligations and implementing appropriate legal and operational controls.

DROP Readiness Checklist for Data Brokers
Use this checklist to prepare your organization before the August 1, 2026 deadline:
Account and Registration
- Review whether your organization meets the data broker definition
- Create a DROP account (approval takes up to two business days)
- Complete the annual registration form and required disclosures
- Pay the $6,000 registration fee plus applicable processing charges
Integration
- Decide between manual login and download or DROP API access
- Review official technical requirements at privacy.ca.gov
- Test integrations in the DROP Sandbox before production use
Identifier Preparation
- Inventory all consumer identifiers your business maintains
- Implement standardization rules consistently across environments
- Adopt prescribed hashing (SHA-256, Base64) across all systems
Processing Workflow
- Define internal SLAs shorter than the 45-day legal limit
- Map which systems store regulated personal information
- Implement deletion, opt-out, and exemption logic
- Set up processes to notify and coordinate with service providers and contractors
Suppression and Auditability
- Design a suppression-list capability retaining minimum identifiers
- Screen new acquisitions against DROP-derived suppression before any sale or sharing
- Log all matches, actions, and request statuses with timestamps
- Consider platforms like UnsubCentral to centralize suppression data and reporting
Frequently Asked Questions About California DROP
These answers reference current public guidance from CalPrivacy as of July 2026 and may evolve as regulations and technical documentation are updated. Check official resources at privacy.ca.gov periodically.
What does DROP stand for?
DROP stands for Delete Request and Opt-out Platform. It is California’s online portal that allows residents to submit a single deletion and sale/sharing opt-out request to all registered data brokers, as required by the California Delete Act (SB 362).
When must data brokers begin processing DROP requests?
Data brokers covered by the Delete Act must begin accessing DROP and processing applicable deletion and opt-out requests no later than August 1, 2026. Data brokers must delete personal data within 90 days of requests, and they must complete processing and status reporting for each request within 45 calendar days of downloading the relevant lists.
How frequently must data brokers access DROP?
Under CalPrivacy guidance, data brokers must access DROP and process requests at least once every 45 calendar days. This means downloading new or updated deletion lists, performing matching and required actions, and submitting status updates within each processing cycle.
Does a consumer have to submit a new request every 45 days?
No. Consumers do not need to resubmit requests. A single DROP deletion and opt-out request remains in effect. Data brokers are responsible for maintaining minimal identifiers such as hashed email or other identifiers on suppression lists to ensure that future data about that consumer is not sold or shared.
Can DROP be handled manually, and how can UnsubCentral help?
Smaller data brokers may initially handle DROP manually by logging into the platform, downloading lists, and processing them with internal tools. However, manual approaches become difficult to scale, coordinate across systems, and audit as request volumes grow and 45-day cycles repeat. UnsubCentral can help by centralizing identifier management, automating suppression screening, coordinating downstream services with contractors, and maintaining the auditable compliance records that state privacy laws increasingly demand.
DROP is not a one-time project. It is a recurring operational obligation under California law that compounds with every new consumer request and every new data acquisition. Organizations that comply only reactively will face escalating risk as volumes grow and the first round of mandatory audits approaches in January 2028.
Contact UnsubCentral to discuss how to build a repeatable, auditable DROP compliance workflow and ongoing privacy suppression management before the August 1, 2026 deadline.