California's data broker deletion platform just got teeth, and most brokers aren't ready

California's Delete Request and Opt-Out Platform, known as DROP, went live in January 2026 as a single portal where a consumer can request their personal data be deleted from every registered data broker in the state at once. It sounded, on paper, like a convenience feature. As of August 1, 2026, it became something closer to a legal minefield for the data broker industry: registered brokers are now required to process DROP deletion requests, and failing to do so triggers a $200-per-request, per-day penalty that accrues for every request mishandled or ignored.
How DROP actually works
The mechanics matter because they explain why compliance is harder than it sounds. A consumer authenticates through an identity gateway or Login.gov and submits one deletion request. Data brokers do not receive that request in real time — they are required to poll and retrieve pending requests at least every 45 days using standardized consumer identifiers, then complete processing within 90 days of retrieval. The California Privacy Protection Agency (CalPrivacy) provides an API and sandbox environment for brokers to integrate DROP retrieval into their existing data pipelines, alongside suppression list requirements to prevent previously deleted records from being re-added through new data acquisition.
That 45-day polling requirement is the part catching brokers off guard. It assumes deletion is a routine, automatable pipeline operation. For brokers whose backend was never built around individual-level deletion — many data broker businesses are architected around bulk acquisition and resale, not granular per-record removal — retrofitting that capability under legal deadline pressure is a real engineering project, not a policy checkbox.
The penalty structure was designed to bite
Registration failures alone have carried a $200-per-day penalty since 2024, plus CalPrivacy's investigative costs. The new deletion-processing penalty stacks on top of that, and because it applies per request per day, the exposure scales directly with how many California consumers submit DROP requests and how slowly a broker processes them. For a data broker holding records on millions of Californians, a slow rollout of deletion infrastructure is not a minor compliance gap — it is a liability that compounds daily and publicly, since CalPrivacy enforcement actions are a matter of public record.
This isn't just California anymore
California is the most mature implementation, but it is not alone. Texas and Oregon have both added data broker registration requirements at the state level, alongside Vermont, which was earlier to the space. Global Privacy Control — a browser-level opt-out signal — is now legally required to be honored in California and carries similar weight in Colorado, Connecticut, Montana, and Oregon's own comprehensive privacy statutes. For any company operating a data broker business — or any company that occasionally sells or shares consumer data in ways that meet a state's broker definition, which is broader than most businesses assume — this is no longer a single-state compliance problem. It is a multi-state patchwork that is only going to add jurisdictions.
A compliance industry is forming around the gap
Whenever a regulatory deadline creates real financial exposure and real engineering complexity, a market for closing that gap follows. Privacy compliance vendors are building DROP-integration tooling specifically for the 45-day polling cycle and the suppression-list maintenance requirement, positioning themselves as the layer between a broker's legacy data pipeline and CalPrivacy's API. That is a predictable pattern — SOC 2 auditors, GDPR consultants, and CCPA compliance platforms all emerged the same way after their respective deadlines created liability that internal teams weren't staffed to handle alone.
What this means if data privacy touches your business
If you operate anything that could meet California's, Texas's, Oregon's, or Vermont's definition of a data broker — and the definitions are broader than "we sell consumer data as our core business," often including any regular sale or licensing of personal information collected about people you don't have a direct relationship with — audit your registration status now, not after an enforcement letter. If you are already registered, verify your DROP retrieval pipeline is actually polling on a sub-45-day cadence and that deletion completion is logged and auditable; manual, email-based deletion handling will not survive scrutiny once the daily penalty clock is running. And if you are a consumer wanting your own data removed, DROP is genuinely useful precisely because of this enforcement pressure — submit one request through CalPrivacy's platform rather than chasing individual opt-outs across dozens of brokers, and expect it to actually get processed now that ignoring it costs brokers real money.