AIO APEX

California's DROP platform forces 500-plus data brokers to honor deletion requests within 45 days

Share:
California's DROP platform forces 500-plus data brokers to honor deletion requests within 45 days

For the first time, a US consumer can send one request and have it legally propagate to every data broker registered in a state. California's Delete Request and Opt-Out Platform, known as DROP, launched January 1, 2026, and as of August 1 it has real enforcement teeth: registered brokers must check the platform at least every 45 days, process verified deletion requests within that window, and continue deleting any newly collected data about opted-out consumers on the same cycle.

That's a meaningfully different model from the opt-out landscape that existed before it — dozens of separate requests to dozens of separate companies, each with its own process, timeline, and frequent lack of follow-through. Whether DROP actually dents an industry estimated at $200 billion to $300 billion globally is the real question, and the early mechanics reveal both what the platform gets right and where it still falls short.

How DROP actually works

The Delete Act, enacted in California in October 2023, required the state's privacy regulator (CPPA) to build a universal deletion mechanism by January 1, 2026. DROP is that mechanism. A California consumer submits one verified request through the platform, and it directs all currently registered data brokers — more than 500 as of the 2026 rollout — to delete the consumer's personal information and stop selling or sharing it going forward.

The August 1 enforcement milestone is what turns DROP from a nice interface into something with actual teeth. From that date, brokers are required to: access DROP at least once every 45 days, process every verified deletion request within that 45-day window, treat unverified requests as blanket opt-outs from sale or sharing even without full verification, direct their own service providers and contractors to delete the same data, and keep deleting newly collected data about the same consumers going forward rather than treating the deletion as a one-time event.

That last point is the detail most opt-out coverage misses: without a recurring deletion cycle, brokers can simply re-acquire and re-list a consumer's data from a new source a few months later, quietly undoing the original opt-out. DROP's 45-day recurring requirement is a direct response to that failure mode.

Where the gaps still are

DROP is a California mechanism enforcing California registration requirements. Three limitations follow directly from that scope:

  • Only registered brokers are covered. A broker that simply doesn't register with the state isn't reachable through DROP at all — and the state's ability to find and compel unregistered brokers is a separate, harder enforcement problem than processing requests from ones that already comply.
  • It only protects California residents. Consumers in other states have no equivalent single-request mechanism, though several states have passed narrower data broker registration laws that could plausibly build toward something similar.
  • Verification and unverified requests get different treatment. Unverified requests are honored as opt-outs from sale and sharing but not full deletion — a meaningful gap for anyone who doesn't complete the verification step.

Penalties are real but not enormous relative to the industry's size: up to $7,988 per intentional CCPA violation, and $200 per day for each unfulfilled Delete Act request. For a large broker with millions of records, the economics of compliance versus the economics of quiet non-compliance are worth watching over the next year — the deterrent value depends entirely on how aggressively CPPA actually audits and enforces, not just on the statute existing.

What this means if you're not in California

If you live outside California, DROP doesn't apply to you directly, but it's worth tracking as a template. Several other states are watching California's rollout before deciding whether to build their own universal deletion mechanisms, and DROP's 45-day recurring cycle — rather than a one-time deletion — is the design choice other states are most likely to copy if they move forward. Until then, the practical path for non-California residents remains the same fragmented one: individual opt-out requests to individual brokers, ideally automated through a paid opt-out service, with the understanding that without a recurring deletion requirement, the data can and often does come back.

Sources: California Privacy Protection Agency DROP documentation, California Delete Act statutory text, and CCPA enforcement penalty schedules.

Share: