AIO APEX

California's Delete Act takes effect, forcing data brokers to honor one-click deletion

California Privacy Protection Agency
Share:
California's Delete Act takes effect, forcing data brokers to honor one-click deletion

As of August 1, 2026, California's Delete Act (SB 362) reaches its most consequential milestone: data brokers operating in the state are now legally required to begin honoring deletion requests submitted through DROP, the Delete Request and Opt-out Platform run by the California Privacy Protection Agency (CPPA). It is the first time anywhere in the United States that consumers can erase their personal data from hundreds of data brokers with a single request instead of chasing each company individually.

The mechanism is what makes the law significant. Since January 1, 2026, Californians have been able to submit a one-time deletion request through DROP. As of today, the obligation flips to the industry: every data broker registered with the CPPA must access the platform at least once every 45 days, retrieve the list of consumers who have asked to be deleted, and remove their personal information — then instruct their own service providers and contractors to do the same. A request that reaches DROP now propagates to all registered brokers at once.

This matters because the data broker industry has operated for decades in near-total obscurity, quietly assembling detailed profiles — location history, purchase behavior, health inferences, political leanings — on people who never knowingly handed over that information. Under the older California Consumer Privacy Act (CCPA), a resident could demand deletion, but only by contacting each broker one at a time, an impractical task given that hundreds of brokers are registered in the state. The Delete Act's scope is also broader than the CCPA: it requires brokers to delete all personal information tied to a consumer, not just the data they collected directly.

The compliance rules have teeth. If a broker cannot verify a deletion request, it must still treat it as an opt-out of the sale or sharing of that person's data. Brokers are barred from selling or sharing newly acquired information about anyone who has filed a request. Non-compliance carries a penalty of $200 per deletion request for each day the broker fails to act, plus $200 per day for failing to register with the CPPA — figures that scale quickly across thousands of requests. Beginning in 2028, brokers will also face mandatory independent audits every three years.

For the broader privacy landscape, the Delete Act is a test case for centralized, government-run deletion infrastructure. Rather than relying on each company to build its own opt-out flow — the fragmented model that has defined U.S. privacy practice — California has built a single state-operated clearinghouse and forced the industry to plug into it. If DROP works as intended, it becomes a template other states and privacy regulators will study closely. The open questions are enforcement bandwidth at the CPPA and how completely brokers actually purge data they have spent years monetizing. What is no longer in question is that, in California at least, deleting yourself from the data broker economy is finally a single click rather than a full-time job.

Originally reported by California Privacy Protection Agency. Read the original article for additional details.

View original source
Share: