California's Delete Act: New Rules for Data Brokers and Compliance Deadlines
Source news: "California's Delete Act forces brokers to erase personal data starting August 1" (ABC7 Bay Area) · Search original The following is original commentary written by AI based on facts verified from 3 real news reports (not a translation or copy of the original). See sources at the end.
California’s newly enacted Delete Act imposes stringent transparency and compliance mandates on data brokers, creating immediate operational challenges for legal teams navigating the state’s expanding privacy enforcement landscape. With the California Privacy Protection Agency and the Attorney General wielding unlimited penalty authority, organizations must urgently align their data handling practices with the new DROP platform requirements to avoid cumulative fines. This regulatory shift underscores the critical need for robust internal governance structures as the January 2026 effective date approaches.
Why Now: The Regulatory Shift for Data Brokers
The regulatory landscape for data brokers in California has shifted significantly with the recent approval of implementing regulations by the California Privacy Protection Agency (CalPrivacy). These rules, which are set to take effect on January 1, 2026, operationalize the Delete Act, legislation originally introduced by Senator Josh Becker and passed in 2023. This approval marks a critical transition from legislative intent to enforceable compliance, establishing a structured framework that requires data brokers to actively manage and erase personal information upon consumer request.
The new regulations are designed to streamline the opt-out process for California residents while imposing strict operational timelines on data brokers. Starting August 1, 2026, brokers will be required to log into the state’s Data Broker Registry and Opt-out Platform (DROP) at least every 45 days to process deletion requests. This bi-monthly check-in mandate ensures that brokers remain responsive to consumer demands, with a requirement to report the status of these requests back through DROP within 45 days of receiving them. This systematic approach aims to close previous gaps where consumers had to navigate complex, broker-specific opt-out procedures individually.
Core Issue: The DROP Platform and Erasure Mandates
Central to the implementation of the Delete Act is the Data Broker Registry and Opt-out Platform (DROP), a unified system operated by the California government to streamline consumer privacy rights. Designed to eliminate the burden of navigating disparate broker systems, DROP allows California residents to submit requests to erase their personal information from multiple data brokers simultaneously. This single-point opt-out mechanism, which becomes fully operational for consumer use in January 2026, represents a significant shift in how personal data is managed, ensuring that individuals do not have to contact each broker individually to exercise their right to deletion.
For data brokers, the platform introduces strict operational timelines and reporting obligations that begin on August 1, 2026. Brokers are required to access DROP at least every 45 days to process consumer deletion requests, a frequency designed to ensure timely compliance. Once a deletion request is received, brokers must not only execute the erasure but also report the status of that request back through the DROP system within 45 days. This mandatory feedback loop ensures that the state and the consumer can verify that the data has been properly removed, creating a transparent audit trail for compliance.
The regulatory reach of DROP and the Delete Act extends beyond entities physically located in California. The law explicitly requires data brokers that do not register in the state to comply if they meet the statutory definitions, effectively imposing extraterritorial obligations on global data handlers. To maintain this oversight, brokers must register annually with California, disclose the types of information they collect and share, and submit to audits. Violations are subject to enforcement by both the California Attorney General and the California Privacy Protection Agency, with no statutory cap on fines; penalties can accumulate based on the duration of non-compliance and the number of affected residents, creating substantial financial risk for those who fail to integrate with the DROP infrastructure.
- Unified Consumer Access: DROP serves as a single portal for California residents to request the deletion of their personal data from multiple brokers simultaneously, starting in January 2026.
- Mandatory Check-in Schedule: Data brokers must log into DROP at least every 45 days to process pending deletion requests, ensuring regular engagement with the compliance system.
- Reporting Timeline: After receiving a deletion request, brokers have 45 days to process the erasure and report the status back through the platform.
- Extraterritorial Scope: The act applies to data brokers regardless of their physical location, provided they meet the law's definitions, requiring annual registration and audit participation.
Practical Impact: Operational Obligations for Brokers
Data brokers face a rigorous operational framework under the newly approved regulations, which take effect on January 1, 2026. The core of this compliance burden is the requirement to interact with the state-run Data Broker Registry and Opt-out Platform (DROP). Starting August 1, 2026, brokers must log into DROP at least every 45 days to check for and process consumer deletion requests. This regular check-in mandate ensures that brokers cannot ignore incoming requests and must maintain an active, responsive interface with the state’s central hub for privacy management.
Beyond the periodic check-ins, brokers are required to report the status of their processing back to DROP within 45 days of receiving a deletion request. This timeline creates a strict window for internal verification and data removal, after which the outcome must be communicated to the platform. Furthermore, the law imposes ongoing administrative duties, including annual registration with California. Brokers must disclose the types of information they collect and share, and they must be prepared to submit to audits, ensuring that their internal data practices remain transparent and compliant with state standards.
The enforcement scope is broad, applying even to data brokers that do not have a physical presence in California but process the data of state residents. Violations are monitored by both the California Attorney General and the CalPrivacy, with penalties that are not capped. This means fines can accumulate based on the duration of the violation and the number of affected residents, creating significant financial risk for non-compliance.
- Mandatory Platform Access: Brokers must access the DROP platform at least every 45 days starting August 1, 2026, to process deletion requests.
- Reporting Timeline: A 45-day window is required to process requests and report the status back to DROP after receiving a consumer request.
- Annual Registration: Brokers must register annually, reporting data types collected/shared and remaining subject to state audits.
- Extraterritorial Reach: The law applies to out-of-state brokers handling California residents' data, with uncapped, cumulative penalties for violations.
What to Check: Enforcement and Penalties
The California Attorney General and the California Privacy Protection Agency (CalPrivacy) hold concurrent authority to enforce the Delete Act, ensuring that both state and specialized regulatory bodies can monitor compliance. This dual-enforcement structure means data brokers must navigate oversight from both general civil rights protections and specific privacy regulations. The Act explicitly grants these agencies the power to investigate violations and take legal action against non-compliant entities, including those operating outside California but targeting its residents. This broad jurisdictional reach ensures that the law’s reach extends beyond state borders, compelling global data brokers to adhere to California’s stringent erasure mandates.
A critical feature of the enforcement framework is the absence of statutory caps on civil penalties. Unlike some other privacy laws that impose fixed maximum fines per violation, the Delete Act allows penalties to accumulate based on the duration of the violation and the number of affected residents. This cumulative fine structure creates significant financial exposure for non-compliant brokers, as penalties can grow substantially over time if failures to delete data or report status are not promptly corrected. The lack of a penalty ceiling serves as a strong deterrent, emphasizing the state’s commitment to rigorous enforcement and immediate compliance with consumer deletion requests.
- Dual Enforcement Authority: Both the California Attorney General and CalPrivacy can investigate and penalize violations, providing multiple avenues for regulatory oversight.
- No Penalty Caps: Civil fines are not limited by a maximum amount, allowing penalties to accumulate based on the severity and duration of non-compliance.
- Cumulative Fines: Penalties scale with the number of affected residents and the length of time the violation persists, increasing financial risk for prolonged non-compliance.
- Broad Jurisdiction: The law applies to data brokers regardless of their physical location, as long as they collect or share data from California residents.
Key Takeaways for Corporate Counsel
The Delete Act’s extraterritorial reach demands that legal teams scrutinize their entire supply chain, not just domestic vendors. Because the law explicitly applies to data brokers regardless of whether they are registered in California, corporate counsel must verify that all third-party partners handling California resident data are aware of and compliant with these new federal-style obligations. This is particularly critical for companies relying on international or out-of-state data aggregators, as the state’s enforcement authorities—the Attorney General and the CalPrivacy Protection Agency—retain full jurisdiction to pursue violations. Ignorance of the broker’s physical location is no longer a viable defense; the law’s scope is tied to the data subjects, not the data processors’ headquarters.
Immediate action is required to ensure contractual alignment with the operational mandates outlined in the new regulations. Companies must confirm that their data broker partners have integrated with the DROP platform and are capable of processing erasure requests within the strict 45-day window. Legal agreements should be updated to include specific warranties regarding compliance with the DROP reporting requirements and the mandatory quarterly logins. Furthermore, counsel should audit existing vendor contracts to ensure they reflect the lack of a statutory cap on penalties, which can accumulate based on the duration of non-compliance and the number of affected residents. Proactive verification of these technical and contractual safeguards is essential to mitigate the risk of significant, uncapped fines and regulatory scrutiny.
- Extraterritorial Liability: The law applies to data brokers outside California, requiring legal teams to vet all global partners handling resident data.
- Platform Integration: Vendors must be technically capable of accessing DROP and reporting status within 45 days of a request.
- Contractual Updates: Agreements must explicitly address compliance with DROP mandates and acknowledge the absence of penalty caps.
- Annual Registration: Ensure all brokers are aware of the requirement to register annually and submit to audits, regardless of their state of incorporation.
Frequently Asked Questions
When do the new regulations under California's Delete Act take effect?
The regulations approved by the California Privacy Protection Agency (CalPrivacy) officially take effect on January 1, 2026. This marks the start of the compliance timeline for data brokers operating within the state.
How can California residents request the deletion of their personal data from brokers?
Residents can use the DROP (Data Broker Registry and Opt-out Platform), a single platform operated by the state government. Starting in January 2026, this tool allows users to submit deletion requests to multiple data brokers simultaneously.
What are the specific deadlines for data brokers to process and report deletion requests?
Data brokers must access DROP at least every 45 days starting August 1, 2026, to handle consumer requests. They are required to report the status of these deletions through the platform within 45 days of receiving a request.
Sources
Adopt AI in legal work, carefully
MeshLaw is an AI case-management tool for lawyers. No hallucinations, fully verifiable.
Explore MeshLaw →