Pull to refresh
Logo
California's one-stop data-deletion system starts enforcing against brokers

California's one-stop data-deletion system starts enforcing against brokers

Rule Changes

A single request through the state's DROP platform now orders 600-plus registered data brokers to erase a person's data every 45 days

August 7th, 2026: Board meeting shows partial first-week compliance

Overview

Updated Aug 11

California's data-broker deletion mandate hit its first bump. At the state privacy agency's August 7 board meeting, only 30% of the 600-plus registered brokers had processed a single request in DROP's first week of enforcement.

Consumers keep signing up. Total requests through the Delete Request and Opt-Out Platform reached 450,000, up from roughly 300,000 before the August 1 deadline. The board also raised the 2027 broker registration fee to $9,500, a $3,500 jump, and moved forward with rules requiring independent audits of broker deletion practices starting in 2028.

Why it matters

One form now orders 600-plus companies to erase your personal data, and California can fine each one $200 a day for ignoring it.

Questions about this story

Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.

No questions yet — be the first to ask.

Key Indicators

450,000+
Deletion requests submitted
Total requests through DROP as of the CPPA's August 7 board meeting, up from over 300,000 before enforcement began.
30%
Brokers processing requests, week one
Share of registered data brokers the CPPA found actively processing DROP requests in enforcement's first week.
$200
Fine per request, per day
Penalty for each consumer a broker fails to delete, accruing daily.
45 days
Deletion and re-check cycle
Brokers must check DROP and complete deletions on this recurring schedule.
$9,500
2027 broker registration fee
Annual registration and access fee for data brokers, up $3,500 from 2026, approved to cover verification and audit costs.

Voices

Curated perspectives — historical figures and your fellow readers.

Ever wondered what historical figures would say about today's headlines?

Sign up to generate historical perspectives on this story.

People Involved

Organizations Involved

Timeline

October 2023 August 2026

7 events Latest: August 7th, 2026 · 1 month ago
Tap a bar to jump to that date
  1. Board meeting shows partial first-week compliance

    Latest Regulatory

    The CPPA reported only 30% of registered brokers had processed DROP requests in enforcement's first week, with 450,000 requests submitted total. The board also raised the 2027 broker fee to $9,500 and advanced audit rules for 2028.

  2. DROP opens to consumers

    Milestone

    Californians can submit a single deletion request that reaches every registered broker. More than 300,000 sign up in the following months.

  3. Agency warns brokers against hiding

    Regulatory

    An enforcement advisory targets undisclosed trade names, unlisted websites, and reliance on parent-company registrations to obscure broker identities.

  4. First broker registration deadline

    Regulatory

    Data brokers must register annually with the state. The agency later fines several firms for failing to do so on time.

Scenarios

1

Agency fines a broker for failing to delete

Likely Resolves by Aug 1, 2027

Discussed by: Alston & Bird, Troutman privacy analysts, AdExchanger

With hundreds of thousands of requests queued and per-day penalties running, the agency brings its first case against a broker that ignored deletions rather than just failing to register. The strike force's earlier registration fines show it will act. A public decision or settlement citing deletion failures would confirm the mechanism has teeth.

2

Industry sues to block or narrow DROP

Possible Resolves by Feb 1, 2027

Discussed by: Privacy defense firms Clark Hill and Hudson Cook; data-broker trade groups

A broker or trade association challenges the deletion mandate in court, arguing it is overbroad, unconstitutional, or technically unworkable, and seeks to pause enforcement. Similar business challenges have followed other California privacy rules. A filed lawsuit naming the CPPA or the Delete Act would trigger this.

3

Another state copies the one-stop model

Possible Resolves by End of 2027

Discussed by: IAPP, state privacy legislators tracking California's lead

California's platform is the first of its kind, and other states have historically followed its privacy moves. A legislature passes a law directing its own centralized data-broker deletion tool, modeled on DROP. Passage into law, not just a bill introduction, marks this as real.

4

Congress creates a national deletion mechanism

Unlikely Resolves by Jan 1, 2028

Discussed by: Federal privacy advocates; Senator Josh Becker

A federal data-broker deletion right, echoing DROP, becomes law and gives every American one place to opt out. Federal privacy bills have repeatedly stalled in Congress for years. This would require a signed statute, not a hearing or a draft.

Historical Context

3 moments from history that rhyme with this story — and how they unfolded.

June 2003

National Do Not Call Registry opens (2003)

The Federal Trade Commission opened a single registry where people could block most telemarketing calls with one signup. By late October 2003 it held 53.7 million phone numbers. Telemarketers had to scrub their lists against it regularly or face fines of up to $11,000 per call.

Then

Tens of millions registered within months, and telemarketers challenged the registry in court before it survived and took effect.

Now

The registry became a lasting model for one-stop, government-run opt-out systems that put the burden on companies to check a central list.

Why this matters now

DROP applies the same design to data deletion: one government list, and companies must check it on a fixed schedule or pay per violation.

May 2018

Vermont's first data-broker registry (2018)

Vermont became the first US state to require data brokers to register and disclose basic information about their practices. The law made the industry visible for the first time. It did not, though, give residents a way to force brokers to delete their data.

Then

Hundreds of brokers registered, revealing an industry that had operated largely in the dark.

Now

Registration spread to California and other states, but registries alone left consumers without a deletion tool.

Why this matters now

DROP is the next step Vermont's law lacked: not just knowing who holds your data, but a working switch to make them erase it.

January 2020

California Consumer Privacy Act takes effect (2020)

California's landmark privacy law gave residents the right to see, delete, and stop the sale of their personal data. Enforcement began in July 2020. The catch: people had to exercise those rights company by company, one request at a time.

Then

Businesses added privacy request forms, but few consumers filed the many separate requests needed to cover the data-broker ecosystem.

Now

The law set the rights but exposed a gap in scale, which the Delete Act and DROP were written to close.

Why this matters now

DROP turns the CCPA's per-company deletion right into a single request that reaches every registered broker at once.

Sources

(11)