California's DROP Is Now Enforceable. Here's What That Means for Your Business.

‍Enforcement of California's Delete Request and Opt-Out Platform (DROP) began August 1. Data brokers now face fines of $200 per request, per day. The first thing to figure out is whether California considers you one.

Enforcement of California's Delete Request and Opt-Out Platform (DROP) began August 1. Data brokers now face fines of $200 per request, per day. The first thing to figure out is whether California considers you one.

When California passed the Delete Act back in 2023, we wrote about it and noted that most CCPA-compliant businesses wouldn't need to worry. The law targeted data brokers, and the definition seemed narrow.

Since then, two developments have made the Delete Act worth another look.

First, the deletion system the law promised is now live and enforceable. DROP (the Delete Request and Opt-Out Platform) opened to California residents on January 1, 2026, and enforcement began August 1. Roughly 350,000 Californians have already signed up.

Second, CalPrivacy (the agency formerly known as the CPPA) issued regulations in January that broadened who counts as a data broker. The definition is wider than it looked in 2023 and wider than most businesses assume. The agency has already fined a dozen companies for failing to register.

Here's where things stand and what to check on your end.

A quick refresher on DROP

Before DROP, a Californian who wanted their data deleted from data brokers had to contact each one individually. There are around 600 registered brokers in the state. Very few people were doing that.

DROP replaces that process with a single request. A resident creates an account, verifies California residency, and submits one deletion request that goes to every registered data broker at once.

For consumers, it's a genuine win. For businesses that meet the data broker definition, it creates an ongoing compliance obligation with real penalties attached.

What changed on August 1

As of August 1, data brokers must retrieve and process those requests. The core obligations:

Retrieve requests every 45 days. Brokers must connect to DROP at least once every 45 days to retrieve new deletion requests. This cycle repeats indefinitely.

Match and delete. For each request, you have to match the consumer against your records using standardized identifiers (name, email, phone, date of birth), then delete all matched personal data. That includes both the underlying records and any inferences derived from them.

Cascade the deletion. The deletion has to flow through to every service provider, contractor, and downstream partner that received the consumer's data. Your CRM, your email platform, your ad systems, your data warehouse.

Report back. Outcomes go back into DROP using standardized status codes, with all determinations completed within 90 days of retrieval.

The penalty for failing to process requests is $200 per request, per day. With 350,000 consumers already enrolled, the potential exposure adds up quickly. A broker sitting on 500 unprocessed requests for a month could face up to $3 million in potential penalties.

The question worth answering first: Are you a data broker?

The legal definition sounds narrow: a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship.

Most ecommerce brands read that and move on. You have direct relationships with your customers, so you're out of scope, right?

Probably. But there are a few things worth knowing before you close the tab.

"Direct relationship" is narrower than you'd expect. Under the new regulations, a direct relationship requires the consumer to intentionally interact with your business. Data collected passively through a pixel or tag on a third-party website the consumer never knew about doesn't establish one. This can include companies that buy data from other sources and resell it, as well as third-party data providers that assumed their downstream contact with consumers counted.

CalPrivacy has made data broker registration a clear enforcement priority since taking over the registry in 2024, even creating a dedicated strike force focused on the issue. Now that DROP is fully operational, businesses that fall within its scope should expect that scrutiny to continue.

Signals you might be in scope

You may have DROP obligations if your business:

  • Sells audience segments or targeting lists to advertising partners
  • Enriches, resells, or licenses consumer profiles
  • Collects or aggregates consumer data from third-party sources
  • Provides intent or contact data to B2B customers
  • Operates tracking technologies on other companies' websites

If any of those describe your business, get legal counsel involved and run a data flow audit before deciding you're in the clear.

If you're not a data broker, what still matters

For most ecommerce brands, the honest answer is that DROP doesn't apply directly. But it's part of a pattern worth paying attention to.

Regulators are raising expectations for how deletion works. Recent enforcement actions make it clear that a deletion request honored in your database but ignored by your ad stack doesn't count. New Jersey's privacy law goes further, requiring deleted consumers to be permanently suppressed from future targeted advertising.

The direction is consistent across states: deletion has to reach every system that stores customer data, and businesses are expected to prove it. If your DSAR workflow runs on spreadsheets and email threads, or your consent tooling and your rights-request tooling don't talk to each other, that gap gets more expensive every legislative session.

What to do now

1. Settle your data broker status. Walk through the signals above with counsel. The 2026 regulations made the definition broader, and CalPrivacy fines businesses that guessed wrong.

2. If you qualify, register. Registration runs $6,000 per year, due by January 31. Late registration costs $200 per day, so if 2026 slipped past you, handle it now.

3. Map where consumer data lives. The cascade requirement means you need visibility into every system and downstream partner holding consumer data. You can't delete what you haven't found. This is worth doing even if DROP doesn't apply to you. Every state deletion right depends on it.

4. Pressure-test your DSAR workflow. Can your workflow handle recurring deletion requests without someone manually chasing them across systems? Does a deletion reach your ad platforms and consent signals, or does it stop at the database? Would your documentation hold up if a regulator asked for proof?

Keeping up is the actual job.

DROP is a good example of how privacy compliance keeps moving after the initial setup. The Delete Act passed in 2023. The DROP system went online in January. Enforcement started this month. Audits begin in 2028. Your business may not have changed at all. The privacy landscape did.

That's exactly where TrueVault fits. We help ecommerce teams understand what changed, decide what requires action, and keep privacy workflows current as laws, vendors, and storefronts evolve. You don't need to become a privacy expert. You just need to know what matters and what to do next.

If you're unsure where DROP leaves you, or your deletion workflows haven't been reviewed in a while, we can help you figure out what matters and what to fix first.

Disclaimer: This content is provided for general informational purposes only and does not constitute legal or other professional advice. Without limiting the foregoing, the content may not reflect recent developments in the law, may not be complete, and may not be accurate or relevant in an applicable jurisdiction. This content is not a substitute for obtaining legal advice from a qualified licensed attorney in the applicable jurisdiction. The content is general in nature and may not pertain to specific circumstances, so it should not be used to act or refrain from acting based on it without first obtaining advice from professional counsel qualified in the applicable subject matter and jurisdictions.

Dive into a world of knowledge, trends, and industry updates on the TrueVault blog.