Starting today, every business registered as a data broker in California has a new, recurring legal obligation: log into the state's Delete Request and Opt-out Platform, known as DROP, and act on whatever consumer deletion requests are waiting there. Miss it, and the penalty is not a flat fine. It is $200 per deletion request, per day, for every day the request goes unprocessed.
That per-request, per-day structure is what makes today's deadline worth paying attention to even if your business has never heard of DROP before. A backlog of a few hundred unprocessed requests left sitting for a couple of weeks can turn into a six-figure exposure fast, and the obligation does not end today, it repeats every 45 days for as long as a business stays registered as a data broker.

Source: California Privacy Protection Agency, DROP data broker guidance, captured August 1, 2026.
What DROP actually is
DROP is the California Privacy Protection Agency's centralized deletion mechanism, built under the Delete Act (SB 362). Instead of a consumer emailing every data broker individually to ask for their information to be deleted, DROP lets a consumer submit one request that reaches every data broker registered with the CPPA at once. You can see the platform and the CPPA's own data broker guidance at cppa.ca.gov/data_brokers.
The mechanics that matter for a registered broker are straightforward on paper and easy to get wrong in practice. Registered data brokers must access DROP and process the accumulated deletion requests through it starting today, August 1, 2026. From here forward, brokers are required to check the platform and process new requests at least once every 45 days, on an ongoing basis, not as a one-time task to check off.
Who counts as a registered data broker
California's definition is broader than the phrase "data broker" tends to suggest. Under the Delete Act, a data broker is any business that knowingly collects and sells the personal information of a consumer with whom it has no direct relationship. That last clause is the one that catches people off guard: it is not about being a household-name data broker, it is about selling personal information you gathered about someone who never interacted with your business directly.
Businesses that meet that definition were already required to register annually with the CPPA and pay a registration fee before today's deadline existed. Failing to register in the first place carries its own daily penalty structure, separate from the deletion-processing penalty this deadline introduces. If your business buys, sells, licenses, or otherwise trades in personal information about people who are not your customers, users, or subscribers, it is worth checking your registration status against the CPPA's public data broker registry rather than assuming the rule does not apply.
The $200/day penalty, in plain terms
Figure: Cumulative exposure on a single unprocessed deletion request over one 45-day DROP recheck cycle, at $200 per request, per day.
The California Privacy Protection Agency and the state attorney general can pursue penalties of $200 for each deletion request a registered broker fails to process, and that amount accrues for every day the request remains unprocessed, not a one-time charge per request. A broker that lets 50 requests sit unprocessed for 10 days is not looking at a single penalty, it is looking at a number that compounds by both request count and elapsed time.
The 45-day recheck requirement is the mechanism that is supposed to prevent that kind of backlog from forming in the first place. A broker that logs into DROP on a fixed schedule, at minimum every 45 days, and processes what is waiting there, stays inside the compliance window the penalty structure is built around. A broker that treats DROP as a one-time task for today and does not return to it is the exact failure pattern the $200/day penalty is designed to catch.
What this means for your privacy policy
The Delete Act and DROP are aimed at data brokers specifically, but the deletion-rights disclosure obligations they sit alongside apply much more broadly under the CCPA. Any business subject to the CCPA, broker or not, is expected to tell consumers in its privacy policy that they have a right to request deletion of their personal information, how to submit that request, and how the business will verify and respond to it. A privacy policy that is silent on deletion rights, or that describes a process that no longer matches how requests actually reach the business, is a gap a regulator or a consumer's attorney does not have to look hard to find.
If your business sells or shares personal information about people you do not have a direct relationship with, your policy also needs to reflect whether you are registered as a data broker and how consumers can exercise their rights through DROP, in addition to whatever direct request channel you already offer. Our Privacy Policy Generator builds CCPA-aligned deletion-rights language into your policy, so the disclosures on your site match the process consumers are actually entitled to use, whether that request reaches you directly or through California's centralized platform.
The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.