Pull to refresh
Logo
California's one-stop data-deletion system starts enforcing against brokers

California's one-stop data-deletion system starts enforcing against brokers

Rule Changes

A single request through the state's DROP platform orders 654 registered data brokers to erase a person's data, and the agency has issued its first fines

September 10th, 2026: CalPrivacy expects few brokers to miss first-cycle deadline

Overview

Updated 15 hours ago

California's one-stop data-deletion platform, the Delete Request and Opt-Out Platform (DROP), closed its first 45-day enforcement cycle on September 15. The agency has already fined two firms that ignored the law: LocateSmarter $116,490 and Cybba $52,400.

More than 530,000 Californians have filed deletion requests, and the average person has seen over 75 deletions so far. The legislature passed AB-883 to shorten the cycle from 45 days to 30, starting July 1, 2027, if the governor signs it. Full compliance reports from the first cycle arrive in late October.

Why it matters

One form orders 654 data brokers to erase your data, and California is already fining firms that dodge the law.

Questions about this story

Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.

No questions yet — be the first to ask.

Key Indicators

530,000+
Consumers registered in DROP
Californians who have filed deletion requests, with 99.9% matched to at least one data broker, as of mid-September.
75+
Average deletions per consumer
Average number of deletions each registered Californian has seen so far, per CalPrivacy's executive director.
654
Registered data brokers
Data brokers in the registry, up from roughly 600 when enforcement began.
$200
Fine per request, per day
Penalty for each consumer a broker fails to delete, accruing daily.
45 days
Deletion and re-check cycle
Brokers must check DROP and complete deletions on this recurring schedule. AB-883 would cut it to 30 days from July 1, 2027.

Voices

Curated perspectives — historical figures and your fellow readers.

Ever wondered what historical figures would say about today's headlines?

Sign up to generate historical perspectives on this story.

People Involved

Organizations Involved

Timeline

October 2023 September 2026

10 events Latest: September 10th, 2026 · 3 weeks ago
Tap a bar to jump to that date
  1. CalPrivacy expects few brokers to miss first-cycle deadline

    Latest Regulatory

    CalPrivacy said the first 45-day deletion window closes September 15 and it expects few of the 654 registered brokers to miss it. Consumer registrations hit 530,000, with an average of 75 deletions per person, and the legislature passed AB-883 to shorten the cycle to 30 days from July 1, 2027.

  2. Board meeting shows partial first-week compliance

    Regulatory

    The CPPA reported only 30% of registered brokers had processed DROP requests in enforcement's first week, with 450,000 requests submitted total. The board also raised the 2027 broker fee to $9,500 and advanced audit rules for 2028.

  3. DROP opens to consumers

    Milestone

    Californians can submit a single deletion request that reaches every registered broker. More than 300,000 sign up in the following months.

  4. Agency warns brokers against hiding

    Regulatory

    An enforcement advisory targets undisclosed trade names, unlisted websites, and reliance on parent-company registrations to obscure broker identities.

  5. First broker registration deadline

    Regulatory

    Data brokers must register annually with the state. The agency later fines several firms for failing to do so on time.

Scenarios

1

Agency fines a broker for failing to delete

Likely Resolves by Aug 1, 2027

Discussed by: Alston & Bird, Troutman privacy analysts, AdExchanger

With hundreds of thousands of requests queued and per-day penalties running, the agency brings its first case against a broker that ignored deletions rather than just failing to register. The strike force's earlier registration fines show it will act. A public decision or settlement citing deletion failures would confirm the mechanism has teeth.

2

Industry sues to block or narrow DROP

Possible Resolves by Feb 1, 2027

Discussed by: Privacy defense firms Clark Hill and Hudson Cook; data-broker trade groups

A broker or trade association challenges the deletion mandate in court, arguing it is overbroad, unconstitutional, or technically unworkable, and seeks to pause enforcement. Similar business challenges have followed other California privacy rules. A filed lawsuit naming the CPPA or the Delete Act would trigger this.

3

Another state copies the one-stop model

Possible Resolves by End of 2027

Discussed by: IAPP, state privacy legislators tracking California's lead

California's platform is the first of its kind, and other states have historically followed its privacy moves. A legislature passes a law directing its own centralized data-broker deletion tool, modeled on DROP. Passage into law, not just a bill introduction, marks this as real.

4

Congress creates a national deletion mechanism

Unlikely Resolves by Jan 1, 2028

Discussed by: Federal privacy advocates; Senator Josh Becker

A federal data-broker deletion right, echoing DROP, becomes law and gives every American one place to opt out. Federal privacy bills have repeatedly stalled in Congress for years. This would require a signed statute, not a hearing or a draft.

5

Governor Signs AB-883, Shortening Deletion Cycle to 30 Days

Likely Resolves by End of 2026

Discussed by: CalPrivacy, which supported the bill

AB-883, passed by the legislature in August, would cut the DROP deletion cycle from 45 to 30 days starting July 1, 2027. CalPrivacy backed the measure. The governor's signature makes it law.

Historical Context

3 moments from history that rhyme with this story — and how they unfolded.

June 2003

National Do Not Call Registry opens (2003)

The Federal Trade Commission opened a single registry where people could block most telemarketing calls with one signup. By late October 2003 it held 53.7 million phone numbers. Telemarketers had to scrub their lists against it regularly or face fines of up to $11,000 per call.

Then

Tens of millions registered within months, and telemarketers challenged the registry in court before it survived and took effect.

Now

The registry became a lasting model for one-stop, government-run opt-out systems that put the burden on companies to check a central list.

Why this matters now

DROP applies the same design to data deletion: one government list, and companies must check it on a fixed schedule or pay per violation.

May 2018

Vermont's first data-broker registry (2018)

Vermont became the first US state to require data brokers to register and disclose basic information about their practices. The law made the industry visible for the first time. It did not, though, give residents a way to force brokers to delete their data.

Then

Hundreds of brokers registered, revealing an industry that had operated largely in the dark.

Now

Registration spread to California and other states, but registries alone left consumers without a deletion tool.

Why this matters now

DROP is the next step Vermont's law lacked: not just knowing who holds your data, but a working switch to make them erase it.

January 2020

California Consumer Privacy Act takes effect (2020)

California's landmark privacy law gave residents the right to see, delete, and stop the sale of their personal data. Enforcement began in July 2020. The catch: people had to exercise those rights company by company, one request at a time.

Then

Businesses added privacy request forms, but few consumers filed the many separate requests needed to cover the data-broker ecosystem.

Now

The law set the rights but exposed a gap in scale, which the Delete Act and DROP were written to close.

Why this matters now

DROP turns the CCPA's per-company deletion right into a single request that reaches every registered broker at once.

Sources

(16)