Pull to refresh
Logo
California's one-stop data-deletion system starts enforcing against brokers

California's one-stop data-deletion system starts enforcing against brokers

Rule Changes

A single request through the state's DROP platform now orders 600-plus registered data brokers to erase a person's data every 45 days

August 7th, 2026: Board meeting shows partial first-week compliance

Overview

Updated Aug 11

California's data-broker deletion mandate hit its first bump. At the state privacy agency's August 7 board meeting, only 30% of the 600-plus registered brokers had processed a single request in DROP's first week of enforcement.

Consumers keep signing up. Total requests through the Delete Request and Opt-Out Platform reached 450,000, up from roughly 300,000 before the August 1 deadline. The board also raised the 2027 broker registration fee to $9,500, a $3,500 jump, and moved forward with rules requiring independent audits of broker deletion practices starting in 2028.

Why it matters

One form now orders 600-plus companies to erase your personal data, and California can fine each one $200 a day for ignoring it.

Questions about this story

Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.

No questions yet — be the first to ask.

Key Indicators

450,000+
Deletion requests submitted
Total requests through DROP as of the CPPA's August 7 board meeting, up from over 300,000 before enforcement began.
30%
Brokers processing requests, week one
Share of registered data brokers the CPPA found actively processing DROP requests in enforcement's first week.
$200
Fine per request, per day
Penalty for each consumer a broker fails to delete, accruing daily.
45 days
Deletion and re-check cycle
Brokers must check DROP and complete deletions on this recurring schedule.
$9,500
2027 broker registration fee
Annual registration and access fee for data brokers, up $3,500 from 2026, approved to cover verification and audit costs.

Voices

Curated perspectives — historical figures and your fellow readers.

Ever wondered what historical figures would say about today's headlines?

Sign up to generate historical perspectives on this story.

Play

Exploring all sides of a story is often best achieved with Play.

Most of these play right now — no account needed. Sign up to save scores, keep a streak, and unlock Debate and Predict. Log in Sign Up
Predict 4 ways this could play out. Back the one you believe — contrarian picks score more when a scenario has a resolution date. Log in to play

People Involved

Organizations Involved

Timeline

October 2023 August 2026

7 events Latest: August 7th, 2026 · 1 month ago
Tap a bar to jump to that date
  1. Board meeting shows partial first-week compliance

    Latest Regulatory

    The CPPA reported only 30% of registered brokers had processed DROP requests in enforcement's first week, with 450,000 requests submitted total. The board also raised the 2027 broker fee to $9,500 and advanced audit rules for 2028.

  2. DROP opens to consumers

    Milestone

    Californians can submit a single deletion request that reaches every registered broker. More than 300,000 sign up in the following months.

  3. Agency warns brokers against hiding

    Regulatory

    An enforcement advisory targets undisclosed trade names, unlisted websites, and reliance on parent-company registrations to obscure broker identities.

  4. First broker registration deadline

    Regulatory

    Data brokers must register annually with the state. The agency later fines several firms for failing to do so on time.

Historical Context

3 moments from history that rhyme with this story — and how they unfolded.

June 2003

National Do Not Call Registry opens (2003)

The Federal Trade Commission opened a single registry where people could block most telemarketing calls with one signup. By late October 2003 it held 53.7 million phone numbers. Telemarketers had to scrub their lists against it regularly or face fines of up to $11,000 per call.

Then

Tens of millions registered within months, and telemarketers challenged the registry in court before it survived and took effect.

Now

The registry became a lasting model for one-stop, government-run opt-out systems that put the burden on companies to check a central list.

Why this matters now

DROP applies the same design to data deletion: one government list, and companies must check it on a fixed schedule or pay per violation.

May 2018

Vermont's first data-broker registry (2018)

Vermont became the first US state to require data brokers to register and disclose basic information about their practices. The law made the industry visible for the first time. It did not, though, give residents a way to force brokers to delete their data.

Then

Hundreds of brokers registered, revealing an industry that had operated largely in the dark.

Now

Registration spread to California and other states, but registries alone left consumers without a deletion tool.

Why this matters now

DROP is the next step Vermont's law lacked: not just knowing who holds your data, but a working switch to make them erase it.

January 2020

California Consumer Privacy Act takes effect (2020)

California's landmark privacy law gave residents the right to see, delete, and stop the sale of their personal data. Enforcement began in July 2020. The catch: people had to exercise those rights company by company, one request at a time.

Then

Businesses added privacy request forms, but few consumers filed the many separate requests needed to cover the data-broker ecosystem.

Now

The law set the rights but exposed a gap in scale, which the Delete Act and DROP were written to close.

Why this matters now

DROP turns the CCPA's per-company deletion right into a single request that reaches every registered broker at once.

Sources

(11)