California's DROP Deadline Is Live. Data Brokers Face a 45-Day Clock.
California just turned its Delete Act from a policy story into an operations story.
According to the state privacy agency, DROP for data brokers now requires brokers to access the system and process deletion requests beginning August 1, 2026. The agency says brokers must begin processing DROP requests at least once every 45 days, and the penalty section says failure to register or process requests can trigger fines.
That sounds abstract until you look at the definition. California says a data broker is a business that knowingly collects and sells consumer personal information to third parties without a direct relationship.
For most small businesses, that is not you.
But if you run lead-gen lists, data enrichment, audience brokerage, identity resolution, or any kind of consumer-data resale, this is not a side note. It is a real compliance calendar item.
The owner takeaway is straightforward:
- confirm whether your business qualifies as a data broker under California law
- check whether you already need a DROP account and registration
- map every vendor or affiliate that handles California consumer data
- set a recurring review window so requests are not missed
Even if you are not a broker, this is still worth paying attention to. If you buy customer lists or outsource list-building, ask the vendor how they handle California deletion requests. A sloppy data chain can become your problem fast.
The state also says the process is not complicated from the consumer side. Californians can submit a single request through DROP, and the system routes it to registered brokers. For businesses, that means the workflow is now standardized enough that "we did not know" is a weak defense.
If your business touches consumer data in California, the question is no longer whether DROP is real.
It is whether your records are ready for it.