Beginning August 1, 2026, registered California data brokers must process consumer deletion requests submitted through the California Privacy Protection Agency's Delete Request and Opt-Out Platform, commonly referred to as DROP. Under the new operational framework, covered businesses are required to check the platform at least once every 45 days and act on the deletion requests they receive. The change represents a significant shift in how consumer privacy rights are exercised in California, moving from a company-by-company request model to a centralized, state-run intake system administered by the CPPA.

DROP is the practical implementation of California's prior data broker legislation, which directed the agency to establish an accessible, one-stop mechanism through which consumers could ask registered data brokers to delete personal information about them. For consumers, DROP is intended to reduce the burden of submitting individual requests to each broker holding their data. For registered brokers, it introduces a new inbound channel that must be monitored, verified, and reconciled against internal data holdings on a recurring cadence.

The immediate compliance question for many companies is threshold rather than technical: do they meet California's definition of a data broker? Businesses that knowingly collect and sell personal information about consumers with whom they lack a direct relationship should evaluate whether registration is required and confirm the accuracy of their current registration status. Companies that assumed they fell outside the definition should revisit that analysis in light of how their data practices have evolved.

Registered brokers should also stand up DROP-facing workflows without delay. That includes assigning ownership for platform monitoring at least every 45 days, integrating DROP-sourced requests into existing consumer rights intake and identity verification processes, coordinating deletion across internal systems and downstream recipients where applicable, and documenting the response to each request. Given the CPPA's enforcement posture, gaps in these workflows can expose companies to administrative penalties and reputational risk.

Now is the time to confirm registration status, validate intake and deletion processes against the platform's requirements, and update internal policies and vendor arrangements to reflect the new obligations. Legal, privacy, and engineering teams should coordinate closely to ensure the August 1 obligations are met on an ongoing basis.

This alert is provided for general informational purposes and does not constitute legal advice; clients should consult counsel for guidance tailored to their specific circumstances.