California’s DROP Platform Shifts Data Deletion Burden to Brokers
The state's new centralized system transforms privacy requests into enforceable technical mandates with steep daily fines.
California has launched the Delete Request and Opt-Out Platform (DROP), a centralized system allowing residents to command all registered data brokers to delete their personal information via a single request. The platform went live on January 1, 2026, marking a critical escalation in the state's effort to automate consumer privacy rights.
Under the California Delete Act (SB 362), these deletion requests become legally enforceable on August 1, 2026. Data brokers must retrieve requests from the platform at least every 45 days and finalize their determinations within 90 days of that retrieval. To protect consumer privacy during the matching process, DROP utilizes a hashing exchange—specifically SHA-256, UTF-8 encoded and Base64 encoded—rather than transmitting plaintext data.
A New Compliance Standard
The Delete Act represents a fundamental shift from the California Consumer Privacy Act (CCPA). While previous laws required consumers to identify and contact individual brokers, SB 362 creates a "one-stop shop" that moves the operational burden to the companies. This transition effectively turns privacy compliance from a legal policy exercise into a rigorous technical engineering requirement.
As Sixteen Pillars noted, the act transforms the "delete my data" request from a simple customer-service ticket into a scheduled batch job that companies must build, execute every 45 days, and prove they have completed. This shift forces firms to treat privacy not as a series of isolated requests, but as a core architectural component of their data pipeline.
Financial and Regulatory Risks
The stakes for non-compliance are high. Starting August 1, 2026, failure to process these deletion requests can result in penalties of $200 per request, per day. This creates massive financial exposure for firms that lack robust data-lineage and suppression systems to ensure information is purged across all internal warehouses and backups. A single missed batch of requests could lead to compounding liabilities that threaten a firm's solvency.
CalPrivacy has already signaled its intent to aggressively police the industry. The agency has begun fining unregistered data brokers, including a $62,000 penalty against S&P Global, Inc. and a $42,000 fine against Rickenbacher Data LLC (doing business as Datamasters).
The Path Forward
Industry observers are now watching how brokers integrate with the state-run API to avoid the looming August deadline. The primary challenge for these firms will be the ability to verify deletions across complex data ecosystems to avoid the compounding daily fines. While the platform is live, the true test of the regime will begin in August when the state begins enforcing the strict retrieval and finalization timelines. For brokers, the window for technical readiness is closing rapidly.