California's data broker deletion platform stopped being a paperwork exercise on August 1, 2026. That's the date every registered broker had to start checking DROP — the Delete Request and Opt-Out Platform — at least once every 45 days and actually process what's sitting in the queue. Two weeks later, the California Privacy Protection Agency (which brands itself CalPrivacy) had already fined two brokers a combined $168,890 for blowing off their obligations. More than 300,000 Californians filed deletion requests before that deadline even hit. This is what the Delete Act's enforcement phase actually looks like, not the theory of it.
What DROP requires, exactly
DROP was created under the Delete Act (SB 362) and is run by CalPrivacy. It opened to consumers on January 1, 2026, letting any California resident file a single deletion request that's supposed to reach every broker registered with the state, instead of hunting down opt-out forms one site at a time.
The consumer side is the easy half. The broker side is where the obligations pile up:
- Pay a $6,000 annual registration fee through the DROP platform just to operate legally as a data broker in California.
- Set up a DROP account configured to actually receive deletion requests — not just register and ignore the inbox.
- Check DROP at least every 45 days, starting August 1, 2026, to pull in whatever new consumer requests have accumulated.
- Delete the non-exempt data and assign a response status to each individual request — silence or inaction isn't a valid response.
- Report back to the consumer within 90 days of the request being submitted, confirming what was done.
That's four separate deadlines and a fee, all enforceable individually. A broker doesn't get credit for registering if it then lets requests sit unprocessed, and it doesn't get credit for deleting data if it never reports back.
Why the August 1 deadline has actual teeth
The reason this deadline matters more than most compliance dates is SB 361, which Governor Newsom signed October 8, 2025 (Chapter 466, Statutes of 2025). It rewrote the penalty structure in two ways that change the math for brokers sitting on a backlog.
First, it doubled the fine for failing to register at all, from $100 to $200 per consumer per day. Second — and this is the part that actually bites brokers who did register — it created a separate $200-per-day fine for every deletion request that goes unprocessed, running until the broker either fulfills it or shows a valid exemption. On top of that, a broker can be billed for back registration fees and CalPrivacy's investigative and administrative costs.
Run the math on a broker that's not even that far behind. Say a mid-size broker has 50 unprocessed deletion requests sitting in its DROP queue and lets a month go by without touching them: 50 requests × $200/day × 30 days = $300,000. That's before any registration penalty, before back fees, before CalPrivacy's costs of investigating. A broker doesn't need a catastrophic backlog to rack up a six-figure exposure — a few dozen ignored requests over a few weeks gets there on its own.
Cybba and LocateSmarter: this is not theoretical
CalPrivacy isn't waiting to make an example of someone. In August 2026, the agency fined data broker Cybba, Inc. $52,400 for failing to register as a data broker by the 2025 deadline. Days earlier, it fined LocateSmarter LLC $116,490 for making its opt-out process too difficult for consumers to actually use — notable because it was CalPrivacy's first enforcement action combining both CCPA and Delete Act violations in a single case.
Neither of these is a hypothetical warning letter. They're closed enforcement actions with dollar figures attached, both landing within the same week, both aimed squarely at the two failure modes the law was written to catch: not registering at all, and registering but making compliance a maze. If you're a broker treating DROP as optional or treating your opt-out flow as good enough because nobody's checked yet, CalPrivacy just checked.
Where DROP still doesn't reach
DROP is a real tool with a real enforcement record behind it now, but it has hard edges, and pretending otherwise doesn't help anyone trying to get their data down.
It only covers brokers that are actually registered. DROP enforces against the list of companies formally registered as data brokers with California. Plenty of people-search sites, background-check services, and out-of-state data aggregators either fall outside that registered universe or simply skip registration — which is precisely the violation CalPrivacy just fined Cybba for. Being unregistered doesn't make a company harmless; it makes it invisible to DROP.
It's California residents only. Nothing in the Delete Act reaches beyond the state's borders. If you live in Arizona, Texas, or anywhere else, DROP does nothing for you — full stop. The 300,000-plus requests filed before August 1 were all from Californians, because that's the only population the law covers.
It's a one-time request, not ongoing protection. DROP gets a deletion request in front of a broker once. It has no mechanism to notice, six months later, when that same broker — or an unrelated broker who bought a data feed containing your information — relists your profile. A processed request is a snapshot of compliance on one day, not a standing guarantee that your data stays deleted.
What to actually do with this
If you're a California resident, file a DROP request. It's free, it's now backed by fines that are demonstrably being issued, and the 45-day check-in requirement means brokers can't just let your request rot in a queue without consequence.
But don't stop there. Any broker that isn't registered with California — which includes a meaningful chunk of the people-search and background-check industry — isn't reachable through DROP at all, and needs to be opted out of directly. If you live outside California, none of this applies to you yet, and you're back to manual opt-outs site by site. And even for the brokers DROP does reach, a single processed request today doesn't stop your data from reappearing on a resold data feed next year. Treat DROP as one input into an ongoing habit, not a finish line.
That's the gap Delist My Data is built to close — continuous, nationwide monitoring and removal that keeps working after the first request is filed, covering the brokers DROP reaches and the ones it doesn't. We're in pre-launch now; join the waitlist for founding-member access as we build it out.