California has entered a new phase of privacy enforcement. Beginning August 1, 2026, businesses that qualify as data brokers must begin processing consumer deletion requests submitted through California’s Delete Request and Opt-Out Platform, known as DROP.
What Is DROP?
DROP allows a California consumer to submit a single request directing registered data brokers to delete personal information associated with that consumer. Previously, consumers generally had to contact individual data brokers separately.
Under California’s Delete Act, covered data brokers must access DROP at least once every 45 days and process applicable deletion requests, subject to statutory exceptions. When a consumer’s information can be matched, the obligation can extend to associated personal information and inferences maintained by the broker or its service providers or contractors.
After processing a deletion request, a data broker generally may not simply reacquire the consumer’s information and resume selling or sharing it unless the consumer requests otherwise or a statutory exception applies.
Why Businesses Should Pay Attention Now
California regulators have already demonstrated that data-broker compliance is an enforcement priority.
In August 2026, the California Privacy Protection Agency announced an enforcement decision involving LocateSmarter LLC, arising under both the California Consumer Privacy Act and the Delete Act. Among other issues, regulators alleged that the company failed to timely register as a data broker and improperly required consumers to provide sensitive personal information before exercising privacy rights.
The action is an important reminder that compliance involves more than simply publishing a privacy policy.
Is Your Business a “Data Broker”?
Not every company that collects customer information is a data broker. The analysis generally focuses on whether a business knowingly collects and sells personal information concerning consumers with whom it does not have a direct relationship.
Companies engaged in activities involving data aggregation, marketing databases, lead generation, identity information, audience analytics, or similar data transactions should determine whether their activities fall within California’s definition.
Businesses that qualify should review their registration status, DROP procedures, deletion workflows, vendor relationships, and recordkeeping requirements now.
Practical Takeaway
California’s privacy regime is increasingly moving from disclosure requirements toward operational compliance and enforcement. For businesses dealing extensively in consumer information, the cost of overlooking data-broker requirements is becoming increasingly significant.
Public Resources
- California Privacy Protection Agency, Delete Request and Opt-Out Platform (DROP)
- California Delete Act
- California Consumer Privacy Act
- California Privacy Protection Agency enforcement decision concerning LocateSmarter LLC (August 2026)
Related practice areas: Civil Litigation · Business and Commercial Litigation