Blogs

Are You Ready for the DROP?

7/30/26

cyber; phone; data

By: Fredrick Hagen and and Kayli Clifford

Any Business Indirectly Handling Consumer Data May Be a Data Broker Under California’s New Privacy Law Subject to Catastrophic Fines for Noncompliance

Beginning August 1, 2026, any business that indirectly handles consumer data belonging to California residents must comply with California’s Delete Act, regardless of where the business is located. Under the Act, any business that qualifies as a data broker must register and timely respond to consumer delete requests under California’s Delete Request and Opt-Out Platform (DROP) or face penalties of $200 per day per consumer delete request. For organizations handling large volumes of consumer personal information, those penalties can quickly escalate into millions of dollars.

What is the Delete Request and Opt-Out Platform (DROP)?

California’s Delete Act (SB 362), enacted in 2023, aimed to expand consumer privacy rights by creating a centralized platform that allows California residents to submit one request to delete their personal information through the state’s portal and have it distributed to all registered data brokers.

The Delete Request and Opt-Out Platform (DROP) became available to consumers on January 1, 2026.  More than 300,000 California residents have already registered and submitted deletion requests through the platform.

August 1, 2026, marks the date on which every registered data broker must:

  • Access and review DROP requests at least every 45 days.
  • Process verified deletion requests within 45 days.
  • Direct service providers and contractors to comply with deletion obligations.
  • Continue deleting newly collected personal information relating to consumers who previously exercised deletion rights.
  • Maintain records demonstrating compliance.
  • Prepare for recurring third-party compliance audits beginning in 2028.

Businesses that Indirectly Collect and Share a Consumer’s Personal Information are Considered Data Brokers Under California’s Privacy Act

Civil Code §§ 1798.99.80 (c) defines a “Data Broker” as a “business that knowingly collects and sells personal information of consumers with whom it does not have a direct relationship.”  The broad language of the statute may make it difficult to determine whether your company falls under this definition.

You may be considered a data broker if your business does any of the following:

  • Sells personal information about a consumer that was collected outside of the consumer’s intended interaction with your company
  • Sells or shares personal information from consumers who have not interacted with the business for over three years or;
  • Sells or receives any benefit from sharing data about consumers collected indirectly through third parties, such as tracking pixels or data enrichment services that provide additional information to internal consumer records

Under the CCPA, with some exceptions, information is considered personal information if it identifies, relates to, describes, or can reasonably be linked to a particular consumer or household, but excludes certain publicly available information.

What are the steps your business may need to take?

Registering as a data broker can be complex

Businesses that meet the definition of a data broker are required to register annually during the month of January with the California Privacy Protection Agency through the Data Broker Registry Online Portal, subject to a separate $200 per day fine. Registration is required for businesses that currently operate as data brokers, recently began brokering the personal information of California residents, or plan to do so in the future.

The registration process requires businesses to disclose specific categories of personal information they collect and whether, during the preceding year, they sold or shared California consumers’ personal information and who it was shared or sold to. As a result, businesses must maintain detailed records to satisfy the registration requirements.

DROP system integration can be costly

Integrating with the DROP system requires businesses to build and maintain specialized technical capabilities to meet its unique compliance requirements. Businesses that lack the internal resources to develop and maintain the required integrations may need to hire third-party vendors to build and support their compliance processes and recordkeeping systems.

With enforcement efforts underway and penalties already being imposed, your business should carefully assess whether you or your vendors qualify as data brokers and ensure compliance is enacted and maintained.

For more information on this topic contact Fredrick Hagen at fred.hagen@fmglaw.com, Kayli Clifford at kayli.clifford@fmglaw.com or your local FMG Law attorney.

Information conveyed herein should not be construed as legal advice or represent any specific or binding policy or procedure of any organization. Information provided is for educational purposes only. These materials are written in a general format and not intended to be advice applicable to any specific circumstance. Legal opinions may vary when based on subtle factual distinctions. All rights reserved. No part of this presentation may be reproduced, published or posted without the written permission of Freeman Mathis & Gary, LLP.

FMG Law Firm Services for Insureds – Emergency Legal Support Blogline