Artifact GuideUSData Broker Deletion Workflow

California Delete Act Data Broker Deletion Workflow

Beginning August 1, 2026, California data brokers must download, match, process, and report DROP deletion requests on a recurring 45-calendar-day cycle.

This workflow separates the binding Delete Act and DROP regulations from CalPrivacy's implementation guidance, and records list selection, hashing, outcomes, downstream instructions, and ongoing suppression.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

A is a CCPA business that knowingly collects and sells to third parties personal information of consumers with whom it has no direct relationship, subject to statutory exclusions. Beginning August 1, 2026, a data broker must access DROP at least once every 45 calendar days, download every applicable consumer list, standardize and hash its own identifiers, process matches and nonmatches, report each status within 45 days of download, and repeat the cycle. This is a Delete Act workflow, not the ordinary CCPA deletion-request process for every business.

Section 1

How should a Data Broker Deletion Workflow run under the California CPRA?

Decide scope for each legal entity. Under the registration regulations, a direct relationship means that the consumer intentionally interacted with the business to obtain, access, buy, use, or request its products or services within the preceding three years. A rights request or identity-verification interaction does not create that relationship. A business may still be a when it has a direct relationship but sells information about that consumer that it did not collect directly.

Complete the applicable DROP account, registration, and fee steps, then select all six list types that can match the broker's holdings: name plus date of birth plus ZIP code, email, phone, mobile advertising ID, name plus VIN, and connected-TV identifier. Fewer lists are allowed only when identifiers across multiple lists lead to the exact same consumers in the broker's records.

For each download, standardize the broker's records, hash them under the current technical specification, and compare hashes locally. A match requires deletion of all non-exempt personal information and instructions to service providers and contractors, not only deletion of the submitted identifier. Where one matched identifier maps to multiple consumers, opt all linked consumers out of sale and sharing and direct downstream providers to do the same.

Report Deleted for a match followed by deletion of non-exempt data, Opted out for the shared-identifier outcome, Exempted only when matched information is exempt, and Not found only after the required matching process finds no match. CalPrivacy's processing page explains the technical steps but labels itself guidance; the Delete Act and regulations control if the guidance and binding text differ.

  • Record the last download time and schedule the next download no later than 45 calendar days later.
  • Select all identifier lists that can match the broker's holdings, unless the rules allow fewer because the lists would identify the exact same consumers.
  • Complete matching, deletion or opt-out, and status reporting within 45 days of download; the next download is also due within 45 days of the last download, so processing and the next cycle may overlap at the deadline.
  • For both matched and unmatched requests, retain only the minimum identifiers needed to screen newly collected records before sale or sharing; do not use that suppression record for another purpose.
  • If the broker later finds a match or another status changes, take the required action and update DROP within 45 days of detecting the change.
  • Retain list selection, download, standardization and hashing version, match evidence, deletion or opt-out evidence, downstream instructions, status-upload receipt, exemption basis, reviewer, and connection-failure or error notice.
Section 2

What fields should the Data Broker Deletion Workflow template capture?

The data-broker privacy or DROP operations owner should maintain the record. It must support the recurring download-process-report cycle and show why each request received its status without retaining raw DROP identifiers or suppression data beyond what ongoing compliance needs.

  • Data-broker entity and scope evidence, registration year, DROP account, selected lists and list-selection rationale, integration method, download timestamp, batch ID, and next-download deadline.
  • Hashing and standardization version, internal datasets searched, match result, quality check, and responsible operator.
  • Deleted, opted-out, exempted, or not-found status; exemption provision when used; shared-identifier branch; completion time; and status-upload receipt.
  • Minimum ongoing suppression fields, newly collected record screen, service-provider and contractor instructions, later status change, 45-day update, connection-failure notice, reviewer, and evidence location.
Section 3

How should teams review and improve the Data Broker Deletion Workflow?

Review every cycle for missed downloads, unselected identifier lists, failed normalization or hashes, partial dataset coverage, wrong status codes, incomplete downstream action, and records collected again after deletion. Re-test after changes to identifiers, matching logic, data stores, acquisitions, vendors, or the official DROP technical specification.

  • Compare the legal entity and direct-relationship analysis with the annual registration; a parent and subsidiary that independently meet the definition register separately.
  • Reconcile selected DROP lists to every identifier held, and document why an omitted list would match the exact same consumers as a selected list.
  • Test the full cycle in the DROP sandbox after hashing, identifier, or integration changes, then preserve production evidence without copying consumer identifiers into tickets.
  • Review suppression matching against newly collected records and confirm that a later match causes deletion and a status update within 45 days.
Primary sources

References and citations

cppa.ca.gov
Referenced sections
  • CPPA registry source for confirming registration status and the DROP registration step used in data-broker deletion workflow triage.
"Data brokers must register and pay the annual fee between January 1-31, 2026, through the Delete Request and Opt-Out Platform (DROP)."
leginfo.legislature.ca.gov
Referenced sections
  • Delete Act bill source for the statutory deletion mechanism and the data-broker workflow duties behind DROP.
"By January 1, 2026, the California Privacy Protection Agency shall establish an accessible deletion mechanism"
cppa.ca.gov
Referenced sections
  • CPPA statutory compilation for the Data Broker Registry and Delete Act provisions effective January 1, 2026.
"DATA BROKER REGISTRY / DELETE ACT effective 01/01/2026"
privacy.ca.gov
Referenced sections
  • Current CalPrivacy instructions for the August 1, 2026 start date and recurring 45-day download, matching, deletion, and status-reporting cycle.
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.