Artifact GuideUSData Broker Registry and DROP

California Delete Act Data Broker Registry and DROP

A business that meets California's data-broker definition must register annually and use DROP for deletion requests beginning August 1, 2026.

Keep this Delete Act analysis separate from ordinary CCPA scope. The definition, exclusions, registration disclosures, request cycle, metrics, and audit duties have their own tests.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

California's Registry lists businesses that meet the state's definition of a data broker, and is the state's Delete Request and Opt-Out Platform for handling deletion requests. This page explains what the registry and DROP are, who must register, what the annual registration and deletion workflow looks like, and which deadlines, evidence records, and review steps teams should track.

Section 1

What should teams decide about Data Broker Registry and DROP under the California Delete Act?

Start with the statutory definition: a is a business that knowingly collects and sells to third parties the personal information of a consumer with whom it has no direct relationship. The statute excludes specified entities to the extent covered by laws such as the FCRA, GLBA, and California's Insurance Information and Privacy Protection Act, and it contains further exemptions. Analyze each business line and data flow rather than relying on the company label.

A business that met the definition in the prior year must register with the California Privacy Protection Agency by January 31 and pay the required fee. Registration includes identity and contact information, required activity and request metrics, data-practice disclosures, and other fields specified by statute and regulation. The public registry reflects information submitted by brokers; it is not a substitute for the business's own scope analysis.

launched for California residents on January 1, 2026. Beginning August 1, 2026, a must access the mechanism at least once every 45 days and process requests received through it. Consumers can submit one request that applies to active brokers, subject to the consumer's selections and statutory exceptions.

  • Scope: record the business, source of personal information, direct-relationship analysis, sale to third parties, exclusions, and exempt data.
  • Registration: retain the annual submission, fee receipt, disclosed practices and metrics, authorized contacts, and later corrections.
  • : retain access logs, request receipt, matching inputs, outcome, deletion and opt-out actions, recipient instructions, and status reporting.
  • Governance: track July 1 metrics, the January registration cycle, August 1, 2026 processing start, recurring 45-day operations, and the independent-audit cycle beginning in 2028.
Section 2

How must a data broker process a DROP request?

Beginning August 1, 2026, access at least every 45 days. Within 45 days after receiving a request from the mechanism, process the request, delete personal information related to the matched consumer as required, and direct associated service providers or contractors to delete the related information in their possession.

If the deletion request cannot be verified, process it as an opt-out of sale or sharing within 45 days, subject to the cited statutory limits. A broker may retain information necessary to honor the deletion or opt-out, but may use that retained information only for the permitted purpose.

After completing deletion, delete later-acquired personal information for that consumer at least every 45 days and do not sell or share new personal information unless the consumer requests otherwise or a statutory provision permits it. The consumer-facing site explains that a status may take up to 90 days because brokers retrieve requests on a recurring cycle and then process them.

  • Privacy operations: own access, matching rules, exception review, outcome reporting, and consumer status evidence.
  • Data engineering: delete matched records, prevent prohibited resale or sharing, run recurring deletion, and preserve only permitted suppression data.
  • Recipient management: instruct service providers and contractors, track completion, and investigate data that returns from a source or downstream system.
  • Legal or privacy: approve exclusions, exemptions, failed-verification opt-out treatment, retained-data purposes, and any denial.
Section 3

Which exclusions, exceptions, and timing points matter?

A direct relationship turns on the consumer's intentional interaction with the business, not merely whether the business can identify, observe, or contact the consumer. Analyze each collection channel and product: a direct relationship for one service does not settle whether another business line brokers information collected without that relationship. An exclusion tied to another law applies only to the extent the statutory wording covers the entity or activity.

deletion has exceptions. Publicly available and exempt information may be retained, and other CCPA deletion exceptions may apply. Record the exact category, legal basis, and resulting DROP status instead of marking the entire consumer record exempt.

The obligations are recurring. Registration is due by January 31 after a year in which the business met the definition; annual metrics are compiled and disclosed by July 1; processing begins August 1, 2026; and independent third-party audits begin January 1, 2028 and repeat every three years.

  • Distinguish no match, failed verification, partial exemption, full exemption, deletion, and opt-out because each requires different action and evidence. A failed verification must be handled as an opt-out of sale or sharing within the applicable 45-day period rather than closed as no action.
  • Do not confuse the broker's 45-day duty after receipt with the consumer-facing statement that status may take up to 90 days across the retrieval and processing cycle.
  • Keep the audit report and related materials for at least six years and be prepared to submit them to the Agency within five business days of a written request.
  • Reassess scope when acquisition sources, direct consumer interactions, sale practices, legal exclusions, or corporate structure change.
Section 4

What records and controls should the broker maintain?

Maintain a scope memorandum, annual registration calendar, disclosure and metrics workbook, access log, matching specification, request ledger, deletion and opt-out job evidence, exception register, recipient instructions, status reports, and audit records. Reconcile registration disclosures with actual data practices before each filing.

Test the workflow with exact and partial matches, no match, failed verification, exempt and nonexempt data in one profile, service-provider copies, newly acquired data after deletion, and a consumer update. The test should prove the recurring 45-day control as well as the first request outcome.

  • Before January 31: confirm prior-year scope, reconcile disclosures and metrics, submit registration, and retain the receipt.
  • Before July 1: compile and disclose the required prior-year request metrics.
  • Every cycle: retrieve requests, match, delete or opt out, instruct service providers and contractors, report status, delete later-acquired information for completed matches, and preserve only the suppression data and exempt information allowed for the recorded purpose.
  • From 2028: complete the independent audit every three years and retain the report and related materials for at least six years.
Primary sources

References and citations

cppa.ca.gov
Referenced sections
  • CPPA registry source for confirming registered data brokers and the DROP registration step teams use before deletion processing.
"Data brokers must register and pay the annual fee between January 1-31, 2026, through the Delete Request and Opt-Out Platform (DROP)."
cppa.ca.gov
Referenced sections
  • CPPA statutory compilation for the Data Broker Registry and Delete Act provisions effective January 1, 2026.
"DATA BROKER REGISTRY / DELETE ACT effective 01/01/2026"
cppa.ca.gov
Referenced sections
  • CPPA DROP regulations source for the accessible deletion mechanism and system requirements created under the Delete Act.
"requires the Agency to establish an accessible deletion mechanism"
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.