Artifact GuideCaliforniaCalifornia data broker registry and DROP

California Delete Act Data broker registry and DROP

A California data broker must register by January 31 after each qualifying year and, beginning August 1, 2026, check DROP at least every 45 days, process retrieved requests, and report their status within 45 days after retrieval.

Apply the cited California statute and regulations to the actual entity, data flow, system, and recipient role; escalate unresolved legal interpretation.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

A that met California's Delete Act definition during a calendar year must register with the California Privacy Protection Agency by January 31 of the following year. It must also maintain a account and, beginning August 1, 2026, check and process platform requests on the statutory cycle. This page explains the entity-level scope test, limited exclusions, registration disclosures, deletion workflow, recurring dates, and evidence to retain.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What should teams do about the California data broker registry and DROP?

The registry and create separate duties under California's Delete Act. Confirm whether each legal entity is a , whether annual registration is due, and whether the entity must connect to and operate the deletion workflow.

Under the statute, a means a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship. The Fair Credit Reporting Act, Gramm-Leach-Bliley Act, Insurance Information and Privacy Protection Act, and Section 1798.146 exclusions apply only to the extent the entity or processing is covered. A regulated data set does not automatically exclude unrelated brokerage activity.

A qualifying must register with the CPPA by January 31 following each year in which it met the definition, pay the fee, and provide the required registration information. The filing covers the broker's identity and addresses, request metrics, specified data categories and recipients, common data types, regulated activities, and a working link to a rights page that does not use dark patterns. Each distinct legal entity registers separately and must keep its account's trade names and public-facing data-broker websites accurate.

Beginning August 1, 2026, a registered must access the Delete Request and Opt-Out Platform () at least once every 45 days. It must process retrieved DROP deletion requests and report their status by its next access session, no later than 45 days after retrieval; direct associated service providers and contractors to delete; and treat a request it cannot verify as an opt-out of sale or sharing within the statutory limits. Deletion exceptions cover information reasonably necessary for a Civil Code section 1798.105(d) purpose and information exempt under sections 1798.145 or 1798.146; retained exception data may be used only for the applicable exception purpose, not marketing.

After completing a deletion, the broker must delete newly collected personal information at least every 45 days and must not sell or share new information unless the consumer requests otherwise or a statutory exception applies. Independent audits begin January 1, 2028 and recur every three years. The broker must keep the report and related materials for at least six years and submit them within five business days if the Agency makes a written request.

  • Document the direct-relationship and exclusion analysis for each legal entity; one affiliate's registration does not automatically cover another.
  • Calendar the January 31 registration, July 1 metrics disclosure, 45-day access and response cycle, and January 1, 2028 audit start.
  • Map every service provider and contractor that must receive deletion or opt-out instructions.
Citations
Question 2

What evidence should teams keep for California data broker registry and DROP under the California Delete Act?

Keep the broker-status analysis, direct-relationship and exclusion evidence, annual registration and fee receipt, required public disclosures and metrics, access logs, request receipt and completion dates, deletion and opt-out propagation logs, service-provider instructions, exception decisions, and consumer status records. From 2028, keep each independent audit report and related materials for at least six years.

  • Entity file: the direct-relationship analysis, covered-business status, each activity-specific exclusion, parent and subsidiary map, trade names, public-facing websites, and the year each entity met or stopped meeting the definition.
  • Registration file: submitted disclosures, payment receipt, account confirmation, working rights-page link, January 31 filing receipt, and the request-volume and response-time metrics published by July 1.
  • Request file: access logs, identifiers used for matching, request and completion dates, deletion and opt-out results, service-provider and contractor instructions, exception section and purpose, newly collected data controls, consumer status, and the six-year audit-retention record.
Citations
Question 3

Which mistakes create risk when handling California data broker registry and DROP under the California Delete Act?

Common failures include registering only a parent while an unregistered subsidiary independently meets the definition, treating one excluded data set as an entity-wide exclusion, missing the 45-day platform check, failing to propagate a request to service providers, deleting once but continuing to sell newly collected data, or confusing the 2026 operational date with the 2028 audit date.

  • Assuming a parent registration covers every qualifying subsidiary or trade name.
  • Treating an exclusion for specified data or activity as an exclusion for unrelated brokerage activity.
  • Closing a request without directing service providers and contractors or controlling newly collected data.
Citations
Primary sources

References and citations

cppa.ca.gov
Referenced sections
  • Official CPPA registry page supporting public registration checks and registry evidence for California data brokers.
"Any business that meets the definition of "data broker" must register with CalPrivacy annually between January 1-31"
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.