---
title: "California Delete Act data broker registry and DROP guide"
canonical_url: "https://www.sorena.io/artifacts/us/california-privacy-rights-act/faq/data-broker-registry-and-drop"
source_url: "https://www.sorena.io/artifacts/us/california-privacy-rights-act/faq/data-broker-registry-and-drop"
author: "Sorena AI"
description: "California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources."
published_at: "2026-05-09"
updated_at: "2026-05-09"
keywords:
  - "California Delete Act"
  - "data broker registry"
  - "DROP"
  - "Delete Request and Opt-Out Platform"
  - "CPPA"
  - "data brokers"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# California Delete Act data broker registry and DROP guide

California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.

*Artifact Guide* *California* *California data broker registry and DROP*

## California Delete Act Data broker registry and DROP

California data broker registry and DROP decisions should identify whether the entity is a data broker, which registration or deletion-platform duty applies, who owns the filing, and what evidence proves completion.

This page offers practical steps for implementation planning. Confirm legal and policy assumptions before implementation.

This page explains California Delete Act data broker registry and DROP obligations in plain English: which businesses must register, which businesses are excluded, what DROP does, and what evidence teams should keep. It focuses on the registration trigger, responsible owner, deadline, evidence record, and review path that privacy, legal, security, and compliance teams can apply.

## What should teams do about the California data broker registry and DROP?

Teams should treat the California data broker registry and DROP as Delete Act operating duties, not as a generic CPRA privacy-notice update. Confirm whether the entity is a data broker, whether registration is required, and what DROP readiness work must be assigned.

Under the statute, a data broker means a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship. The statute also excludes entities covered by the federal Fair Credit Reporting Act, the Gramm-Leach-Bliley Act, and the Insurance Information and Privacy Protection Act, as well as some processing exempt under Section 1798.146.

The safest first step is to identify the broker status analysis, registration owner, annual filing evidence, deletion-request workflow, vendor dependencies, and review date before assigning implementation work.

- Write the registry or DROP decision in one sentence before drafting controls.
- Attach the CPPA registry or DROP source URL and a short source quote to the evidence record.
- Route unclear broker-status, exemption, or deletion-platform questions to privacy counsel before filing.

Sources for this answer:

- [California Privacy Protection Agency - data broker registry](https://cppa.ca.gov/data_broker_registry/?ref=sorena.io) - Official CPPA registry page supporting public registration checks and registry evidence for California data brokers.
- [California Privacy Protection Agency - Accessible Deletion Mechanism (DROP) regulations](https://cppa.ca.gov/regulations/drop.html?ref=sorena.io) - Official CPPA rulemaking page for DROP requirements and the accessible deletion mechanism regulations.
- [California Data Broker Registry / Delete Act statute](https://cppa.ca.gov/regulations/pdf/data_broker_reg_delete_act_statute_eff_20260101.pdf?ref=sorena.io) - Official CPPA statutory text for Delete Act amendments affecting data broker registration and deletion duties.

## What evidence should teams keep for California data broker registry and DROP under the California Delete Act?

Useful evidence is not just a privacy policy. Keep the source, threshold notes, request logs, GPC test evidence, notice screenshots, vendor terms, retention logic, and approval trail together.

- Source URL and quote used for the decision.
- Scope notes, screenshots, data-flow or system references, and role mapping.
- Implementation ticket, approval record, exception notes, and review date.

Sources for this answer:

- [California Privacy Protection Agency - data broker registry](https://cppa.ca.gov/data_broker_registry/?ref=sorena.io) - Official CPPA registry page supporting public registration checks and registry evidence for California data brokers.
- [California Privacy Protection Agency - Accessible Deletion Mechanism (DROP) regulations](https://cppa.ca.gov/regulations/drop.html?ref=sorena.io) - Official CPPA rulemaking page for DROP requirements and the accessible deletion mechanism regulations.
- [California Data Broker Registry / Delete Act statute](https://cppa.ca.gov/regulations/pdf/data_broker_reg_delete_act_statute_eff_20260101.pdf?ref=sorena.io) - Official CPPA statutory text for Delete Act amendments affecting data broker registration and deletion duties.

## Which mistakes create risk when handling California data broker registry and DROP under the California Delete Act?

The common failure pattern is treating every California privacy issue as a generic CCPA notice update instead of checking CPRA amendments, sharing, sensitive data, GPC, and phased CPPA rulemaking.

- Using an old threshold, deadline, source page, or contract template without checking current source text.
- Treating a source-linked exclusion as a general exemption for every product or data flow.
- Publishing notices, controls, or answers that do not match the actual product behavior.

Sources for this answer:

- [California Privacy Protection Agency - data broker registry](https://cppa.ca.gov/data_broker_registry/?ref=sorena.io) - Official CPPA registry page supporting public registration checks and registry evidence for California data brokers.
- [California Privacy Protection Agency - Accessible Deletion Mechanism (DROP) regulations](https://cppa.ca.gov/regulations/drop.html?ref=sorena.io) - Official CPPA rulemaking page for DROP requirements and the accessible deletion mechanism regulations.
- [California Data Broker Registry / Delete Act statute](https://cppa.ca.gov/regulations/pdf/data_broker_reg_delete_act_statute_eff_20260101.pdf?ref=sorena.io) - Official CPPA statutory text for Delete Act amendments affecting data broker registration and deletion duties.

## Primary sources

- [California Privacy Protection Agency - data broker registry](https://cppa.ca.gov/data_broker_registry/?ref=sorena.io) - Official CPPA registry page supporting public registration checks and registry evidence for California data brokers.
  - Quote: "Data brokers are required to register with the State of California annually in January"
- [California Privacy Protection Agency - Accessible Deletion Mechanism (DROP) regulations](https://cppa.ca.gov/regulations/drop.html?ref=sorena.io) - Official CPPA rulemaking page for DROP requirements and the accessible deletion mechanism regulations.
  - Quote: "Accessible Deletion Mechanism"
- [California Data Broker Registry / Delete Act statute](https://cppa.ca.gov/regulations/pdf/data_broker_reg_delete_act_statute_eff_20260101.pdf?ref=sorena.io) - Official CPPA statutory text for Delete Act amendments affecting data broker registration and deletion duties.
  - Quote: "a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship"

## Topic Guides

- [California CPRA Checklist](/artifacts/us/california-privacy-rights-act/checklist.md): Practical guidance for the California CPRA checklist, with practical decisions, evidence, edge cases, and external source citations.
- [California CPRA FAQ](/artifacts/us/california-privacy-rights-act/faq.md): Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
- [California CPRA penalties and fines Guide](/artifacts/us/california-privacy-rights-act/penalties-and-fines.md): US CPRA guidance for penalties and fines, with practical decisions, evidence, edge cases, and external source citations.
- [California CPRA Requirements Guide](/artifacts/us/california-privacy-rights-act/requirements.md): Practical guidance for California CPRA requirements, with practical decisions, evidence, edge cases, and external source citations.
- [California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide](/artifacts/us/california-privacy-rights-act/risk-assessments-cybersecurity-audits-and-admt.md): California CPRA guidance for risk assessments, cybersecurity audits, and ADMT, with practical decisions, evidence, edge cases, and external source citations.
- [California Data Broker Deletion Workflow Guide](/artifacts/us/california-privacy-rights-act/data-broker-deletion-workflow.md): California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
- [California Data Broker Registry and DROP Guide](/artifacts/us/california-privacy-rights-act/data-broker-registry-and-drop.md): California Delete Act guide to the Data Broker Registry and DROP, with practical decisions, evidence, edge cases, and official source citations.
- [CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation](/artifacts/us/california-privacy-rights-act/faq/enforcement-advisories.md): US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
- [CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ](/artifacts/us/california-privacy-rights-act/faq/gpc.md): US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Applicability Test Guide](/artifacts/us/california-privacy-rights-act/applicability-test.md): Practical guidance for the US CPRA applicability test, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA CCPA vs CPRA Guide](/artifacts/us/california-privacy-rights-act/ccpa-vs-cpra.md): US CPRA guidance for CCPA vs CPRA, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Compliance Guide](/artifacts/us/california-privacy-rights-act/compliance.md): Practical guidance for the US CPRA compliance, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Consumer Rights Workflow Guide](/artifacts/us/california-privacy-rights-act/consumer-rights-workflow.md): US CPRA guidance for Consumer Rights Workflow, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Contract Terms Guide](/artifacts/us/california-privacy-rights-act/contract-terms.md): US CPRA guidance for Contract Terms, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Contracts Contractors And Service Providers Guide](/artifacts/us/california-privacy-rights-act/contracts-contractors-and-service-providers.md): US CPRA guidance for Contracts Contractors And Service Providers, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Correction Rights Guide](/artifacts/us/california-privacy-rights-act/correction-rights.md): US CPRA guidance for Correction Rights, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Cppa Regulations Tracker Guide](/artifacts/us/california-privacy-rights-act/cppa-regulations-tracker.md): US CPRA guidance for Cppa Regulations Tracker, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Cyber Audit Readiness Workflow Guide](/artifacts/us/california-privacy-rights-act/cyber-audit-readiness-workflow.md): US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Deadlines and Compliance Calendar Guide](/artifacts/us/california-privacy-rights-act/deadlines-and-compliance-calendar.md): US CPRA guidance for Deadlines and Compliance Calendar, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA DSAR And Correction Workflow Guide](/artifacts/us/california-privacy-rights-act/dsar-and-correction-workflow.md): US CPRA guidance for DSAR And Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA GPC Handling Guide](/artifacts/us/california-privacy-rights-act/gpc-handling.md): US CPRA guidance for GPC Handling, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA GPC Handling Workflow Guide](/artifacts/us/california-privacy-rights-act/gpc-handling-workflow.md): US CPRA guidance for GPC Handling Workflow, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Retention Guide](/artifacts/us/california-privacy-rights-act/retention.md): US CPRA guidance for Retention, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Risk Assessment Intake Workflow Guide](/artifacts/us/california-privacy-rights-act/risk-assessment-intake-workflow.md): US CPRA guidance for Risk Assessment Intake Workflow, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Risk Assessment Template Guide](/artifacts/us/california-privacy-rights-act/cpra-risk-assessment-template.md): US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Risk Assessments And Cybersecurity Audits Guide](/artifacts/us/california-privacy-rights-act/risk-assessments-and-cybersecurity-audits.md): US CPRA guidance for Risk Assessments And Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Sensitive Personal Information Guide](/artifacts/us/california-privacy-rights-act/sensitive-personal-information.md): US CPRA guidance for Sensitive Personal Information, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Sensitive Personal Information Limits Guide](/artifacts/us/california-privacy-rights-act/sensitive-personal-information-limits.md): US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA Sharing and Cross-Context Behavioral Advertising Guide](/artifacts/us/california-privacy-rights-act/sharing-and-cross-context-behavioral-advertising.md): US CPRA guidance for Sharing and Cross-Context Behavioral Advertising, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA vs Colorado Privacy Act Guide](/artifacts/us/california-privacy-rights-act/cpra-vs-colorado-privacy-act.md): US CPRA guidance for CPRA vs Colorado Privacy Act, with practical decisions, evidence, edge cases, and external source citations.
- [US CPRA vs Virginia Vcdpa Guide](/artifacts/us/california-privacy-rights-act/cpra-vs-virginia-vcdpa.md): US CPRA guidance for CPRA vs Virginia Vcdpa, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about ADMT under the US CPRA?](/artifacts/us/california-privacy-rights-act/faq/admt.md): US CPRA guidance for ADMT, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about Contract Terms under the US CPRA?](/artifacts/us/california-privacy-rights-act/faq/contract-terms.md): US CPRA guidance for Contract Terms, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about Correction Rights under the US CPRA?](/artifacts/us/california-privacy-rights-act/faq/correction-rights.md): US CPRA guidance for Correction Rights, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about Cybersecurity Audits under the US CPRA?](/artifacts/us/california-privacy-rights-act/faq/cybersecurity-audits.md): US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about retention under the California CPRA?](/artifacts/us/california-privacy-rights-act/faq/retention.md): California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
- [What should teams do about Risk Assessments under the US CPRA?](/artifacts/us/california-privacy-rights-act/faq/risk-assessments.md): US CPRA guidance for Risk Assessments, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about Sensitive Personal Information Limits under the US CPRA?](/artifacts/us/california-privacy-rights-act/faq/sensitive-personal-information-limits.md): US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
- [What should teams do about Sharing and Cross-Context Behavioral Advertising under the California CPRA?](/artifacts/us/california-privacy-rights-act/faq/sharing-and-cross-context-behavioral-advertising.md): California CPRA guidance for Sharing and Cross-Context Behavioral Advertising, with practical decisions, evidence, edge cases, and external source citations.

*Recommended next step*

*Placement: after the practical guidance*

## Turn registry and DROP work into assigned tasks

This California Delete Act guide turns turn data broker registry and DROP obligations into owners, evidence requests, review checkpoints, and reusable operating records inside Sorena.

- [Open Assessment Autopilot for California Delete Act](/solutions/assessment.md): Turn California data broker registry and DROP into scoped questions, evidence fields, and review tasks.
- [Review California Delete Act source evidence](/solutions/research-copilot.md): Use Research Copilot to answer follow-up questions with cited source material.
- [Talk through implementation](/contact.md): Review scope, evidence, owners, and the next compliance actions with Sorena.


---

[Privacy Policy](https://www.sorena.io/privacy) | [Terms of Use](https://www.sorena.io/terms-of-use) | [DMCA](https://www.sorena.io/dmca) | [About Us](https://www.sorena.io/about-us)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/us/california-privacy-rights-act/faq/data-broker-registry-and-drop
