FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
33of33items
Across 11 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
California Delete Act data broker registry and DROP guide

What should teams do about the California data broker registry and DROP?

The registry and DROP create separate duties under California's Delete Act. Confirm whether each legal entity is a data broker, whether annual registration is due, and whether the entity must connect to and operate the deletion workflow.

Under the statute, a data broker means a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship. The Fair Credit Reporting Act, Gramm-Leach-Bliley Act, Insurance Information and Privacy Protection Act, and Section 1798.146 exclusions apply only to the extent the entity or processing is covered. A regulated data set does not automatically exclude unrelated brokerage activity.

A qualifying data broker must register with the CPPA by January 31 following each year in which it met the definition, pay the fee, and provide the required registration information. The filing covers the broker's identity and addresses, request metrics, specified data categories and recipients, common data types, regulated activities, and a working link to a rights page that does not use dark patterns. Each distinct legal entity registers separately and must keep its DROP account's trade names and public-facing data-broker websites accurate.

Beginning August 1, 2026, a registered data broker must access the Delete Request and Opt-Out Platform (DROP) at least once every 45 days. It must process retrieved DROP deletion requests and report their status by its next access session, no later than 45 days after retrieval; direct associated service providers and contractors to delete; and treat a request it cannot verify as an opt-out of sale or sharing within the statutory limits. Deletion exceptions cover information reasonably necessary for a Civil Code section 1798.105(d) purpose and information exempt under sections 1798.145 or 1798.146; retained exception data may be used only for the applicable exception purpose, not marketing.

After completing a DROP deletion, the broker must delete newly collected personal information at least every 45 days and must not sell or share new information unless the consumer requests otherwise or a statutory exception applies. Independent audits begin January 1, 2028 and recur every three years. The broker must keep the report and related materials for at least six years and submit them within five business days if the Agency makes a written request.

  • Document the direct-relationship and exclusion analysis for each legal entity; one affiliate's registration does not automatically cover another.
  • Calendar the January 31 registration, July 1 metrics disclosure, 45-day DROP access and response cycle, and January 1, 2028 audit start.
  • Map every service provider and contractor that must receive deletion or opt-out instructions.
Citations
California Delete Act data broker registry and DROP guide

What evidence should teams keep for California data broker registry and DROP under the California Delete Act?

Keep the broker-status analysis, direct-relationship and exclusion evidence, annual registration and fee receipt, required public disclosures and metrics, DROP access logs, request receipt and completion dates, deletion and opt-out propagation logs, service-provider instructions, exception decisions, and consumer status records. From 2028, keep each independent audit report and related materials for at least six years.

  • Entity file: the direct-relationship analysis, covered-business status, each activity-specific exclusion, parent and subsidiary map, trade names, public-facing websites, and the year each entity met or stopped meeting the definition.
  • Registration file: submitted disclosures, payment receipt, DROP account confirmation, working rights-page link, January 31 filing receipt, and the request-volume and response-time metrics published by July 1.
  • Request file: DROP access logs, identifiers used for matching, request and completion dates, deletion and opt-out results, service-provider and contractor instructions, exception section and purpose, newly collected data controls, consumer status, and the six-year audit-retention record.
Citations
California Delete Act data broker registry and DROP guide

Which mistakes create risk when handling California data broker registry and DROP under the California Delete Act?

Common failures include registering only a parent while an unregistered subsidiary independently meets the definition, treating one excluded data set as an entity-wide exclusion, missing the 45-day platform check, failing to propagate a request to service providers, deleting once but continuing to sell newly collected data, or confusing the 2026 operational date with the 2028 audit date.

  • Assuming a parent registration covers every qualifying subsidiary or trade name.
  • Treating an exclusion for specified data or activity as an exclusion for unrelated brokerage activity.
  • Closing a DROP request without directing service providers and contractors or controlling newly collected data.
Citations
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation

What enforcement and penalty risks should teams plan for under the US CPRA?

CPPA Enforcement Advisories discuss selected CCPA statutes and regulations and show issues the Enforcement Division is watching. They do not implement or interpret the law, establish substantive policy or rights, constitute legal advice, reflect the Board's views, or provide a safe harbor. The statute and regulations control if an advisory appears to conflict with them, and the Enforcement Division makes case-by-case decisions.

Use an advisory as an enforcement-priority and control-review signal. Advisory 2024-01, issued April 2, 2024, applies data minimization to consumer requests and warns against excessive verification data. Advisory 2024-02, issued September 4, 2024, addresses dark patterns, plain language, and symmetry in privacy choices. Advisory 2025-01 addresses timely and complete data-broker registration, including separate registrations for qualifying subsidiaries and accurate trade names and websites.

For each relevant advisory, identify the binding provision it cites, then compare the actual facts with both the rule and the advisory's hypothetical. For 2024-01, test what information each request path collects and why it is necessary. For 2024-02, compare the time, steps, wording, and visual treatment for privacy-protective and less protective choices. For 2025-01, test each legal entity's registration, payment, trade names, websites, and DROP account. Assign an owner and record the legal source, factual comparison, decision, remediation, and retest date.

  • Label the advisory as nonbinding enforcement guidance and identify the binding statute or regulation separately.
  • Test the actual consumer journey or registration record rather than treating a policy edit as remediation.
  • Escalate fact-specific legal interpretation; an advisory does not determine whether a particular practice violates the CCPA.
Citations
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation

What evidence should teams keep for Enforcement Advisories under the US CPRA?

Keep the advisory number and publication date, the binding provisions it cites, an inventory of affected interfaces or processing, screenshots or tests of current behavior, the factual comparison, the gap decision, remediation ticket, owner approval, and dated retest. Preserve the version reviewed because a later enforcement action or guidance document may address the topic differently.

  • Authority record: advisory number, issue date and saved version, each cited statute or regulation, and a note that the advisory is nonbinding Enforcement Division guidance.
  • Fact record: affected legal entities, interfaces or request flows, inputs collected, choice-path steps, trade names and websites, screenshots, test data, and the differences from the advisory's hypothetical.
  • Decision record: control owner, legal and product review, remediation ticket, implementation evidence, dated retest, unresolved factual or legal issue, and the trigger for another review.
Citations
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation

Which mistakes create risk when handling Enforcement Advisories under the US CPRA?

Common failures include treating an advisory as binding law, assuming it offers a safe harbor, copying a hypothetical conclusion without matching the facts, citing only the advisory instead of the underlying rule, or updating policy text without fixing the interface, request workflow, or registration record at issue.

  • Quoting an advisory without identifying the statute or regulation that creates the duty.
  • Treating a hypothetical example as a conclusion about a product with different facts.
  • Changing policy language while leaving the interface, request flow, or registration record unchanged.
Citations
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement

What should teams do about GPC under the US CPRA?

A covered business that sells or shares personal information must treat a qualifying Global Privacy Control or other opt-out preference signal as a request to opt out for the browser or device that sends it. The signal must use a format commonly used and recognized by businesses, such as an HTTP header or JavaScript object, and the sending mechanism must make clear that it is meant to opt the consumer out of sale and sharing. If the business knows the consumer, the signal also applies to the consumer and associated profiles, including pseudonymous profiles. The signal is a request made directly by the consumer, so the business cannot require signed authorization or verification.

The business must process the signal even if it also posts a "Do Not Sell or Share My Personal Information" link. It may omit that link only if it meets the separate statutory and regulatory conditions for frictionless processing, including fully effectuating the opt-out and making the required privacy-policy disclosures. Frictionless processing cannot charge a fee, change the product experience, or display an interstitial in response to the signal.

GPC covers sale and sharing. Deletion, correction, access, and sensitive-data limitation use their own request processes. Map the signal to every relevant online sale and cross-context behavioral advertising flow, the associated profile when known, and downstream recipients. Stop sale or sharing as soon as feasibly possible and no later than 15 business days, notify affected third parties for transfers during that period, show a confirmation state, and keep dated logged-in and logged-out tests.

  • Test recognized signal formats across browsers, devices, consent tools, tags, server-side transfers, and account states.
  • Apply the signal before optional scripts or downstream sale or sharing occurs; do not wait for login to honor the browser or device request.
  • Document any conflict with a business-specific privacy setting or financial incentive and follow the specific section 7025 rule rather than silently overriding the signal.
Citations
California Privacy Protection Agency FAQ

Official CPPA consumer guidance confirming that businesses must honor qualifying opt-out preference signals, including Global Privacy Control, for sale/sharing opt-outs.

CPRA Global Privacy Control (GPC): opt-out requirements and enforcement

What evidence should teams keep for GPC under the US CPRA?

Keep browser and device test cases, the raw signal observed, linked-profile behavior, sale/share tags blocked, downstream instructions, conflict and consent handling, privacy-choice status shown to the consumer, persistence tests, and dated results across logged-in and logged-out journeys.

  • Signal record: raw header or JavaScript value, sending mechanism and disclosure, detection timestamp, browser or device, account state, pseudonymous and known-profile associations, and confirmation state.
  • Behavior record: tag and server-side transfer results before and after detection, offline propagation when the consumer is known, third-party notices, suppression timestamps, persistence across sessions, and the 15-business-day outside deadline.
  • Decision record: link-versus-frictionless path, privacy-policy disclosure, financial-incentive or account-setting conflict, consent record if the consumer changes the choice, owner approval, exception note, and dated regression test.
Citations
California Privacy Protection Agency FAQ

Official CPPA consumer guidance confirming that businesses must honor qualifying opt-out preference signals, including Global Privacy Control, for sale/sharing opt-outs.

CPRA Global Privacy Control (GPC): opt-out requirements and enforcement

Which mistakes create risk when handling GPC under the US CPRA?

Common failures include detecting GPC without changing downstream behavior, honoring it only after login, treating a cookie banner as the sale-or-sharing request mechanism, claiming frictionless processing when offline sales remain unaffected, overriding the signal with an older cookie or account setting without following the conflict rule, or blocking one ad-tech endpoint while other sale or sharing flows continue.

  • Detecting the signal after sale or sharing has already occurred on the page.
  • Honoring GPC in a browser cookie while server-side or linked-profile transfers continue.
  • Claiming frictionless processing when the signal cannot fully effectuate the business's sale-or-sharing opt-out.
Citations
California Privacy Protection Agency FAQ

Official CPPA consumer guidance confirming that businesses must honor qualifying opt-out preference signals, including Global Privacy Control, for sale/sharing opt-outs.

Global Privacy Control project site

The GPC project's public overview supports the description of the browser-level signal; California legal effects come from the statute and CPPA regulations.

What counts as sharing under the California CPRA?

How do you decide whether an advertising data flow is sharing?

Trace the information from collection to the advertising recipient and ask four questions: Is it personal information? Does the business communicate or make it available to another person? Is that person a third party for this service? Will the recipient target advertising using information obtained from the consumer's activity across other businesses or distinctly branded sites, apps, or services? If all four answers are yes, the flow is sharing even when the arrangement is unpaid.

The statute excludes three situations from sharing: the consumer directs an intentional disclosure or intentionally interacts with a third party; the business passes an opt-out or sensitive-information limitation identifier so others can honor the choice; or personal information transfers as an asset in a merger, acquisition, bankruptcy, or similar change-of-control transaction and remains subject to the statutory conditions. These are narrow exclusions. A consumer's ordinary use of a website is not enough by itself to show that the consumer directed an ad-tech disclosure.

Contextual or nonpersonalized advertising based only on the consumer's current interaction can fall outside cross-context behavioral advertising. A service provider or contractor may provide advertising or marketing services, but cannot contract to provide cross-context behavioral advertising in that role. A person providing cross-context behavioral advertising is a third party for that service. The label in the contract does not override the recipient's actual use of the data.

  • Inventory pixels, cookies, SDKs, server-side events, identity matching, audience uploads, and real-time bidding rather than reviewing browser tags alone.
  • Record the personal-information categories, recipient, advertising purpose, source contexts, contract role, and whether the recipient combines data across contexts.
  • Test sale separately. A flow may trigger the sale opt-out even when it is not sharing for cross-context behavioral advertising.
Citations
What counts as sharing under the California CPRA?

What notice and opt-out controls must a sharing business provide?

A business that shares must tell consumers that their personal information may be sold or shared and that they have a right to opt out. Its privacy policy must describe the right and the available method. Unless the business qualifies for the frictionless preference-signal alternative in Civil Code section 1798.135(b) and section 7025 of the regulations, it must also provide the required "Do Not Sell or Share My Personal Information" link or compliant alternative link.

The business must offer at least two designated opt-out methods, chosen for how it interacts with consumers and collects the information. An online business must, at minimum, accept a qualifying opt-out preference signal and provide an interactive form through the required link, alternative link, or privacy policy when the frictionless alternative applies. It cannot require an account or identity verification and may request only information needed to carry out the opt-out.

A qualifying opt-out preference signal applies to the browser or device and associated consumer profiles, including pseudonymous profiles. If the business knows the consumer, it must also apply the signal to that consumer. An anonymous browser signal does not require the business to connect data it cannot reasonably associate with that browser. Posting an opt-out link does not excuse the business from processing qualifying signals.

Stop sharing as soon as feasibly possible and no later than 15 business days after receiving the request. Notify third parties that received the consumer's information after the request but before compliance, direct them to honor the request, and require them to pass it to anyone to whom they made the information available during that period. The business must provide a way for the consumer to confirm that the opt-out was processed and generally must wait at least 12 months before asking the consumer to consent again.

  • Test the link or alternative choice, qualifying preference signals, account and pseudonymous-profile propagation, tag suppression, downstream notice, and confirmation state.
  • Do not treat the absence of a later preference signal as consent when a known consumer previously sent one.
  • For a consumer under 16 whom the business actually knows is under 16, obtain the age-appropriate affirmative authorization before selling or sharing; willfully disregarding age counts as actual knowledge.
Citations
CPPA approved regulations, sections 7025-7026

Binding operational requirements for qualifying opt-out preference signals, linked profiles, frictionless processing, designated methods, the 15-business-day outside limit, downstream notification, confirmation, and later consent requests.

What counts as sharing under the California CPRA?

What contracts and evidence should the business maintain?

A business that shares with a third party must have an agreement identifying the limited and specified purposes, limiting the third party to those purposes, requiring the same level of CCPA protection for the information, and giving the business rights to check, stop, and remediate unauthorized use. The agreement must also require notice if the third party can no longer comply. A service-provider or contractor agreement needs the separate terms in section 7051; using that label without the required contract and restricted use may leave the recipient outside that role.

Keep a dated inventory of advertising technologies and server-side transfers; data-flow and recipient-role maps; the sale and sharing analysis; contracts and due diligence; privacy-policy and choice-interface captures; preference-signal test results; consent and under-16 authorization records where applicable; suppression and downstream-notification logs; confirmation-state tests; and retests after material product, vendor, or purpose changes.

Test actual behavior before and after an opt-out. Common failures include sending identifiers before the choice takes effect, failing to cover server-side transfers or a known consumer's linked profile, treating an unpaid disclosure as outside sharing, or relying on contract wording while the recipient combines data for cross-context advertising.

  • Assign an owner for each tag, SDK, audience list, bidding integration, and server-side advertising event.
  • Match the public notice, preference center, contracts, consent state, and runtime behavior to the same data-flow inventory.
  • Reclassify the recipient if its actual use no longer fits the contracted role, and stop the transfer until the required controls are in place.
Citations
CPPA approved regulations, sections 7050-7053

Binding recipient-role rules and contract terms for service providers, contractors, and third parties, including purpose limits, compliance duties, oversight, remediation, and downstream request handling.

What should teams do about ADMT under the US CPRA?

How should teams inventory and govern ADMT under the US CPRA?

Apply four gates to each use. First, confirm that the entity is a covered CCPA business. Second, identify whether the technology processes personal information and uses computation. Third, decide whether its output replaces or substantially replaces a person's decision; human involvement requires a reviewer who understands the output, considers other relevant information, and can change the result. Routine storage, firewall, calculator, database, and spreadsheet functions remain outside the definition when they do not replace human decisionmaking.

Fourth, connect the output to a significant decision about the consumer. Article 11 covers decisions that provide or deny financial or lending services, housing, education enrollment or opportunities, employment or independent-contracting opportunities or compensation, or healthcare services. Advertising is excluded. A prediction, score, ranking, or recommendation can still be covered when the business uses it to make a listed decision without qualifying human review.

Representative covered examples include software that screens resumes to decide whom to hire, evaluates productivity to allocate work or compensation, screens student work to decide suspension, or scores an exam to decide whether to grant a diploma. These examples depend on how the business uses the output. The same software used only to organize records or assist a reviewer who retains real decision authority may fall outside the ADMT definition.

The regulations became effective January 1, 2026, but Article 11 has a separate compliance date. A business using covered ADMT before January 1, 2027 must comply by January 1, 2027; a use beginning on or after that date must comply whenever it is used. Before processing, provide a Pre-use Notice that states the specific purpose, data categories affecting the output, output type, role of the output and any human reviewer, access right, opt-out or appeal path, and alternative decision process. The same use may also require a risk assessment before it begins or materially changes.

Consumers generally receive access and opt-out rights. An opt-out exception applies only if its conditions are met. One exception replaces opt-out with an appeal to a human reviewer who understands the output, considers the consumer's information, and can overturn the decision. Separate exceptions for specified admission, hiring, work-allocation, and compensation uses require the ADMT to work for the stated purpose and not unlawfully discriminate; document the exact exception rather than treating these fields as categorically exempt.

  • Record the decision domain, the ADMT's input and output, and whether a human reviewer has authority to change the outcome.
  • Map the Pre-use Notice, access response, opt-out path, exception, and any required appeal to the exact use case.
  • Complete the related risk-assessment analysis before starting or materially changing covered processing.
  • Reassess when the purpose, decision domain, personal-information inputs, model or rules, output, human-review authority, vendor, or consumer path changes.
Citations
What should teams do about ADMT under the US CPRA?

What evidence should teams keep for ADMT under the US CPRA?

Keep the ADMT inventory, significant-decision analysis, purpose, data categories, logic and output documentation, Pre-use Notice, access and opt-out tests, exception and appeal analysis, human-review authority, vendor terms, related risk assessment, approval, and January 1, 2027 readiness evidence. Record material changes because they can require the analysis, risk assessment, and notice to be updated.

For each consumer request, retain the receipt date, verification record where required, response or appeal due date, information supplied, outcome, and downstream action. Keep test evidence showing that opt-out routes do not require an account or unnecessary data and that the non-ADMT alternative or human appeal works in the live decision process.

  • Source URL and quote used for the decision.
  • Scope notes, screenshots, data-flow or system references, decision owner, vendor, and role mapping.
  • Implementation ticket, approval record, exception conditions, appeal test, access-response sample, and review date.
Citations
California CCPA ADMT regulations

Sections 7021 and 7200-7222 support the ADMT inventory, notice, access, opt-out, exception, appeal, timing, and request evidence described in this section.

What should teams do about ADMT under the US CPRA?

Which mistakes create risk when handling ADMT under the US CPRA?

Common failures include classifying a nominal human check as meaningful review when the reviewer cannot change the decision, treating every automated tool as covered, overlooking employment or independent-contractor decisions, using a generic privacy notice instead of a pre-use notice, or claiming an opt-out exception without implementing the required appeal path.

  • Calling review meaningful when the reviewer lacks authority, competence, or enough information to change the decision.
  • Reusing one exception across different significant decisions without checking its conditions and appeal requirement.
  • Describing the model generally while omitting how its output affects the consumer's decision.
Citations
Page 1 of 3
Previous123Next