What should teams do about the California data broker registry and DROP?
The registry and DROP create separate duties under California's Delete Act. Confirm whether each legal entity is a data broker, whether annual registration is due, and whether the entity must connect to and operate the deletion workflow.
Under the statute, a data broker means a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship. The Fair Credit Reporting Act, Gramm-Leach-Bliley Act, Insurance Information and Privacy Protection Act, and Section 1798.146 exclusions apply only to the extent the entity or processing is covered. A regulated data set does not automatically exclude unrelated brokerage activity.
A qualifying data broker must register with the CPPA by January 31 following each year in which it met the definition, pay the fee, and provide the required registration information. The filing covers the broker's identity and addresses, request metrics, specified data categories and recipients, common data types, regulated activities, and a working link to a rights page that does not use dark patterns. Each distinct legal entity registers separately and must keep its DROP account's trade names and public-facing data-broker websites accurate.
Beginning August 1, 2026, a registered data broker must access the Delete Request and Opt-Out Platform (DROP) at least once every 45 days. It must process retrieved DROP deletion requests and report their status by its next access session, no later than 45 days after retrieval; direct associated service providers and contractors to delete; and treat a request it cannot verify as an opt-out of sale or sharing within the statutory limits. Deletion exceptions cover information reasonably necessary for a Civil Code section 1798.105(d) purpose and information exempt under sections 1798.145 or 1798.146; retained exception data may be used only for the applicable exception purpose, not marketing.
After completing a DROP deletion, the broker must delete newly collected personal information at least every 45 days and must not sell or share new information unless the consumer requests otherwise or a statutory exception applies. Independent audits begin January 1, 2028 and recur every three years. The broker must keep the report and related materials for at least six years and submit them within five business days if the Agency makes a written request.
- Document the direct-relationship and exclusion analysis for each legal entity; one affiliate's registration does not automatically cover another.
- Calendar the January 31 registration, July 1 metrics disclosure, 45-day DROP access and response cycle, and January 1, 2028 audit start.
- Map every service provider and contractor that must receive deletion or opt-out instructions.
Official CPPA registry page supporting public registration checks and registry evidence for California data brokers.
Official CPPA rulemaking page for DROP requirements and the accessible deletion mechanism regulations.
Official CPPA statutory text for Delete Act amendments affecting data broker registration and deletion duties.
CPPA Enforcement Division guidance supporting separate registration for each qualifying legal entity and accurate trade names, websites, and DROP account information.