💰 Affiliate Disclosure

Some links on this page are affiliate links, and this site may earn a commission if you sign up through them. Ratings and recommendations are independent of any commercial relationship. Full policy: affiliate disclosure.

TL;DR: On January 1, 2026, California launches DROP, the Delete Request and Opt-Out Platform. Submit one request and it goes to every registered data broker in the state. Brokers must check the platform every 45 days and respond within 45 days. The CPPA has already filed 8 enforcement actions against non-compliant data brokers. One company got fined $55,400 just for failing to register. If you're a California resident, this is the easiest way to mass-delete your personal data.

What changed (August 27, 2026): On January 8, 2026, the CPPA brought a fresh round of enforcement actions against data brokers that failed to register by the January 31 deadline: Datamasters (Rickenbacher Data LLC, Texas) at $45,000, and S&P Global, Inc. (New York) at $62,600. A Data Broker Enforcement Strike Force, launched in early 2026, is the dedicated enforcement arm now bringing these actions. As of August 1, 2026, registered brokers must access DROP at least once every 45 days, with $200 per request per day in penalties for non-compliance.

What DROP Actually Does

DROP is a state-run website where California residents can submit a single deletion request that automatically goes to every registered data broker [1].

The old way: Find each data broker individually. Navigate their opt-out process. Submit separate requests. Repeat dozens of times. Hope they comply.

The new way: One form. One submission. Every data broker gets the request.

Here's how it works:

  • You submit a deletion request through DROP
  • Data brokers must check DROP at least every 45 days
  • They must update your request status within 45 days of receiving it
  • Failure to comply means enforcement action from the CPPA

California Is Actually Enforcing This

The California Privacy Protection Agency isn't waiting around. On December 17, 2025, they issued Enforcement Advisory No. 2025-01 warning data brokers to register by the January 31 annual deadline CPPA Enforcement Advisory 2025-01[1].

The numbers so far:

  • Multiple enforcement actions already filed against non-registered brokers
  • $55,400 fine against Accurate Append, Inc. (Bellevue, Washington) for failing to register (announced July 29, 2025) CPPA July 29, 2025
  • "Strike Force" established specifically for data broker violations [1]

The CPPA calls it the "Data Broker Enforcement Strike Force." They're not being subtle about the crackdown.

What Data Brokers Must Do

Under the Delete Act regulations approved November 13, 2025, data brokers must CPPA November 13, 2025 regulations approval[1]:

  1. Register annually with the CPPA
  2. Disclose information about their data processing practices
  3. Submit independent audits every three years
  4. Check DROP at least every 45 days
  5. Process requests within 45 days

That last requirement matters. It puts a hard deadline on deletion. No more "we'll get to it eventually."

Who Can Use DROP

California residents. That's the legal requirement.

But here's the thing about data brokers: they often can't easily verify where you actually live. If your data is in their systems with a California address (even an old one) you may be able to use DROP.

The platform launches January 1, 2026. The CPPA will host it at a state website (not yet publicly available at time of writing).

What DROP Won't Do

DROP is powerful, but it has limits:

  • Only registered brokers: Companies that don't register aren't in the system (though they face fines)
  • Only California: Other states don't have this yet
  • Data comes back: Brokers can re-acquire your data from other sources
  • Not all data holders: Companies that aren't legally "data brokers" aren't covered

This is one tool in the toolkit, not a complete solution. But it's a significant one.

What You Should Do

California Residents

• Bookmark DROP when it launches January 1
• Submit a deletion request immediately
• Set a calendar reminder to re-submit periodically
• Your data gets re-collected; deletion isn't permanent

Everyone Else

• Use our manual opt-out guide
• Consider data removal services like Optery, Incogni, or DeleteMe
• Push your state legislators for similar laws
• California often sets the template others follow

Ongoing Protection

• Minimize data you share going forward
• Use email aliases for signups
• Freeze your credit
• Deletion is reactive; prevention is better

Why This Matters Beyond California

California has a history of setting privacy standards that spread nationally. The CCPA influenced privacy laws across multiple states. DROP could do the same for deletion mechanisms.

Currently, 20 states have comprehensive data privacy laws [2]. Many classify biometric data, location data, and health information as "sensitive" requiring stricter consent. But California is the first with a centralized deletion platform.

If DROP works, if it actually forces data brokers to delete information at scale, expect other states to copy it.

Data brokers are already nervous. The $55,400 fine for just failing to register? That's the warning shot.

Update (August 27, 2026): Strike Force fines, August 1 deadline, $200-per-day penalties

The California Privacy Protection Agency (CPPA, branded as "CalPrivacy") followed up on the December 17, 2025 enforcement advisory with a fresh round of actions on January 8, 2026, fining two more data brokers for failing to register before the January 31, 2026 deadline: Datamasters (operating as Rickenbacher Data LLC, Texas) at $45,000, and S&P Global, Inc. (New York) at $62,600. These came on top of the earlier $55,000-class fines (most notably Accurate Append's $55,400 fine from July 2025) and were brought by the Data Broker Strike Force, the dedicated enforcement unit CalPrivacy launched in early 2026 specifically for Delete Act violations. Crowell's January 6, 2026 analysis of the Strike Force launch framed it as the CPPA's response to the volume of brokers that had not registered despite the December advisory.

The platform moved from "go live" to "actually operational" on August 1, 2026. From that date, registered data brokers must access DROP at least once every 45 days and process verified deletion requests they find there. The December 2025 enforcement advisory named the penalty that now attaches to missed requests: $200 per request per day, plus registration fees and enforcement expenses. CalPrivacy's Data Broker Registry page tracks the brokers that have registered and is the public ledger of who is in scope for the August 1 deadline.

The first deletion requests are now being processed. The platform launched on January 1, 2026, and the August 1 deadline is the first time brokers have been legally required to actually pull and respond to those requests, not just monitor the system. The full deletion cycle can take up to 90 days from submission, so the first wave of substantive deletion work has only just started. The Strike Force's pattern of low-five-figure fines for the failure to register is the calibration phase; the August 1 deadline is when the per-request-per-day penalty structure begins to bind.

Sources for this update: CPPA. "CalPrivacy Brings New Round of Enforcement Actions Against Data Brokers." January 8, 2026; Crowell. "California Privacy Agency Launches Data Broker Strike Force Amid Delete Act Crackdown." January 6, 2026; CPPA. "CalPrivacy Issues Enforcement Advisory Highlighting Data Broker Registration Requirements." December 17, 2025; TrustArc. "California DELETE Act: What Data Brokers Must Do by August 1, 2026." July 31, 2026; CPPA. "Delete Request and Opt-out Platform (DROP).".

References

  1. National Law Review - Privacy and Cybersecurity Legal Updates for December 2025
  2. Smarsh - US Data Privacy Laws in 2025: New State Rules & Rising Risks
  3. Help Net Security - What 35 years of privacy law say about the state of data protection (December 12, 2025)