California SB 362: Deletion Requests, Deadlines, and Broker Penalties

The California Delete Act (Senate Bill 362) lets California residents delete their personal information from every registered data broker in the state through a single online request. Governor Newsom signed the law on October 10, 2023, and its centerpiece, the Delete Request and Opt-out Platform (DROP), went live on January 1, 2026.1California Privacy Protection Agency. January 2026 DROP Is Coming Data brokers must begin processing those requests by August 1, 2026, and face daily fines if they ignore them.

How to Submit a Deletion Request

DROP is a free tool run by the California Privacy Protection Agency (CPPA). You go to the platform and verify your California residency through the California Identity Gateway, the state’s secure digital identity system. You can enter your information directly or verify through Login.gov. There is no permanent account to create, and the information you provide during verification is not stored by DROP.2California Privacy Protection Agency. Delete Request and Opt-out Platform (DROP)

Once verified, your request goes out to every registered data broker at once. Before DROP existed, Californians had to hunt down each broker and file separate requests, which is why most people never did it.

A few practical features are worth knowing:

  • You can exclude specific brokers from your request if you want a particular one to keep your information.3California Legislative Information. California Civil Code 1798.99.86
  • You can modify a previous request, but only after 45 days have passed since your last submission.
  • Parents can submit on behalf of their children, family members can submit for elderly relatives, and authorized agents can act on a consumer’s behalf.2California Privacy Protection Agency. Delete Request and Opt-out Platform (DROP)

What Data Brokers Have to Do With Your Request

Starting August 1, 2026, registered brokers must access DROP at least once every 45 days and process all pending requests.4California Privacy Protection Agency. Information for Data Brokers They then have 90 days from receipt to delete your data.2California Privacy Protection Agency. Delete Request and Opt-out Platform (DROP)

The obligation is ongoing. After the initial deletion, the broker must keep checking DROP every 45 days and delete any new information it later acquires about you. That turns a one-time purge into a standing opt-out, which is the feature that makes this law meaningfully different from filing individual requests: a broker cannot simply re-buy your data next quarter and start over.

Brokers can refuse to delete in narrow circumstances: retention needed to complete a transaction, comply with a legal obligation, exercise free speech, conduct certain research, or maintain security. The general exemptions under the California Consumer Privacy Act also apply.3California Legislative Information. California Civil Code 1798.99.86 Because data brokers by definition have no direct relationship with you, most of these exceptions rarely apply in practice.

One boundary worth flagging: if you submit a request before August 1, 2026, brokers are not yet legally required to act on it. Requests queue up for processing once the deadline arrives.

The Dates That Matter

  • January 1, 2026. DROP launched and began accepting consumer deletion requests.1California Privacy Protection Agency. January 2026 DROP Is Coming
  • August 1, 2026. Data brokers must begin accessing DROP and processing verified requests every 45 days.4California Privacy Protection Agency. Information for Data Brokers
  • January 1, 2028. Mandatory independent compliance audits begin. Brokers must undergo a third-party audit every three years and submit the report to the CPPA on request.4California Privacy Protection Agency. Information for Data Brokers
  • January 2029. Brokers must publicly report their audit status as part of their annual registration.

Who Can Use It and Who It Covers

Only California residents can submit through DROP. The Delete Act defines “consumer” by reference to the California Consumer Privacy Act, which covers natural persons who are California residents.5California Legislative Information. California Civil Code Title 1.81.48 – Data Broker Registration If you live outside California, you cannot use DROP, even if California-registered brokers hold your data.

The law reaches farther than the state’s borders on the broker side, however. A company based in New York or overseas that sells the personal information of California residents must register with the CPPA and comply with deletion requests the same as a California-based company.

Not every company that has your information is a data broker under this law. California Civil Code Section 1798.99.80 defines a data broker as a business that knowingly collects and sells to third parties the personal information of consumers it does not have a direct relationship with.5California Legislative Information. California Civil Code Title 1.81.48 – Data Broker Registration If you signed up for a company’s app or bought something from its website, that company has a direct relationship with you and is not a data broker for that relationship. Data brokers are the companies you never interacted with that buy, aggregate, and resell your information.

Businesses already regulated by the federal Fair Credit Reporting Act, the Gramm-Leach-Bliley Act, the Insurance Information and Privacy Protection Act, and HIPAA-related CCPA exemptions are carved out to the extent their activities fall under those laws.5California Legislative Information. California Civil Code Title 1.81.48 – Data Broker Registration

Looking Up Who Has Your Data

The CPPA publishes a searchable Data Broker Registry online. You can filter by the categories of data brokers collect and by who they sell to, including filters for brokers that collect minors’ data or sell to law enforcement or developers of generative AI systems.6California Privacy Protection Agency. Data Broker Registry Clicking on a broker shows its contact details and consumer request metrics, and the full dataset is available as a CSV download.

Every data broker doing business in California must register with the CPPA annually by January 31 and pay a fee ($6,000 for 2026, plus a third-party processing fee for electronic payments).4California Privacy Protection Agency. Information for Data Brokers Registration happens through DROP, and the public-facing registry is how you can see which companies are on the list before or after you file a request.

What Happens if a Broker Ignores Your Request

Enforcement sits entirely with the CPPA. The Delete Act does not create a private right of action, so consumers cannot sue brokers directly; complaints go to the CPPA, which investigates and brings administrative actions.7California Privacy Protection Agency. Final Statement of Reasons – Data Broker Registration Regulations

The penalties are structured to add up. Brokers that miss the January 31 registration deadline face fines of $200 for each day they remain unregistered. Failing to process a verified deletion request carries a separate $200 per request for each day the broker fails to act. The CPPA can also recover its investigation and enforcement costs, and there is no cure period, so a broker cannot avoid fines by rushing to comply after being caught.4California Privacy Protection Agency. Information for Data Brokers

Those daily amounts look modest per violation, but they compound quickly for companies handling large volumes. A broker ignoring 10,000 requests for 30 days faces exposure of $60 million. The absence of a cure period is deliberate, and it is unusual: many privacy laws give companies a window to fix problems before penalties attach. California chose not to offer that grace here.