See how Syrenis helps simplify compliance, build trust, and gain greater control over customer data. Book a Demo

Blog Article

500,000 Deletion Requests and Counting: California DROP

Posted: September 22, 2026

On August 25, 2026, the California Privacy Protection Agency (CalPrivacy) announced that more than 500,000 Californians had registered with its Delete Request and Opt-out Platform (DROP). Each registration is a legally binding deletion request sent to 654 registered data brokers at once. 

Within weeks of the August 1 processing deadline, brokers had reported deleting tens of millions of records.

For the first time, a privacy right is operating on an industrial scale by design. That changes the economics of privacy rights request handling for every organization in the data supply chain, and it exposes any consent and preference management setup that still relies on centralized records maintained by hand.

What DROP Actually Does

Under California’s Delete Act, any business that knowingly collects and sells personal information about consumers with whom it has no direct relationship must register as a data broker. 

Since August 1, 2026, each registered broker must log into DROP at least every 45 days, match the request list against its records, delete matching personal information including any inferences derived from it, and report the status of each request within 45 days.

A privacy rights request is a legally enforceable instruction from an individual to a business about their personal data: Delete it, stop selling it, correct it, or hand over a copy. 

DROP removes the friction that once kept those requests rare, replacing hundreds of individual submissions with a single free sign-up that takes under ten minutes.

The Penalty Math Changes the Risk Calculation

The Delete Act fines a broker $200 per unprocessed deletion request per day, plus CalPrivacy’s investigation costs, and the statute sets no aggregate cap. A backlog of 5,000 matching requests left unprocessed for one 45-day cycle produces a theoretical exposure of $45 million.

Before DROP, a company’s exposure to privacy rights requests scaled with how many people bothered to write in. Now it scales with how many Californians have registered, and that number is still climbing. The typical DROP user has already had their information removed by more than 40 brokers.

Enforcement Started Before the Requests Did

CalPrivacy spent two years building an enforcement record so that DROP would land on prepared ground. 

In August 2026 alone it fined a people-search data broker $116,490 for failing to register and for demanding partial Social Security numbers before honoring opt-outs, and fined an advertising technology company $52,400 for operating as an unregistered broker.

At its August 7 board meeting, the agency reported that 30 percent of registered brokers had begun processing DROP requests in the first week after the deadline, and by August 25 roughly a quarter had reported completed deletions. The agency has also opened rulemaking on the compliance audits brokers will face from 2028.

You May be Closer to “Data Broker” Than You Think

The statutory definition of a “data broker” captures more than the household names of the industry. 

A business that licenses enriched contact lists, appends third-party data to its customer file, builds lookalike audiences from purchased signals, or resells analytics derived from other companies’ users can meet the test even where brokerage is a side line.

CalPrivacy’s own actions reflect that breadth: The advertising technology company was deemed a broker because it sold geolocation, browsing, and inference data about people it had no relationship with, using it to build custom advertising audiences. Every enterprise with a data licensing arrangement should have a documented answer to the registration question.

The effect reaches companies that never sell a record. Speaking on Syrenis’s recent 2026 Privacy Playbook webinar, Jodi Daniels of Red Clover Advisors made the point that if a sales or marketing team buys data, the pool of Californians available in that data will shrink as opt-outs accumulate, and that Connecticut has now added Delete Act-style requirements of its own. Her advice was to raise it with marketing and sales before they discover it in their campaign numbers.

Deletion Requests Have to Reach the Whole Data Chain

Two features of the Delete Act matter well beyond brokers: 

  • First, a deletion has to flow through to service providers and contractors, so a broker’s obligation becomes a contractual obligation on every vendor holding a copy. 
  • Second, where a broker cannot verify a request, it must treat the request as an opt-out of sale and sharing rather than simply declining it.

That second rule is the one enterprises tend to miss. A request that fails verification still changes what the business is allowed to do with the data, and that change has to propagate to marketing platforms, partners, and downstream licensees.

Browsers Are the Next Scale Multiplier

DROP is one half of a coordinated push. Under the California Opt Me Out Act, signed in October 2025, every browser operating in the state must ship an easy-to-find setting that sends an opt-out preference signal to the websites a consumer visits, effective January 1, 2027.

Universal opt-out signals such as Global Privacy Control (GPC) currently reach a minority of users through niche browsers and extensions. 

Once the major browsers carry the setting natively, the volume of machine-readable opt-outs arriving at enterprise websites will rise in the same way DROP raised the volume of deletions.

Manual privacy rights request handling assumed volumes in the dozens per month. A DROP-era operation needs three capabilities that most fragmented stacks lack:

  1. A single record of each individual’s rights status, so that a deletion or an opt-out is recorded once and visible to every system. 
  2. Automated propagation to internal platforms and to vendors, with confirmation flowing back. 
  3. An audit trail showing when each request arrived, when it was completed, and by whom.

Consent and preference management platforms are converging on this model, treating a privacy rights request, a cookie choice, and a marketing preference as three entries on the same record. 

Rights that were once exercised one person at a time are now exercised half a million at a time, and processes built for the former do not survive the latter.

The Delete Act and what it means for non-brokers is one of the developments covered in the full Privacy Playbook webinar.