ProductsWorkServices Gov ContractsIndustriesPricingBlogFree ScanDone For YouLegal NurseThe MathCulture Book a Call
← All stories
Privacy & Data··8 min read

The California DELETE Act DROP Cycle, Explained by Someone Who Built For It

Forty-five days, no cure period, $200 per request per day, and two fines already issued. What the obligation actually is and where brokers are getting caught.

MCStandingMillennials Creatives

Since 1 August 2026, every data broker registered in California has had a recurring obligation that most of them are running in a spreadsheet.

Here is what it requires, and where the failures are actually happening.

The obligation, precisely

At least once every forty-five days you must access the Delete Request and Opt-out Platform, download the consumer deletion list, match it against your own records, action every request, and report an outcome for each one.

Three details catch people:

Registration with CalPrivacy is $6,000 a year, due between 1 and 31 January. From 1 January 2028 an independent third-party audit is required every three years, records must be retained six years, and produced within five business days of a written request.

It has already happened to two companies

This is not a hypothetical regime waiting for its first enforcement.

On 11 August 2026, CalPrivacy ordered LocateSmarter LLC to pay $116,490. Two days later, Cybba Inc. was ordered to pay $52,400. Both for DELETE Act failures.

Two actions in one week, early in the regime's life, is a regulator making a point.

Where brokers are actually getting caught

Not, in our experience, by deciding to ignore the law. The failures are quieter than that.

The cycle ran, and nobody can prove it

The most common. The deletions happened. The spreadsheet was updated. Nobody kept evidence an auditor could independently verify, and "our system says we deleted them" is not evidence. In 2028 that becomes a five-business-day production requirement.

The deleted came back

The one almost nobody has solved. You delete a consumer in March. In April you acquire a list, and they are in it. Your March cycle ran correctly, your April file is clean on its face, and that person is back on your books with nothing in any log to tell you it happened.

This is suppression screening, and it is a different problem from running the cycle. Most brokers are doing the first and not the second.

The denial rate

Registry filings are public, and some brokers are filing denial rates above eighty percent. Given you may not verify the requester, a high denial rate is a number that invites a question.

The uncomfortable part about compliance vendors

To screen your records against a deletion list, a vendor normally needs your records. You are solving a privacy obligation by shipping your consumer database to a third party, which is its own exposure and its own line in the audit.

It is worth asking any vendor where the matching physically happens, and whether your security team can verify the answer from the response headers rather than from a sales call.

What to do this quarter

  1. Confirm the date of your last DROP access. If it is more than forty-five days ago, that is the live problem.
  2. Find out whether you screen acquired data against prior deletions. If nobody knows, the answer is no.
  3. Look at your own filed denial rate the way a regulator would.
  4. Work out what you would hand over if a written request arrived and you had five business days.

That last one is the audit, two years early, and it is free to run today.

data brokerDELETE ActDROPprivacyCCPAcompliance
Story by Millennials Creatives · Work with us →

Keep reading

ML
Legal & Clinical
What a Legal Nurse Consultant Costs, and When You Actually Need One
M
Accessibility & Compliance
An ADA Demand Letter Arrived. What Happens Next
READY TO
GO FROM BORING
TO ICONIC?
Start Your Project → View Packages