California Delete Act (SB 362) & DROP Platform: 2026 Complete Consumer & Data Removal Guide
California's SB 362 launches the DROP platform. Mandatory August 1, 2026 data broker processing deadline, $200/day fines, and how to protect your privacy nationwide.
The California Delete Act (Senate Bill 362) marks the most significant evolution in personal data privacy legislation in the United States since the enactment of the California Data Broker Opt-Out frameworks under CCPA and CPRA. Enacted to address the systemic issue of unauthorized data collection by commercial data brokers, SB 362 creates a centralized state-managed system: the Delete Request and Opt-Out Platform (DROP).
Administered directly by the California Privacy Protection Agency (CPPA), DROP enables consumers to submit a single, verifiable deletion request that automatically applies to all registered data brokers operating within California. As compliance deadlines take full legal force in 2026, understanding how DROP operates, its legal enforcement mechanisms, and its practical limitations is essential for anyone seeking total digital privacy. Learn more about statutory opt-out options in our comprehensive guide to California Data Broker Opt-Out Laws.
What is the California Delete Act (SB 362)?
Passed in late 2023 and systematically implemented through 2026, Senate Bill 362 shifts the burden of data privacy from individual consumers onto data brokers. Prior to SB 362, opting out of data broker databases required individuals to navigate hundreds of separate opt-out forms, upload government IDs, submit faxed requests, or pay recurring subscription fees to third-party data removal services.
SB 362 mandates three structural changes to California data privacy enforcement:
Tired of dealing with data exposure?
Your personal data is likely on 545 data brokers. Use OfflistMe to generate pre-filled opt-out emails for all of them in one go.
- Centralized Deletion (DROP): The CPPA built and maintains a single online portal where California residents (and authorized representatives) can initiate a universal deletion command across all registered data brokers.
- Mandatory 45-Day Processing Cycle: Starting August 1, 2026, every registered data broker in California must connect to the DROP system at least once every 45 days. Upon connecting, brokers must process all pending deletion requests and instruct their contractors and service providers to purge the matching consumer data.
- Severe Non-Compliance Penalties: Data brokers that fail to register with the CPPA or fail to process deletion requests from the DROP system face administrative fines of $200 per deletion request, per day of non-compliance, alongside cost recovery fees incurred during CPPA enforcement actions.
2026 Compliance Timeline & Legal Milestones
The Delete Act follows a strict phased rollout schedule designed to give data brokers setup time while establishing uncompromising enforcement deadlines.
| Date | Statutory Requirement | Legal & Operational Impact |
|---|---|---|
| January 1, 2024 | Registry Transfer to CPPA | Data broker registration moved from the California Department of Justice to the CPPA. Annual registration fee doubled to fund enforcement. |
| January 31, 2026 | Mandatory Broker Re-Registration | All data brokers doing business in California must register with the CPPA and declare whether they collect sensitive personal data, reproductive health information, or minor data. |
| January 1, 2026 | DROP Consumer Platform Launch | CPPA officially opened the DROP online portal for consumer registration and verifiable deletion request submissions. |
| August 1, 2026 | Mandatory Deletion Processing Deadline | Data brokers are legally obligated to begin querying DROP every 45 days and deleting consumer records across primary and vendor databases. |
| January 1, 2028 | Independent Compliance Audits | Data brokers must undergo triennial independent cybersecurity and privacy audits to verify ongoing compliance with DROP deletion requests. |
How the DROP Platform Works
The Delete Request and Opt-Out Platform operates as a secure government clearinghouse. Here is the step-by-step mechanism of how a deletion request flows from consumer to data broker:
1. Consumer Identity Verification
To prevent malicious actors from deleting records belonging to other people, the CPPA requires consumers to verify their identity through standard single-sign-on or verifiable credentials (such as name, address history, and verified email address).
2. Universal Deletion Dispatch
Once verified, the consumer's deletion request is hashed and cryptographically stored within the DROP queue. The request contains matching data points (such as full name, historical residential addresses, phone numbers, and birth dates).
3. Broker Querying & Execution
Starting August 1, 2026, all registered data brokers must access DROP at minimum every 45 days. The broker runs the DROP batch file against its active databases:
- Exact Match: The consumer's profile, historical records, location data, and associated phone numbers are permanently deleted from active databases and backup files.
- Service Provider Downstream Cascade: The data broker must forward the deletion order to all downstream service providers, data purchasers, and marketing partners who acquired the data within the preceding 12 months.
- Unverifiable Match Fallback: If a broker cannot definitively confirm identity for deletion, SB 362 requires the broker to treat the request as an explicit Do Not Sell or Share opt-out.
California Delete Act (SB 362) vs. Other Privacy Frameworks
While SB 362 is currently the most aggressive state-level data broker legislation in the United States, consumers often wonder how it compares to the EU's GDPR or other state comprehensive privacy laws (such as Virginia VCDPA, Texas TDPSA, and Colorado CPA).
| Feature / Law | California SB 362 (DROP) | EU GDPR | Virginia VCDPA / Texas TDPSA |
|---|---|---|---|
| Centralized One-Stop Deletion | Yes (Government DROP Portal) | No (Direct request to each company) | No (Individual request required) |
| Covered Entities | Registered Data Brokers | All Commercial Entities | Large Controllers / Data Brokers |
| Deletion Frequency Obligation | Access & delete every 45 days | 30 days per individual request | 45 days per individual request |
| Downstream Cascade Mandate | Explicit (Must notify contractors) | Explicit (Article 17 right to erase) | Partial (Reasonable effort) |
| Mandatory Penalties | $200/day per unfulfilled request | Up to 4% global annual turnover | Up to $7,500 per violation |
| Independent Audit Mandate | Yes (Every 3 years starting 2028) | No statutory audit mandate | No statutory audit mandate |
Key Limitations of the California Delete Act: Why DROP Isn't Enough Alone
While SB 362 is a landmark victory for privacy rights, relying solely on state-level government portals leaves critical security coverage gaps:
1. California Jurisdiction Limit
SB 362 directly governs registered data brokers operating in California or processing data of California residents. While many national data brokers apply California opt-outs nationwide to simplify compliance, brokers with no California nexus or non-compliant off-shore people-search sites remain outside DROP enforcement.
2. Unregistered & Illegal Data Aggregators
The CPPA maintains a public registry of compliant data brokers. However, hundreds of obscure shadow brokers, scrapers, dark web database compilers, and offshore background search engines refuse to register with state authorities. These rogue platforms will never query the DROP platform.
3. Re-Listing & Groundhog Day Re-Ingestion
Public records (such as property deeds, marriage licenses, voter registration rolls, and court filings) are updated continuously by county clerks. When a data broker re-scrapes public records 60 days after executing a DROP deletion, your profile can be automatically re-created unless ongoing deletion requests are continuously resubmitted.
4. Dark Patterns & Direct Site Search Results
Search engines like Google and Bing cache people-search results directly from broker pages. While a broker may process a DROP request within 45 days, removing immediate live links from Google search results often requires direct webmaster removal requests and cache purging tools.
How OfflistMe Complements the Delete Act
OfflistMe is engineered to bridge the exact gaps left by government platforms like DROP:
- Nationwide Coverage: OfflistMe targets over 500+ curated data brokers, people-search websites, and credit header aggregators nationwide regardless of state residency.
- Direct Authority Opt-Outs: Instead of waiting up to 45 days for a periodic batch query, OfflistMe dispatches direct automated opt-out payloads to data brokers within hours.
- Continuous Re-Listing Defense: OfflistMe continuously monitors public registries and re-scraped databases, immediately neutralizing re-indexed profiles before they resurface.
- Zero-Data Privacy Architecture: Unlike legacy data removal subscription services that store your sensitive information on central servers indefinitely, OfflistMe processes removals directly through client-side encryption and zero-data retention pipelines.
Frequently Asked Questions (FAQs)
Is the California DROP platform free to use?
Yes. The CPPA operates the DROP platform as a free public service funded by annual data broker registration fees.
Do I have to live in California to benefit from SB 362?
Technically, SB 362 grants statutory rights to California residents. However, because data brokers find it technically complex to segregate state records, many major data brokers honor DROP deletion requests across their entire US database.
What happens if a data broker ignores a DROP request after August 1, 2026?
The CPPA has statutory authority to levy administrative fines of $200 per day per unfulfilled request, along with mandatory cost recovery fees. Consumers can also file administrative complaints directly with the CPPA.
How quickly does my data disappear once submitted to DROP?
Brokers are legally required to access DROP every 45 days. Therefore, total removal across all compliant brokers can take up to 45 to 90 days after submission, depending on where the submission falls within a broker's query cycle.
Summary Checklist for Total Privacy Protection
- [x] Submit your verifiable deletion request through California's DROP platform.
- [x] Freeze your credit reports at Equifax, Experian, TransUnion, and Innovis.
- [x] Opt out of high-impact people-search brokers (Whitepages, Spokeo, BeenVerified, FastPeopleSearch).
- [x] Deploy an automated removal engine like OfflistMe to clean non-registered brokers, shadow scrapers, and ongoing re-listing risks.
Understand your privacy rights
Every removal request cites a specific statute. These plain-English explainers show what each law covers and how enforcement actually works.
Related Data Broker Removal Guides
Take back your privacy today
Remove your personal information from data brokers and platforms in seconds.
Remove Your Personal Data NowFrom $7.00 one-time · 545 data brokers · No subscription
