Skip to main content
California Law · Updated August 25, 2026

The California Delete Act (SB 362)

A plain-English guide to SB 362, the CPPA DROP mechanism, current broker timing, scope, exceptions, and evidence-aware next steps.

Rahul Kandoriya
Written byRahul Kandoriya·Founder, OfflistMe·Last updated August 25, 2026

Quick summary

  • What: SB 362 created DROP, a centralized mechanism for a single verifiable request directed to active data brokers covered by California law, subject to exceptions.
  • Who: California residents may use it subject to the current CPPA process, verification requirements, statutory exceptions, and matching limits.
  • When: Consumers can submit DROP requests; the CPPA says brokers must begin processing them from August 1, 2026 and access DROP at least every 45 days.
  • Cost: Free through the portal. Private services may charge a convenience fee.
  • Today: CCPA provides a separate business-by-business route, subject to scope, verification, and exceptions. You can also use the live DROP process or prepare user-reviewed requests for selected catalog profiles with OfflistMe.

1. What does SB 362 actually do?

Signed into law by Governor Gavin Newsom on October 10, 2023, the Delete Act (SB 362, Becker) directs the California Privacy Protection Agency to build a single website through which a California resident can submit a deletion request to active data brokers covered by California law.

Before DROP, exercising a CCPA deletion right generally meant contacting each business individually. DROP adds a centralized mechanism for covered active data brokers, but it does not change every provider's scope, verification, exception, matching, or downstream-copy behavior.

2. When does SB 362 kick in?

  1. October 10, 2023
    SB 362 signed into law by Governor Newsom.
  2. January 1, 2024
    The CPPA assumed administration, enforcement, and rulemaking authority for the state data broker registry.
  3. January 1, 2026
    CPPA rules for the accessible deletion mechanism took effect.
  4. August 1, 2026
    The CPPA says data brokers must begin processing DROP requests.
  5. At least every 45 days
    Data brokers must access DROP and process requests within the required timeline, subject to the law and its exceptions.
  6. January 1, 2028
    Data brokers must undergo independent audits every 3 years (first audit due by this date).

3. What rights does SB 362 give you?

One-request mechanism

A single verifiable request can be directed to active data brokers covered by the mechanism, subject to exceptions and matching.

Non-exempt data

The CPPA describes the mechanism as covering deletion of non-exempt personal information within the statutory scope.

Recurring access

The CPPA says brokers must access DROP at least every 45 days and report request status within the required timeline.

State-run route

DROP is separate from paid research or request-preparation services; check the current CPPA consumer instructions for access details.

Authorized agent

The mechanism supports an authorized agent subject to the current CPPA process, but OfflistMe uses a first-party workflow: you review and send the generated request yourself.

Verification matters

A request is verifiable under the current CPPA process; do not assume that no provider may request additional matching evidence.

4. Which brokers must comply?

Any business that qualifies as a "data broker" under California law (Cal. Civ. Code §1798.99.80), a business that knowingly collects and sells the personal information of consumers with whom it has no direct relationship, must register annually with the CPPA. The registry is public and searchable.

The official registry is live and changes over time. Use it to check a business's registration and current information rather than relying on a static count. The statutory definition, registration duties, active status, exceptions, and DROP processing obligations are related but not interchangeable; consult the current CPPA guidance and law for a specific broker.

Check the live registry

Search the live registry and current CPPA guidance; registration alone is not a substitute for checking the request's scope and exceptions.

cppa.ca.gov/data_broker_registry ↗

5. Delete Act vs CCPA. What's the Difference?

 CCPA (§1798.105)SB 362 (Delete Act)
ScopeA covered business and the request-specific rights/exceptionsActive data brokers and non-exempt data within the Delete Act mechanism
How to requestUse the business's current first-party routeUse the CPPA DROP mechanism
Current statusExisting California routeConsumers can submit; broker processing began August 1, 2026 under CPPA guidance
Matching/repeat checksProvider-specific follow-upBrokers must access DROP at least every 45 days and process within the required timeline
ExceptionsCCPA/CPRA exceptions applyDelete Act and implementing-rule exceptions apply
Agent allowedYesYes
EnforcementCPPA + AGCPPA administration and statutory penalties; separate CCPA routes may apply

6. What can you do today?

DROP is now the centralized California route described by the CPPA, while CCPA requests to individual businesses remain available subject to scope, verification, and exceptions. Here are three ways to plan the work:

Option 1. Use the official DROP route

Start with the current CPPA consumer instructions. Record eligibility, verification, status, exceptions, and any broker-specific follow-up rather than assuming the request covers every copy.

Privacy note: DROP verifies California residency before submission. Its current Terms say that submitting a request consents to disclosure of the personal information you provide to data brokers for processing. The consumer guidance describes encryption and hashed matching; review the live Terms and provide only information you are comfortable submitting.

Full manual guide →

Option 2. Prepare selected requests with OfflistMe ($9 once) user-reviewed

Prepares user-reviewed request drafts and route links for the catalog profiles you choose. You review and send them from your own inbox; this is separate from DROP and does not guarantee a provider outcome.

Start for $9 →

Option 3. Compare provider-managed services

Review each service's current price, named source scope, authorization model, monitoring, renewal, evidence, and outcome limitations. Do not treat a plan price or coverage count as a removal guarantee.

Compare services →

Generate requests in under 60 seconds

Generate Your Opt-Out Requests

CCPA routes and DROP have different scopes. OfflistMe prepares user-reviewed requests for selected catalog profiles for $9; you send them yourself and keep the evidence trail.

7. How is SB 362 enforced and what are the penalties?

The CPPA administers the Delete Act's data-broker registry and deletion mechanism. Other CCPA enforcement routes may involve the California Attorney General; do not treat them as the same authority. Under the current Delete Act text:

  • Failure to register: $200 per day while required registration is missing

    Confirm the entity's status, registration duty, and applicable law before applying the penalty.

  • Failure to delete after a covered request: $200 per request per day

    The statutory amount and applicable exceptions depend on the request, entity, and facts.

  • Audit duty: independent audit begins January 1, 2028 every 3 years

    Audit reports and related materials must be provided within 5 business days of a written CPPA request; the statutory text reviewed here does not state a standalone fixed audit penalty.

  • Consumer complaints

    Use the current CPPA complaint or enforcement information; a California Attorney General privacy complaint route is separate.

Primary Sources & Authorities

8. FAQ

What is the California Delete Act?+

The California Delete Act (SB 362) requires the California Privacy Protection Agency (CPPA) to provide an accessible deletion mechanism. DROP lets a California resident submit a single verifiable request directed to active data brokers covered by the mechanism, subject to statutory exceptions and the provider matching process.

When does the California Delete Act take effect?+

The Delete Act required the CPPA to establish the accessible deletion mechanism by January 1, 2026. The CPPA says data brokers must begin processing DROP requests on August 1, 2026, access the mechanism at least once every 45 days, and report request status within the required timeline. Check the live CPPA and DROP pages for current availability and exceptions.

Do I have to wait for the portal to go live?+

No. California residents already have a CCPA route for a request to an individual business, subject to verification and exceptions. DROP is a separate centralized mechanism for covered active data brokers. OfflistMe prepares user-reviewed request drafts for the catalog profiles you choose; it does not submit to DROP or guarantee a provider outcome.

Which data brokers are covered by SB 362?+

Use the live CPPA Data Broker Registry and the DROP information pages to check a business, its registration status, and the current scope of the mechanism. Registration, active operation, statutory exceptions, and the provider matching process all matter; a third-party catalog count is not a substitute for the official registry.

Does the California Delete Act cover non-Californians?+

DROP is the California mechanism and its eligibility is defined by California law and the current CPPA process. Residents elsewhere must check the privacy rights, scope, verification rules, and request routes that apply in their own jurisdiction; do not assume another state has an equivalent portal.

What is the difference between the CCPA and the Delete Act?+

The CCPA provides a direct request route to a covered business, subject to its own verification and exceptions. SB 362 adds DROP, a centralized mechanism through which a California resident can make one verifiable request directed to active data brokers covered by the Delete Act. The routes have different scope and operational steps.

Can I sue a data broker for ignoring my deletion request?+

The CCPA does not create a general private right of action for an ordinary deletion-request failure. Enforcement routes and penalties depend on the applicable provision and mechanism. Preserve your request, verification, response, and re-check evidence, then use the current CPPA or California Attorney General complaint route where appropriate.

Will the CPPA portal charge a fee?+

The current statute says the accessible deletion mechanism may not charge a consumer, and the CPPA consumer page describes DROP as free. Private services that help with research or request preparation may charge a convenience fee and are separate from the state portal.

Related Resources

Generate requests in under 60 seconds

Generate Your Opt-Out Requests

DROP and business-by-business CCPA requests have different scopes. OfflistMe prepares user-reviewed requests for selected catalog profiles for $9; you send them yourself and retain the evidence trail.