California DROP Watch
This page records what the California Privacy Protection Agency currently says about the Delete Request and Opt-Out Platform (DROP). It is a source-linked checkpoint, not a promise that every broker or downstream copy will be deleted.
Current official checkpoints
Agency mechanism
The CPPA identifies DROP as its accessible deletion mechanism for a California resident's verified request to participating registered data brokers within the Delete Act's covered scope.
Verify at official source →August 1, 2026 duty
Beginning August 1, 2026, covered data brokers must access the accessible deletion mechanism at least once every 45 days and process matched requests under the program rules and exemptions.
Verify at official source →Implementation materials
The CPPA publishes the regulations and system-requirement materials that explain how the mechanism is implemented.
Verify at official source →Statutory broker-audit requirement
Beginning January 1, 2028, and every three years after that, a data broker must undergo an independent third-party audit for compliance with California Civil Code §1798.99.86(e)(1). That is the statute’s own audit-duty start date; the statute does not by itself set a first-report filing deadline.
Verify at official source →Are the DROP-audit rules final?
No, not as of 2026-09-16. The CPPA's own regulations-status page currently states that proposals under “Preliminary Rulemaking Activities” have “not yet advanced to formal rulemaking” and that “the Agency does not have any proposed regulation packages at this time.” The DROP-audits page separately describes the work as the CPPA “exploring whether to adopt regulations to clarify or further specify the audit requirement.”
The CPPA's Board discussed staff recommendations and draft regulatory text — including a draft, not-yet-adopted November 1, 2028 first-report date for a defined group of brokers — at its August 6–7, 2026 meeting. Draft Board materials are not the same as a formally noticed regulation; the CPPA's own FAQ says formal rulemaking begins when a Notice of Proposed Action is published in the California Regulatory Notice Register, and no DROP-audit notice had been published as of 2026-09-16.
What DROP does not establish
- It is not a universal request to every website, data holder, or downstream recipient.
- A submitted request is not proof that a specific record was matched or deleted.
- The 45-day access cadence is not a universal consumer-facing deletion guarantee.
- The January 1, 2028 statutory audit requirement is not the same as the still-preliminary DROP-audit regulations the CPPA is separately considering; the two should not be conflated.
- Users should retain confirmations, check important listings, and follow up when necessary.
Practical next step
Use the current CPPA consumer materials for DROP. For brokers or sites outside its covered scope, send an individual request using the applicable law and the broker's current privacy channel. OfflistMe can prepare a request draft for you to review and send from your inbox; you decide how to verify the result and follow up.
