California's DELETE Act moved from statute to standing operational duty on 1 August 2026, when the Delete Request and Opt-Out Platform — DROP — hit its first major compliance milestone.
The mechanism is deliberately simple. Rather than sending individual deletion requests to hundreds of data brokers, a California consumer submits one request through a single state-run platform. Registered data brokers are then required to come to the platform, collect the requests, and act on them.
That inversion is what makes this different from previous privacy obligations. The consumer no longer chases the broker. The broker must check, on a clock, forever.
⚠️ Important: ⏱️ THE 45-DAY CYCLE IS NOW LIVE: Since 1 August 2026, every registered data broker must access California's DROP platform at least once every 45 days, process the deletion requests waiting there, and delete covered personal information within 45 days. This is a recurring obligation with no completion date — missing a single cycle is a compliance failure, and the CPPA can levy civil penalties of up to $2,500 per violation or $7,988 per intentional violation.
What the 1 August Milestone Actually Requires
• Process the deletion requests found there — matching submitted consumer identifiers against your records.
• Delete covered personal information within 45 days of the request.
• Maintain records of compliance — you will need to demonstrate the cycle was run, not merely assert it.
Why This Is Harder Than It Sounds
• Deletion that reaches every copy — production databases, analytics warehouses, backups, exports sitting with downstream customers, and any vendor you have shared the data with.
• A suppression list — deleting a record without suppressing the identifier means re-acquiring the same consumer from your next data purchase and starting the violation again.
• An audit trail — dated evidence of each cycle: when you accessed DROP, how many requests you processed, when deletion completed.
Know What You Are Collecting Before You Are Asked to Delete It
Deletion obligations are only manageable if you know what your website collects and which third parties receive it. Run a free privacy scan to map the trackers and data flows on your site. Scan your website now.
What Comes Next: The January 2027 ADM Deadline
The DELETE Act's DROP platform changes the shape of data broker compliance from a filing to a heartbeat. Every 45 days, indefinitely, with penalties attached to each miss.
If you are a registered data broker, the immediate questions are whether the first cycle has been run, who owns it, and whether the deletion actually reaches backups, downstream recipients and your suppression list. If you are not sure whether you are a registered data broker, that is the question to resolve first.
Related reading: California SB 361 and the data broker rules • 2026 state privacy laws
Disclaimer: This article is general information about California privacy obligations as of August 2026 and is not legal advice. Consult qualified counsel about your registration status and specific compliance duties.