California's DELETE Act Platform Went Live: The 45-Day Clock Data Brokers Now Face

California's DELETE Act moved from statute to standing operational duty on 1 August 2026, when the Delete Request and Opt-Out Platform — DROP — hit its first major compliance milestone.

The mechanism is deliberately simple. Rather than sending individual deletion requests to hundreds of data brokers, a California consumer submits one request through a single state-run platform. Registered data brokers are then required to come to the platform, collect the requests, and act on them.

That inversion is what makes this different from previous privacy obligations. The consumer no longer chases the broker. The broker must check, on a clock, forever.

⚠️ Important: ⏱️ THE 45-DAY CYCLE IS NOW LIVE: Since 1 August 2026, every registered data broker must access California's DROP platform at least once every 45 days, process the deletion requests waiting there, and delete covered personal information within 45 days. This is a recurring obligation with no completion date — missing a single cycle is a compliance failure, and the CPPA can levy civil penalties of up to $2,500 per violation or $7,988 per intentional violation.

What the 1 August Milestone Actually Requires

📋 The recurring obligation in plain terms
Access DROP at least every 45 days — this is a floor, not a target. Checking on day 44 and then day 90 is a failure.
Process the deletion requests found there — matching submitted consumer identifiers against your records.
Delete covered personal information within 45 days of the request.
Maintain records of compliance — you will need to demonstrate the cycle was run, not merely assert it.
The obligation applies to registered data brokers. If your business buys, sells, licenses or shares personal information about California consumers with whom you do not have a direct relationship, review your registration status before assuming this does not reach you. Registration status is the trigger, and the definition captures more businesses than most owners expect.

Why This Is Harder Than It Sounds

⚙️ The operational reality
A 45-day recurring cycle cannot be run manually at scale without eventually missing one. The practical requirements are:
An identity matching process — DROP supplies consumer identifiers, and you must match them against your own records reliably enough to delete the right data and no more.
Deletion that reaches every copy — production databases, analytics warehouses, backups, exports sitting with downstream customers, and any vendor you have shared the data with.
A suppression list — deleting a record without suppressing the identifier means re-acquiring the same consumer from your next data purchase and starting the violation again.
An audit trail — dated evidence of each cycle: when you accessed DROP, how many requests you processed, when deletion completed.
The suppression point is the one most often missed. Deletion without suppression is a loop, not a fix.

Know What You Are Collecting Before You Are Asked to Delete It

Deletion obligations are only manageable if you know what your website collects and which third parties receive it. Run a free privacy scan to map the trackers and data flows on your site. Scan your website now.

What Comes Next: The January 2027 ADM Deadline

📅 The next California date to plan for
California's compliance date for automated decision-making technology is 1 January 2027. If you use automated processing to make or substantially inform significant decisions about consumers — credit, employment, housing, insurance, essential services — the obligations attaching to that use begin then.
Taken with DROP, the direction of travel is clear: California is moving from disclosure-based privacy law, where you tell people what you do, to operational privacy law, where you must run a process on a schedule and be able to prove it.
The organisations that will struggle are those treating each new requirement as a separate project. The ones that will cope have built a single inventory of what data they hold, where it flows, and who else has it. Our guide to the 2026 state privacy landscape covers the wider picture.

The DELETE Act's DROP platform changes the shape of data broker compliance from a filing to a heartbeat. Every 45 days, indefinitely, with penalties attached to each miss.

If you are a registered data broker, the immediate questions are whether the first cycle has been run, who owns it, and whether the deletion actually reaches backups, downstream recipients and your suppression list. If you are not sure whether you are a registered data broker, that is the question to resolve first.

Related reading: California SB 361 and the data broker rules2026 state privacy laws

Disclaimer: This article is general information about California privacy obligations as of August 2026 and is not legal advice. Consult qualified counsel about your registration status and specific compliance duties.

Stay Updated on Privacy & Security Compliance

Get the latest updates on privacy laws, security threats, and compliance requirements.

Read More Articles Test Your Site