California Puts Data Brokers On Notice
Coverage from CalMatters, Governor of California, and others

California is moving from company-by-company privacy requests to state-managed deletion of residents’ information held by registered data brokers.
Through the Delete Request and Opt-out Platform, or DROP, one verified request can reach hundreds of brokers, which must process deletions, monitor for newly acquired data, and report compliance under California Privacy Protection Agency oversight. The development increases operational and enforcement obligations for brokers while highlighting California’s broader role in shaping privacy rules amid limited federal regulation and unsettled litigation over website tracking.
The current version largely confirms the existing implementation story, while clarifying the program’s scale and framing related tracking disputes across a broader set of online tools.
The current version largely confirms the prior account: DROP remains in operational rollout with the same timeline, broker duties, and enforcement framework. No materially new event, actor, or outcome is introduced.
DROP’s enforcement mechanics are now more concretely defined: brokers must report outcomes and continue removing newly acquired data. The parallel CIPA issue is framed less as a single pending bill and more as active litigation creating uncertainty around common tracking tools.
The main new development is that SB 690 has passed the legislature and is awaiting gubernatorial action, potentially shifting specified CIPA claims from private lawsuits to Attorney General enforcement. DROP’s implementation is largely confirmed rather than materially changed.
California’s Delete Act has moved beyond rollout into active enforcement, with the CPPA issuing its first reported data-broker order against LocateSmarter. This provides concrete evidence that noncompliance now carries operational and financial consequences, while CIPA litigation remains unresolved.
The story is now framed more squarely as an implementation update: California has moved DROP into an active Delete Act rollout with explicit timelines, recurring broker duties, and enforcement penalties. The new version also narrows the broader context by dropping the earlier SB 690 and gig-economy angles, leaving the main issue as whether DROP can reach all brokers and function at scale.
The story has shifted from rollout and compliance planning to active enforcement, with CalPrivacy now auditing the sector and documenting concrete failures in broker response and registry coverage. It also broadens into a second regulatory front, as SB 690 could reshape website-tracking litigation while gig platforms come under scrutiny for data-use practices.
- CalPrivacy has begun its first formal sectoral audit.
- Reported DROP enrollment exceeded 322,000 residents by July 1, 2026.
- The state registry contained nearly 600 data brokers.
- SB 690 would restrict certain private CIPA website-tracking claims.
- Gig economy platforms are now under scrutiny for algorithmic data use.
The story has shifted from a general rollout of California’s DROP system to a more operational phase, with enforcement, compliance sweeps, and penalties now taking center stage. It also newly highlights that the program covers especially sensitive categories of personal data and that other states are actively considering similar systems.
The story has shifted from general implementation of California’s Delete Act to a more concrete, enforcement-centered phase: DROP now has a firm start date for deletion processing, and regulators are explicitly extending pressure to unregistered brokers. The framing also broadens from California-only compliance to a potential model for other states amid limited federal action.
- Broker deletion processing begins August 1, 2026.
- Noncompliance penalties can reach $200 per affected person per day.
- CPPA is using a dedicated data broker strike force.
- Other states are considering California-style data broker rules.
- Federal data broker regulation remains limited.
The story now adds concrete implementation and enforcement detail: CPPA is not only running DROP but also broadening broker compliance obligations through audits, deadlines, penalties, and shutdown actions. It also newly splits out a parallel California tracking-litigation thread, showing the broader privacy fight extends beyond data brokers.
- Expanded broker definitions and audit requirements were added.
- Shutdown and settlement actions against noncompliant brokers are now mentioned.
- Separate litigation over website tracking and pixels under CIPA is now included.
- California courts and ad-tech vendors are newly part of the story.
- Mandatory broker processing schedules are now described as in place.
The update provides concrete evidence that DROP is operating at scale, with substantial early consumer uptake and defined 2026 compliance deadlines. It reinforces the shift from policy development to trackable enforcement rather than materially changing the broader story.
The story has shifted from a narrow focus on DROP uptake and broker compliance into a broader enforcement regime, with CPPA actions now extending to privacy-rights violations beyond registration and deletion. California is also adding adjacent compliance layers and widening the policy frame with federal and cross-border privacy implications.
- CPPA is investigating privacy-rights failures beyond broker registration.
- California is adding cybersecurity audit, risk-assessment, and automated decision-making requirements.
- Cross-border EU adequacy and federal preemption concerns are now part of the story.
- Legislative proposals remain pending, with enactment uncertain.
The cluster is dominated by California's operational rollout of the Delete Act through the DROP platform, paired with increasingly active CPPA enforcement against data brokers. The current signal centers on growing resident participation, broker registration and compliance deadlines, strike-force-led enforcement, and additional legislative proposals that would further tighten deletion timelines and sensitive-data limits.
