Find a lawyerOur capabilitiesYour career
Locations
Our capabilities
News

Select language:

Locations
Our capabilities
News

Select language:

hamburger menu showcase image
  1. Our thinking
  2. Blogs
  3. A Fresh Take
  4. DROP is Live: What Data Brokers Need to Know as CalPrivacy Ramps Up Oversight
3MIN

DROP is Live: What Data Brokers Need to Know as CalPrivacy Ramps Up Oversight

Subscribe
Aug 20 2026

California’s data brokers are officially on the clock. As of August 1, 2026, data brokers must start processing consumers’ deletion requests on the Delete Request and Opt-out Platform (DROP) mandated by the state’s Delete Act. DROP’s rollout has been staggered: consumers gained access to submit deletion requests on January 1, 2026, and data brokers’ obligations to process consumers’ deletion requests at least once every 45 days have now taken effect (more on the background of the Delete Act here). 

On Friday, August 7, just days into this new phase, and with 345,000+ deletion requests submitted to date, the California Privacy Protection Agency (CalPrivacy) Board met to discuss proposed DROP compliance audit regulations, additional DROP regulations amendments, and key updates on the rollout of data brokers’ obligations.

DROP Compliance Audits

To prepare for the Delete Act’s audit requirements taking effect January 1, 2028, the Board has begun the formal rulemaking process for proposed regulations to establish audits of data brokers’ DROP compliance. Under the proposed regulations, audits must be conducted every three years, and auditors must examine data brokers’ policies and procedures, hashing evidence, deletion commands, system logs, status reports, and suppression lists to assess compliance with DROP. The proposed regulations prohibit auditors, who must be independent third parties, from basing their findings primarily on assertions, attestations, or a review of policies and procedures alone. Instead, auditors must consider and independently verify nine essential components: deletion list selection, DROP access, standardization, hashing, matching, actioning, status reporting, suppression list, and service providers/contractors.

Other Amendments to DROP Regulations

Additionally, CalPrivacy proposed a set of amendments to the general DROP regulations aimed at streamlining and clarifying the existing regulations. The changes touch on three areas: account and registration accuracy, suppression list obligations, and data broker information and status lookup requirements.

On registration, the proposed amendments would remove the current 45-day limit on changing which identifier list a data broker downloads from DROP, allowing data brokers to make real-time adjustments that match their business practices. CalPrivacy expects this change to improve the matching of DROP requests with data broker records.

On suppression list obligations, the proposed amendments would define the term “suppression list” and specify the information a data broker may retain on such a list. They would also require data brokers to screen incoming data against data submitted by consumers who have previously submitted DROP requests, including those for whom no match was initially found, closing a gap where later-acquired data could otherwise evade an earlier deletion or opt-out request.

The proposed amendments would also require data brokers to update their account information, including contact details, within ten business days of any change.

Increase in Data Broker Fees

The CalPrivacy Board also approved an increase in data broker registration and access fees, citing rising administrative costs. Data brokers’ registration and access fees will now be $9,500 for the 2027 registration period, an increase of $3,500 from 2026’s fees, prorated by just under $792 per month based on when a data broker’s DROP obligations begin. 

What’s Next

The Board voted to open a 45-day public comment period on the proposed DROP compliance audit regulations and general DROP amendments. The Board agreed to review comments, finalize the regulations, and have the framework settled well ahead of the first round of data broker audits in 2028. CalPrivacy also unveiled a new guidance resource site aimed at helping data brokers meet their obligations, which can be found here.

The Takeaway

            CalPrivacy’s data broker enforcement has entered into a new phase, and the clock is now ticking on two fronts. Data brokers must now access DROP and process deletion requests at least once every 45 days in accordance with the Delete Act’s requirements, and the public comment period for the proposed regulations is open. CalPrivacy’s moves to increase its oversight and raise registration fees signal that it is ramping up enforcement infrastructure well ahead of the first audits due in 2028.

To receive the latest insights on US legal developments, subscribe to the Freshfields A Fresh Take Blog.

Tags

data cybersecurity and tech regulationregulatory and compliance advisorystate attorneys generalunited states

Authors

San Francisco, Silicon Valley

Megan M. Kayo

Partner
San Francisco

Christine Chong

Senior Associate
New York

Jackson Myers

Associate
New York

Yusuf Tarr

Associate
Latest Insights

Latest Insights

NAVIGATE TO
About usLocations and officesYour careerOur thinkingOur capabilitiesNews
CONNECT
Find a lawyerAlumniContact us
NEED HELP
Fraud and scamsComplaintsTerms and conditions
LEGAL
AccessibilityCookiesLegal noticesTransparency in supply chains statementResponsible procurementPrivacy

Select language:
Select language:
© 2026 Freshfields. Attorney Advertising: prior results do not guarantee a similar outcome