If your business buys, enriches, or resells consumer data about people who never bought anything from you, a compliance clock started running on Saturday. Under California’s Delete Act, data brokers had to begin pulling consumer deletion requests from the state’s new platform on August 1, 2026, and they now have to do it at least once every 45 days.
The penalty for missing it is $200 per day, per deletion request.
Most store owners will read that and assume it does not apply to them. Some of them will be wrong.

What actually changed on August 1
California’s Delete Act (Senate Bill 362, signed in October 2023) created something no other state has: a single form that lets a resident tell every registered data broker at once to delete their personal information. The California Privacy Protection Agency, which now brands itself CalPrivacy, built it and called it DROP, short for Delete Request and Opt-Out Platform.
Consumers have been able to submit requests since January 1, 2026. Brokers were not required to act on them yet. That grace period is over.
According to CalPrivacy’s guidance for data brokers, from August 1 a registered broker must download the consumer deletion lists, standardize and hash its own customer records, match them against the list, delete what matches, and report the status of each request inside DROP within 45 days. Then repeat the cycle. Requests submitted before August 1 were queued and are now in that first batch.
This is not a one-time cleanup. It is a recurring operational process on a 45-day heartbeat, in perpetuity.
You may be a data broker without ever calling yourself one
California’s definition is short and much broader than the phrase suggests. Under Civil Code section 1798.99.80(c), a data broker is a business that “knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship.”
Read that again, because the trap is in the last nine words. The test is not whether data is your main business. The test is whether the people in the data know who you are.
Writing for Alston & Bird’s Privacy, Cyber & Data Strategy blog in July 2026, associate Santi Villar noted the definition “is broad enough to capture many companies that do not view themselves as traditional data brokers,” and flagged adtech platforms, analytics providers, audience-segment sellers, people-search services, marketing vendors, and companies that monetize aggregated consumer datasets as groups that should check their status.
Translated into e-commerce terms, you should look closely if you:
- Buy third-party email or postal lists, append them to your own records, and sell or license any of that back out
- Run a marketplace, directory, or lead-gen operation that resells enquiry data to other merchants
- Sell or share audience segments built partly from purchased data
- Operate a review, comparison, or coupon site that monetizes visitor data beyond your own advertising
There are carve-outs. Alston & Bird notes that businesses subject to the Fair Credit Reporting Act, HIPAA covered entities and business associates, and financial institutions under the Gramm-Leach-Bliley Act are not data brokers under the Delete Act. Selling only to people you have a direct relationship with also keeps you out.

The fines are already real
CalPrivacy has not been shy. On January 8, 2026, the agency announced two settlements from its Data Broker Enforcement Strike Force.
Rickenbacher Data LLC, doing business as Datamasters, a Texas reseller of personal information for targeted advertising, was ordered to pay a $45,000 fine for failing to register as a data broker, and ordered to stop selling all Californians’ personal information. According to the agency’s decision, Datamasters bought and resold contact details of millions of people with conditions including Alzheimer’s disease and drug addiction, plus lists segmented by age, perceived race, and political views.
The second decision hit S&P Global with a $62,600 fine for failing to register, which the agency described as an administrative error, along with a requirement to build registration and compliance auditing procedures.
“Reselling lists of people battling Alzheimer’s disease is a recipe for trouble,” said Michael Macko, CalPrivacy’s head of enforcement, in the announcement.
The registration failure alone carries $200 per day. Miss a filing for a year and the arithmetic gets ugly before anyone looks at your deletion queue. For context on how the same agency treats ordinary retailers, its September 2025 decision required Tractor Supply Company to pay $1.35 million for CCPA violations.
The clause most people miss: a failed match becomes an opt-out
Here is the detail buried in the mechanics. If a broker denies a deletion request because it cannot verify the consumer, it does not get to close the ticket. Alston & Bird points out that the Delete Act requires the broker to process that request as an opt-out of sale or sharing instead, and to direct its service providers and contractors to do the same.
So DROP readiness is not just a deletion script. It touches suppression lists, vendor contracts, and every downstream system that could quietly repopulate a deleted record from a backup or a fresh data purchase next month. If your suppression list does not survive your next data append, you have not solved the problem, you have scheduled it.
This is the same operational pattern that trips stores up on payment compliance. If you have not audited your third-party scripts lately, our breakdown of how checkout pages quietly break PCI rules covers the same class of blind spot.

What to do this week
Five steps, in order.
1. Answer the direct-relationship question honestly. Map every dataset you sell, license, append, or syndicate. For each one, ask whether the consumers in it have a direct relationship with your business. If any bucket fails that test, you are potentially in scope.
2. Check the registry. CalPrivacy publishes the public data broker registry. If you should be on it and are not, registration runs January 1 to 31 each year, and the 2026 fee was $6,000 plus payment processing. Waiting quietly is the expensive option.
3. Build the match pipeline before the volume arrives. The process requires hashing your own records to compare against the state’s lists. That is an engineering task, not a legal memo. CalPrivacy opened a DROP sandbox in March 2026 for exactly this.
4. Make suppression permanent. A deleted consumer must stay deleted, including in data you acquire later. Test that by running a fresh append against your suppression list and confirming nothing comes back.
5. Push the obligation down your vendor chain. Service providers and contractors have to delete too. If your contracts do not say so in writing, fix the contracts.
Why this matters even if you sell nothing but your own products
Two reasons.
First, the vendors you buy audiences from are in scope, and the ones that comply properly are about to have smaller, more expensive files. Expect list quality and match rates to move. Budget for it.
Second, California keeps setting the template other states copy. Senate Bill 361, passed in 2025, already expanded what brokers must disclose at registration, including whether they have shared data with foreign actors, law enforcement, or developers of generative AI systems. From January 1, 2028, brokers face independent third-party audits every three years.
The pattern is familiar to anyone who watched accessibility rules move from guidance to courtroom, or who dealt with the AI chatbot disclosure deadline in July. Regulators publish a date, most businesses treat it as advisory, and then a strike force shows up with a decision letter.
The businesses that got the AI disclosure requirement right did one boring thing: they checked whether the rule applied to them before assuming it did not. That is the whole job here too. Twenty minutes of dataset mapping this week is cheaper than $200 a day.
Sources
- CalPrivacy (California Privacy Protection Agency), “DROP for data brokers” — processing obligations from August 1, 2026, the 45-day cycle, registration fee, and penalty amounts
- CPPA, “Delete Request and Opt-Out Platform (DROP)” information for data brokers — account creation, SB 361 disclosures, 2028 audit requirement
- CPPA announcement, January 8, 2026: “CalPrivacy Brings New Round of Enforcement Actions Against Data Brokers” — Datamasters and S&P Global decisions and fines
- Alston & Bird Privacy, Cyber & Data Strategy Blog, “DROP Is Coming Due,” July 17, 2026 — scope analysis, exemptions, and the unverified-request-becomes-opt-out point
- California Senate Bill 362 (Delete Act), California Legislative Information
- Kathryn M. Rattigan, Robinson & Cole LLP, via The National Law Review, March 5, 2026 — CPPA-reported figures of more than 575 registered brokers and over 242,000 resident signups, with more than 18,000 deletion requests in the first 48 hours
Last reviewed: August 3, 2026.
This article is general information, not legal advice. If you think the Delete Act may apply to your business, talk to a privacy lawyer.
Affiliate disclosure: e-commpartners.com may earn a commission from links in our articles, at no additional cost to you. This does not affect our editorial opinions or the sources we cite.









