Long Read · August 8, 2026 · 2 min read

California DROP Portal Enforcement Launches August 1, 2026: What Data Brokers Must Know

Beginning August 1, 2026, data brokers registered in California must begin processing consumer deletion requests submitted through the Delete Request and Opt-Out Platform,…

Beginning August 1, 2026, data brokers registered in California must begin processing consumer deletion requests submitted through the Delete Request and Opt-Out Platform, commonly referred to as DROP. Established under the California Delete Act, the DROP portal represents a significant shift in how personal information deletion requests are administered in the state, consolidating what has historically been a fragmented, broker-by-broker process into a single, centralized mechanism. For businesses that meet California's data broker registration requirements, the launch of enforcement marks the transition from preparation to active compliance, and internal readiness will be tested from day one.

The DROP system is designed to empower California residents to exercise their deletion rights efficiently. With a single request submitted through the platform, a consumer can compel hundreds of registered data brokers to delete their personal information. This represents a substantial expansion of practical consumer privacy rights, shifting the administrative burden from individuals to the businesses that collect, process, and sell personal information. Data brokers should anticipate a meaningful increase in the volume of deletion requests they receive, particularly in the initial months following the enforcement date.

Compliance timelines are central to avoiding enforcement risk. Data brokers are subject to defined obligations of 45 to 90 days for status reporting in connection with deletion requests processed through the DROP portal. These windows demand disciplined internal workflows, including verified intake procedures, coordination with downstream data recipients, accurate record-keeping, and reliable status confirmation protocols. Businesses that lack automated tooling or clearly documented response procedures may find it difficult to meet these deadlines consistently, particularly if request volumes exceed initial projections.

In the weeks leading up to and following August 1, 2026, data brokers should consider conducting focused compliance audits. Key areas of review include registration status, DROP portal integration readiness, personnel training, vendor coordination protocols, and internal escalation paths for atypical or complex requests. A well-structured compliance program will not only reduce enforcement exposure but also demonstrate good-faith engagement with California's evolving privacy framework.

This article is provided for general informational purposes only and does not constitute legal advice. Businesses with specific questions about their obligations under the California Delete Act or the DROP portal should seek tailored advice from qualified counsel.