Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Delete Act Compliance topic

No spam. Unsubscribe anytime.

California Privacy Protection Agency urges data brokers to prepare for Drop workflow, warns of steep daily penalties

California Privacy Protection Agency · June 11, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

In a webinar, Cal Privacy detailed the Drop deletion workflow and critical deadlines: brokers must begin processing deletion requests on Aug. 1 and complete reporting within 45 days of each download. The agency reiterated enforcement tools and monetary penalties tied to registration and failure to process requests.

Marissa Rosenblatt, assistant deputy director for the Delete Act at the California Privacy Protection Agency, opened a webinar for data brokers explaining how to process consumer deletion requests through Drop, the state'mandated centralized Delete Request and Opt'Out Platform. She called the system "designed to be simple, accessible, and of course it's free for consumers to use."

Liz Allen, an attorney working on Drop, said the Delete Act has four major components including annual registration, a July 1 privacy'policy reporting requirement and forthcoming audit obligations. "Coming 2028, you'll need to complete an independent third'party audit of the deletion request processing flow," Allen said, noting brokers should prepare how they will demonstrate compliance to auditors.

Allen also outlined enforcement risks. She said failure to register can trigger a $200 per day penalty plus registration fees and agency costs, and that failure to process deletion requests carries a penalty of $200 per day per consumer. Citing the agency'shared totals, Allen observed Drop has received more than 300,000 requests to date and noted the potential scale of noncompliance exposures if processing lapses.

Agency presenters emphasized Drop'specific deadlines: August 1 is the date the obligation to begin processing deletion requests takes effect, and brokers must download their first consumer deletion list within 45 days of that date (the agency noted Sept. 14 as an example deadline). After each download, brokers have 45 days from that download date to upload a response that includes a status for every record.

The status codes accepted by Drop are limited and prescriptive: deleted, exempted, opted out, or not found. Marissa Rosenblatt stressed that the 45'day clock begins at the download date, not at the time a broker completes hashing or matching work.

Panelists also described broader operational obligations: maintain suppression (screening) lists so consumers do not have to resubmit requests, direct service providers and contractors to delete matched records, and be prepared to demonstrate compliance (logs, timestamps, record counts) for the forthcoming audit regime.

The agency encouraged data brokers to create or confirm active Drop accounts, use the sandbox and technical documentation linked in Drop and on privacy.ca.gov/databrokers, and to contact the agency via the Drop "Contact Us" form with implementation questions. The webinar was recorded and the agency said materials would be shared with attendees; an additional session was announced for the following Thursday.