California Delete Act regulations and dates
SB 362 — the California Delete Act — is the statute. Cal. Code Regs., tit. 11 §§ 7610–7616 are the regulations that implement it. This page lines up both against the actual dates so you can see what applies when.
Is there a single "effective date"?
No — the Delete Act took effect in phases, and "California Delete Act effective date" doesn't have one clean answer. SB 362 became law in October 2023, but the duties it created switched on at different points over the following three years.
| Date | What took effect |
|---|---|
| 2019 (AB 1202) | The California data broker registry itself — SB 362 kept this, it didn't create it. |
| October 2023 | SB 362 is signed into law, adding the deletion mandate and requiring CalPrivacy to build DROP. |
| Every Jan 1–31 | Annual data broker registration window (Civ. Code § 1798.99.82(a)) — an existing duty SB 362 left in place. |
| January 1, 2026 | CalPrivacy's statutory deadline to have DROP running (Civ. Code § 1798.99.86(a)). |
| March 2026 | DROP Sandbox opens for brokers to test hashing and integration against fake data. |
| August 1, 2026 | Brokers must begin processing deletion requests through DROP — the first real compliance deadline. |
| Every 45 days after Aug 1, 2026 | The processing cycle repeats indefinitely; there's no end date in the statute. |
Why the rollout is phased instead of a single date
The registration duty predates SB 362 by four years and never paused; the deletion duty is brand new and needed a platform built from nothing, which is why CalPrivacy got a separate runway — a January 2026 launch deadline, two months of sandbox testing, then a live processing deadline in August. Nothing in the statute grandfathers a broker in based on when it first registered: a business that has been on the registry since 2019 faces the same August 1, 2026 processing deadline as one that registers for the first time in January 2027, because the deletion duty is tied to current registry membership, not tenure on it.
The regulations behind the statute
SB 362 itself sits in Civil Code Title 1.81.48 (§§ 1798.99.80–1798.99.89). The mechanics brokers actually have to follow — which lists to select, how to report a broken connection, and so on — live in CalPrivacy's implementing regulations at Cal. Code Regs., tit. 11 §§ 7610–7616. Two sections come up constantly in practice:
- § 7610(a)(3) — you can skip a deletion list only if selecting it would match the exact same consumers as a list you already selected.
- § 7612(b)(1) — if your automated connection to DROP fails, you must notify CalPrivacy in writing through your DROP account within 45 days.
Registration-side rules sit slightly apart: Civil Code § 7604(b) is what limits which registry fields you can correct after the January window closes.
The two duties, restated
Everything above resolves to two independent obligations. See California data broker registration and what the DROP program is for each in detail:
- Register every January for the prior calendar year and pay the fee.
- Process DROP deletion requests at least every 45 days, starting August 1, 2026.
Registering doesn't discharge the processing duty, and processing on time doesn't excuse a missed registration — CalPrivacy enforces them separately. See California DROP program requirements for the broker-side checklist.
Recordkeeping
The regulations don't lay out a formal audit calendar, but the practical expectation is continuous: keep evidence of what you ran, when, and against how many records for every 45-day cycle. If CalPrivacy ever asks why a request shows as "Not found," a broker with no record of the matching run it claims to have done is in a much worse position than one with a dated log. That evidence trail matters most for the "Opted out" and "Exempted" statuses, since both require you to justify a decision other than outright deletion if a consumer or CalPrivacy later disputes it.
Penalties
| Failure | Fine | Authority |
|---|---|---|
| Not registered | $200 per day, plus fees owed, plus CalPrivacy's investigation costs | § 1798.99.82(c) |
| Not processing deletion requests on time | $200 per unprocessed request, per day, plus CalPrivacy's costs | § 1798.99.82(d) |
The second fine is the one that scales: a single missed request left open for a month is $6,000; a hundred of them left open for a week is $140,000. Enforcement is by administrative action brought by CalPrivacy, and recovered amounts go to the Data Brokers' Registry Fund (§ 1798.99.82(e)).
Drop45 does the matching half of this. Upload a DROP consumer deletion list and your own records; standardization, SHA-256 hashing and matching all run in your browser, so consumer data never leaves your machine. Free for up to 500 records per run.
Names and bills people mix up
There's no statute called the "California DROP Act" — DROP is the platform's name, not a bill; the law is SB 362, the Delete Act. SB 362 is also not SB 361, a separate and later bill about data broker disclosure requirements — the two get swapped constantly in secondhand summaries because the numbers are one digit apart.
Frequently asked questions
What is the California Delete Act effective date?
There isn't one single date. SB 362 was signed in October 2023, DROP had to be running by January 1, 2026, and the first real processing deadline for brokers is August 1, 2026.
What regulations implement the Delete Act?
Cal. Code Regs., tit. 11 §§ 7610–7616, issued by CalPrivacy under the authority SB 362 grants it.
Do the regulations exempt small data brokers?
No. Neither SB 362 nor its implementing regulations set a revenue or headcount threshold — registry membership is the only test.
Where do I check the requirements broker-by-broker?
See California DROP program requirements for the checklist version of everything on this page.