California DROP program requirements
This is a compliance checklist for registered California data brokers — the businesses that must pull DROP deletion lists and act on them. If you are a California resident who wants your own data deleted, use the state's free consumer platform at privacy.ca.gov/drop instead; the rest of this page does not apply to you.
Who has to meet these requirements
The DROP program requirements bind any business on the public California data broker registry. A data broker, under Civil Code § 1798.99.80(c), is a company that knowingly sells personal information about consumers it has no direct relationship with. There is no revenue or headcount exemption: a two-person lead-gen shop on the registry carries the same DROP duty as a national platform.
Registration and DROP processing are separate obligations with separate deadlines. Registering by January 31 puts you on the registry; being on the registry is what triggers everything below, starting August 1, 2026.
The 45-day pull-and-process cycle
From August 1, 2026, every registered broker must connect to DROP at least once every 45 calendar days and complete a full cycle before that window closes. Missing a cycle does not pause the clock — it exposes you to the per-request fine covered below.
| Step | What it requires |
|---|---|
| Pull | Download your selected deletion list(s) from DROP, by API or manually. After your first pull you receive only new or amended requests. |
| Standardize | Reformat your own records to CalPrivacy's rules — lowercase, strip punctuation, normalize dates/phone/ZIP — then hash them the same way DROP hashes its lists. |
| Match | Compare your hashed records against the DROP hashes you downloaded. |
| Act | Delete non-exempt personal information for every match, or opt the affected consumers out of sale and sharing where an identifier is shared by several people. |
| Report | Upload a status for every request in the list, inside the same 45-day window. |
If your connection to DROP breaks, you must notify CalPrivacy in writing through your DROP account within 45 days rather than letting the cycle lapse silently.
Matching against your own records
DROP publishes hashed consumer identifiers across several lists — see what DROP actually is for the full breakdown of which lists exist and when you're allowed to skip one. The requirement is to select every list whose identifier type could plausibly match someone in your data; you can't narrow your selection just because matching more lists is more work.
The four statuses you must report back
Every request line item in your response file gets exactly one status:
| Status | When it applies |
|---|---|
| Deleted | A match was found and the non-exempt personal information was deleted. |
| Opted out | The matched identifier was shared by more than one consumer, so all of them were opted out of sale and sharing instead of deleted. |
| Exempted | A match was found but the information falls under a CCPA exemption. |
| Not found | No match after running the full matching process. |
The suppression duty doesn't end at "Not found"
A "Not found" result is not the end of your obligation to that consumer. You must keep a running suppression list of everyone who has ever submitted a DROP request and screen every new batch of records you acquire against it before you sell or share it. Treat a deletion request as a standing instruction that outlives the 45-day cycle it arrived in, not a one-time task you close out.
The fine for missing the cycle
Failing to process a request on time carries an administrative fine of $200 per unprocessed deletion request, per day (Civ. Code § 1798.99.82(d)), plus CalPrivacy's investigation costs. This is separate from — and larger in practice than — the $200-a-day fine for failing to register at all, because it multiplies by request count: a hundred requests left unprocessed for a week is $140,000. See SB 362, the Delete Act for how the two fines compare.
Requirements checklist
- Confirm you're on the California data broker registry and current on your annual fee.
- Pick every DROP list whose identifiers could match your records.
- Pull the list(s) on a fixed schedule you can defend — note the pull date, it starts your 45-day clock.
- Standardize and hash your own records to DROP's exact specification.
- Match, then delete or opt out every hit, and instruct any service providers or contractors to do the same.
- Upload your status file inside 45 days of the pull.
- Add every requester to your permanent suppression list.
- Keep evidence of each cycle — what ran, when, against how many records — in case CalPrivacy asks.
Drop45 does the matching step of this checklist. Upload a DROP consumer deletion list and your own records; standardization, SHA-256 hashing and matching all run in your browser, so consumer data never leaves your machine. Free for up to 500 records per run.
Frequently asked questions
Do the DROP program requirements apply to small data brokers?
Yes. The statute sets no revenue or headcount threshold — if you're on the registry, the 45-day cycle applies to you the same way it applies to a large platform.
What's the difference between registering and processing?
Registration puts your business on the public registry and is due every January. Processing is the ongoing 45-day DROP cycle described above, and it's what actually creates deletion obligations. See California data broker registration for the registration side.
Where do these requirements come from?
SB 362, the Delete Act, plus CalPrivacy's implementing regulations. See California Delete Act regulations and dates for the full timeline.
I'm a consumer — how do I get my own data deleted?
Submit a request through the state's free consumer platform at privacy.ca.gov/drop. Everything on this page describes the broker's side of that same request.