Drop45 › Guides

DROP compliance guides

Plain-language guides to California's DROP program for registered data brokers — registration, the 45-day cycle, response file mechanics and the Delete Act timeline. None of this is legal advice; consult a privacy attorney about your specific obligations.

DROP status codes explained: 2, 3, 4, 5

What each response-file status code means, how to build the Id,Status CSV, and how to amend a code you already submitted.

What is the California DROP program?

The Delete Request and Opt-Out Platform explained — what CalPrivacy publishes, what the 45-day cycle requires, and what you send back.

California data broker registration

Who must register, the annual fee and deadline, and how registration decides whether DROP applies to you.

SB 362, the Delete Act

What the law requires of California data brokers from Aug 1, 2026, and how the $200/day penalty is calculated.

California DROP program requirements

The broker-side obligations checklist: the 45-day cycle, matching, status reporting and the ongoing suppression duty.

California Delete Act regulations

A dates-and-duties timeline of SB 362 and its regulations, from registration through the recurring processing deadlines.

California data breach notification law

Who must notify, what triggers it, the AG's 500-resident threshold, and how it ties to CCPA/CPRA and the Delete Act.

California Consumer Privacy Act compliance

A CCPA/CPRA compliance overview and how it relates to a data broker's DROP obligations.