Drop45 › DROP guides

SB 362, the Delete Act: what California data brokers must do

SB 362, signed in October 2023 and known as the California Delete Act, is the law that created DROP and rewrote what data broker deletion in California requires.

What SB 362 changed

California had a data broker registry since 2019. SB 362 — the Delete Act — kept it and bolted on something much heavier: a single deletion mechanism that every registered broker has to answer to. That mechanism is DROP, the Delete Request and Opt-Out Platform.

You will see it called the data broker Delete Act, and the data broker deletion California now mandates is entirely a creature of it. The operative text sits in Civil Code Title 1.81.48 (§§ 1798.99.80–1798.99.89), with the processing rules in the implementing regulations at Cal. Code Regs., tit. 11 §§ 7610–7616.

The two duties

  1. Register with CalPrivacy every January 1–31 for the previous year, and pay the fee — see California data broker registration.
  2. Process deletion requests through DROP at least once every 45 days, starting August 1, 2026, and report a status for each one.

They are independent. Registering does not discharge the deletion duty, and being small does not exempt you from either — the California DROP law has no revenue or headcount threshold.

The penalties

SB 362 sets two separate $200-a-day fines, and it is worth being precise about which is which:

FailureFineAuthority
Not registered$200 per day, plus the fees that were due, plus CalPrivacy's costs§ 1798.99.82(c)
Not deleting as required$200 per deletion request, per day, plus CalPrivacy's costs§ 1798.99.82(d)

The second one is the dangerous one, because it multiplies. One missed request left for a month is $6,000. A hundred unprocessed requests accrue $20,000 a day — which is why a missed 45-day cycle is not a small administrative slip.

Enforcement is by administrative action brought by CalPrivacy; recovered amounts go to the Data Brokers' Registry Fund (§ 1798.99.82(e)).

What compliance looks like in practice

For most small brokers the hard part is not the law, it is the matching. You have to standardize your records to CalPrivacy's exact rules, SHA-256 hash them, compare against hashed identifiers you cannot reverse, and return a status file — every 45 days, forever.

Enterprise privacy platforms sell this as part of a $10,000-a-year suite. A lead-gen firm with one database does not need the suite; it needs the match done correctly and evidence that it ran.

What SB 362 is not

There is no California DROP Act. Searchers reasonably guess that name because the platform is called DROP, but no statute carries it — the law is SB 362, the Delete Act, and DROP is the mechanism it required CalPrivacy to build.

SB 362 is also not SB 361, a separate and later California bill on data broker disclosure requirements — the two are easy to confuse and are frequently swapped in secondhand summaries. It also does not make deletion absolute: exemptions under the CCPA and other law still apply, which is exactly what the Exempted status in DROP is for. Drop45 is software, not legal advice — take exemption questions to a privacy attorney.

Drop45 does the matching half of this. Upload a DROP consumer deletion list and your own records; standardization, SHA-256 hashing and matching all run in your browser, so consumer data never leaves your machine. Free for up to 500 records per run.

Run a match now — free