California Raises the Bar on Data Deletion
California is entering a new phase of privacy enforcement with the implementation of the Delete Request and Opt-out Platform (DROP) under the California Delete Act (SB 362). Beginning August 1, 2026, every registered data broker must connect to the state-operated platform, retrieve verified consumer deletion requests at least every 45 days, process them within the mandated timeframe, and maintain auditable records of compliance.
The Delete Act closes a major gap in California's privacy framework. While the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) gave consumers the legal right to delete their personal information, individuals previously had to submit separate requests to each data broker. DROP replaces this fragmented process with a centralized portal, allowing consumers to submit a single verified request that reaches all registered data brokers simultaneously.
| Key 2026 milestones: | ||
|
Milestone
|
Date | Requirement |
|
DROP Available
|
January 1, 2026 | Platform opens for consumer submissions |
| Operational Mandate | August 1, 2026 | Data brokers must retrieve and process DROP requests every 45 days |
| Audit Cycle Initiation | January 1, 2028 | Mandatory independent third-party compliance audits begin |
| Cybersecurity Audits | April 1, 2028 | First certifications due for companies with 2026 revenues exceeding $100M
|
The new requirements significantly expand compliance obligations. Organizations must regularly connect to the DROP platform, retrieve updated deletion requests, erase personal information across internal systems, ensure third-party vendors and data-sharing partners also delete the corresponding records, and provide verifiable evidence that every request has been completed. Compliance is no longer a one-time activity but a recurring operational process.
California has also introduced stringent enforcement measures. Businesses that fail to process valid requests can face penalties of US$200 per consumer, per day, while repeated failures may trigger regulatory investigations, audits, and significant financial settlements. The law places greater emphasis on automation, governance, auditability, and accountability across the entire data lifecycle.
The Delete Act signals a broader shift in global privacy regulation—from granting consumer rights to enforcing those rights through continuous operational compliance. Privacy is no longer just a legal obligation; it has become a technology challenge requiring organizations to automate data discovery, deletion workflows, identity verification, consent management, vendor coordination, and compliance reporting at scale.
For enterprises, manual privacy processes will quickly become unsustainable. Organizations will need AI-powered privacy platforms capable of discovering personal data across structured and unstructured systems, orchestrating deletion requests, validating user identity, maintaining immutable audit trails, and ensuring downstream vendors comply with the same requirements.
As similar regulations emerge worldwide, California's DROP framework is likely to become a benchmark for future privacy laws. Enterprises that invest early in automated privacy operations, Zero Trust data governance, and privacy-by-design architectures will be better positioned to meet evolving regulatory expectations while strengthening customer trust in the digital economy.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




