From Registry to Obligation
August 1, 2026 is the date California's Delete Act (SB 362) stopped being a paperwork exercise and became an enforceable deletion mandate. Under regulations administered by the California Privacy Protection Agency (CPPA), every one of the 614 data brokers currently listed in the state's broker registry must now log into the Delete Request and Opt-Out Platform (DROP) at least once every 45 days, pull any pending consumer requests, delete the associated personal information — including inferences drawn from it — and stop selling or sharing that data going forward. It is the first deadline of its kind in the country: no other state runs a centralized clearinghouse that converts a single consumer click into a legal deletion obligation on hundreds of companies at once.
DROP itself opened to consumers on January 1, 2026, letting any Californian file a single verified request that fans out to every registered broker at once, rather than requiring them to hunt down and individually petition hundreds of companies whose data-collection practices they've likely never heard of. More than 155,000 residents had already filed requests through the platform before enforcement even began, according to the governor's office.
The Case for It
The strongest argument for the Delete Act is a straightforward market-failure one, and it deserves to be stated plainly before any criticism. Data brokers by definition deal with people who never chose to be their customers — the whole business model is trading in information about individuals who have no direct relationship with the buyer or seller. Before DROP, exercising a deletion right meant identifying which of the hundreds of registered brokers held your data and filing a separate request with each, a task so impractical that few consumers ever completed it. The Electronic Frontier Foundation, no fan of regulatory half-measures, calls DROP "a fantastic tool" precisely because it collapses that asymmetry into one government-verified form. A centralized, standardized opt-out mechanism is close to the textbook fix for a market where transaction costs — not consumer indifference — were the real barrier to exercising a legal right that already existed on paper since the CCPA.
Where the Design Gets Risky
The compliance mechanics, however, are where the Delete Act's proportionality breaks down. SB 362 sets penalties at $200 per unprocessed deletion request, per day. That figure sounds modest until it's multiplied against the volume DROP is designed to generate. As one ad-tech trade analysis put it, if a broker falls behind processing even a large batch of requests for a single day, exposure can run into the hundreds of millions of dollars — the author's phrase was that it amounts to "using a bazooka to destroy an anthill." A penalty regime that scales linearly with request volume rather than with culpability or actual harm creates existential tail risk for a mid-sized compliance team that misses a processing window because of a software bug, not bad faith — the same liability a broker that simply refuses to comply would face. That asymmetry matters most for the smaller and mid-sized brokers in the registry's long tail, which lack the dedicated compliance staff that the largest advertising and analytics firms can deploy on short notice.
The second problem is definitional. "Data broker" status turns on whether a company sells personal information about consumers with whom it has no "direct relationship" — and the CPPA has read that to require the consumer to have intentionally interacted with the business. Ad-tech firms running third-party pixels that fire invisibly on websites a consumer never knowingly engaged with can find themselves swept into broker status without having built anything resembling a classic brokerage business. Combined with the per-request fine structure, that ambiguity punishes uncertainty about scope as harshly as it punishes deliberate noncompliance.
A Right With Real Gaps
Even EFF's enthusiasm comes with a caveat worth taking seriously: DROP only binds brokers who registered in the first place. Companies operating outside the registry — the piece names Google specifically — are untouched, and nothing stops a newly formed broker from harvesting a consumer's data the day after a deletion request clears. CalMatters' coverage of the rollout notes the same structural limit: the law carves out several exemptions that let brokers retain certain categories of data even after a valid request. The result is a regime that is simultaneously under-inclusive on coverage and over-punitive on enforcement mechanics — precisely backwards from what proportionate regulation should look like.
The Fix Is Calibration, Not Repeal
None of this argues for scrapping the Delete Act. A single, government-run deletion clearinghouse is a genuine consumer-protection innovation, and California deserves credit for building infrastructure that individual opt-out laws in other states still lack. But the CPPA should use its rulemaking authority to tier penalties by broker size and by whether a lapse reflects negligence versus willful refusal, and it should publish clearer safe-harbor guidance on the "direct relationship" test so good-faith ad-tech operators can determine their obligations before, not after, a $200-a-day meter starts running per request. Proportionate enforcement is what will make this law durable rather than merely litigated.