Compliance · September 23, 2026

The DELETE Act: California's Data Broker Purge Button

Your personal information can circulate through companies you have never contacted, creating profiles used for advertising, marketing, and other purposes. The California DELETE Act gives residents a centralized way to request deletion from registered data brokers. For California businesses, it also creates compliance questions that extend beyond a privacy policy. Here is what the law does, which deadlines now matter, and how individuals and businesses can distinguish a deletion right from a promise that every copy of someone’s information will disappear.

What the California DELETE Act actually does

The DELETE Act expanded California’s data broker law. Effective January 1, 2026, the operative data broker provisions are codified in California Civil Code sections 7610 through 7616. The Act’s central feature is an “accessible deletion mechanism” administered by the California Privacy Protection Agency, or CPPA. The agency calls the system the Delete Request and Opt-Out Platform, commonly shortened to DROP.

Instead of submitting separate requests to each registered broker, a California resident can use the centralized mechanism to submit one verifiable deletion request directed to every registered data broker that maintains personal information about that consumer. The law required the agency to establish the mechanism by January 1, 2026. Brokers’ mandatory processing obligations began August 1, 2026.

That distinction matters: making a request and completing deletion are separate steps. The system is not an immediate eraser for the entire internet. It targets covered data brokers, applies legal exceptions, and operates through scheduled processing rather than instantaneous removal.

The DELETE Act supplements the California Consumer Privacy Act, or CCPA, rather than replacing the rights available under that law.

Which businesses qualify as data brokers?

The statutory definition generally covers a business that knowingly collects and sells personal information about consumers with whom it does not have a direct relationship. Whether an organization qualifies depends on its actual activities, not whether it describes itself as a “data broker.”

For example, a company selling lists assembled from outside sources may need a closer review. A retailer collecting information directly from its own customers is not automatically a data broker merely because it maintains a customer database. However, separate activities involving information about people outside that customer relationship can change the analysis.

  • Review where information originates. Identify direct customer information, purchased lists, public-source records, and third-party enrichment data.
  • Examine transfers. Selling personal information can involve more than an ordinary cash transaction.
  • Check statutory coverage. The definition incorporates CCPA concepts and contains exclusions whose scope requires careful review.

Companies should not assume that a regulated industry or a particular data source creates a blanket exemption. An attorney providing regulatory compliance guidance can evaluate the relevant activities and exclusions.

What data brokers must do after August 1, 2026

As of this article’s publication date, the mandatory processing phase has begun. Covered brokers must access DROP at least once every 45 calendar days, process requests under the applicable requirements, and report each request’s status within 45 calendar days after downloading or retrieving it. Applicable exceptions and special procedures may affect the required response. Annual registration with the CPPA is a separate obligation; registration alone does not satisfy deletion duties.

A compliance workflow should address more than removing a row from one database:

  • Request intake and verification: Assign responsibility for accessing DROP, matching requests, and following the required procedures when a request cannot be verified.
  • Deletion across systems: Identify covered information in active databases and other relevant locations, subject to applicable exceptions.
  • Downstream instructions: Establish procedures for directing service providers and contractors to delete information as required.
  • Future collection: Maintain a suppression list or another compliant method to ensure that later data purchases or updates do not simply rebuild a deleted profile.
  • Documentation: Record processing dates, actions taken, request-status reports, and the basis for any applicable exception.

After fulfilling a deletion request, a broker must continue deleting newly collected personal information about that consumer at least once every 45 days, subject to applicable exceptions. Compliance requires a suppression process or equivalent controls that apply the request to later-acquired information, not just a one-time deletion. The law also restricts selling or sharing the consumer’s personal information unless the consumer later consents as permitted by law.

What individuals can expect from a deletion request

California residents should use the official CPPA platform and follow its identity-verification instructions. A request is free, and consumers do not need to locate and contact every broker separately to use the centralized mechanism.

Deletion is not absolute. Applicable exceptions may permit retention for purposes such as meeting legal obligations or addressing security concerns. A company’s preference to keep useful marketing data is not, by itself, a legal exception.

The system also does not automatically delete information from every company with which you have a direct relationship. Your bank, online store, or subscription provider may require a separate privacy request, and different rules can apply to its records. Information available from public sources may remain available there even when a broker must delete its own covered records.

Keep a record of your submission and review available request-status information. If you believe a broker is not complying, the CPPA’s complaint process may be relevant. Avoid treating continued unwanted advertising alone as proof that a particular broker violated the law.

Practical steps for California businesses

Businesses that buy marketing lists or use data enrichment services should review their vendors, even if they are not themselves data brokers. Vendor deletion practices can affect whether purchased information remains usable and whether your own privacy obligations are met.

  1. Map the data flow. Identify who collects information, who receives it, and why.
  2. Review contracts. Address lawful sourcing, deletion cooperation, permitted uses, and compliance documentation.
  3. Test suppression procedures. Confirm that deleted information is not automatically restored during the next import.
  4. Update internal responsibilities. Coordinate privacy, marketing, technology, and legal functions.

California businesses should also distinguish DROP requests from ordinary CCPA requests. Related obligations may overlap, but one process does not automatically satisfy every requirement of the other.

Talk to a California business attorney

Itkin Law offers a free consultation to discuss DELETE Act compliance questions for businesses and data deletion concerns for individuals. Schedule a free consultation or call (424) 603-8888.

This article is attorney advertising and provides general information only. It is not legal advice and does not create an attorney–client relationship. The law changes, and this article reflects the law as of its publication date. Every situation is different — contact us to discuss how the law applies to your exact circumstances. See our full disclaimer.

Free Consultation

Ready to move? Start with a free consultation.

Tell us what you're facing — a contract, a dispute, a debt, a decision. We will map the legal path in plain language, and you will leave the first call knowing your options.

Call Now Free Consultation