California’s DROP: What the Delete Act changes for consent, preferences, and data deletion

Skip to main content

OneTrust Named a Visionary in the 2026 Gartner® Magic Quadrant™ for AI Governance Platforms

Download the report

On-demand webinar coming soon...


On-demand webinar coming soon...

Blog

California’s DROP: What the Delete Act Changes for Consent, Preferences, and Data Deletion

January 6, 2026

Table of contents

California is preparing to introduce a new privacy mechanism that reshapes how deletion rights work for consumers and data brokers alike. Starting January 1, 2026, Californians will gain access to the Delete Request and Opt-Out Platform, known as DROP.

DROP marks a shift in how deletion requests are submitted, processed, and enforced. Instead of navigating dozens or even hundreds of individual requests, consumers will be able to submit a single deletion request to every data broker registered and operating in California, including organizations headquartered elsewhere. For privacy, marketing, and data teams, this introduces a new operational reality where deletion requests arrive through a centralized system with strict timelines and reporting obligations.

For organizations focused on consent and preferences, DROP reinforces a broader regulatory direction already taking shape. Consumer choices around data use are becoming centralized, standardized, and easier to exercise. Compliance increasingly depends on systems that receive, verify, and act on those choices consistently.

What Is DROP: From Fragmented Deletion Rights to a Single Consumer Control

DROP is a free online tool created by the California Privacy Protection Agency (CPPA) under the Delete Act. It allows California residents, or their authorized agents, to send deletion requests to registered data brokers in a streamlined way, enabling consumers to delete their personal information from multiple data brokers with a single request. Through a centralized portal, DROP facilitates the exercise of deletion rights that consumers already have under the DELETE Act and related privacy laws.

While consumers already have the right to request deletion from businesses they interact with directly, DROP extends that right to data brokers that collect and sell personal information outside of first party interactions. Over time, these brokers can build detailed profiles about individuals who may never realize their data is being traded. DROP brings visibility and control back to the consumer.

To register, data brokers must provide information including:

The consumer experience is designed to reduce friction. Individuals confirm California residency, provide basic identifying details such as name, date of birth, phone number, and email address, and submit a request. Consumers can also return to the platform to check the status of their deletion requests.

For data brokers, DROP establishes a standardized intake channel for deletion requests along with recurring processing requirements. Starting August 1, 2026, data brokers must access DROP at least once every 45 days to retrieve deletion requests, delete all associated personal data including inferences, and report request status.

Key DROP Timelines and Compliance Expectations

DROP introduces a rollout schedule that data brokers and affected organizations should already be planning around.

On January 1, 2026, DROP opens for consumers to submit deletion requests. Data brokers must also begin account creation on that date and complete registration between January 1 and January 31, 2026.

API integration opens in Spring 2026, creating a path for automated request retrieval and processing. Beginning August 1, 2026, data brokers must access DROP every 45 days to download deletion requests, delete all matched personal data, and report outcomes.

Who Qualifies As a Data Broker Under DROP

A data broker is defined under the Delete Act as 'a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship.'

The regulations implementing the Delete Act clarify who qualifies as a data broker, which may capture more organizations than expected. A business does not have a direct relationship with a consumer simply because it collects personal information directly. The consumer must intend to interact with the business.

If personal information is sold or shared outside of that intended interaction, the organization may still qualify as a data broker and fall under DROP obligations. This distinction matters for companies that rely on downstream data sharing, enrichment, or resale models.

In addition, the regulations introduce technical requirements for how deletion requests are fulfilled. Data brokers must standardize records and use a specified hashing algorithm to match consumer identifiers. For every confirmed match, all associated personal information must be deleted. Brokers must also keep DROP account details up to date and notify the CPPA of any unauthorized access or related security incidents.

What DROP Means for Consent and Preference Programs

DROP does more than introduce a new deletion workflow. It reflects a broader regulatory expectation that consumer controls operate beyond individual websites, banners, or one-off requests.

For teams managing user consent and preferences at a business level, this reinforces an important shift. Consumer choices are no longer isolated events. They are persistent signals that must be honored across systems, vendors, and data lifecycles. Deletion, like opt-out preferences, requires infrastructure that connects intake, verification, execution, and proof.

Manual workflows or fragmented tooling will struggle to keep pace with DROP’s cadence and new requirements. Requests arrive on a fixed schedule. Deletions must include derived data and inferences. Status updates must be tracked and reported back through the platform. Like any regulatory-driven business process, teams also need visibility into request volumes, processing status, and completion timelines to stay in control.

A centralized approach to data subject request automation and consent governance becomes essential. It allows teams to receive deletion requests, validate them, route actions to the right systems, and maintain records that demonstrate compliance. For marketing teams, this reduces the risk of activating outdated or noncompliant data. For privacy teams, it creates defensible workflows aligned with regulatory expectations.

How Teams Can Prepare Now for DROP

With January 2026 approaching, privacy leaders and marketing technology teams should focus on operational readiness rather than policy updates alone.

Data brokers should first assess whether they meet the definition under the Delete Act, especially where data is collected outside of direct consumer interactions. From there, teams should evaluate how deletion requests will be received, matched, and executed across internal systems and downstream partners.

Organizations should also review how deletion workflows are currently handled. DROP introduces recurring processing requirements, not one time events. Systems need to support repeatable deletion cycles, confirmation tracking, and reporting without introducing manual bottlenecks.

From a tooling perspective, DROP aligns closely with existing data subject request (DSR) obligations. For OneTrust customers, DROP will be supported through Data Subject Request Automation with a specialized deletion request workflow. This allows teams to centralize intake, automate fulfillment across systems, and maintain clear records of what was deleted, when, and why.

The CPPA has not yet released full technical specifications for DROP. We are monitoring updates closely and will provide clear guidance as soon as additional details are available. Teams with established consent and preference programs will be better positioned to adapt once those details are finalized.

Looking Ahead

DROP highlights how privacy enforcement continues to evolve. Consumer rights are becoming easier to exercise, and regulators are enforcing those rights with operational mandates. Consent, preferences, and deletion are no longer separate conversations. They are part of a unified expectation around control, transparency, and accountability.

Organizations that build centralized, automated approaches to honoring consumer choices will find compliance easier to sustain as new mechanisms like DROP come online.

Talk to a consent expert or explore how OneTrust helps teams operationalize consent, preferences, and deletion at scale.

California DROP: FAQs

What is the California DROP system?

DROP is the Delete Request and Opt-Out Platform created by the California Privacy Protection Agency. It allows California residents to submit a single deletion request to all registered data brokers. In summary, DROP enhances the accessibility and enforcement of existing consumer deletion rights by providing a centralized, user-friendly platform rather than introducing new rights per se.

When does DROP launch?

DROP goes into effect on January 1, 2026. Consumers can submit deletion requests starting that date, and data brokers must register during January 2026.

Who must comply with DROP requirements?

Registered data brokers that sell or share personal information collected outside of direct consumer interactions must comply with DROP requirements. This typically includes companies involved in data aggregation, enrichment, resale, or profiling that operate in California, regardless of where they are based.

How often must data brokers process deletion requests?

Starting August 1, 2026, data brokers must access DROP at least once every 45 days to retrieve requests, delete associated data including inferences, and report request status.

How does DROP affect consent and preference management?

DROP reinforces the need for centralized systems that honor consumer choices across the data lifecycle. Deletion requests, like opt-out preferences, require automation, verification, and consistent execution across systems and partners.