Delete Act fines: what a missed DROP request costs
California fines data brokers by the request and by the day. The math, with a calculator.
- Failing to delete: $200 per deletion request, per day.
- Failing to register: $200 per day, plus the fees you should have paid.
- Both come with the agency's investigation costs on top.
The two fines in the Delete Act
Civil Code § 1798.99.82 sets out what CalPrivacy can fine a data broker in an administrative action.
Not processing deletion requests
The fine is $200 for each deletion request, for each day you fail to delete information as required (§ 1798.99.82(d)(1)). It's counted per request, so the total grows with every request left open and every day it stays open.
Not registering
A broker that fails to register owes $200 for each day it isn't registered, plus an amount equal to the registration fees that were due, plus CalPrivacy's reasonable investigation and administration costs (§ 1798.99.82(c)). The registry is public, so this one is easy to spot.
What a miss could cost
Move the sliders to see how fines for unprocessed deletion requests add up.
The calculator multiplies the statutory amount. Actual penalties depend on the facts of each case.
How small misses become big numbers
Over 345,000 Californians had filed DROP requests by early August 2026. Most brokers will match only a small share of them, but a few common failures can leave hundreds or thousands of requests open at once:
- A missed download. If a scheduled job fails silently and nobody notices for a month, every new request in that window sits unprocessed.
- A formatting mismatch. If your records aren't standardized exactly the way the regulations require, matches fail without any error. Every missed match is a request you didn't act on. See how DROP hashing works.
- A new data feed. Data you acquire after a request still has to be screened against it. One unscreened feed can reintroduce many consumers at once.
Enforcement is already happening
CalPrivacy has been actively enforcing the Delete Act's registration requirement and has set up a dedicated data broker enforcement team. Independent audits of brokers start January 1, 2028, and repeat every three years, so how you processed requests will be reviewed by a third party.
What reduces the risk
- Automate downloads well inside the 45-day window, with alerts when one fails.
- Standardize records exactly as
§ 7613describes before hashing. - Screen every new data source against all past requests before it's sold or shared.
- Keep timestamped records of each download, match, deletion and status upload.
These steps won't guarantee you avoid fines. They do make it far less likely that requests sit unprocessed without anyone noticing.
Check every record against DROP with one API call
Purgepath keeps your DROP list current daily and tells you exactly what to delete. Unlimited scrubs by API or CSV upload, $500/month.
Sources
This article is general information as of October 5, 2026, not legal advice. Rules and fees can change; check the sources above and talk to counsel about your situation.