DROP for data brokers: what you have to do every 45 days
The full cycle a California data broker runs on DROP every 45 days, step by step.
- Download your DROP lists at least every 45 days.
- Standardize and hash your records, then match. Delete everything tied to a match within 45 days.
- Keep unmatched requests and screen all new data against them before you sell or share it.
- Report a status for every request at your next access session.
Since August 1, 2026, every data broker registered in California has had to process consumer deletion requests through DROP, the Delete Request and Opt-out Platform run by CalPrivacy. The obligation repeats every 45 days for as long as you're in business. Each cycle has seven parts.
1. Download your deletion lists
Access DROP and download your selected lists at least once every 45 calendar days (§ 7612). The first download is the full list. After that, each download only includes new or amended requests since your last one. You can ask CalPrivacy to re-download a complete list if you need to reconcile records or prepare for an audit.
You can download manually through the portal or automatically through the API. If automation fails, you're still on the hook to download manually. See how to log in and get your API key.
2. Standardize, hash and match
Every identifier on a DROP list is hashed, so you can't read it. You have to put your own records into the same format, hash them the same way, and compare. The regulations spell out the formatting: lowercase, special characters removed, dates as YYYYMMDD, ZIP codes as five digits, phone numbers as the last ten digits (§ 7613).
This is where most missed matches come from. A trailing space or an accented character produces a different hash, and the miss is silent. We cover it in detail in how DROP hashing works.
3. Delete what matches
For every match, delete all personal information tied to that identifier, including inferences, within 45 days of receiving the request (Civil Code § 1798.99.86(c)). "Delete" means permanently erasing it, deidentifying it, or aggregating it. Backups can wait until they're restored or accessed for commercial use.
Some data doesn't have to go: information that's exempt under the statute, and information you collected directly from the consumer as a first party.
If one identifier matches more than one consumer in your records, you can't tell which person made the request. In that case, opt every matched consumer out of sale and sharing instead.
4. Tell your service providers and contractors
You have to direct every service provider and contractor holding that consumer's data to delete it too (§ 7613(d)). Keep a record of who you told and when.
5. Keep suppressing new data
After a consumer's first deletion, you have to keep deleting their personal information at least every 45 days, and you can't sell or share new information about them (Civil Code § 1798.99.86(d)).
For requests that didn't match anything, keep the deletion list. Before you sell or share newly collected records, compare them against every past request (§ 7613(c)). A record you buy next quarter for someone who filed in January still counts.
6. Report status at your next access
At each access session, report a status for every request you received in the previous session (§ 7614). There are four response codes:
| Status | When to use it |
|---|---|
| Record deleted | You matched the identifier and deleted the associated personal information. |
| Record opted out of sale | Multiple consumers matched, so you opted all of them out of sale and sharing. |
| Record exempted | You matched, but everything you hold on that consumer is exempt. |
| Record not found | No match after standardizing and hashing correctly. |
If a "not found" request later matches newly collected data and you delete it, report the change to "record deleted" at your next session. If you upload manually, upload the status report before downloading a new list, as a CSV in the same format as the list you downloaded, with response codes added.
7. Keep proof for the audit
Starting January 1, 2028, and every three years after, brokers have to be audited by an independent third party. You have to hand the report to CalPrivacy within five business days of a written request, and keep it for at least six years (Civil Code § 1798.99.86(e)). Logs of each download, match, deletion, vendor notice and status upload make that much easier.
The cycle at a glance
| Step | Deadline |
|---|---|
| Download lists | At least every 45 days |
| Delete matched data | Within 45 days of receiving the request |
| Re-delete for past requesters | At least every 45 days |
| Screen new data | Before any sale or sharing |
| Report status | At the next access session |
| Independent audit | From January 1, 2028, every 3 years |
Check every record against DROP with one API call
Purgepath keeps your DROP list current daily and tells you exactly what to delete. Unlimited scrubs by API or CSV upload, $500/month.
Sources
This article is general information as of October 5, 2026, not legal advice. Rules and fees can change; check the sources above and talk to counsel about your situation.