Aug 04, 2026 · 7 min read
California Data Brokers Now Face $200 a Day, Per Request
Californians have been filing deletion requests through the state's DROP platform since January 1. On August 1, 2026 the obligation flipped to the other side of the transaction, and the fine is calculated per request, per day.
More than 300,000 Californians have told a state run platform to make every registered data broker erase their personal information. Until August 1, the roughly 600 brokers on the receiving end had no legal obligation to act on any of it.
That obligation is now live. No grace period, no cure window, and the penalty is not a flat number. It is $200 for each deletion request, for each day the broker fails to delete.
Key Takeaways
- California Civil Code section 1798.99.86 requires every registered data broker to access the Delete Request and Opt-Out Platform at least once every 45 days beginning August 1, 2026.
- CalPrivacy reported on June 2, 2026 that 300,000 Californians had signed up for DROP and 581 data brokers were registered, the highest count since the registry opened in 2020.
- The fine for failing to delete is $200 per deletion request per day, so a broker sitting on a 5,000 request backlog accrues $1 million in exposure every 24 hours.
- The Delete Act's definition covers any business that knowingly sells personal information about consumers it has no direct relationship with, sweeping in adtech platforms and audience segment sellers that never call themselves brokers.
- CalPrivacy fined S&P Global $62,600 and Datamasters $45,000 on January 8, 2026 for registration failures alone, months before any deletion obligation existed.
What Is DROP, and What Changed on August 1?
DROP is a free California Privacy Protection Agency platform that lets one resident send a single deletion request to every data broker registered with the state. Consumers have been filing since January 1, 2026. What changed on August 1 is that brokers now have to read the queue.
Under Civil Code section 1798.99.86, a data broker "shall access the accessible deletion mechanism at least once every 45 days and within 45 days after receiving a request, process all deletion requests and delete all personal information related to the consumers making the requests." Mechanically that is a batch job: download the hashed lists, hash your own records the same way, match, delete, report status. A request the broker cannot verify has to be treated as an opt out of sale, not ignored.
Why Does $200 a Day, Per Request, Compound So Fast?
Because the multiplier is the size of your queue, not the number of things you did wrong. One policy failure, applied to a list, becomes thousands of simultaneous violations that each tick over at midnight. CCPA civil penalties, by contrast, run $2,500 per violation and are assessed once.
- 5,000 unprocessed requests — $1,000,000 for a single day.
- 50,000 unprocessed requests — $10,000,000 a day, the illustration Fenwick uses in its compliance guidance.
- The full 300,000 request queue — $60,000,000 a day for a broker that matches every requester and processes none.
The agency applies that arithmetic literally. Clark Hill notes S&P Global was unregistered for 313 days. Multiply 313 by $200 and you get $62,600 — the exact fine CalPrivacy announced. No rounding, and no discount for an omission the company reportedly blamed on administrative error.
Is Your Business a Data Broker?
More often than the marketing team assumes. The test is behavioral, not reputational: a data broker is a business that knowingly collects and sells to third parties the personal information of a consumer with whom it has no direct relationship.
Nothing there requires you to run a people search site. Clark Hill flags retailers selling audience segments to brand partners, lead providers building audiences from third party data, and enrichment vendors monetizing attributes derived from non customers. CalPrivacy's position is that consumer facing businesses should not assume they are exempt.
The carve outs are narrow: Fair Credit Reporting Act entities, HIPAA covered entities and their business associates, and Gramm Leach Bliley financial institutions. Everyone else pays a $6,000 annual fee, runs the DROP cycle, and from January 1, 2028 faces an independent third party audit every three years.
Why Your Email Address Sits at the Center of This
Email is the identifier that makes the rest of the profile possible, which is why DROP asks for it and why it is one of the lists brokers subscribe to. Everything you submit is hashed with SHA-256 on arrival, so the agency holds digests rather than a plaintext directory of everyone who wants out. As CalPrivacy explained in July 2026, a broker has to standardize its own records — lowercase fields, strip stray characters, normalize dates and phone numbers — then hash them identically and compare. That is trivial for an email address and hard for a human name. "Rob Smith" and "Robert Smith Jr." do not hash alike. rob.smith@example.com always does.
Which is why brokers built their graphs on email to begin with. Names collide, street addresses churn, phone numbers get recycled. An email address is close to unique, stable for years, and present in nearly every dataset a broker can buy — the thing that lets one company merge a purchase history from one source with a location trail from another and be confident both describe you. Deleting the record where that key lives removes the seam, not just a row.
Be honest about the ceiling. The Electronic Frontier Foundation notes that brokers keep collecting after a deletion, new ones register later, public records like vehicle and property ownership are excluded, and unregistered companies sit outside the apparatus entirely. DROP degrades the graph; it does not erase you. What that graph costs is in our coverage of the $21 billion identity theft bill tied to data broker records.
How Do You File a DROP Request?
You complete one form at the CalPrivacy consumer portal and get a DROP ID to track it. The agency needs name, address, phone and email to verify you; optional fields like a mobile advertising ID or a vehicle identification number improve your match rate. Our walkthrough of how to file a DROP deletion request covers the consumer side step by step.
- One request reaches the whole registry. EFF counted 614 brokers in July 2026, up from 581 in June.
- You can exclude specific brokers, and file for an elderly relative by attesting they are a California resident.
- Status lags. Deletions run on a rolling 45 day basis and a status can take 90 days to appear, so an empty dashboard in week three proves nothing.
- Refile periodically. A company that registers in 2027 never saw your 2026 request.
One limit deserves emphasis: DROP reaches registered data brokers, not companies you deal with directly. Your bank, your airline and the retailer whose newsletter you subscribed to still require individual CCPA requests.
Has CalPrivacy Actually Been Enforcing?
Yes, and it built dedicated capacity before the deadline arrived. The agency launched a data broker enforcement strike force in November 2025, issued a registration focused advisory in December, and has brought more than ten actions against unregistered brokers since October 2024.
The January 8, 2026 round shows what it treats as aggravating. Rickenbacher Data, trading as Datamasters, paid $45,000 over allegations it resold personal information segmented by health condition, ethnicity, age and purchasing behavior. Michael Macko, CalPrivacy's head of enforcement, put it in one sentence: "Reselling lists of people battling Alzheimer's disease is a recipe for trouble."
Note what those fines punished: a missing registration form, at a time when no deletion obligation existed. The enforcement surface roughly tripled on August 1. Registration, processing and status reporting are now three separate ways to accrue $200 a day.
What Should Non California Readers Take From This?
The model is spreading, slowly, and California is still the only place one form reaches an entire industry. New Jersey's data broker law A5328 took effect in July 2026, and Connecticut's SB4 passed in May 2026 with its own registry and single deletion request mechanism. Oregon, Texas and Vermont run registries with no centralized platform behind them.
There is also a spillover no statute promises. Suppression is a database problem, and a California only suppression table means maintaining two deletion pipelines forever. Some brokers will. Others will find one global rule cheaper, quietly extending a California resident's request to people with no such right. That is engineering economics, not a guarantee. If you run compliance elsewhere, the useful question is not whether your state has a DROP yet — it is whether your records could survive a hashed match against 300,000 identifiers on 45 days' notice.
Sources: California Civil Code sections 1798.99.82 and 1798.99.86, CalPrivacy DROP guidance for data brokers, CalPrivacy registration and signup figures, June 2, 2026, CalPrivacy enforcement announcement, January 8, 2026, Alston & Bird, Fenwick, Clark Hill and the Electronic Frontier Foundation.