Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

California’s DROP Regime will Change the Data Broker Risk Equation

By Kathryn Rattigan on April 23, 2026
Email this postTweet this postLike this postShare this post on LinkedIn

California’s new Delete Request and Opt-Out Platform (DROP) goes live on August 1, 2026, and the compliance stakes are enormous. State officials have warned that a single missed deletion cycle could create theoretical penalty exposure of $1.5 billion for one data broker. That number reflects how aggressively the Delete Act is designed to work. One consumer request can now cascade across every registered data broker in the state, turning deletion compliance into a centralized, high-volume, enforcement-ready system.

The bigger surprise for many companies is not the platform itself—it is who may be covered. California is signaling that “data broker” should be read broadly, and the analysis turns on the data, not just the business as a whole. A company can have direct customer relationships and still be a data broker if it sells personal information obtained from third parties. If your business acquires consumer data indirectly and monetizes it, this is not a definition to skim past.

Operationally, DROP is not just a periodic deletion exercise. Registered brokers must access the system at least once every 45 days, pull hashed identifiers, match them against their records, process deletions, and report status before they can access the next batch. Even more important, unmatched identifiers still have to go on a permanent suppression list. That means if you buy relevant third-party data later, you may already be prohibited from selling or sharing it. Compliance is ongoing, and it reaches future data ingestion as much as current inventories.

Companies should now assess whether they have California data broker obligations, especially where third-party sourced data is involved. They should also be preparing for API integration, workflow design, suppression screening, and internal ownership before the August deadline arrives. California has built the system, consumers are already in the queue, and the window for treating DROP as a future problem is closing fast.

Photo of Kathryn Rattigan Kathryn Rattigan

Kathryn Rattigan is a member of the Business Litigation Group and the Data Privacy+ Cybersecurity Team. She concentrates her practice on privacy and security compliance under both state and federal regulations and advising clients on website and mobile app privacy and security…

Kathryn Rattigan is a member of the Business Litigation Group and the Data Privacy+ Cybersecurity Team. She concentrates her practice on privacy and security compliance under both state and federal regulations and advising clients on website and mobile app privacy and security compliance. Kathryn helps clients review, revise and implement necessary policies and procedures under the Health Insurance Portability and Accountability Act (HIPAA). She also provides clients with the information needed to effectively and efficiently handle potential and confirmed data breaches while providing insight into federal regulations and requirements for notification and an assessment under state breach notification laws. Prior to joining the firm, Kathryn was an associate at Nixon Peabody. She earned her J.D., cum laude, from Roger Williams University School of Law and her B.A., magna cum laude, from Stonehill College. She is admitted to practice law in Massachusetts and Rhode Island. Read her full rc.com bio here.

Read more about Kathryn RattiganEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Data Privacy + Cybersecurity Insider
  • Organization:
    Robinson & Cole LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo