Opinion

Why California just gave the Delete Act real teeth

Image by DIY 13.

Capitol Weekly welcomes Opinions on California public policy or politics. Please read our guidelines for opinion pieces before submitting an Op-Ed. Submissions that do not adhere to our guidelines will not be considered for publication. 

OPINION — When California lawmakers passed the Delete Act in 2023, they made a promise that was easy to write into statute and hard to actually deliver: one request, sent to one place, that would reach every data broker registered in the state. 

That promise became operational on Aug. 1, when registered data brokers were required to begin accessing the Delete Request and Opt-out Platform, known as DROP, at least once every 45 days to download and process the deletion requests that more than 300,000 Californians have already submitted since the platform opened to consumers in January.

The California Privacy Protection Agency Board met last week on Aug. 6 and 7 in San Francisco as this new phase takes hold. The agenda covered the unglamorous work of funding and staffing the agency that must now verify whether brokers are actually honoring the requests DROP forwards. Together, the live processing obligation and the Board’s ongoing capacity decisions show an agency moving from the design phase of a major privacy program into sustained operations.

It’s worth remembering why DROP exists in the first place. Before the Delete Act, a Californian who wanted their personal information removed from the data broker ecosystem faced a genuinely absurd task: identifying which of hundreds of registered brokers held their data, then filing individual deletion requests with each one, often through inconsistent web forms or opt-out processes that varied broker to broker. 

The right to delete meant little if exercising it required a part-time research project. DROP was built to collapse that process into a single request that fans out to the entire registered universe of brokers at once.

But a centralized deletion tool only works if the agency behind it can verify that brokers are actually honoring the requests it forwards. That gap remains the critical enforcement challenge. Rather than relying solely on complaints or self-reporting to surface noncompliance, the CPPA is building formal audit capacity, having already launched its first targeted review of gig economy platforms under the California Consumer Privacy Act. Statutory independent third-party audits of data broker compliance with the Delete Act begin in 2028 and recur every three years, giving the agency a standing mechanism to check whether deletion requests are being processed the way the law requires.

The fee discussion that accompanies these meetings is the less visible half of the story, but it is what makes the enforcement ambitions credible rather than aspirational. The CPPA is a self-funded agency, and registration and access fees currently set at $6,000 plus processing costs are the primary source of the budget that pays for audit staff, legal review, and the technical infrastructure DROP depends on. As the number of registered data brokers and the scope of verification work both grow, adjusting those fees is simply how the agency keeps its operating capacity aligned with its mandate. It is a budgeting conversation before it is anything else.

Seen together, the August 1 go-live and last week’s Board meeting tell a coherent story about institution-building. California created the CPPA because it judged that consumer privacy rights needed a dedicated regulator with real investigative authority, not just statutory language enforced occasionally through the Attorney General’s office. With DROP now requiring recurring deletions, the agency is using its rulemaking, fee, and audit authority to make sure the platform has verification mechanisms behind it and the resources to sustain them.

For the businesses that register as data brokers under California law, this moment is worth watching closely, not because it signals a sudden crackdown, but because it signals maturity. The CPPA is moving DROP from a compliance obligation measured by whether a broker registered and set up an intake process, to one measured by whether deletion requests are actually being honored on a 45-day cycle and can be verified as such. That is a meaningful shift in what compliance will mean going forward, and it is the kind of infrastructure-building work that determines whether a consumer right written into a statute becomes a consumer right that people can actually use.

Other states drafting their own data broker and deletion frameworks would do well to watch how California builds out the audit and funding mechanisms behind DROP now that the system is live. The statute was the easy part. Making it real is the harder, and now underway, part.

Richart Ruddie is CEO of Captain Compliance, a privacy compliance platform.

Want to see more stories like this? Sign up for The Roundup, the free daily newsletter about California politics from the editors of Capitol Weekly. Stay up to date on the news you need to know.

Sign up below, then look for a confirmation email in your inbox.


Leave a Reply

Your email address will not be published. Required fields are marked *

Support for Capitol Weekly is Provided by: