Outbound Wiki

Article

Getting Ready to Use the DROP

kelleydrye.com

Open at publisher

Quoted on this wiki

Every place a page here uses this source, in the order the words come in it.

  1. The January 31 deadline for companies that operated as data brokers in 2025 to register in California has passed, but registration is just the beginning of what lies ahead for data brokers in the remainder of 2026 (and beyond). Most significantly, beginning on August 1, 2026, data brokers will be required to access deletion requests submitted by consumers (i.e., residents of California) through the California Privacy Protection Agency’s (CalPrivacy) Delete Request and Opt-out Platform (DROP). Preparing to use the DROP requires data brokers to thoroughly understand their data and data flows and implement new processes to interact with the platform.The core element of the DROP is the array of “consumer deletion lists” that contain identifiers of consumers who sign up and request deletion through the DROP.But pulling consumer deletion lists from the DROP is just the operational first step. The bulk of the work needed to process DROP requests will occur on the back end, where data brokers must ingest, standardize, hash, match, and systematically purge identifiers across fragmented data ecosystems.

    In Outbound vendor data retention

  2. The January 31 deadline for companies that operated as data brokers in 2025 to register in California has passed, but registration is just the beginning of what lies ahead for data brokers in the remainder of 2026 (and beyond). Data brokers must act on those requests within 45 days of downloading and will need to repeat a similar process at least once every 45 days going forward. Preparing to use the DROP requires data brokers to thoroughly understand their data and data flows and implement new processes to interact with the platform.The core element of the DROP is the array of “consumer deletion lists” that contain identifiers of consumers who sign up and request deletion through the DROP.But pulling consumer deletion lists from the DROP is just the operational first step. The bulk of the work needed to process DROP requests will occur on the back end, where data brokers must ingest, standardize, hash, match, and systematically purge identifiers across fragmented data ecosystems.

    In Outbound vendor data retention

  3. Most significantly, beginning on August 1, 2026, data brokers will be required to access deletion requests submitted by consumers (i.e., residents of California) through the California Privacy Protection Agency’s (CalPrivacy) Delete Request and Opt-out Platform (DROP). Data brokers must act on those requests within 45 days of downloading and will need to repeat a similar process at least once every 45 days going forward. The core element of the DROP is the array of “consumer deletion lists” that contain identifiers of consumers who sign up and request deletion through the DROP. This post takes a close look at how the DROP regulations will require data brokers to obtain, process, and report on DROP requests.

    In Outbound vendor data retention

  4. Most significantly, beginning on August 1, 2026, data brokers will be required to access deletion requests submitted by consumers (i.e., residents of California) through the California Privacy Protection Agency’s (CalPrivacy) Delete Request and Opt-out Platform (DROP). Data brokers must act on those requests within 45 days of downloading and will need to repeat a similar process at least once every 45 days going forward. But pulling consumer deletion lists from the DROP is just the operational first step. This post takes a close look at how the DROP regulations will require data brokers to obtain, process, and report on DROP requests.

    In Outbound vendor data retention