California's DROP platform becomes binding on data brokers from 1 August 2026, forcing over 600 registered brokers to work through queued deletion requests and raising compliance urgency across US and European firms
California's Delete Request and Opt-out Platform (DROP) went live for consumers on 1 January 2026, giving California residents a free centralised mechanism to request deletion of their personal data from more than 600 registered data brokers at once. The obligation that bites on 1 August 2026 falls on the brokers: from that date they must check DROP at least every 45 days, delete matching records and report the outcome, with administrative fines of $200 per consumer per day for non-compliance. The platform is managed by the California Privacy Protection Agency (CPPA) and was mandated under the Delete Act, passed by California legislators in 2023. More than 20 US states have passed or enacted data privacy laws requiring parties to delete personal data at consumer request, mirroring the "right to be forgotten" framework established under the EU's General Data Protection Regulation (GDPR). The DROP launch represents the most operationally significant implementation of those rights to date, given the scale of simultaneous requests it enables. For UK and European firms with California operations or US data broker exposure, the launch has immediate compliance implications. Data brokers that have not built workflows to handle centralised DELETE requests at scale face the risk of falling behind response obligations under the Delete Act. The broader pattern of US state-level privacy legislation increasingly converging toward GDPR-style individual rights is also significant for UK practitioners advising multinational clients on their data governance frameworks. No specific UK regulatory enforcement actions or named advisers were linked to the DROP launch in the available sources.
Why this matters
The DROP platform is the first time a US state has created a single centralised deletion request mechanism at this scale, and from 1 August 2026 it binds over 600 registered data brokers, who must now work through requests that have been queuing since the platform opened to consumers in January. The practical compliance pressure on those brokers is significant: companies that have not invested in automated data deletion workflows will struggle to respond to a surge of simultaneous requests. For UK and European practitioners, the relevance is twofold: first, many multinational clients are data brokers or use data broker services and will need advice on US compliance obligations that now materially resemble GDPR data-subject rights; second, the convergence of US state privacy law toward European standards reinforces the importance of globally harmonised data governance frameworks.
On the Ground
The DROP launch generates data privacy and regulatory compliance work for firms advising US-facing clients. Practice areas activated include data privacy (compliance gap analysis, deletion workflow design), technology transactions (reviewing data processor agreements to ensure deletion obligations flow down to sub-processors), and regulatory (advising on CPPA enforcement risk and response timelines). A trainee would assist with compliance gap analysis memos comparing a client's existing data deletion capabilities against the Delete Act's requirements, draft regulatory notification templates, and prepare summaries of how existing data processing agreements address deletion obligations.
Interview prep
Question you might get
“How does California's DROP platform compare to GDPR's right to erasure, and what compliance steps would you recommend for a UK firm with US data broker operations?”
Sign up free to see the full answer
A model answer you can lift into an interview — how to frame this story for a partner.
Sign up freeMy notes
saved