Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Which Data Broker Path Applies to You Under DROP?Data Subject Rights
5 min readFor Data Privacy Officers

Which Data Broker Path Applies to You Under DROP?

California's Delete Request and Opt-Out Platform (DROP) launched in January 2026. You have until August 1, 2026, to determine if your organization falls under its scope. This deadline doesn't leave much time to set up the necessary systems for handling deletion requests through the state-administered platform.

Determining your status isn't always straightforward. Your organization might manage consumer data without considering itself a "data broker" under California's Delete Act. Or you might mistakenly assume an exemption applies. Here's how to evaluate your position and choose the right compliance path.

The Decision You're Facing

You need to answer one question: Does your organization meet the Delete Act's definition of a data broker, and if so, must you register and process DROP requests?

This is critical because the consequences vary significantly. If you register and comply, you'll process requests every 45 days, maintain suppression lists, and report back through DROP. If you fail to register when required, you face monetary penalties starting at $200 per day, plus potential enforcement actions from Cal Privacy.

The Delete Act defines data brokers as businesses that knowingly collect and sell consumers' personal information without a direct relationship with them. This definition is broader than it might seem.

Key Factors That Affect Your Choice

Before you decide, consider these factors:

Nature of your data collection. Do you collect personal information from sources other than direct consumer interaction? If you're purchasing data sets, scraping public records, or aggregating information from third-party sources, you're in scope.

Purpose of data use. Are you selling or sharing this information with third parties? The Delete Act targets the sale and sharing of personal information, not just collection. If you collect data solely for internal analytics without selling it, your obligations differ.

Existing regulatory coverage. Does your primary business activity already fall under the Fair Credit Reporting Act or HIPAA? These carve-outs exist because those frameworks already impose data handling requirements. But pay attention: if you perform data broker activities outside your FCRA-covered credit reporting business, that portion still requires registration.

First-party vs. third-party relationships. Do consumers provide information directly to you as part of a transaction or service? First-party data collection doesn't automatically make you a data broker. The Delete Act focuses on businesses that lack direct consumer relationships.

Path A: Register as a Data Broker and Prepare for DROP Integration

Choose this path if your organization:

  • Collects personal information about California residents from third-party sources
  • Sells or shares that information with other businesses
  • Lacks direct relationships with the consumers whose data you handle
  • Doesn't qualify for FCRA or HIPAA exemptions for these specific activities

What you must do by August 1, 2026:

Build a system to retrieve DROP requests at least every 45 days. This isn't optional frequency. You can check more often, but 45 days is your maximum interval.

Establish a 90-day processing window. From retrieval to action, you've got 90 days to determine whether a deletion request is valid and execute it. That timeline includes verification, system searches across all databases, and actual deletion.

Create suppression lists that prevent re-collection. Deleting data once isn't enough. You need technical controls that flag deleted consumer identifiers and block them from re-entering your systems through new data purchases or collection activities.

Implement third-party forwarding. Unlike other state privacy laws that only require you to delete first-party data, the Delete Act requires you to forward deletion requests to service providers, processors, and other data brokers with whom you've shared the consumer's information. Map those data flows now.

Set up compliance reporting through DROP. You'll need to report back through the platform on each request's status. Build that reporting capability into your workflow before the deadline.

Operational reality: If you handle hundreds of thousands of consumer records and sell data commercially, you're likely looking at process automation. Manual retrieval and deletion won't scale. Budget for API integration, automated record matching, and audit logging that proves compliance.

Path B: Operate Under an Existing Regulatory Framework

Choose this path if your organization:

  • Performs activities already governed by FCRA (consumer reporting agencies, credit bureaus)
  • Handles protected health information under HIPAA as a covered entity or business associate
  • Doesn't perform data broker activities outside these regulated functions

What you must do:

Verify your exemption applies to all relevant activities. Don't assume HIPAA coverage for your healthcare business automatically exempts your marketing analytics division that purchases consumer data. Segment your operations and evaluate each business unit separately.

Document your exemption basis. When Cal Privacy audits (and they've hired their first Chief Privacy Auditor), you'll need clear documentation showing why you're not registered. That means mapping your data flows, identifying legal bases, and maintaining records of your analysis.

Monitor for scope creep. If you expand into new data products or services that fall outside FCRA or HIPAA, you'll need to revisit this decision. Exemptions are activity-specific, not blanket organizational protections.

Path C: Restructure to Exit Data Broker Classification

Choose this path if your organization:

  • Currently sells third-party consumer data but can shift to a first-party model
  • Can eliminate data sales while maintaining core business operations
  • Wants to avoid ongoing DROP compliance obligations

What you must consider:

Revenue impact. If data sales represent a significant revenue stream, exiting the business entirely has obvious financial implications. Model those costs against ongoing compliance expenses.

Contractual obligations. You may have existing agreements with data buyers that you can't simply terminate. Review your contracts and understand exit timelines.

Competitive positioning. Some businesses use data sales as a loss leader or customer acquisition strategy. Understand the strategic implications before you exit.

This path isn't about gaming the system. It's about aligning your business model with your compliance capacity. If you're a small operation that stumbled into data broker classification through a side business, exiting might be more sustainable than building DROP infrastructure.

Summary Matrix

Factor Path A: Register Path B: Exemption Path C: Exit
Data source Third-party Direct consumer relationship or regulated activity Shift to first-party only
Data sales Yes No (or exempt activity) Eliminate sales
Compliance deadline August 1, 2026 N/A Before August 1, 2026
Technical requirements DROP integration, suppression lists, third-party forwarding Document exemption basis Wind down data broker operations
Ongoing obligations 45-day retrieval, 90-day processing, compliance reporting Maintain exemption documentation None (if fully exited)
Penalty exposure $200/day for non-compliance Misclassification risk None (if completed before deadline)

The Delete Act doesn't give you much room to delay this decision. Cal Privacy has already demonstrated enforcement willingness with its action against ROR Partners LLC. If you're still evaluating your classification in July 2026, you've waited too long.

Map your data flows this month. Identify every source of consumer information, every sale or sharing arrangement, and every potential exemption. Then pick your path and execute.

Promotional banner for the Pentest Readiness checklist download

You Might Also Like