Steps to Address California’s Intricate DROP Mandates As Data Broker Cases Grow

August marked the start of a sweeping new mandate requiring data brokers to permanently delete the PI of a half million Californians, with violations carrying a penalty of $200 per user per day. CalPrivacy punctuated this consumer privacy milestone by announcing three settlements with unregistered brokers. The latest settlements highlight the agency’s broad interpretation of who qualifies as a regulated data broker and how enforcers can stack multiple laws in cases against brokers. This article examines the settlements, the challenges of satisfying Delete Request and Opt-Out (DROP) requirements and enforcement priorities, and offers practical DROP compliance steps, with comments from experts at Barnes & Thornburg, Davis & Gilbert, Fenwick, InfoLawGroup and In-House Privacy. It also discusses an industry letter to CalPrivacy seeking limited enforcement for the first year of DROP compliance and a new law passed last week that shortens brokers’ DROP cycle from 45 days to 30 days. See “Lessons From the Trenches on How Data Brokers Can Manage Consumer Rights Requests” (Jan. 7, 2026).

To read the full article

Continue reading your article with a CSLR subscription.