California Delete Act DROP Mechanism 2026: What AI Data Brokers Must Do
The Delete Act's one-click deletion platform is now live, and it doesn't work like standard CCPA opt-out. A single consumer request now reaches every registered California data broker at once — and AI companies that buy, license, or train on third-party consumer datasets need to know whether that includes them.
Why DROP Is a Different Animal Than Standard CCPA Opt-Out
Most of the CCPA compliance conversation around AI has centered on opt-out rights against a single business you have a direct relationship with — the SaaS vendor whose chatbot you used, the retailer whose site you browsed. The Delete Act targets a structurally different problem: data brokers that consumers have never directly interacted with, who accumulate and resell profiles built from other sources.
DROP — the Delete Request and Opt-out Platform — is the California Privacy Protection Agency's answer to the fact that consumers can't meaningfully exercise deletion rights against brokers whose names they don't even know. One request through the platform now propagates to every broker on the state's registry, and brokers must act on the accumulated queue at least once every 45 days going forward, not just when a business happens to receive a direct request.
Where AI Companies Get Pulled Into Broker Status
The data broker definition doesn't mention AI at all — it's about the relationship (or lack of one) between the business and the consumer, plus whether personal information is sold to third parties. But AI business models intersect with that definition more often than teams expect.
Likely in scope
- ☐Selling AI-enriched consumer profiles or lead lists built from third-party data
- ☐Licensing scraped or aggregated consumer datasets to model developers
- ☐Reselling inferences (interests, propensity scores) derived from data bought from other sources
- ☐Operating a marketplace that connects data sellers with AI training-data buyers
Usually out of scope
- ☐Training models only on data collected directly from your own users
- ☐Using AI internally without selling any resulting consumer data to third parties
- ☐Buying data under a service-provider contract that doesn't constitute a 'sale' under CCPA's definition
- ☐First-party SaaS tools with no data resale business line
The distinction that matters most is the "no direct relationship" prong. A business that markets AI tools straight to the consumers whose data it processes generally isn't a data broker under this framework. A business that buys consumer data secondhand, enriches it with AI-derived inferences, and resells the result is exactly the pattern the Delete Act targets.
Registration and Deletion Obligations for Brokers
- Annual registration with the CPPA is required for any business meeting the data broker definition, with registration fees and required disclosures about the categories of data sold.
- DROP compliance means checking the accumulated deletion request queue on the required recurring cycle and deleting matched consumer data across all systems — not just the record a consumer happens to know about.
- Onward deletion extends to third parties the broker has previously sold or shared the data with, unless a specific exception applies.
- Audit obligations apply to larger registered brokers, who must undergo independent audits of DROP compliance on a periodic basis.
- Unregistered operation — selling consumer data as a broker without registering — is a separate, independently enforceable violation on top of any deletion failures.
What to Check Before Your Next Model Training Run
If your team licenses or purchases third-party consumer datasets for model training, the Delete Act creates a chain-of-custody problem worth checking before you rely on that data again: was the seller a registered broker, and if so, has any of the data you're using already been subject to a DROP deletion request the seller was obligated to honor?
This sits alongside — but is legally distinct from — the general CCPA question of whether consumers can force deletion of data already baked into a trained model. The Delete Act obligation attaches to the broker's live systems and downstream transfers; it doesn't by itself require unwinding a model that has already been trained, though contracts with data sellers increasingly push that risk downstream to buyers.
See where your AI product is exposed
RatedWithAI helps SaaS and platform teams surface compliance and trust gaps across their web properties. Start with a free scan to understand how your product presents to users and regulators alike.
Scan Your Product for Free →Frequently Asked Questions
Does the Delete Act replace regular CCPA deletion requests?
No. The Delete Act's DROP mechanism is an additional, broker-specific channel. Consumers can still send individual deletion requests directly to any business under standard CCPA rights — DROP exists specifically because that individual-request model doesn't work well against brokers consumers have never heard of.
What counts as 'selling' data for data broker purposes?
CCPA's definition of sale is broad and includes exchanging personal information for monetary or other valuable consideration, not just a traditional cash purchase. Data-for-data swaps, or data provided as part of a business partnership where value flows back to the provider, can qualify — check the exact contract terms rather than assuming a non-cash exchange is exempt.
What happens if a business should have registered as a broker but didn't?
Failure to register when required is independently enforceable by the California Attorney General and the CPPA, separate from any deletion-related violations. Given the registry is public and used to compile DROP's broker list, unregistered data-selling activity is also easier for regulators and researchers to spot through data-flow investigations than it was before the registry existed.
Is this the same law as the CCPA data broker registration requirement from a few years ago?
The Delete Act builds on California's earlier data broker registration law by adding the centralized DROP deletion mechanism, recurring deletion cycles, and mandatory audits — it's an expansion of the existing registration framework, not a separate standalone statute.