By Staff Reporter
California’s Delete Act (SB 362) reached a critical operational milestone on August 1, as registered data brokers officially became required to access and process consumer erasure requests submitted through the state’s centralized deletion system.
The mechanism at the heart of the law—the Delete Request and Opt-out Platform (DROP)—is administered by the California Privacy Protection Agency (CPPA). Designed to streamline data deletion, DROP allows California residents to submit a single, free request to purge their personal information across more than 600 registered data brokers. Since the portal opened to consumers in January, more than 300,000 residents have submitted opt-out profiles.
For consumer reporting agencies (CRAs), screening firms, and background data suppliers operating in or handling records of California residents, the start of enforcement marks a fundamental shift in state-level data compliance.
How the Process and Timeline Work
Under the Delete Act, a "data broker" is broadly defined as any business that knowingly collects and sells personal information of consumers with whom it lacks a direct relationship. This definition sweeps in entities that aggregate online activity, commercial files, and public records to sell or share with background screening services, marketing networks, and corporate intelligence firms.
Starting August 1, registered data brokers are legally mandated to access the DROP platform at least once every 45 days. Upon retrieving a consumer’s request, the broker has 45 days to query its databases, delete covered records, and report the status back to the CPPA. Consequently, an individual request can remain in the processing pipeline for up to 90 days.
To match records, the state portal collects a consumer's name, date of birth, and ZIP code, along with optional identifiers such as phone numbers, email addresses, mobile ad IDs, or vehicle identification numbers (VINs).
Once a broker processes a submission, one of four outcomes is logged:
- Deleted: The vendor matched the record and erased the non-exempt personal information.
- Record Not Found: No matching consumer profile was located within the vendor’s systems.
- Exempted: The vendor retained specific records under statutory exemptions provided by law.
- Opted-Out: The vendor could not verify an exact identity match, but applied a mandatory fallback stopping the sale or sharing of the consumer’s data.
Crucially, deletion is not a one-time event. Once a match is confirmed and processed, data brokers must continue to query DROP every 45 days and automatically purge any newly acquired personal information linked to that individual on an ongoing basis.
Statutory Exemptions and FCRA Safeguards
A central area of focus for background screeners is the boundary between covered commercial data and exempt reporting files.
The Delete Act does not eliminate all records across all databases. Specific statutory exemptions protect data collected, processed, or disclosed pursuant to federal framework statutes, including:
- The Fair Credit Reporting Act (FCRA) for background checks and credit reports.
- The Gramm-Leach-Bliley Act (GLBA) for financial data.
- The Driver’s Privacy Protection Act (DPPA).
- Publicly available records maintained by government bodies.
Information held by background screening vendors that falls strictly within these federal frameworks or primary public record exceptions is generally exempt from mandatory deletion. However, the law imposes a strict usage restriction: any exempt information retained by a broker may only be used for the specific purpose supporting that exemption. It cannot be repurposed, repackaged, or leveraged for secondary commercial services, such as cross-selling, lead generation, or un-exempt marketing feeds.
Vendors that offer hybrid products—combining FCRA-regulated screening reports with non-FCRA contact enrichment, web scraping, or predictive risk scoring—face distinct operational exposure. Personal information used in non-exempt product lines remains fully subject to DROP deletion mandates.
Regulatory Penalties and Compliance Audits
Enforcement rests exclusively with the California Privacy Protection Agency; the statute does not grant consumers a private right of action to file civil lawsuits for DROP violations.
However, administrative penalties for non-compliance are severe:
- Failure to process covered requests: Administrative fines of $200 per request for every day the violation continues, plus state investigation and enforcement costs.
- Failure to register as a data broker: A separate penalty of $200 per day of non-registration.
Beginning in 2028, all registered data brokers will also be required to undergo independent third-party compliance audits every three years to verify adherence to DROP processing and recurring deletion rules.
As the first wave of 300,000-plus requests flows out to registered vendors, data suppliers and screening firms serving the California market must ensure clear segmentation between FCRA-exempt files and non-exempt data assets to maintain full statutory compliance.
