On August 1, a major part of California’s privacy experiment moves from preparation to operations.
The state’s Delete Request and Opt-out Platform, better known as DROP, has actually been open to California consumers since January 1, 2026. What changes on August 1 is what happens on the other side.
Data brokers must begin retrieving the deletion requests sitting in DROP, comparing those requests against their databases, deleting matching non-exempt personal information, and reporting what happened.
This is not a small batch of privacy requests.
On July 10, the California Privacy Protection Agency, or CalPrivacy, said more than 325,000 consumers had already submitted DROP requests. The system sends a consumer’s request to more than 600 active data brokers.
Until now, a consumer who wanted to disappear from the data brokerage market often had to track down companies individually, find each company’s privacy form, verify an identity, and repeat the process.
DROP turns that model around.
A California resident makes one request. Registered data brokers have to do the work.
For companies that buy consumer mailing lists, prospect databases, email data, phone records, demographic files, or other third-party marketing data, that makes August 1 worth understanding even when the buyer is not itself legally classified as a data broker.
First, What Is California’s DELETE Act?
California enacted Senate Bill 362, commonly called the Delete Act, in October 2023.
The law expanded California’s existing data broker registration system and ordered CalPrivacy to build a centralized mechanism through which a California consumer could ask registered data brokers to delete personal information about that consumer.
That mechanism became DROP.
California law defines a data broker as a business that knowingly collects and sells personal information about a consumer to third parties when the business does not have a direct relationship with that consumer.
The definition matters because not every company that possesses a marketing list is automatically a data broker.
A roofing company that purchases a homeowner mailing list and uses it to advertise its own services, for example, does not become a data broker merely because it bought data. The core statutory definition is aimed at qualifying businesses that collect personal information and sell it to third parties without the required direct consumer relationship.
California also defines a “sale” broadly. It can include selling, renting, releasing, disclosing, transferring, or otherwise making personal information available to a third party in exchange for money or other valuable consideration.
That means companies that think of themselves as data providers, audience platforms, list managers, aggregators, lead vendors, or information services should not assume the label “data broker” depends on what appears on their website.
It depends on what the company actually does with consumer information.
The law contains exemptions for certain entities and processing covered by laws including the Fair Credit Reporting Act, Gramm-Leach-Bliley Act, California insurance privacy law, and certain medical privacy provisions. Those exemptions are specific, however. A company should not assume that having some regulated data makes every activity exempt.
What Actually Happens on August 1, 2026?
August 1 starts the mandatory processing cycle.
Under California Civil Code Section 1798.99.86, a data broker must access DROP at least once every 45 days.
The workflow is more technical than simply receiving an email saying, “Delete Jane Doe.”
DROP protects consumer information through hashing. Consumers submit identifiers through the state system, and data brokers retrieve hashed deletion lists. Brokers must standardize and hash identifiers in their own databases so they can compare records without DROP handing them consumers’ raw personal information.
CalPrivacy currently provides six types of deletion lists, including matches based on:
- First and last name combined with date of birth and ZIP code
- Email address
- Phone number
- Mobile advertising ID
- Name combined with vehicle identification number
- Connected TV identifier
A broker must select the deletion lists appropriate to the identifiers it holds.
When a match is found, the broker generally must delete the consumer’s non-exempt personal information, not merely the identifier used to find the person.
An email address may be what produces the match. The deletion obligation can reach the other personal information associated with that consumer record, including sensitive information and inferences, subject to statutory exemptions.
The broker must also direct its service providers and contractors to delete covered personal information associated with the consumer.
If a request cannot be verified sufficiently for deletion, California law generally requires the broker to treat it as an opt-out of sale or sharing rather than simply ignoring the request.
And this is not designed as a one-time cleanup.
After a consumer has successfully submitted a deletion request and the broker has deleted the data, the broker must continue deleting subsequently acquired personal information associated with that consumer at least once every 45 days, unless an exception applies or the consumer changes the request.
The broker also cannot simply acquire the person again and resume selling the data.
The statute says that after deletion, the data broker may not sell or share newly obtained personal information about that consumer unless the consumer requests otherwise or an applicable legal exception permits it.
In practical terms, DROP functions partly as an ongoing suppression system.
The 45-Day Rule Does Not Mean Everything Must Vanish on August 1
August 1 is the beginning of processing, not a midnight deadline requiring hundreds of thousands of records to disappear simultaneously.
Data brokers must access DROP at least once every 45 days. Once a broker receives a request through the system, it generally has 45 days to process it.
That is why CalPrivacy tells consumers that a DROP request may take as long as roughly 90 days to show a final status. A broker could retrieve the request near the end of one 45-day access window and then have another processing period.
The important point for the data industry is that August 1 starts a permanent recurring workflow.
There is no “August compliance project” that gets checked off and archived.
The database has to keep responding to DROP.
The Penalties Can Compound Quickly
California attached a significant enforcement mechanism to the Delete Act.
A data broker that fails to register can face an administrative fine of $200 for each day it remains unregistered, plus unpaid fees and the state’s investigation and administrative costs.
More important for DROP, a registered broker that fails to delete information as required can face $200 per deletion request for each day of noncompliance, plus enforcement costs.
Consider what “per request, per day” means when a database contains thousands of affected consumers.
The compliance exposure is not structured like a modest annual licensing fee.
California has also already demonstrated that data broker registration is an enforcement priority. CalPrivacy previously announced investigative sweeps focused on registration compliance, so businesses should not treat the registry as a voluntary directory.
Beginning in 2028, data brokers must also undergo an independent third-party audit every three years to assess compliance with the deletion requirements.
The operational record being built today may therefore matter long after the first August processing cycle.
What Does the DELETE Act Mean for Mailing List Buyers?
This is where confusion is likely.
A company does not automatically become a California data broker because it purchases a marketing list.
If you purchase a list and use those records to advertise your own products or services, the Delete Act’s data broker definition may not apply to you in the same way it applies to the company compiling and selling the records.
But that does not make DROP irrelevant to buyers.
It changes the data supply chain.
Companies using consumer mailing lists, direct mail data, prospect databases, email records, phone lists, and demographic targeting increasingly need to know not only whether a record is accurate, but where it came from, when it was refreshed, and what suppression processes were applied before delivery.
List Freshness Now Has a Privacy Dimension
Marketers have always cared about list freshness.
People move. Businesses close. Phone numbers change. Employees change companies. Email addresses bounce.
Privacy requests add another form of expiration.
A consumer record may still be factually accurate while no longer being eligible for sale by a particular data broker because that consumer has submitted a DROP request.
That makes “How recently was this list updated?” only part of the question.
List buyers should also understand how frequently a vendor processes consumer suppression and privacy requests.
For campaigns using third-party consumer data, a database built six months ago and a database processed through current privacy controls are not necessarily the same product, even when the names and addresses appear identical.
That is especially relevant when purchasing data for high-volume direct mail campaigns or repeatedly licensing similar audiences throughout the year.
A DROP Request Does Not Necessarily Erase Every Copy Previously Sold to a Buyer
This distinction deserves attention.
The Delete Act expressly requires a covered data broker to delete matching personal information from its own systems and to direct associated service providers and contractors to delete covered information.
A third-party list buyer is not necessarily the broker’s service provider or contractor.
So businesses should not assume that when a consumer submits a DROP request, every historical copy of that person’s record already delivered to every advertiser in America instantly disappears.
Separate obligations under the California Consumer Privacy Act may apply.
For example, when a CCPA-covered business receives a qualifying deletion request under the CCPA, California Civil Code Section 1798.105 requires the business, subject to exceptions, to delete the information and notify service providers, contractors, and third parties to whom it sold or shared the information to delete it.
That is related to DROP, but it is not identical to DROP.
For list buyers, the takeaway is simple: do not outsource your entire privacy program to the assumption that the data vendor handled it.
A buyer that independently qualifies as a business under the CCPA may have its own consumer-rights obligations.
Buyers Should Start Asking Vendors Better Questions
Buying marketing data has traditionally involved questions about record count, deliverability, geographic coverage, demographic filters, price, and accuracy.
Privacy should now be part of the same conversation.
Before licensing California consumer data, buyers should consider asking:
Is the vendor a registered California data broker when registration is required?
California maintains a public Data Broker Registry, making this easier to verify.
How does the vendor process DROP requests?
A credible answer should involve more than saying the company is “privacy compliant.” Brokers now have specific recurring obligations.
When was the dataset last processed or refreshed?
For frequently updated campaigns, the timing of privacy suppression may matter alongside address, email, and telephone hygiene.
How does the vendor distinguish directly collected data from third-party sourced data?
Source provenance becomes increasingly important because DROP focuses on data broker information, while information obtained through a direct customer relationship can be treated differently.
What happens when privacy instructions change after a file is delivered?
The answer depends on the parties’ relationship and applicable law, but buyers should know whether update or suppression procedures exist.
For businesses still learning how third-party consumer data is sourced and evaluated, see our guide to buying consumer mailing lists.
Direct Mail Is Not Automatically Outside the Law
Because DROP is often discussed alongside digital advertising, some direct mail marketers may assume physical addresses are outside its scope.
They are not automatically excluded.
California’s definition of personal information includes identifiers such as a person’s real name, postal address, email address, phone number, IP address, and other information that can reasonably be linked to a consumer or household.
There is, however, an important public-information distinction.
The CCPA excludes certain “publicly available” information from its definition of personal information, including information lawfully available from federal, state, or local government records and certain information a business reasonably believes the consumer made available to the general public.
That means the legal treatment of a mailing record can depend on its source and context.
A postal address copied from a public government record is not necessarily treated the same way as a commercial consumer profile combining an address with purchase behavior, estimated income, lifestyle characteristics, interests, inferred preferences, and other nonpublic attributes.
This is another reason provenance matters.
The relevant question is not simply, “Is this a mailing address?”
It is, “What information is in this record, where did it come from, how is it used, and what legal rules apply to that information?”
Businesses purchasing mailing list services should be asking those questions before campaign deployment, not after a complaint arrives.
Business Lists and Consumer Lists Present Different Risk Profiles
DROP applies to personal information about California consumers, and California defines “consumer” as a natural person who is a California resident.
That means B2B marketing is not automatically outside privacy law simply because the campaign targets companies.
A list containing “ABC Manufacturing, 100 Industrial Road” is different from a file containing a named executive, that executive’s direct email, personal mobile number, professional history, inferred interests, and other data linked to an identifiable person.
The more a B2B database shifts from company-level information toward individual-level contact and profile information, the more carefully buyers should assess privacy requirements.
Businesses purchasing business mailing lists should distinguish firmographic information about organizations from personal information about the people working inside them.
The Delete Act does not create a broad exemption simply because the marketing objective is B2B.
DELETE Act Compliance Does Not Replace CAN-SPAM, TCPA or Do-Not-Call Rules
Another mistake would be treating DROP compliance as permission to contact someone through every channel.
It is not.
Privacy law and marketing-channel law answer different questions.
A record surviving a DROP review does not automatically mean you may text the phone number, place a telemarketing call, or send email without considering the rules governing that channel.
Commercial email campaigns must still consider CAN-SPAM requirements. See our guide to CAN-SPAM compliance when using purchased email data.
Telephone campaigns still need to consider the Telephone Consumer Protection Act, federal and state Do Not Call requirements, calling-time restrictions, consent requirements where applicable, and related FCC and FTC rules.
Businesses using telemarketing lists should continue treating Do Not Call and privacy suppression as separate compliance processes.
SMS is even more sensitive because consent and messaging rules can differ substantially from ordinary postal marketing. A list that can lawfully be held in a database is not automatically a list that can lawfully receive an automated marketing text.
The safest operational model is to think in layers:
Privacy permission, data-source rules, channel rules, consumer opt-outs, and campaign-specific restrictions.
One list may pass one layer and fail another.
What Data Brokers Should Have Ready Before August 1
For a business that qualifies as a data broker, the question on July 30 is no longer whether DROP is coming.
It is whether the process works.
CalPrivacy says brokers beginning processing on August 1 must be prepared to download their applicable consumer deletion lists, standardize and hash their own records, match requests, process the result, and report request status back through DROP.
Data brokers can use manual processing or an API and have had access to a DROP sandbox environment for testing.
Operationally, that means a broker should know where consumer identifiers live across its databases.
It should know which systems contain emails, phone numbers, postal information, advertising identifiers, connected television identifiers, vehicle information, demographic attributes, inferences, and other consumer-linked data.
It should know which service providers and contractors hold copies.
It should know how deletions propagate.
It should know how suppressed consumers are prevented from simply returning in the next data import.
And it needs a process for recording statuses such as deleted, exempted, opted out, not found, or pending.
This is data governance work, not a privacy-policy rewrite.
What Mailing List Buyers Should Do Now
Mailing list buyers do not need to panic and abandon third-party data on August 1.
They do need to become more selective about their supply chain.
- Identify which vendors supply consumer-level information involving California residents.
- Determine which vendors qualify as data brokers and whether their registration and DROP processes are in place where required.
- Review contracts and purchasing terms. Compliance representations, permitted uses, privacy responsibilities, source documentation, suppression practices, and data-refresh procedures should not be left to assumptions.
- Preserve source information when data enters your systems. A record collected through your own website, a record purchased from a data broker, and a record obtained from a public source may need to be treated differently.
- Keep your own suppression systems healthy. A fresh vendor file should not cause your organization to contact someone who has already opted out directly from your company.
- Audit what happens downstream. If your business resells, rents, shares, enriches, or otherwise transfers purchased personal information to other companies, your legal position may be very different from that of a business that buys data solely for its own marketing.
Calling yourself a “buyer” does not settle that question.
The Bigger Change Is Not Deletion. It Is Persistence.
The most consequential feature of DROP may not be the first wave of deletion requests.
It is what happens afterward.
Historically, deleting a person from one database did not necessarily stop the same record from being purchased again from another source weeks later.
The Delete Act attempts to address that cycle.
Once a covered broker processes a consumer’s request, California requires continuing deletion of subsequently acquired personal information at least every 45 days and restricts future sale or sharing of new personal information about that consumer, subject to exceptions.
That changes the economics of list maintenance.
A privacy request is no longer simply a ticket to close.
It becomes a continuing data state.
For data brokers, that means suppression controls become part of database architecture.
For list buyers, it means the strongest providers will increasingly be judged not only on the size of their database but on their ability to explain where records came from, when they were updated, what rights attach to them, and how consumer preferences are carried through the system.
Will California’s DELETE Act Kill Mailing Lists?
No.
The Delete Act does not prohibit direct mail, consumer lists, B2B prospecting, demographic targeting, or the purchase of marketing data.
It also does not say that every consumer record must be deleted.
Some information is exempt. Some publicly available information falls outside the CCPA definition of personal information. Businesses with direct consumer relationships can hold information that DROP does not require them to erase through the data broker mechanism. Other legal exceptions may apply.
What California has changed is the amount of control a consumer can exercise over the third-party data broker market.
A consumer no longer has to discover hundreds of companies one by one.
DROP allows one request to reach hundreds of registered brokers.
That creates pressure on the industry to know its data better.
- Where did this record come from?
- Is this consumer subject to a deletion request?
- Is the data exempt?
- Can it still be sold?
- Can it still be used for marketing?
- Has the broker collected the person again?
- Does the buyer have its own legal obligations?
Those are database questions now.
August 1 Is the Start, Not the Finish
The headline date is August 1, 2026.
But California’s Delete Act is designed around repetition.
Every 45 days, brokers return to DROP.
New requests arrive.
Old requests remain relevant.
Newly acquired consumer information may have to be deleted again.
Request statuses must be maintained.
Service providers and contractors have to be accounted for.
And beginning in 2028, independent compliance audits enter the picture.
For mailing list buyers, the lesson is less dramatic but just as practical.
Third-party data is not becoming obsolete.
Untraceable third-party data is becoming harder to defend.
The buyers most likely to avoid problems will be the ones who know who supplied their data, how it was collected, when it was refreshed, which privacy controls were applied, what their contracts say, and which rules govern the marketing channel they plan to use.
The best mailing list is no longer simply the file with the most records.
It is the file whose records can be explained.
Disclaimer: This article is for general informational purposes only and does not constitute legal advice. Businesses should consult qualified legal counsel about their specific obligations under the California Delete Act, CCPA, CPRA, TCPA, CAN-SPAM Act, and other applicable privacy and marketing laws.

