California’s SB 361 expands California’s Delete Act and will soon require registered data brokers to regularly check California’s data deletion database, known as DROP, to determine whether a California consumer has requested deletion of their personal information. Beginning August 1, 2026, data brokers must access DROP at least every 45 days and, when a request appears, delete the consumer’s personal information within 45 days and direct applicable service providers and contractors to do the same. Once the information is deleted, the data broker generally may not sell or share new personal information about that consumer unless the consumer indicates otherwise.
The penalties are significant: failures to register can trigger $200-per-day penalties, and failures to honor deletion requests can result in $200 per deletion request for each day the information is not deleted. Companies that may fall under California’s definition of a “data broker” should prepare now by confirming whether registration is required, mapping California personal information flows, identifying vendors and contractors that may need deletion instructions, and building a documented process to check DROP at least every 45 days. Even companies that do not intend to collect information from California consumers should revisit their data sources and screening practices, as the CPPA has already shown interest in out-of-state businesses that handle Californians’ personal information.