California’s SB 361 expands California’s Delete Act and will soon require registered data brokers to regularly check California’s data deletion database, known as DROP, to determine whether a California consumer has requested deletion of their personal information. Beginning August 1, 2026, data brokers must access DROP at least every 45 days and, when a request appears, delete the consumer’s personal information within 45 days and direct applicable service providers and contractors to do the same. Once the information is deleted, the data broker generally may not sell or share new personal information about that consumer unless the consumer indicates otherwise.

Companies that collect, buy, sell, or share Californians’ personal information should carefully evaluate whether they fall under California’s broad definition of a “data broker.” In general, a data broker is a business that knowingly collects and sells personal information to third parties about consumers with whom tit does not have a direct relationship. This can include businesses outside California, and the analysis may be more complicated for companies using third-party tracking technologies, purchasing personal information from others, or selling data collected indirectly. Data brokers also must register annually with the California Privacy Protection Agency between January 1 and January 31 and provide detailed disclosures, including categories of personal information collected and whether personal information is sold or shared with certain recipients, such as generative AI developers.

The penalties are significant: failures to register can trigger $200-per-day penalties, and failures to honor deletion requests can result in $200 per deletion request for each day the information is not deleted. Companies that may fall under California’s definition of a “data broker” should prepare now by confirming whether registration is required, mapping California personal information flows, identifying vendors and contractors that may need deletion instructions, and building a documented process to check DROP at least every 45 days. Even companies that do not intend to collect information from California consumers should revisit their data sources and screening practices, as the CPPA has already shown interest in out-of-state businesses that handle Californians’ personal information.

Photo of Kathryn Rattigan Kathryn Rattigan

Kathryn Rattigan is a member of the Business Litigation Group and the Data Privacy+ Cybersecurity Team. She concentrates her practice on privacy and security compliance under both state and federal regulations and advising clients on website and mobile app privacy and security…

Kathryn Rattigan is a member of the Business Litigation Group and the Data Privacy+ Cybersecurity Team. She concentrates her practice on privacy and security compliance under both state and federal regulations and advising clients on website and mobile app privacy and security compliance. Kathryn helps clients review, revise and implement necessary policies and procedures under the Health Insurance Portability and Accountability Act (HIPAA). She also provides clients with the information needed to effectively and efficiently handle potential and confirmed data breaches while providing insight into federal regulations and requirements for notification and an assessment under state breach notification laws. Prior to joining the firm, Kathryn was an associate at Nixon Peabody. She earned her J.D., cum laude, from Roger Williams University School of Law and her B.A., magna cum laude, from Stonehill College. She is admitted to practice law in Massachusetts and Rhode Island. Read her full rc.com bio here.