DROP Is Live: Which California Data-Broker Claim Is Current?
Check California data-broker registration and DROP claims against dated CPPA pages and Civil Code sections before treating a forwarded deadline as a consulting opportunity.

Signals to watch
- A privacy or ad-tech group says a broker has “missed the DROP deadline” without distinguishing annual registration from request processing
- A forwarded checklist still says DROP is coming, although consumers have been able to submit requests since January 1, 2026
- A vendor claims every request must be completed on a 45-day cycle but does not identify receipt date, verification outcome, exception or service-provider data
The answer first: on August 18, 2026, three different California data-broker dates are current. Registration is due on or before January 31 after a year in which a business met the statutory data-broker definition. California residents have been able to submit requests through the Delete Request and Opt-out Platform (DROP) since January 1, 2026. Registered data brokers had to begin accessing and processing DROP requests on August 1, 2026. A message that says only “the DROP deadline passed” has not identified which duty, actor or evidence it means.
That distinction is commercially useful to a privacy-operations consultancy lead reading authorised privacy, advertising-technology and data-governance Telegram groups. The Signal worth finding is not a generic mention of California privacy. It is a dated mismatch: an organisation is working from an old launch date, treating registration as request processing, or missing the evidence needed to show what happened after a request was received. Seeing that mismatch a day late can mean missing the short window to join a remediation discussion before the organisation selects legal counsel, registry support or an integration provider.
One forwarded sentence can contain three different clocks
Consider this illustrative composite thread, not a customer conversation or proof of a compliance failure:
“CA broker renewal was done earlier this year. Are we still waiting for DROP to start?”
“Someone says Aug 1 passed and the portal hasn’t cleared the requests.”
“Do we have 45 or 90 days here?”
The fragments sound urgent, but crucial facts are absent. Nobody names the legal entity, says whether it met the definition of data broker during 2025, identifies the date a request was received, shows whether it was verifiable, or distinguishes a deletion from the status displayed to the consumer. “Renewal was done” has no registry receipt. “The portal hasn’t cleared” has no download or upload record. The consultancy lead should recover the source chain before assigning a specialist.
What DROP is—and why a current definition matters
DROP is the CPPA’s statewide accessible deletion mechanism. Civil Code section 1798.99.86 requires it to let a consumer make one verifiable request asking every covered data broker that holds the consumer’s personal information to delete that information, subject to statutory limits. The consumer may exclude selected brokers and may check request status. The mechanism does not charge the consumer.
Why this definition matters: DROP is not merely a directory, and registration is not proof that a broker processed a particular request. The CPPA Data Broker Registry publishes registration information. DROP carries deletion requests and status. A consultancy may need one workstream for the entity’s registration record and another for request matching, deletion, service-provider instructions and status uploads.
The CPPA’s current registry page says the businesses shown in the 2026 registry operated as data brokers in 2025. It also states that any business meeting the definition must register annually between January 1 and 31. The controlling statutory wording is more exact: section 1798.99.82(a) says on or before January 31 following each year in which a business meets the definition. A company name absent from a quick registry search is a fact to investigate, not automatic proof of a violation; spelling, legal entity, timing and statutory scope remain open.
The dated claim-to-primary-source chain
Use four fields for every forwarded deadline. This is the original contribution that turns a chat fragment into a source check a legal or implementation specialist can review.
1. Capture the claim exactly
Preserve the sentence, sender, group, message time and any linked document. Do not rewrite “DROP isn’t live yet” as “the broker failed to process requests.” Those are different claims. Record whether the message refers to registration, consumer submission, broker access, deletion, opt-out treatment or status.
2. Name the actor and action
The actor may be the CPPA, a California consumer, a data broker, a service provider or contractor. The action may be establishing DROP, registering, submitting a request, accessing the mechanism, deleting matched information, treating an unverifiable request as an opt-out, directing downstream providers, or reporting status. If the actor and verb are missing, the deadline cannot yet be applied.
3. Match the claim to the current official text
Use the live CPPA page for operational status and the current Civil Code for legal duties:
- Registration: section 1798.99.82 sets the January 31 timing and registration duties.
- Consumer launch: the official DROP page says DROP launched January 1, 2026.
- Broker processing: section 1798.99.86(c) says that beginning August 1, 2026, a data broker must access DROP at least once every 45 days and process requests within 45 days after receipt.
- Continuing deletion: after a request has been submitted and the broker has deleted the consumer’s data, section 1798.99.86(d) requires deletion of newly collected personal information at least once every 45 days, subject to the stated exceptions and consumer choice.
Save the access date because agency copy, regulations and code can change. A 2024 law-firm alert may describe enactment accurately but cannot prove what the live system says on August 18, 2026.
4. Write the unknown beside the source
A complete source citation does not complete the facts. For the composite thread, the unknowns include statutory status, registration receipt, request receipt date, matching identifiers, verification result, applicable deletion exception, downstream service-provider completion and status-upload evidence. Those gaps determine whether to send the matter to legal scope review, registry repair or a technical deletion workflow team.
The 45-day and 90-day statements are not interchangeable
The official consumer DROP page says brokers must access DROP at least once every 45 days beginning August 1, 2026. It also warns consumers that seeing an updated status in DROP could take up to 90 days. The How DROP works page explains that brokers process deletion requests at least every 45 days.
The statute supplies the operational detail. Under section 1798.99.86(c), a broker must access the mechanism at least once every 45 days and, within 45 days after receiving a request, process it and delete the consumer’s personal information as required. If a request cannot be verified, the broker must process it as an opt-out of sale or sharing within 45 days, within the cited statutory limits. It must also direct associated service providers or contractors to perform the corresponding deletion or opt-out action.
Therefore, “the site says 90 days” is not evidence that every legal processing step has a 90-day deadline. It is a consumer-facing statement about when a status update may appear. A review needs the download date, receipt record, match result, deletion evidence and upload status before identifying a missed duty.
What the statute says about fees and administrative fines
Avoid copying a dollar figure from an old registration invoice into a general article. Section 1798.99.82 requires a registration fee in an amount determined by the CPPA, limited to reasonable costs described in the statute. Section 1798.99.86(f) separately allows an access fee that does not exceed reasonable costs of providing access to DROP. The actual amount and which fee applies should be checked against the current CPPA account and registration instructions.
The current statute does state fixed administrative-fine formulas. Failure to register can carry $200 for each day of failure, plus the fees due and reasonable investigation and administration expenses. Failure to delete as required by section 1798.99.86 can carry $200 for each deletion request for each day the required information is not deleted, plus reasonable expenses. Those provisions make a current source check important, but a group message cannot establish liability. The business’s statutory role, dates, request history, exceptions and enforcement posture need qualified legal review.
How discovery tooling should handle the fragment
TOP Prospect can filter, merge, deduplicate and rank fragments from Telegram groups the user deliberately connects and is authorised to access. It can retain the original message, source, time, AI summary and reason for human review. A newly saved matching target records what the user wants to find; saving it alone does not automatically create a new candidate. The product cannot determine data-broker status, inspect DROP, verify deletion, calculate liability, contact the poster or read private or unauthorised sources.
Use the official-source ladder when a forwarded compliance claim has lost its regulator or statute link. Use the business-Signal confidence method to keep source evidence separate from interpretation. The Telegram business-Signal workflow explains how authorised sources become review candidates without automatic outreach.
Key facts as of August 18, 2026
- Civil Code section 1798.99.82 requires registration on or before January 31 following each qualifying year.
- The CPPA says DROP launched for consumer requests on January 1, 2026.
- The broker access and processing obligations began August 1, 2026.
- Brokers must access DROP at least every 45 days and process a request within 45 days after receiving it, subject to statutory rules and exceptions.
- A consumer-facing status update may take up to 90 days; that statement is not a substitute for the statutory processing analysis.
- The statute allows CPPA-determined registration and access fees within reasonable-cost limits and states $200 administrative-fine formulas for specified failures.
- None of these facts proves that a named organisation is a data broker or has violated the law.
FAQ
When must a California data broker register?
On or before January 31 following each year in which the business met the statutory definition of data broker. Scope and legal-entity identity must be checked separately.
When did consumers gain access to DROP?
The CPPA states that DROP launched on January 1, 2026, and California residents could begin submitting requests then.
When did brokers have to begin processing DROP requests?
August 1, 2026. That is the date section 1798.99.86 makes the recurring access, request-processing and continuing-deletion duties operative.
Does every 45 days mean a broker may wait 90 days after receipt?
No. The statute requires processing within 45 days after receiving a request. The separate up-to-90-day statement concerns when consumers may see a status update in DROP.
What happens if a request cannot be verified?
The broker must process it as an opt-out of sale or sharing within 45 days, subject to the limits cited in section 1798.99.86(c).
Does a registry entry prove DROP compliance?
No. It proves that registration information was published. Request receipt, matching, deletion, downstream directions and status evidence are separate records.
Can a Telegram message prove a statutory violation?
No. It can surface a dated mismatch worth reviewing. Liability depends on the entity, scope, evidence, exceptions and current law.
Return to the composite thread: the useful reply is not “45” or “90.” It is a request for the legal entity, registration receipt, DROP receipt date, verification outcome and processing record, each tied to the current official source. That turns a stale deadline claim into a reviewable privacy-operations handoff without pretending the missing facts are known.
Frequently asked questions
When must a California data broker register?
Civil Code section 1798.99.82(a) requires registration on or before January 31 following each year in which the business met the statutory definition of data broker. Whether a specific company meets that definition is a separate legal-scope question.
When did consumers gain access to DROP?
The CPPA states that DROP launched on January 1, 2026, when California residents could begin submitting deletion requests.
When did data brokers have to begin processing DROP requests?
Civil Code section 1798.99.86(c) makes the access and processing duties operative beginning August 1, 2026.
Does every 45 days mean a broker may ignore a received request for 90 days?
No. Section 1798.99.86(c) requires access to the mechanism at least once every 45 days and processing within 45 days after receiving a request. The consumer site separately warns that a status update in DROP can take up to 90 days.
What penalties does the current statute state?
Section 1798.99.82 states a $200 administrative fine for each day of registration failure, plus due fees and reasonable expenses, and $200 for each deletion request for each day required information is not deleted, plus reasonable expenses. Application to a particular business requires qualified legal review.
Does a registry entry prove DROP compliance?
No. A registry entry shows that registration information was published. Request receipt, matching, deletion, downstream directions and status evidence are separate records.
Can a Telegram message prove a statutory violation?
No. It can surface a dated mismatch worth human review, but liability depends on the entity, statutory scope, evidence, exceptions and current law.
Sources and further reading
- California Privacy Protection Agency, California Data Broker Registry, current page, accessed August 18, 2026
- California Civil Code section 1798.99.82, current official code text, effective January 1, 2026, accessed August 18, 2026
- California Civil Code section 1798.99.86, current official code text, effective January 1, 2026, accessed August 18, 2026
- CalPrivacy, Delete Request and Opt-out Platform (DROP), accessed August 18, 2026
- CalPrivacy, How DROP works, accessed August 18, 2026
How a Signal worth attention is found
See how Top Prospect finds and organizes Signals worth checking, keeps the original Telegram context, removes duplicates, and helps you decide what to review first. You decide whether to follow up and what to do next.
