Tool

DROP Deadline Tracker

The California Delete Act has two fixed calendar dates and one rolling obligation that operators routinely model wrong. Here they are with live countdowns, each carrying the statute or regulation it comes from.

Annual data-broker registration deadline

Data brokers must register with the California Privacy Protection Agency during the registration period, January 1–31 each calendar year. Failing to register carries an administrative fine of $200 for each day the business is not registered.

Source: 11 CCR § 7601(k) (registration period); Cal. Civ. Code § 1798.99.82(c)(1) ($200 per day)

January 31, 2027

176 days away

recurs annually

Consumers can submit DROP deletion requests

Since January 1, 2026, California residents can use DROP — the Delete Request and Opt-out Platform — to send a single deletion request to every registered data broker at once.

Source: Cal. Civ. Code § 1798.99.86; CPPA, “Information for Data Brokers”

January 1, 2026

In effect now

Brokers must begin accessing DROP and processing deletions

The statute is specific: “Beginning August 1, 2026, a data broker shall access the accessible deletion mechanism … at least once every 45 days.” On each access the broker must compare the consumer deletion list against its own records, delete all personal information associated with a matched identifier, and direct its service providers and contractors to do the same.

Source: Cal. Civ. Code § 1798.99.86(c)(1); 11 CCR §§ 7612–7613 (compare, delete, direct service providers)

August 1, 2026

In effect now

Outer limit for a broker’s first DROP accessDerived

A broker that has not yet accessed DROP runs out of room 45 days after the August 1 start. This date is our arithmetic on the cited 45-day rule, not a deadline published by the Agency — you will see September 14 quoted elsewhere; neither date appears in the statute or the regulations. Treat mid-September as the outer limit and access earlier. A DROP account must exist before the first access, and the account must select every consumer deletion list that could match records the broker holds.

Source: Derived from Cal. Civ. Code § 1798.99.86(c)(1) (45 days from August 1, 2026); account and list selection per 11 CCR § 7610(a)

September 15, 2026

38 days away

Rolling 45-day DROP access interval

The regulation states it plainly: “A data broker must access the DROP to download its selected consumer deletion list(s) at least once every 45 calendar days.” The interval runs from that broker’s own last access, not from a shared calendar date — after the first download, each later download returns only the requests received since that broker’s most recent one. At each access session the broker must also report the status of every request received during the previous session. Failing to delete carries $200 for each deletion request, for each day.

Source: 11 CCR § 7612(a), (c) (45 calendar days; incremental downloads); 11 CCR § 7614(a) (status reporting); Cal. Civ. Code § 1798.99.82(d)(1) ($200 per request per day)

September 15, 2026

38 days away

recurs every 45 days

New data brokers: 45 days from commencing operation

A business that starts operating as a data broker outside the January registration window must create a DROP account and begin accessing the platform within 45 calendar days of commencing operation, then register during the following January. The first-time access fee is on a sliding scale by month of first access — $6,000 in January down to $500 in December.

Source: 11 CCR § 7611(a)(1)–(3)

August 1, 2026

In effect now

Countdowns are calculated in your browser from today's date. Verify against the official California Privacy Protection Agency guidance before relying on a specific date.

The 45-day clock is yours, not the calendar’s

This is the detail worth getting right. The 45-day DROP interval is not a shared quarterly tick that every broker observes together. Civil Code § 1798.99.86(c)(1) requires each broker to access the mechanism at least once every 45 days from August 1, 2026, and the regulation confirms the interval is per-broker: after your first download, each later download returns only the requests that arrived since your most recent access (11 CCR § 7612(c)). Your clock restarts when you access. Nobody else’s does.

The practical consequence: there is no date on which the industry collectively becomes compliant or non-compliant. If you access on August 20, your next deadline is October 4. If you have not accessed at all, you run out of room 45 days after August 1 — mid-September.

You will see September 14 quoted as a hard deadline. It is not in the statute and not in the regulations. Neither is September 15 — that is simply where our own arithmetic on the 45-day rule lands. We show it flagged as derived rather than presenting it as a published date, because the difference matters when a $200-per-request-per-day fine is attached (Civ. Code § 1798.99.82(d)(1)).

This is an educational tool, not legal advice. It offers general, best-practice guidance from an operator's perspective and does not account for your specific facts or jurisdiction. Using it does not create an attorney–client relationship. For advice on your situation, consult qualified counsel.