California Data Brokers Face Aug. 1 Deadline on Deletion Requests
TestNews Desk
Sunday, August 2, 2026
Starting August 1, data brokers registered in California must process consumer deletion requests sent through the state's new centralized portal. The milestone marks the second phase of the 2023 Delete Act, which was designed to replace paperwork-heavy privacy requests with a single mechanism. Brokers now have 45 days to delete personal data and to push those deletions downstream to their contractors. The California Privacy Protection Agency has pledged to begin enforcement immediately after the deadline.
Enforcement begins
California's landmark Delete Act enters its most consequential phase on August 1, when registered data brokers must begin honoring consumer deletion requests transmitted through the state's centralized deletion portal. The California Privacy Protection Agency (CPPA) will no longer treat the act as informational or preparatory: after this date, every registered broker that receives a request through the portal is legally obligated to remove the consumer's personal information from its systems and from the systems of its service providers and contractors. The deadline transforms what had been a registration and record-keeping law into an operational privacy regime that reaches hundreds of companies in an industry often criticized for operating in the shadows.
State officials have signaled that the transition will be closely watched. In the months leading up to August 1, the agency updated its compliance guidance, held workshops for data brokers, and made clear that a failure to act on a valid deletion request could trigger an investigation and potential penalties. The new requirement is not simply a polite reminder. Under California law, data brokers that do not process requests through the official mechanism face liability under the Consumer Privacy Act, including administrative fines, civil penalties, and corrective orders.
How the Delete Act came together
The story begins with a growing recognition that the California Consumer Privacy Act, despite giving residents the right to deletion, was unwieldy in practice. Consumers could send requests to companies they knew, but data brokers often operate silently, buying, aggregating, and reselling personal information to advertisers, researchers, and analytics firms. To know which brokers held a person's data, residents would need to identify an opaque web of hundreds of companies, many of which market to businesses rather than consumers.
Lawmakers responded with Senate Bill 362, known as the Delete Act, which Governor Gavin Newsom signed in October 2023. The law requires data brokers to register annually with the CPPA and pay a fee based on their revenue. Those fees were intended to fund a one-stop deletion portal. The law also gave the agency authority to verify that data brokers are accurately reporting their practices and to begin the rulemaking process for a single deletion mechanism. The idea was simple in spirit but complex in execution: a Californian should be able to ask every registered data broker to erase their personal information at once, through one web form.
Initially, the Delete Act called for the portal to be live by January 1, 2026. The agency accelerated its efforts, launched a prototype, and then established the August 1 compliance date during its rulemaking process. According to agency documents, the earlier deadline was chosen to give consumers meaningful relief without waiting until the legislative end date. The portal itself now allows a user to verify their identity and send the same deletion request to all registered brokers at once, or to selected brokers.
How the deletion mechanism works
When a consumer submits a request through the portal, the system routes it to each selected data broker. The broker must confirm receipt and verify the requester's identity through the way provided by the portal. Once the request is validated, the broker has 45 days to delete the consumer's personal information from its own files. Critically, the obligation extends beyond the broker. Under the law, a data broker must also cause its service providers and contractors to delete the same personal information, rather than simply removing it from a primary database. After the deletion is complete, the broker is required to notify the consumer in writing that the request has been fulfilled.
The mechanism is designed to eliminate the need for consumers to visit each broker's individual website, fill out multiple forms, and repeatedly provide proof of identity. Previous research showed that many deletion forms were difficult to find, broken, or buried in pages of legal disclaimers. The state portal standardizes the process and provides an audit trail, making it easier for the CPPA to determine whether a broker has ignored a request.
One open question is how identity verification will work at scale. The portal must balance security against accessibility, and some consumer advocates have warned that overly aggressive verification could lock people out of the system. The agency has responded with multiple verification paths, including email, password-protected accounts, and document submission. Still, observers expect that the first weeks of enforcement will reveal technical bottlenecks and edge cases, especially for consumers who have minimal digital records or who suspect that a broker holds information based on address history rather than email.
Who is affected and what exemptions may apply
The law's definition of a data broker is broad. It covers any business that knowingly collects and sells the personal information of California consumers to third parties, with no direct relationship to the consumer. That definition sweeps in people-search websites, marketing data providers, advertising analytics platforms, and many so-called lookalike audience firms. Brokers have been registering with the state since January 2024, and the registry now includes hundreds of companies, from well-maintained corporate entities to obscure firms with prerecorded voicemail and little public presence.
Research firms that only collect data from surveys and interviewers are sometimes excluded, as are businesses that fall under sectoral privacy regimes such as health care providers regulated by HIPAA. The law also respects legal obligations that require data to be retained, such as tax recordkeeping, and it does not compel brokers to violate court orders. Consumer advocates have worried about loopholes, especially around so-called public record data. People-search sites often claim that their information is publicly sourced and therefore cannot be erased entirely. The CPPA has pushed back in guidance, stating that a public record source does not exempt the broker from deleting derivative data compiled into a profile. The agency is expected to address disputes on a case-by-case basis during enforcement.
Data brokers subject to the law have spent the past year mapping their data flows, negotiating contracts with downstream partners, and preparing automated systems to handle bulk deletion requests. Industry representatives have expressed concern about the breadth of the obligation, noting that a single consumer can appear across dozens of datasets, backup copies, and precomputed analytics. Some have argued that the 45-day window is too tight when a broker must track down data sold to a third party many years ago. Supporters of the law counter that the industry has known about the requirement since 2023 and that the entire point of the portal is to make the process as routine as possible.
Enforcement and penalties
The CPPA does not need to wait for a consumer complaint to audit a data broker. Under the Delete Act, the agency may initiate reviews to determine whether a broker is complying with the registration, deletion, and disclosure provisions. If the agency finds a violation, it can issue a notice to cure within 30 days for certain issues, but the legislature narrowed that cure period for entities already subject to the CCPA. For serious violations, the CPPA can refer the case to the California Attorney General or pursue administrative enforcement directly.
Civil penalties under the CCPA can reach $2,500 for each unintentional violation and $7,500 for each intentional violation. Because a deletion request may involve dozens of brokers and many distinct data elements, penalties could multiply quickly if a broker deliberately ignores a request. A separate administrative fine under the Delete Act can be imposed for a broker's failure to register or pay the requisite fee. State officials have not announced specific enforcement targets, but they have emphasized that August 1 is not a symbolic deadline. The agency's enforcement staff has already begun requesting information from some registered brokers, and additional sweeps are likely as the portal processes its first wave of consumer requests.
What the future holds
The August 1 milestone is not the end of the Delete Act's timeline. The law instructs the CPPA to continue refining the portal and to review the data broker registry annually. The agency also has broader rulemaking authority under the CCPA, which could eventually extend to automated decision-making and artificial intelligence training data. Privacy experts say that California's approach is being watched around the world, both because of its technical design and because of the precedential value of a single deletion request controlling an entire ecosystem of data resale.
Business groups have raised the possibility of litigation, arguing that the statute's broad definition of data broker could capture companies that are not traditionally considered data sellers, such as loyalty program administrators or background check providers. Courts have not yet ruled on the law's scope, and legal challenges could be refiled as enforcement picks up. Even in the absence of a lawsuit, compliance will often be uneven in the first months. Some brokers may struggle with consumers who are homeless or have no fixed digital footprint, while others will find that legitimate records are entangled with predictive analytics. The CPPA says it will publish guidance and hold stakeholder meetings later this year.
For Californians, the immediate practical benefit is a shortened path to requesting deletion of years of accumulated profiles. Privacy advocates note that the portal does not prevent data brokers from recollecting information in the future, so consumers may need to resubmit deletion requests periodically. Still, they see the launch as a meaningful shift in power from companies to individuals.
State regulators have promised transparency about compliance rates, and the portal itself may eventually display aggregate metrics showing how many requests were completed on time. If those metrics are strong, other states may attempt to duplicate the model; if not, the experiment will provide a cautionary lesson in the difficulty of regulating a data economy that has long resisted meaningful oversight.
Comments (0)
No comments yet. Be the first to share your thoughts.
Loading stories...