SB 362 is the California bill known as the Delete Act. If you are reading this you probably want three things: the bill's identity, the code sections it landed in, and what it obliges a data broker to do. This page is written for that, not for a general audience.
Bill identity
- Bill
- SB 362
- Session
- 2023 to 2024 California Legislature
- Short title
- The Delete Act
- Codified at
- Cal. Civ. Code sections 1798.99.80 and following
- Penalty section
- Cal. Civ. Code section 1798.99.82
- Administered by
- California Privacy Protection Agency
The full bill text, votes, committee analyses and the enrolled version are on the Legislature's own site. Read the enrolled text rather than a summary if the exact wording matters to your analysis.
What SB 362 changed
California already required data brokers to register with the state and to answer a set of disclosure questions. SB 362 kept that structure and added the part that actually reaches consumers: a single, state-operated deletion mechanism that every registered broker must connect to.
- A state-run platform through which a consumer submits one deletion request that reaches all registered brokers.
- A duty on every registered broker to access that platform on a fixed interval rather than on request.
- A duty to process what the platform returns, and to record a status for each matched record.
- Registration duties that continue annually, with expanded disclosure questions.
The structural shift is worth naming plainly. Under a request-by-request model, a broker's duty is triggered by an incoming request it can see. Under SB 362, the duty is triggered by the calendar. Nothing arrives in your inbox. You are required to go and look.
The DROP mandate
The platform is DROP, the Delete Request and Opt-out Platform, run by the California Privacy Protection Agency. Registered brokers access it through an API using a key issued from the Data Broker Portal, scoped to the deletion lists the broker selected. The agency has published the technical specification brokers build against, including the normalization and hashing rules that make matching possible without either side handing over raw identifiers.
The published operating dates are specific. Consumers could begin submitting deletion requests in January 2026. A sandbox environment became available to brokers in March 2026. Brokers were required to begin processing DROP requests on August 1, 2026, and from there to access the platform at least once every 45 days.
The submission side has its own mechanics. A broker uploads a status file mapping each matched identifier to a status. The platform accepts the upload for validation first, and returns record-level validation results separately. Acceptance is not the same as a clean, validated filing, and a broker's internal record should not collapse the two states into one.
The registration duty
Registration runs on the Data Broker Portal, which is one account covering registration, fees and the API key. The annual registration deadline is January 31. The registration fee is $6,000 plus a processing fee, paid to the state directly. The disclosure questions were expanded by SB 361 to cover sensitive data categories and who the broker shares data with.
One point regularly missed by advisers: the portal account is required to be associated with the data broker itself, not with an agent or a service provider acting in its own independent capacity. A broker may authorize an agent to access the account on its behalf and may add that agent as a primary or secondary contact, but the account is the broker's.
Enforcement mechanics
The California Privacy Protection Agency administers the registry and brings enforcement. The statute sets an administrative fine of up to $200 per day for failing to register, and provides for recovery of the registration fees that were not paid along with the agency's expenses in the matter. The daily figure is a statutory ceiling that scales with the number of days the broker was unregistered, which is why late registration matters more than the headline number suggests.
| Duty | Evidence a broker can produce |
|---|---|
| Registration in effect for the year | Portal confirmation number and the public registry entry |
| Disclosure answers current and accurate | The submitted registration record |
| DROP accessed within the interval | Timestamped pull records for each cycle |
| Requests processed | Per-record statuses in the uploaded status file |
| Filing validated, not merely accepted | The platform's record-level validation outcome |
What to ask a broker client
If you are reviewing a registered broker's position, the questions that produce useful answers are operational rather than doctrinal. The duty is not seriously disputed. What varies between clients is whether anyone can evidence that it was discharged in a particular interval.
- Who inside the business owns the 45-day cycle, and what happens when that person is on leave?
- For the last completed interval, what is the timestamp of the pull from DROP?
- Was the interval logged even when no records matched, or does a zero-match cycle leave no trace at all?
- Who decides deleted versus exempted, and is a reason recorded against each exemption?
- Do the internal records distinguish an upload that was accepted from a filing that was validated?
- Is the API key scoped to the list selection the business actually processes, and who can regenerate it?
The zero-match question is the one that catches people. A cycle in which nothing matched still has to have happened, and it produces no natural artefact unless the business deliberately records one. A broker with six clean quarters and no evidence of the intervals in between is in a weaker position than the facts deserve.
The exemption question matters for a different reason. Deciding that a matched record is exempt rather than deleted is a legal determination about the business's own entitlement to keep data. It should not be defaulted by a system, and the reason should be attributable to a named person at a known time.
Reading the statute yourself
- Bill text, analyses and votes: https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB362
- The agency that administers and enforces it: https://cppa.ca.gov/
- The public data broker registry: https://cppa.ca.gov/data_broker_registry/
- DROP program page, including the operating dates: https://privacy.ca.gov/drop-for-data-brokers/
- The technical reference: https://privacy.ca.gov/drop-for-data-brokers/technical-specifications/reference/
This page describes the statute and the published program. It is not legal advice, and it is not a substitute for reading the enrolled bill text against your client's facts.
If you advise a broker that is already registered, the practical question is rarely whether the duty exists. It is whether the client can show, for any given 45-day interval, that the platform was accessed, that matching was run, and that a status was recorded for every match. That is a records question, and it is answered before an enquiry arrives or not at all. The 45-day cycle guide sets out what each interval should leave behind.