top of page
pexels-borkography-4389409.jpg

Your privacy obligations don't wait.
Most businesses aren't ready.

California's regulatory calendar is moving fast. The DELETE Act's DROP obligations take effect August 1, 2026 — and data brokers who miss the 45-day retrieval window face $200 per day, per request in penalties. That's before CCPA enforcement, CPRA updates, or a data incident enters the picture.

Ground Layer Advisory provides operational privacy compliance for California businesses — the hands-on work of getting your practices, documentation, and processes into a defensible state. Remote delivery. Fixed fees. No retainer required unless you need one.

J.D. & CIPP/E certified

Operational Privacy Specialist

Fixed-fee, No surprises

100% remote delivery

August 1, 2026 is closer than it looks.

If your business is registered as a California data broker — or should be — the DELETE Act's Data Rights Opt-out Platform (DROP) creates mandatory, recurring compliance obligations starting this year. Every 45 days, you must retrieve deletion request lists, act on them within 90 days, and maintain a documented audit trail proving you did.

What will that cost your business?

Missed or unresolved requests carry a $200-per-day, per-request penalty. There are no grace periods.
 

I help data brokers get compliant before the deadline and stay compliant through the ongoing 45-day cycle — whether you already run a compliance platform or are starting from scratch.

Three Focused Services

Fixed Fees. No Ongoing Retainer Required.

DROP compliance — California data brokers

Contact for services and pricing

Whether you need a one-time readiness sprint before August 1, ongoing managed operations through every 45-day cycle, or a full compliance program including annual registration and quarterly reporting — I scope each engagement to your actual situation. No assumption that you already have a platform in place.

Vendor Privacy Risk Review

$2,200

From

An audit of every third-party platform with access to your customer or operational data — POS systems, loyalty tools, delivery apps, age verification software. You'll know exactly what your tech stack is doing with your data, and whether your vendor agreements protect you.

Delivery In 7 Business Days

Privacy Impact Assessment (PIA)

$3,500

From

A comprehensive assessment of every data flow in your operation — from ID collection at the counter to Metrc reporting to your loyalty platform's third-party integrations. The result is a risk-rated report and a clear remediation plan, built to satisfy DCC and CCPA expectations

Delivery In 10 Business Days

Who this is for

Built for California businesses with real data obligations.

  • Data brokers navigating DROP registration, retrieval cycles, and audit trail requirements

  • Adtech and performance marketing companies managing lead data and downstream sharing obligations

  • SaaS platforms handling personal data under enterprise vendor agreements

  • Cannabis operators managing CCPA, DCC, and Metrc data obligations simultaneously

  • Any business that has received legal guidance on privacy but hasn't yet closed the gap between advice and documented practice

bottom of page