
Your privacy obligations don't wait.
Most businesses aren't ready.
California's regulatory calendar is moving fast. The DELETE Act's DROP obligations take effect August 1, 2026 — and data brokers who miss the 45-day retrieval window face $200 per day, per request in penalties. That's before CCPA enforcement, CPRA updates, or a data incident enters the picture.
Ground Layer Advisory provides operational privacy compliance for California businesses — the hands-on work of getting your practices, documentation, and processes into a defensible state. Remote delivery. Fixed fees. No retainer required unless you need one.
J.D. & CIPP/E certified
Operational Privacy Specialist
Fixed-fee, No surprises
100% remote delivery
August 1, 2026 is closer than it looks.
If your business is registered as a California data broker — or should be — the DELETE Act's Data Rights Opt-out Platform (DROP) creates mandatory, recurring compliance obligations starting this year. Every 45 days, you must retrieve deletion request lists, act on them within 90 days, and maintain a documented audit trail proving you did.
What will that cost your business?
Missed or unresolved requests carry a $200-per-day, per-request penalty. There are no grace periods.
I help data brokers get compliant before the deadline and stay compliant through the ongoing 45-day cycle — whether you already run a compliance platform or are starting from scratch.
Three Focused Services
Fixed Fees. No Ongoing Retainer Required.
DROP compliance — California data brokers
Contact for services and pricing
Whether you need a one-time readiness sprint before August 1, ongoing managed operations through every 45-day cycle, or a full compliance program including annual registration and quarterly reporting — I scope each engagement to your actual situation. No assumption that you already have a platform in place.
Vendor Privacy Risk Review
$2,200
From
An audit of every third-party platform with access to your customer or operational data — POS systems, loyalty tools, delivery apps, age verification software. You'll know exactly what your tech stack is doing with your data, and whether your vendor agreements protect you.
Delivery In 7 Business Days
Privacy Impact Assessment (PIA)
$3,500
From
A comprehensive assessment of every data flow in your operation — from ID collection at the counter to Metrc reporting to your loyalty platform's third-party integrations. The result is a risk-rated report and a clear remediation plan, built to satisfy DCC and CCPA expectations
Delivery In 10 Business Days
Who this is for
Built for California businesses with real data obligations.
-
Data brokers navigating DROP registration, retrieval cycles, and audit trail requirements
-
Adtech and performance marketing companies managing lead data and downstream sharing obligations
-
SaaS platforms handling personal data under enterprise vendor agreements
-
Cannabis operators managing CCPA, DCC, and Metrc data obligations simultaneously
-
Any business that has received legal guidance on privacy but hasn't yet closed the gap between advice and documented practice
