top of page
California Delete Act / DROP Compliance Services

Tier 1 - DROP Readiness Sprint

One-time engagement.  4–6 weeks.   Best before August 1, 2026

  • Confirm data broker status and DROP registration/account standing

  • Audit consumer rights page and SB 361 registration disclosures

  • Map internal data stores and vendor relationships against DROP scope

  • Build an exception framework (FCRA/HIPAA/GLBA, public data, transaction/fraud exceptions) for counsel sign-off

  • Deliver a go-live checklist and 45-day operating calendar

Tier 2 — Managed DROP Operations

Recurring retainer · runs on the mandatory 45-day DROP cycle

 

Path A - You already run a compliance platform (e.g. OneTrust, DataGrail)

  • Configure the platform's DROP/deletion-request workflow to your systems

  • Run the recurring cycle: retrieve lists, monitor matching, verify results

  • Handle everything the platform doesn't automate: exception review, service-provider/contractor deletion coordination, status reporting back through
    DROP, audit trail and documentation

Path B — You don't yet have a compliance platform

  • Recurring 45-day cycle management: deadline tracking, retrieval scheduling, status logging

  • Exception review and documentation for counsel sign-off

  • Service-provider/contractor deletion coordination and attestation tracking

  • Audit trail maintenance and DROP status reporting (Matching/hashing of records against DROP lists requires a platform or engineering resource)

Tier 3 — Full Compliance Program

Retainer · Tier 2 plus annual program management

  • Everything in Tier 2 (Path A or B)

  • Annual DROP registration renewal and SB 361 disclosure updates (Jan 1–31)

  • Quarterly compliance reporting for executives/board

  • Legal-liaison coordination and enforcement-inquiry response support

Beginning August 1, 2026, every registered California data broker must retrieve DROP deletion lists at least every 45 days, act on them within 90
days, and prove it.

 

Missed or unresolved requests carry a $200/day, per-request penalty. We help data brokers meet this obligation on an ongoing,
audited basis — remotely, without disrupting your existing tech stack.

bottom of page