California Delete Act / DROP Compliance Services
Tier 1 - DROP Readiness Sprint
One-time engagement. 4–6 weeks. Best before August 1, 2026
-
Confirm data broker status and DROP registration/account standing
-
Audit consumer rights page and SB 361 registration disclosures
-
Map internal data stores and vendor relationships against DROP scope
-
Build an exception framework (FCRA/HIPAA/GLBA, public data, transaction/fraud exceptions) for counsel sign-off
-
Deliver a go-live checklist and 45-day operating calendar
Tier 2 — Managed DROP Operations
Recurring retainer · runs on the mandatory 45-day DROP cycle
Path A - You already run a compliance platform (e.g. OneTrust, DataGrail)
-
Configure the platform's DROP/deletion-request workflow to your systems
-
Run the recurring cycle: retrieve lists, monitor matching, verify results
-
Handle everything the platform doesn't automate: exception review, service-provider/contractor deletion coordination, status reporting back through
DROP, audit trail and documentation
Path B — You don't yet have a compliance platform
-
Recurring 45-day cycle management: deadline tracking, retrieval scheduling, status logging
-
Exception review and documentation for counsel sign-off
-
Service-provider/contractor deletion coordination and attestation tracking
-
Audit trail maintenance and DROP status reporting (Matching/hashing of records against DROP lists requires a platform or engineering resource)
Tier 3 — Full Compliance Program
Retainer · Tier 2 plus annual program management
-
Everything in Tier 2 (Path A or B)
-
Annual DROP registration renewal and SB 361 disclosure updates (Jan 1–31)
-
Quarterly compliance reporting for executives/board
-
Legal-liaison coordination and enforcement-inquiry response support
Beginning August 1, 2026, every registered California data broker must retrieve DROP deletion lists at least every 45 days, act on them within 90
days, and prove it.
Missed or unresolved requests carry a $200/day, per-request penalty. We help data brokers meet this obligation on an ongoing,
audited basis — remotely, without disrupting your existing tech stack.
