Observed Signal · May 18, 2026 · Regulation · Source: AdExchanger · Impact: 5/5 · Sentiment: Negative

California Delete Act and DROP Raise Broker Risk

Executive Signal Summary

AdExchanger reports that new U.S. privacy rules and enforcement are placing a renewed regulatory spotlight on companies that collect and sell consumer data. California’s Delete Act takes effect August 1 and introduces DROP, a centralized Delete Request and Opt‑Out Platform that allows residents to send one deletion request to all registered data brokers. Registered brokers must check DROP at least every 45 days and comply with deletion requests within 90 days; failures can trigger fines of $200 per request per day. Connecticut’s SB 4 (effective October 1 if signed) creates a separate data‑broker registry and defines “brokered personal data,” potentially sweeping in firms that buy, organize and resell third‑party information. Industry counsel warn companies cannot rely on informal self‑assessments (“I don’t think I’m a data broker”) and should reassess practices to avoid significant enforcement risk from CalPrivacy and state regulators.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

State privacy laws (California Delete Act and Connecticut SB 4) introduce centralized deletion infrastructure, strict timelines and steep per‑request fines that materially increase compliance risk and potential liability for companies handling third‑party data.

SIGNAL RADAR

Track Frankfurt Kurnit Klein & Selz Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • California’s Delete Act enforcement begins August 1, 2026 with the DROP platform operational.
  • DROP (Delete Request and Opt‑Out Platform) lets California residents send a single deletion request to all registered data brokers.
  • Data brokers must check DROP at least every 45 days and process deletion requests within 90 days.
  • Noncompliance can incur fines of $200 per request per day under California law.
  • Connecticut’s SB 4 would create a data broker registry and defines "brokered personal data," with an effective date of October 1 if signed.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: AdExchanger•Published: May 18, 2026
Original Coverage Title: “‘I Don’t Think I’m A Data Broker’ Is Not A Defense”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

PrivacyJun 16, 2026

CalPrivacy Warns Ad Tech on California Broker Rules

Tom Kemp, executive director of CalPrivacy (the California Privacy Protection Agency), told AdExchanger that ad tech companies should re‑examine whether they qualify as "data brokers" under California law. The article explains the DELETE Act — California’s new data broker law — which establishes a statewide broker registry and a CPPA-run portal called DROP (Delete Request and Opt-Out Platform) that lets residents submit bulk deletion and opt-out requests to registered brokers. Kemp says more than 300,000 Californians have signed up for DROP. The piece warns that companies that collect, aggregate and sell personal information about people with whom they have no direct relationship likely meet the statutory definition of a data broker, with implications for onboarders, ID vendors, audience-extension platforms and other intermediaries. It also flags enforcement trends around dark patterns, data minimization, and rules for automated decision‑making technology.

Read assessment
PrivacyFeb 25, 2026

California's DROP Tool: A Wake-Up Call for B2C Marketers

California launched the Delete Request Opt-Out Platform (DROP) on January 1, 2026, enabling roughly 40 million residents to delete personal data from more than 500 registered data brokers with a single request. By August 1, 2026 data brokers must begin regularly checking DROP and processing deletions, creating operational privacy obligations (90-day processing, 45-day checks) and monetary penalties for noncompliance. The change is expected to accelerate deletion requests, reduce the availability and reliability of third-party data, and worsen attribution and measurement accuracy for B2C marketers. The article urges marketing leaders to audit third-party dependencies, accelerate first‑party data collection, implement incrementality testing, and invest in media-mix / cross-channel measurement to maintain performance insights as third-party data degrades.

Read assessment
Privacy RegulationNov 3, 2025

California Simplifies Privacy: No More Legal Jargon!

Privacy policy developments in California continue to evolve as regulators push for easier consumer rights. The article discusses the so-called privacy paradox and argues opt-out processes should be straightforward rather than buried in legal jargon. Tom Kemp was appointed executive director of the California Privacy Protection Agency (CalPrivacy) in March 2025, succeeding Ashkan Soltani who left in January. CalPrivacy previously issued enforcement advisories on dark patterns and highlighted penalties under the California Consumer Privacy Act. Notable fines cited include Healthline's $1.55 million penalty in July 2025 for deceptive consent banners and failing to honor opt-outs, and Tractor Supply's $1.35 million penalty in September 2025 for similar infractions. The Delete Act created the Delete Request and Opt-Out Platform (DROP), launching January 1, 2026, with data brokers required to check the platform every 45 days starting August 1, 2026 to process deletion requests at scale.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.