California DROP cycle readiness

One delete request. A recurring company-wide handoff.

California created a single place where residents can ask registered data brokers to delete personal information. The simple public action creates a recurring operating responsibility inside each broker. DROPClear explains that responsibility in plain language, shows who owns which decision, and gives teams a no-data way to prepare before sensitive work begins.

First, the domain

What is DROP?

DROP is California's Delete Request and Opt-out Platform. It lets a California resident submit one request intended for registered data brokers, instead of contacting each broker separately.

Current CalPrivacy guidance says broker processing began August 1, 2026 and describes recurring access at least once every 45 calendar days. That does not tell a particular company whether it is a data broker, whether an exception applies, or how its systems should act. Those are separate decisions for authorized leaders and qualified professionals.

A fictional morning

Elena opens one task and finds six owners.

Fictional scenario. Elena leads privacy operations at a company that has already made its own registration and applicability decisions. On Monday, she is told, “Make sure we are ready for the next DROP cycle.”

At first it sounds like a portal reminder. Then the questions arrive. Counsel must own legal interpretation. Privacy must define the authorized process. Security and engineering must decide how sensitive operations work in approved systems. Vendor management must resolve third-party responsibilities. The authorized account holder must follow the regulator's account rules. An officer must own statements only that officer is authorized to make.

The risk is not simply forgetting a date. It is letting one team silently make another team's decision, using stale guidance, or moving sensitive data before authority and controls are clear. DROPClear turns that confusion into a blank, source-dated handoff map - without receiving any company or consumer records.

Why the cycle is hard

BEFORE

Set decision authority

Identify who may decide legal status, privacy process, system behavior, vendor duties, account access, and officer release.

DURING

Keep execution in authorized systems

Real requests, identifiers, matches, deletion work, evidence, credentials, and portal activity remain outside DROPClear.

AFTER

Preserve the human handoff

Authorized people resolve exceptions, release decisions, corrections, and the next source review. DROPClear does not certify the result.

Decision owner map

Clear lanes prevent borrowed authority.

Who owns each decision before any sensitive work
LaneOwnsDROPClear boundary
Leadership and California privacy counselEntity status, applicability, exceptions, interpretation, deadlines, legal response.Records the question only; never answers it.
Privacy ownerAuthorized operating process, minimization, retention, escalation, correction.Provides a blank responsibility map.
Security and engineeringSystem architecture, approved data paths, access, execution, evidence controls.Performs no security assessment or system work.
Vendor ownerContracts, instructions, dependencies, evidence, escalation.Does not direct or supervise vendors.
Authorized broker account holderBroker-owned account access and official portal steps.Never logs in or handles credentials.
Authorized officer and regulatorRegistration, reporting, certifications, regulator determinations.Does not file, certify, contact, or represent.

The bounded service

A useful first layer before sensitive operations.

For an appropriate buyer, DROPClear replaces vague “someone owns it” assumptions with a shared, source-dated operating picture.

Deliverable

Newcomer brief

Plain definitions, the recurring-cycle story, current source dates, and explicit limits.

Deliverable

45-day handoff table

A blank role, question, source, owner, escalation, and review structure. No company facts are entered here.

Deliverable

Decision-boundary map

A visual separation of legal, privacy, security, engineering, vendor, account, officer, and regulator authority.

Deliverable

Safe handoff questions

Six fixed prompts for a qualified internal discussion. Selections stay only in page memory and disappear on reload.

Method

Orient. Map. Source. Handoff.

Orient the newcomer

Define DROP and distinguish the public request mechanism from the broker's internal responsibilities.

Map decisions, not personal data

Name roles and unanswered questions without collecting requests, identifiers, records, credentials, or system details.

Attach dated official sources

Show exactly which public statement came from which current primary source, with access date and limitation.

Release a bounded handoff

A qualified human reviews the exact package; real decisions and execution remain with authorized people in approved environments.

Proof discipline

What we know - and what we do not claim.

Official sources support the public process statements below. They do not prove that DROPClear produces compliance, savings, faster deletion, lower exposure, or any commercial outcome.

No customer proof has been published.Publication alone is not client evidence.
No outcome evidence is claimed.The service prepares questions and handoffs.
Pricing remains unpublished.No public price or savings claim is authorized.

Current primary sources

Read the rule at its source.

Accessed 2026-08-02. Official pages can change; a qualified owner must recheck them before action.

CalPrivacy

For data brokers

Processing start, recurring access, and the regulator's public penalty statement.

Open official overview
CalPrivacy

Process DROP requests

Public description of selection, standardization, hashing, matching, processing, status reporting, and repetition.

Open process guidance
CalPrivacy

Account and annual registration

Broker-entity account guidance and the published 2026 annual fee of $6,000 plus the disclosed payment-processing fee.

Open account guidance
California Legislature

Current Civil Code text

Codified definitions, registration, deletion mechanism, processing, reporting, audit, and penalty provisions.

Open codified title
CalPrivacy

DROP regulations

Current regulation materials effective January 1, 2026.

Open regulation page
CalPrivacy

Technical specifications

Current public technical-specification hub; real system decisions remain with authorized security and engineering owners.

Open specifications

No-data question map

Which conversations still need a named owner?

Choose prompts only for this browser session. Do not enter facts anywhere. A selection means “take this question to the authorized person”; it does not mean ready, deficient, applicable, exempt, or compliant.

No prompts marked for discussion.

Hard limits

Clarity is valuable only when the boundary is visible.

No legal or regulator decision

DROPClear does not decide data-broker status, exceptions, registration, fee, deadline, penalty, privacy, security, or compliance.

No data or portal work

No records, identifiers, requests, matches, deletions, files, credentials, accounts, portal access, reporting, or certification.

No representation or filing

No regulator contact, submission, registration, filing, attestation, officer statement, or representation.

No outcome promise

No promise of deletion, acceptance, timing, accuracy, compliance, penalty avoidance, savings, demand, or revenue.

DROPClear is not a law firm and does not provide legal, tax, medical, financial, or other licensed professional advice. It does not decide eligibility or entitlement. Specialist-dependent questions must be routed to a verified qualified specialist. A qualified human must review and release every client deliverable. Do not submit sensitive material through this public site.

Likely questions

What a cautious buyer should ask.

Does DROPClear tell us whether we are a data broker?

No. That is a fact-specific legal decision for your authorized leadership and California privacy counsel, with regulator guidance as appropriate.

Will DROPClear log in, process requests, match people, or direct deletion?

No. The public offer is no-data education and handoff preparation only.

Can we upload our records or describe a live matter here?

No. This site has no form, account, upload, workspace, analytics, or tracking. Keep all real information in your authorized environment.

Why pay attention if this does not perform the cycle?

Because a recurring obligation can fail at the handoff long before execution. A common vocabulary, named decision owners, dated sources, and clear stop points make the qualified internal conversation more efficient without borrowing anyone's authority.

What does it cost?

No public price is authorized. The public page makes no pricing, savings, return, demand, or outcome claim.

What should happen next?

Use the six prompts with your own authorized counsel, privacy, security, engineering, vendor, account, and officer teams. Recheck current official sources before action.

Safe next step

Bring better questions to the people who can decide.

Start with the no-data question map. Name an owner for each unresolved lane. Then review current primary sources and real company facts inside your approved process with qualified professionals. Nothing on this page should receive sensitive information.