News & Updates

California's Delete Act Is Live. Here's How Deep Sync Is Handling It.

Below is the plain-language version: what changed, what it means for the data you license from us, and why our approach to consumer privacy requests was largely built before this regulation arrived.

As of August 1, 2026, California consumers have a single place to delete themselves from every registered data broker at once. The platform is called DROP, and the obligation it creates for data brokers is not a future compliance item; DROP is active now!

What changed

California's Delete Act (SB 362) directed the California Privacy Protection Agency (CPPA) to build the Delete Request and Opt-Out Platform (DROP). It replaces a process that had a structural flaw: a consumer who wanted their information deleted had to identify every data broker holding it and contact each one individually. In practice, that meant the right existed on paper more than in effect.

The consumer side of the platform opened first. California announced DROP's public launch in January 2026 as the first tool of its kind in the country, giving residents roughly seven months to submit requests before the broker-side obligation took effect.

DROP consolidates the process, and a California consumer submits one verified deletion request through a state-operated platform. That request is then made available to every data broker registered with the CPPA.

The broker obligation runs in the other direction. As of August 1, 2026, registered data brokers are required to access DROP, retrieve the list of consumers who have submitted requests, and process those requests in accordance with the applicable requirements, then repeat that check at least once every 45 days. The request creates an ongoing compliance obligation rather than a one-time interaction with the consumer.

Two further points matter for anyone evaluating how seriously a data partner treats this. First, the obligation extends downstream: brokers are required to direct their service providers and contractors to delete the same information. Second, beginning in 2028, registered brokers will be subject to independent third-party audits of their compliance, conducted every three years, with records retained for regulatory review.

In other words, this is a regime designed to create accountability around how consumer privacy requests are received, processed, and maintained over time.

Where Deep Sync stands

Deep Sync is a registered California data broker and is live-integrated with DROP today. We register proactively in every state where registration is required, not after receiving a notice, and our standing is publicly verifiable through each state's official registry.

Operationally, that means:

  • We check DROP at least every 45 days, per brand. Each registered Deep Sync brand retrieves and processes requests on its own cadence, so no brand depends on another's compliance activity.
  • DROP requests are handled through our established consumer privacy request workflows. We didn't build a parallel, bolt-on process for this law. When we receive an opt-out, delete, or do-not-sell request, our established process uses suppression to help ensure that the consumer's information is not added back into our databases later.
  • Consumer requests are applied across the Deep Sync family of brands. Requests submitted to Deep Sync are applied across our family of brands, helping ensure that a consumer's choice is consistently honored across our marketing databases.
  • Every request is logged on our Privacy Compliance Dashboard. Retrieval, processing, and completion are recorded and retained so the activity is auditable, by us, by our clients' compliance teams, and by regulators.
  • Privacy obligations are incorporated into our provider relationships. Each provider agrees to a Data Privacy, with applicable privacy and compliance requirements also reflected throughout our agreements.

The reason integration was straightforward is worth stating plainly: our data is built on deterministic, permissioned sourcing with consumer choice as an operating input rather than an exception to be handled. When consumer privacy requests and suppression are already part of the operating process, a new opt out channel can build on processes already in place.

What it means for your data

For Deep Sync clients, the practical impact is straightforward: your existing integrations, deliveries, and licensing terms remain unchanged. DROP establishes an additional regulatory mechanism for consumer deletion requests, and those requests are incorporated into our existing privacy processes.

DROP does not:

  • Restrict a particular data category or attribute
  • Change file structure, schema, or delivery format
  • Alter how our products are licensed, packaged, or priced
  • Create new operational steps for clients using licensed Deep Sync data

As with existing privacy activity, consumer choices can result in normal incremental changes to available records over time. Because consumers were able to begin submitting requests before the August 1 broker processing requirement took effect, initial processing cycles may include accumulated requests rather than the steadier pattern expected over time.

For clients closely monitoring match rates or record volumes, that context may help explain small variations during the initial implementation period.

Privacy as an operating posture

Privacy regulation continues to evolve, but the underlying direction is increasingly clear: organizations that work with consumer data are expected to demonstrate greater accountability around how that data is sourced, maintained, and governed. At Deep Sync, we don't view those expectations as separate from data quality; consumer choice and responsible data governance are part of maintaining a reliable data asset.

Deep Sync has maintained consumer privacy processes for decades, and today we apply established privacy controls across our marketing databases and operations. That's why regulations such as the Delete Act are less about creating an entirely new approach and more about incorporating a new regulatory framework into practices that already exist.

And we don't expect DROP to be the last development of its kind.

Centralized consumer controls, recurring compliance requirements, stronger documentation, and independent verification all point toward a market where data providers will increasingly need to demonstrate not only the scale of their data, but how responsibly that data is maintained.

What that means for our clients

Ultimately, privacy infrastructure matters because it contributes to something every organization licensing data should care about: whether that data can be defended. When legal, privacy, or compliance teams ask where data comes from, how it is maintained, and whether consumer choices are honored over time, data providers should have documented answers.

For Deep Sync clients, that's the practical value of the infrastructure behind our data.

DROP introduces a new regulatory framework, but the principle behind it isn't new to us: responsible data requires ongoing governance, documented processes, and systems designed to respect consumer choices.

As privacy requirements continue to evolve, we'll continue incorporating them into the same infrastructure and governance standards that support the data our clients rely on every day.

References

Privacy by design, not by deadline.

See how Deep Sync handles consumer deletion and opt-out requests across all 50 states, and what that means for the data you license from us.

Julia Andrade
Product Marketing, Deep Sync

Julia is Director of Product Marketing at Deep Sync, specializing in identity resolution, customer data, audience activation, and go-to-market strategy. She helps brands turn complex data into actionable insights that power better marketing, personalization, and customer engagement.

Let's connect →