Skip to Content

CalPrivacy discusses DROP enforcement, data broker fee hike

During its 7 Aug. meeting, California Privacy Protection Agency Board advanced proposed rules for DROP auditing requirements to formal rulemaking and voted to increase data broker registration fees.

Published
Subscribe to IAPP newsletters

Contributors:

Lexie White

Staff Writer

IAPP

California's data broker enforcement entered a new phase when requirements related to consumer requests through the Delete Request and Opt-out Platform became enforceable 1 Aug. At its 7 Aug. board meeting, the California Privacy Protection Agency noted 30% of registered data brokers began processing DROP requests in the first week following the compliance deadline, with 450,000 requests submitted to date.

The board meeting also included an initiation of formal rulemaking for DROP compliance audits and the approval of an increased 2027 data broker registration fee following a slight decrease the prior year.

CalPrivacy Assistant Deputy Director of Public and External Affairs Marissa Rosemblat said in addition to the agency’s DROP enforcement efforts, staff have also been “able to streamline aspects of the residency verification process, simplify the check status and profile update flows, and enhance messaging across the platform to better explain how processing will work.”

Consumer feedback on DROP functions indicated 29% of consumers were grateful to have a simplified process to request the deletion of their data.

However, a separate CalPrivacy survey found only 20% of consumers had heard of the agency. Among those who were aware of it, 82% “had a positive view of the agency.”

“One of our goals with DROP is to make privacy easy, and the enhancements that we've made to the experience to date really reflect that commitment,” Rosemblat said.

DROP compliance audits

In preparation for the Delete Act's audit requirements that take effect 1 Jan. 2028, CalPrivacy has launched formal rulemaking on proposed regulations establishing independent audits of data brokers’ compliance with DROP. The draft is now subject to a 45-day public comments period.

Third-party assessments will examine companies’ data deletion logs and status reports to determine whether data brokers' DROP processes are compliant. Audits will be conducted on a triennial basis.

The draft rules layout criteria for a "qualified, objective, and independent auditor" and the components of an audit, including processes and policies reviews; deletion system testing; and in-person interviews with relevant DROP compliance personnel. CalPrivacy Attorney Liz Travis Allen noted the proposed rules include “provisions to ensure the scope of the audit and the information it relies on are appropriate.”

The draft rules also list nine minimum required audit areas, many of which focus on accuracy and timeliness with fulfilling DROP requests.

Increased data broker fees

The board approved the proposed increase for data broker registrations and access fees to USD9,500 next year, an USD3,500 increase to 2026's fee. According to the agency, the increase addresses additional residency verification, infrastructure and staffing costs.

The change is notable after CalPrivacy reduced this year's fee by USD600 in 2025. Rosemblat noted the prior reduction, approved at the board level, was "based on a higher-than-anticipated registrant population, an increase in penalty revenue, and utilization of the fund's existing balance."

"As the platform and program evolve, we will monitor expenditures and adjust fees as necessary to cover costs,” she added. 

During the meeting's public comment session, In-House Privacy Principal Ben Isaacson urged the agency to consider using revenue from enforcement actions against unregistered data brokers to offset costs rather than increasing fees for registered companies.

Isaacson highlighted the potential for "significant strain" and burdens among data brokers stemming from an increased fee.

"With the major statutory penalties that are afforded to the enforcement division for those unregistered data brokers, especially again with the track record CalPrivacy has shown for now years of enforcing against unregistered data brokers, I would think only one of those enforcement actions at this point would clearly subsidize DROP for 2027," he said.

Audits Division

CalPrivacy Chief Auditor Sabrina Boyson Ross made her first appearance before the board to present the Audits Division's first annual review. The presentation focused on highlighting the processes the unit has established since Ross was appointed in February.

"My division seeks to increase regulated entities' voluntary compliance through proactive engagement and structured review," Ross said. "The Audits Division is designed to depart from a traditional reactive compliance review model. This is one where there's a static approach and formulaic audits. Rather, we will tend to pursue a risk and harm-based approach, which is calibrated to detect real-world failures in statutory rights.”

Ross' team has notable public initiatives already up and running. It recently launched its first sectoral inquiry into gig economy platforms and issued a request for technical input on inference and reidentification capabilities among emerging technologies.

Ross told the board the request for information is "focused on developing methods for detecting and measuring inferences, advancing techniques for evaluating and mitigating re-identification risk, and exploring how legal concepts can be operationalized in real-world systems."

As CalPrivacy continues to expand its efforts to increase enforcement and navigate the evolving digital landscape, Ross noted the agency wants to "make sure that our audits can be a productive force that sheds light on the importance of user privacy and whether interventions might need to change."

CPE credit badge

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.

Submit for CPEs

Contributors:

Lexie White

Staff Writer

IAPP

Tags:

AdtechEnforcementU.S. state regulationRisk managementAdvertising and marketingPrivacy

Related Stories