In this article

Sign up for our newsletter

Share this article

Since January, more than 300,000 residents have filed deletion requests through California’s new DROP platform. Until last week, that number was just a queue. Now, it’s a to-do list.

Starting August 1, data brokers on the registry have to run the queue against their own records every 45 days and act on deletion requests for matching records. The penalty for sitting on unprocessed requests is $200 per request, per day, which will easily add up to eye-watering figures.

I spoke with CPPA Executive Director Tom Kemp earlier this year on our podcast, the Privacy Insider, and he discussed some of the implications of the DROP system for consumers and businesses. Give it a listen if you’d like to learn more about DROP and how Tom Kemp and the CPPA think about privacy enforcement.

And if you’re panicking over whether your organization counts as a data broker or not under California law, you would likely know at this juncture–but the definition is fairly broad. A data broker is, with some exceptions, “a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship.”

If you’d like to check out the definition in more detail, you can find the relevant statute here on the California legislature’s website. You wouldn’t be the only one–when I double-checked the definition the other day, the site hit me with a 503 error!

Best,
Arlo

Resource Listing - State of US Privacy Enforcement

Highlights From Osano

New From Osano

Blog: Why Companies Are Leaving OneTrust in 2026

Unpredictable renewal pricing, months-long implementations, and support that favors the biggest accounts—mid-market teams are naming the same friction points as they evaluate OneTrust alternatives this year.

Read more

In Case You Missed It…

Blog: Inside the VDPOSA: Vermont’s Unique Take on Data Privacy

Vermont has joined the US privacy patchwork with a privacy law that’s made things even patchier. Broadly, the law resembles Connecticut’s privacy law. But when it comes to consumer health data, neural data, and a statutory willingness to add a private right of action in the future, the VDPOSA differs from its peer laws significantly.

Read more

On-Demand Webinar: Opted Out. Still Tracked. The Marketing & Consent Webinar Series

A three-part series exploring the practically universal problem of marketing data trackers continuing to fire even after consumer opt-outs. Learn why 79% of websites have broken opt-outs in part one, how to fix broken opt-outs in part two, and see how it all comes together in part three, where we conduct a real-world audit of websites with broken and functioning consent flows.

Watch on-demand



Top Privacy Stories of the Week

California's Data Broker Deletion Deadline Arrives With $200-a-Day Penalties

California's Delete Act just entered its enforcement phase. As of August 1, the roughly 600 registered data brokers must act on the 300,000-plus deletion requests already filed through the state's DROP platform, or face fines of $200 per request, per day. Data brokers now must check DROP at least once every 45 days. After retrieving a request, a broker generally has another 45 days to match the consumer’s information, delete covered records, and report the result.

Read more

FTC Sues Hims & Hers Over Sharing Patients' Medical Data with Advertisers

The FTC has sued telehealth giant Hims & Hers, alleging the company let pixel trackers from Meta, Snap, Microsoft, and other ad platforms quietly capture customers' health information, despite privacy policies that said otherwise. For any company handling health or wellness data, it's a reminder that privacy policies and actual data processing behaviors need to match.

Read more

EU Begins Enforcing AI Act Transparency Rules for Chatbots and Deepfakes

Starting August 2, the EU's AI Act requires chatbots to disclose they're not human and deepfakes to carry disclosure labels. For any business deploying AI-generated content or conversational agents touching EU users, meeting these new transparency obligations will be a priority.

Read more

Amgen Discloses Cloud Breach Exposing Patient Health Data

Biotech giant Amgen disclosed that hackers stole patient health information and proprietary data from cloud environments run by third-party service providers. The company says it's still determining the scope, including whether R&D and intellectual property were also swept up. It's a pointed reminder that a company's data security is only as strong as its weakest vendor.

Read more

UK MP Sues xAI Over Grok's Non-Consensual Sexualized Images

British MP Jess Asato is asking a UK court to force xAI to permanently stop Grok from generating non-consensual sexualized images of her, and to delete every copy already made. Her claim leans on UK GDPR and data protection law rather than platform content policy, arguing that xAI—as the company that designed, trained, and instructed Grok—is the controller responsible for what the chatbot produces about a real person. If successful, it could be the first ruling to hold an AI developer directly liable under data protection law for what its model generates.

Read more

Like What You See in the Privacy Insider newsletter?

There's more to explore:

🎙️The Privacy Insider Podcast

We go deeper into additional privacy topics with incredible guests monthly. Available on Spotify or Apple.

📱 The Osano Subreddit

Join our official subreddit to stay up to date on the latest news, analysis, guidance, and content from Osano!

đź“– The Privacy Insider: How to Embrace Data Privacy and Join the Next Wave of Trusted Brands

The book inspired by this newsletter: Osano CEO, Arlo Gilbert, covers the history of data privacy and how companies can start building a privacy program from the ground up. More details here.

If you’re interested in working at Osano, check out our Careers page! 

Get a demo of Osano today
Share this article