At its August 6–7, 2026, board meetings, the California Privacy Protection Agency (CalPrivacy) Board directed staff to prepare formal rulemaking to name Global Privacy Control (GPC) in the California Consumer Privacy Act (CCPA) regulations and tighten how opt-out preference signals must be honored. It also advanced separate rulemaking on data broker deletion audits and Delete Request and Opt-out Platform (DROP) rule amendments. Finally, the Board raised annual data broker registration and DROP access fees from $6,000 to $9,500 for 2027 and previewed its audit program.
Formal Rulemaking on Opt-Out Preference Signals (OOPS)
The Board voted 4–0 to direct staff to prepare formal rulemaking, including draft text, on four OOPS recommendations.
DROP Is Live and the Delete Act’s Penalties Carry No Cure Period
As of August 7, DROP has received roughly 450,000 deletion requests covering more than 200 million identifiers. Nearly 30 percent of registered brokers are already processing DROP requests, and registration has climbed to roughly 600 brokers. Registered brokers have 45 days to download deletion lists and 45 days from download to report back. The Delete Act’s $200-per-request-per-day penalty currently carries no cure period. So, failure to process requests within the 45-day period can carry fines in the tens of millions of dollars per day.
Data Broker Registration and Access Fees Rise to $9,500
The Board amended Sections 7600 and 7611 to raise the data broker registration and access fees each by 58 percent to $9,500, up from $6,000. The access fee is set at $9,500 in January and is prorated by $792 each month thereafter. Because the Delete Act funds the platform through fees, CalPrivacy raised them to cover the higher cost of running a now-live DROP. The fee increase is final starting in 2027, and the Board approved it over broker objections that a flat fee disadvantages small data brokers.
New Rulemaking Would Require Independent Data Broker Deletion Audits and Amend the DROP Rules
The Board advanced draft regulations to formal rulemaking and authorized a 45-day comment period. The proposed rules would amend Sections 7601–7622 and adopt new Sections 7630–7633. The package does two things. First, registered data brokers would have to retain an independent, qualified third party to audit whether they processed DROP deletion requests correctly and on time. Findings must be evidence-based, with system logs, hashing evidence, deletion commands, status reports, and personnel interviews, and may not rest primarily on management attestations or the mere existence of a policy. Unlike the cybersecurity-audit rules, internal auditors are not permitted and there is no threshold for triggering the audit requirement. A business that becomes a data broker under the Delete Act by knowingly collecting and selling to a third party the personal information of a single consumer with whom the business does not have a “direct relationship” (as defined in the regulations) would still have to undergo a third-party audit (in addition to paying $19,000 in annual fees). Under the proposed rulemaking, the first audit reports would be due November 1, 2028, and cover an audit period beginning August 1, 2026. Data brokers would need to undergo new audits every three years thereafter. Second, the package amends the existing DROP regulations. For instance, it would tighten registration accuracy requirements and add a 10-business-day window to update registration information.
The Audit Program: Gig-Economy, ADMT, and Cybersecurity Audits
The Audits Division delivered its first annual update. Its first sectoral audit targets the gig economy. Because CalPrivacy has confirmed that gig platforms are only the first in a planned series of sectoral audits, businesses across all industries should treat audit-readiness as a present priority, particularly as the following audit and assessment obligations phase in. Automated Decision-Making Technology (ADMT) obligations take effect January 1, 2027, followed by cybersecurity and risk-assessment audits. The first cybersecurity-audit certifications are due April 1, 2028, for businesses with over $100 million in annual gross revenue and phase in by revenue for smaller organizations after that. Businesses with $50 - $100 million in annual gross revenue must certify by April 1, 2029, and all other businesses engaged in processing activities that pose a “significant risk” to consumers’ security by April 1, 2030. Risk-assessment submissions are first due April 1, 2028, and annually after that.
Wilson Sonsini Goodrich & Rosati routinely helps companies navigate complex privacy and data security issues pertaining to CalPrivacy rulemaking, guidance, and enforcement. For more information or advice concerning your CCPA, data broker, or ADMT compliance efforts, please contact Tracy Shapiro, Eddie Holman, Ekaterina Moiseeva, or Malcolm Yeary, or any member of the firm’s Data, Privacy, and Cybersecurity practice.