DROP enforcement is live. Don't miss a cycle.
A compliance operations layer for California data brokers handling DROP deletion requests, suppression lists, service-provider routing, status reporting, and audit evidence.
Counted in 45-day intervals from August 1, 2026. Your own deadline is 45 calendar days after your last DROP access.
DROP is not a one-time project. It's a recurring obligation.
The Delete Request and Opt-out Platform forces every registered California data broker into a perpetual deletion cycle — with serious financial consequences for falling behind.
Enforcement is live
Since August 1, 2026, registered California data brokers must access DROP at least once every 45 calendar days and process the deletion requests they download.
45-day deletion cycle
Every 45 days, brokers must re-check the DROP list and delete newly matching consumer data — indefinitely.
Audit evidence required
The CPPA expects documented proof: who you matched, what you suppressed, when you completed each cycle.
Penalties compound fast
$200 per unresolved deletion request, per day. A backlog of 50 requests over a month is six figures of exposure.
Five steps from raw DROP list to audit-ready evidence.
A purpose-built workflow that operationalizes every CPPA requirement, without forcing your engineering team to build it from scratch.
Import your DROP list
You authenticate to DROP with your own credentials and export your cycle list. DropAudit ingests it and runs everything downstream. We never access DROP.
Match identifiers
Run hashed identifier matching against your internal systems, CRMs, and warehouses.
Generate deletion tasks
Auto-create deletion and suppression tasks with owners, SLAs, and approval gates.
Route to vendors
Dispatch deletion instructions to downstream service providers and track acknowledgments.
Export audit evidence
Produce regulator-ready evidence packs with timestamps, hashes, and chain of custody.
Your DROP credentials never leave your team.
DropAudit never logs in to DROP, never holds your DROP credentials, and never connects to DROP on your behalf. California's DROP regulations require you to restrict credential access and make you responsible for every action taken through your DROP account (11 CCR §7610(a)(1)). DropAudit is built for that reality: you hold the credentials, we run the compliance operation around them.
Everything required to operate a DROP program.
From intake to evidence export — every capability your privacy, legal, and engineering teams need in one system of record.
Deletion request tracker
A single queue for every DROP request, with status, owner, and SLA countdown.
Suppression list manager
Persistent suppression of opted-out identifiers across re-ingestion and new datasets.
Vendor deletion routing
Pre-built connectors and email workflows for service providers and third parties.
45-day compliance calendar
Automated cycle scheduling so you never miss a re-check window.
Status reporting dashboard
Real-time visibility into open, in-progress, and completed requests.
Audit log exports
Immutable logs exportable as PDF or CSV for CPPA inquiries and internal audit.
Penalty exposure estimator
Quantify open-request risk at $200/request/day in real time.
Readiness checklist
Step-by-step preparation tailored to your stack, vendors, and team size.
How much DROP exposure is on your books today?
Estimate your statutory penalty exposure at the California DROP rate of $200 per request, per day. We'll email a private summary with recommended next steps — no sales pitch.
- Quantifies real-time exposure across open requests
- Benchmarks against typical broker backlogs
- Includes a 30-day remediation roadmap
Built for California data brokers without a giant privacy engineering team.
If you're a 10–200 person broker with a registered status and a small compliance team, DropAudit gives you the operational backbone you'd otherwise need to build from scratch — without hiring a six-person privacy engineering org.
Predictable pricing for serious compliance programs.
All plans include unlimited 45-day DROP cycles.
Starter
DROP readiness + tracker
- DROP list intake (planned: file upload & ingestion API)
- Deletion request tracker
- 45-day cycle scheduling
- Basic status dashboard
- Up to 2 users
Compliance
Suppression + vendor routing + audit exports
- Everything in Starter
- Persistent suppression list manager
- Vendor deletion routing & acknowledgments
- Audit log exports (PDF / CSV)
- Penalty exposure dashboard
- Up to 10 users
Enterprise
Custom workflows + API integration
- Everything in Compliance
- Direct integrations with warehouses & CDPs
- Dedicated compliance engineer
- Custom evidence packs & DPA support
Know your DROP exposure before your next cycle closes.
Run a free readiness check today. 15 minutes of input, a clear picture of where you stand before your next 45-day deadline.