Compliance pricing without the enterprise tax.
Plans designed for small and mid-size California data brokers. Every tier includes unlimited 45-day DROP cycles.
Predictable pricing for serious compliance programs.
All plans include unlimited 45-day DROP cycles.
Starter
DROP readiness + tracker
- DROP list intake (planned: file upload & ingestion API)
- Deletion request tracker
- 45-day cycle scheduling
- Basic status dashboard
- Up to 2 users
Compliance
Suppression + vendor routing + audit exports
- Everything in Starter
- Persistent suppression list manager
- Vendor deletion routing & acknowledgments
- Audit log exports (PDF / CSV)
- Penalty exposure dashboard
- Up to 10 users
Enterprise
Custom workflows + API integration
- Everything in Compliance
- Direct integrations with warehouses & CDPs
- Dedicated compliance engineer
- Custom evidence packs & DPA support
Frequently asked
August 1, 2026. Since then, registered data brokers must access DROP at least once every 45 calendar days and process the deletion requests they download.
Every 45 days, brokers must re-check the DROP list and process new matching consumer deletions — indefinitely.
No. DropAudit is designed to work with hashed identifiers, so raw PII stays inside your systems. The service is pre-launch and is not processing customer data yet — see the Security page for how this is documented.
No. DROP obligations recur every 45 days, so each cycle run through a documented process counts. DropAudit can't change cycles already past — talk to your counsel about any you've missed.