privacy-lawdelete-actdropdata-brokersreference

The State-by-State Deletion-Law Reference

Sirveil TeamUpdated 6 min read

California's DELETE Act stopped being theory this month. Data brokers registered with the CPPA in January. Consumers began filing deletion requests through DROP — the Delete Request and Opt-out Platform — the same month. And since August 1, every registered broker has been required to access DROP at least once every 45 days and process what it finds. The first 45-day cycle closes in mid-September.

That makes this a good moment for a reference that mostly doesn't exist in one place: what every US state actually requires on data deletion and data-broker registration, cited to statute, with the dates that matter next. We'll keep this page current as legislatures move.

This is a reference, not legal advice. Every claim below carries a citation; anything we could not verify against a primary source is marked as such.

The anchor: California's DELETE Act and DROP

California runs the only operating central deletion mechanism in the country. The pieces:

The registry (AB 1202, 2019). A "data broker" — a business that knowingly collects and sells personal information about consumers with whom it has no direct relationship — must register annually (Cal. Civ. Code §§ 1798.99.80–.82). Registration moved from the Attorney General to the California Privacy Protection Agency under the DELETE Act, with the annual window running January 1–31 and a $6,000 fee for 2026. Per figures the CPPA reported at its February 2026 board meeting, the registered population grew from 459 brokers in June 2025 to over 575 by February 2026.

The mechanism (SB 362, 2023). The CPPA was required to stand up an accessible deletion mechanism by January 1, 2026 (Civ. Code § 1798.99.86(a)). DROP launched on schedule: one free request, filed once, reaching every registered broker, with selective exclusions and authorized-agent support (§ 1798.99.86(b)). The CPPA reported more than 242,000 Californians had filed by February 2026.

The 45-day clock (§ 1798.99.86(c)–(d)). Beginning August 1, 2026, every registered broker must access DROP at least once every 45 days, process all deletion requests within 45 days of receipt, and — this part is under-appreciated — keep re-deleting each requesting consumer's data at least once every 45 days thereafter, indefinitely, without selling or sharing newly collected data about them. A request that can't be verified as a match must be honored as an opt-out of sale and sharing instead.

Teeth. Failure to register: $200 per day (§ 1798.99.82(c)). Failure to honor DROP: $200 per deletion request per day (§ 1798.99.82(d)). Brokers must compile annual deletion metrics (§ 1798.99.85), and beginning January 1, 2028 must undergo independent third-party compliance audits every three years, producing the report to the CPPA within five business days of a written request (§ 1798.99.86(e)).

The other registry states

Six states now require data-broker registration. Only California's regime deletes anything; Connecticut's will in 2028.

State Statute Registrar Fee Penalty Deletion mechanism
California Civ. Code §§ 1798.99.80–.89 CPPA $6,000 (2026) $200/day; $200/request/day DROP — live since Jan 2026, processing since Aug 2026
Vermont 9 V.S.A. §§ 2446–2447 (2018) Secretary of State $100 $50/day, $10k/yr cap None (registry, security, disclosure)
Texas Bus. & Com. Code ch. 510 (2023) Secretary of State $300 $100/day, $10k/12-mo cap None
Oregon ORS 646A.593 (2023) Dept. of Consumer & Business Services set by dept. up to $500/violation/day, $10k/yr cap None
Connecticut S.B. 4 (2026) Dept. of Consumer Protection $2,500/yr (register by Jan 1, 2027) $200/day/consumer/violation DROP-style mechanism due July 1, 2028; broker processing from Oct 1, 2028
New Jersey P.L. 2026, c. 25 Div. of Consumer Affairs (operative Mar 27, 2027) $5,000–$1.5M tiered $2,500/day unregistered; $50k/record for barred sensitive sales None (disclosure of deletion options only)

Maryland tried twice — 2025's HB 1089 and 2026's SB 616/HB 1220 both died in committee. New Jersey's law is notable for reaching "data collectors" (businesses that collect directly from consumers and sell to brokers), not just brokers.

Twenty-four states, twenty-four deletion rights

As of August 2026, twenty-four states have comprehensive consumer privacy laws, and every one includes a deletion right. The details diverge where it counts:

  • Scope. Most states let consumers delete data "provided by or obtained about" them. Utah and Iowa are the narrow outliers: only data the consumer themselves provided.
  • Authorized agents. Only California permits agents to submit deletion requests on a consumer's behalf (Civ. Code § 1798.130; DROP builds agents in at § 1798.99.86(b)(8)). Roughly nine states (CO, CT, DE, MT, NE, NH, NJ, OR, TX) allow agents for opt-outs only; the rest have no agent provision at all. This single design choice largely determines what deletion-at-scale can look like outside California.
  • The clock. The standard is 45 days to act, extendable once by 45 (California pairs it with a 10-business-day receipt confirmation, 11 CCR § 7021). Iowa allows 90.
  • Cure periods. A patchwork in motion: permanent cure rights in TX, UT, IA, NE, TN, IN, KY, OK, AL; expired or sunset in CO, OR, MN, NJ; discretionary in CT, DE, NH, FL, MD. Montana eliminated its cure period entirely as of October 2025.
  • The 2026 wave. Indiana, Kentucky, and Rhode Island took effect January 1, 2026. Louisiana and Oklahoma follow January 1, 2027; Alabama May 1, 2027; Vermont's comprehensive law January 1, 2028. None creates a private right of action for deletion violations.

The verification gap

Here is the part of the statute books that says the least: what proof of deletion the consumer actually receives.

Every comprehensive law requires the company to inform the consumer of action taken within the response window. None requires evidence of the outcome — no logs, no certificate, no independently checkable artifact. California's DROP goes furthest, and what it provides is a status flag: the statute requires that consumers and agents be able to "verify the status of the consumer's deletion request" (§ 1798.99.86(b)(9)) — status tracking, not deletion evidence. The system's real verification is institutional and delayed: broker-compiled metrics due each July 1 (§ 1798.99.85) and triennial independent audits beginning January 2028 (§ 1798.99.86(e)).

In other words: the consumer asks, the company confirms, and the confirmation is produced by the same workflow that performed the act. Whether the public web actually stopped showing the data is a question the statutes leave open — and it's the question that will decide how much these laws end up meaning.

The dates that matter next

Date What happens
~Sept 15, 2026 First DROP 45-day access/processing cycle closes (computed from the Aug 1 start)
Oct 1, 2026 Connecticut's 2026 CTDPA amendments take effect
Jan 1, 2027 Connecticut broker registration deadline; Louisiana and Oklahoma privacy laws effective
Jan 1–31, 2027 California (CPPA) and Vermont annual registration windows
Mar 27, 2027 New Jersey broker/collector registration provisions operative
May 1, 2027 Alabama Personal Data Protection Act effective
Jul 1, 2027 First CA broker deletion-metrics compilation covering a DROP processing year
Jan 1, 2028 CA triennial independent audits begin; Vermont comprehensive law effective
Jul 1, 2028 Connecticut's central deletion mechanism due
Oct 1, 2028 Connecticut brokers begin 45-day processing

Primary sources: California Civ. Code §§ 1798.99.80–.89 and the CPPA's data-broker and DROP regulation pages (cppa.ca.gov); 9 V.S.A. § 2446; Tex. Bus. & Com. Code ch. 510 (sos.texas.gov); ORS 646A.593; Connecticut S.B. 4 (2026); N.J. P.L. 2026, c. 25; state statute texts for the comprehensive-law table. Corrections welcome — this page is maintained against the statutes, and we'd rather be told than be wrong.

Sirveil builds exposure-verification infrastructure. This reference is published as a public resource; nothing here should be read as implying participation in or certification under any program described.

Share this article

PostShare

Get privacy insights delivered

No spam. Unsubscribe anytime. We send one email per week with new guides and data broker news.

Start protecting your personal data

Scan, verify, remove: Sirveil finds where brokers list you, you confirm which entries are yours, and your takedown requests are prepared, transmitted, and chased on your behalf — tracked end to end.

Get Sirveil

Available now on the App Store and Google Play.