For counsel and compliance

The nine things California requires

Registered data brokers have nine obligations under the Delete Act, and an audit tests all of them rather than only whether you filed. Each one below carries the regulation it comes from, so you can check it against the text rather than take our word for it.

01

Choose your lists

§7610(a)(3)

Tell the state which kinds of identifier you hold. You have to select every list type your records could match, and you may narrow that only where your identifiers are fully duplicative across consumers.

Done looks like: Selection covers every identifier you actually store. You can change it once every 45 days.

02

Download the list on time

§7612(a)

Access the state's system and download your lists at least once every 45 calendar days. This is a rolling maximum interval, not a fixed window you can plan around a quarter.

Done looks like: Never more than 45 days between accesses. It applied to every registered broker from 1 August 2026, with no phase in.

03

Standardize your records

§7613

Clean each of your own records into the exact format the state specifies before converting it. Email, phone, date of birth, ZIP, name, advertising ID and vehicle identifiers each have their own rule.

Done looks like: Your output matches the state's published examples for every field type you hold.

04

Convert records to codes

§7613

Turn each standardized record into a code with SHA-256, encoded as standard Base64 including the padding. Two of the six list types combine several fields, and the parts join in a fixed order.

Done looks like: Your codes match the state's worked examples exactly. Getting the order wrong produces zero matches, which looks the same as having no Californians.

05

Match against the state's list

§7613

Compare your codes against the codes the state sent. Where they overlap, that person is in your data.

Done looks like: Every list type you selected has been compared, and you can name which of your records matched.

06

Act on every match

§7613

For each match, remove all personal information tied to that identifier, including inferences drawn from it and including archived and backup copies. Deidentifying or aggregating also counts. Where one identifier covers more than one person, opt each of them out of sale and sharing instead of deleting.

Done looks like: Nothing tied to the matched identifier survives, and backups are covered when they are next restored or accessed.

07

Report a status for every request

§7614(a)

At each access session, report the outcome of every deletion request you received in the previous session. On the manual route you report the previous session before you download a new list.

Done looks like: Every request from the last session carries a status code, filed in the format the state accepts.

08

Keep the permanent block list

§7613(b)(1)(B), (c)

Requests that did not match anything still have to be kept. Screen newly collected records against them before you sell or share, and report the change if one matches later.

Done looks like: Every new file you acquire is checked against the list before it is used, and the list is retained until the consumer cancels.

09

Pass the instruction to your vendors

§7613(d), (e)

Direct the service providers and contractors you shared the data with to delete it as well. Share only the minimum personal information they need in order to suppress.

Done looks like: You can show who was told, what they were told, and when.

What happens if one of them is missed

The penalty is $200 per deletion request per day, with no grace period, and a separate $200 a day for not being registered at all. Independent audits begin in January 2028 and look at how you matched, what you removed and what your records show, not only whether a report was filed.

Talk to usThe same thing, step by step