We all know the TCPA (Total Cash cow for Plaintiffs’ Attorneys), and hopefully we are aware that CIPA (commonly pronounced “sip-uh”) isn’t a drink you want to order on a California beach. But now I am hearing more and more about the Delete Act. I am finding a surprisingly high number of industry users who are NOT familiar with CCPA and the looming DROP deadline that hits on August 1, 2026.
What Is California's Delete Act?
CIPA is a commonly used acronym, but in California, CIPA is the California Invasion of Privacy Act. Many of our DNC.com followers also follow TCPAWorld, but did you know that the same trusted name behind that site has another dedicated to just CIPA? CIPA was originally introduced in the 1960’s as an anti-wiretapping law, but, more recently, has been updated to prevent many of the data tracking techniques used by websites.
I’m not just talking about fraud (i.e. stealing your credit card info), but common tracking cookies used by virtually every app on your smartphone to deliver targeted (versus random) ads. While arguments can be held on the merits of tracking cookies, know that this has, much like the TCPA, been weaponized as the next frontier for private right of action claims.
As an example, the infamous Javier case was based on the usage of ActivePropsect’s technology on a consent form to avoid lead fraud and risk under the TCPA. Think about it; you are trying to prevent yourself from getting sued by verifying who is filling out the form. Frustrated that party can’t trigger a TCPA claim (hypothetically speaking, of course), they make a claim under CIPA instead. You can’t win!
Ok, so once you solve for TCPA and CIPA, you are now ready to tackle the CCPA – California’s game changing privacy act that was just one more bit of fun in the dumpster fire year that was 2020. While we are strong proponents of consumer privacy rights, this bill introduced cumbersome collection and disclosure requirements that were complex to navigate. The poorly written bill (in this author’s option), had enough vague requirements to require case law to later define, making the “game changer” equivalent to someone seemingly deciding, midgame, that if you roll a 4 in Monopoly, you automatically go to jail. Next turn, it could be 6…or 3….who knows? Roll the dice and find out later!
How the Delete Act Differs From CCPA and CIPA
CIPA and CCPA, separate applications but both very relevant
What is CCPA and how does it differ from CIPA? In the simplest form, CCPA is more about what you collect, whereas CIPA is more about who is getting what you collect. How does this relate to the Delete Act? The Delete Act is an expansion of CCPA, giving consumers not just control over who gets their data, but it also gives them a “magic erase” button that can remove their digital footprints left with a specific data broker.
Who Has to Comply With the Delete Act?
How does it work? Well, let’s say you are a data broker as defined in the CCPA and you knowingly collect and sell information to third parties (think Lead Gen). You collect John Doe’s information – maybe from a lead form - and sell it.
Over time, Mr. Doe is likely to go from receiving calls about the gutter replacement he genuinely wanted to calls and texts for pet insurance, solar panels, and maybe even an extended warranty on his car. Enough is enough! John wants this to stop but, in today’s market, what option does he have? His information has been bought and sold so many times that he is now required to tell an unending line of sellers to leave him alone when they call, reply stop on every new text chain.
There has to be a better way…
How California's DROP Platform Works
Enter the Delete Act.
The Delete Act utilizes California’s DROP platform, which, last I heard, is still working out some kinks. Once fully functional, consumers can request that their information be deleted from all data brokers servicing the state. Data brokers are obligated to register with the platform and perform routine checks for a deletion signal from a consumer. Once they see the signal, they are required to scrub all information related to that consumer from their end. This is a bit of an oversimplification, but for the purposes of this article, it will do.
What Are the Penalties for Violating the Delete Act?
Perhaps the more consequential piece of this legislation is the fine. $200. At face value, that is a rounding error for most of our businesses. However, you need to understand how that $200 is applied. It’s $200 per violation, per day. As Fenwick observes, “if just 50,000 California residents request that a data broker delete any of their personal information held by the business, and the data broker fails to do so within the required 45-day window, the potential fine could be $10 million for each day that the data broker fails to delete the in-scope personal information as required by the Delete Act.” Read that last part again…$10 million PER DAY. I am aware of no caps, which means a single month could quickly become a $300 million liability!
Will Other States Adopt Similar Data Broker Laws?
Is this a typical “California Special,” or a sign of what’s to come nationwide? New Jersey is moving on bill A5328, which has much of the same data broker registration references as we see in California, but with differing definitions. Right now, they are looking for brokers to to document whether or not consumers can delete information captured by the broker, similar to what California did when they first introduced CCPA. Are they going to follow their west coast counterparts and introduce DROP requests with scary fines for not compliance in another year or so? Are other states going to follow?
How Businesses Should Prepare Before the August 1, 2026 Deadline
Like anything else, these are all important things to monitor and discuss with your compliance team and/or qualified legal counsel. New companies, such as Forgetmenaut are entering the scene with solutions to help monitor and comply with these regulations and are certainly worth checking out as well.
Regardless, if you do business in the state or even have employees in the state, you have just a couple of weeks before the scary August 1, 2026 deadline hits and your risk profile changes substantially.