
California is set to reinforce its commitment to consumer privacy by introducing stricter regulations for data brokers that fail to comply with data deletion requests. Beginning in the first week of August, companies that do not process eligible deletion requests within the legally mandated timeframe will face a penalty of $200 per day for every delayed request. The measure is part of California’s ongoing effort to strengthen data privacy protections and hold organizations accountable for the collection, storage, and sale of personal information.
Under California’s privacy laws, residents have the right to request that data brokers delete the personal information they have collected. Businesses are generally required to respond to these requests within 45 days. If a company fails to complete the deletion within this period without a valid legal reason, it may now be subject to significant financial penalties. The new enforcement mechanism is designed to encourage timely compliance and discourage organizations from delaying or ignoring consumer requests.
In addition to imposing financial penalties, the updated regulations introduce greater transparency in the data deletion process. Data brokers must now provide a clear explanation whenever a deletion request is denied. They can no longer reject requests using vague or generic reasons such as claiming that the request is “illegitimate” or “cannot be verified” without sufficient justification. This change aims to ensure that consumers receive meaningful responses and that businesses follow fair and consistent practices when handling privacy requests.
According to official announcements, the new rules will not only apply to future users but will also extend to approximately 350,000 Californians who have already registered through the Delete Request and Opt-Out Platform (DROP). This platform allows individuals to submit a single request requiring registered data brokers to delete their personal information and stop selling or sharing it. By expanding the law’s coverage to existing users, California seeks to provide broader protection for residents who have already exercised their privacy rights.
The legislation, developed by the California Privacy Protection Agency (CPPA), is intended to reduce the widespread collection, sharing, and commercialization of sensitive personal information. The law places particular emphasis on safeguarding highly confidential data, including precise geolocation information, gender identity, government-issued identification numbers, information relating to minors, biometric identifiers, security credentials, health records—including reproductive healthcare information—and physical address data. These categories of information are considered especially sensitive because they can expose individuals to identity theft, discrimination, surveillance, or other forms of misuse if improperly handled.
Another significant feature of the updated law is its enhanced accountability requirements. Data brokers must maintain detailed records of every deletion request they receive, process, approve, or deny. These records must be retained for auditing purposes and may need to be submitted to government authorities upon request. This reporting obligation enables regulators to monitor compliance, identify patterns of non-compliance, and take enforcement action against companies that repeatedly violate consumer privacy rights.
With these strengthened measures, California continues to position itself as a leader in digital privacy regulation. By introducing stricter enforcement, greater transparency, and stronger oversight, the state aims to ensure that consumers have greater control over their personal data while encouraging businesses to adopt more responsible and privacy-focused data management practices.
Join our LinkedIn group Information Security Community!










