California Delete Act and DROP FAQ for Political Consultants

California’s Delete Act and DROP: What Political Consultants Need to Know

California’s Delete Act is the law (SB 362). DROP—the Delete Request and Opt-out Platform—is the state system consumers use to send one deletion request to registered data brokers. Calling it the “DROP Act” is inaccurate.

The practical warning: a consultant does not avoid the law merely because the client purchased the voter file or a human makes the final choice. The moment you add household relationships, matched phones or emails, demographic attributes, modeled scores, or even a selected universe such as “4 or 5 out of 5,” you are handling information linked or reasonably linkable to people or households, including associations and inferences. You are in covered-data territory.

That does not automatically make every consultant a data broker. Broker status still depends on the statutory elements: the consultant must be a CCPA “business,” knowingly collect and sell personal information to a third party, and lack a direct relationship with the consumers. A properly limited service-provider or contractor relationship may prevent the transfer from being a “sale,” but the written contract and actual data practices must satisfy the CCPA—not merely use those labels.

This page provides general information, not legal advice. Facts, contracts, thresholds, and data flows matter; consult qualified California privacy counsel.

Why householding and “4 out of 5” selection matter

California’s definition of personal information includes information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked—directly or indirectly—with a particular consumer or household. It also expressly includes inferences used to create a profile reflecting preferences, characteristics, behavior, attitudes, abilities, and similar attributes.

Example: a campaign buys a voter file and asks its consultant to return only voters rated 4 or 5 out of 5 for likelihood of support. The consultant’s output reveals a person-level inference and a selected audience. If the consultant also households records, it creates or reveals a household association. Those steps concern covered personal information even if the client bought the underlying file and even if a person—not software—clicked the filters.

Whether the consultant also becomes a data broker turns on the remaining elements. Risk is especially high if the consultant licenses or delivers the enriched list for consideration, bundles it into a retainer, combines it with other sources, retains it for its own purposes, or reuses the resulting audiences or insights across clients.

Who is a data broker?

Under California law, a data broker is generally a CCPA “business” that knowingly collects and sells to third parties the personal information of a consumer with whom it does not have a direct relationship. The CCPA business thresholds include, among other routes, annually buying, selling, or sharing the personal information of 100,000 or more consumers or households.

“Sale” is broader than a cash sale. It includes making personal information available to a third party for monetary or other valuable consideration. A license, custom audience, or data deliverable bundled with consulting services may qualify. In 2025, the CPPA’s ROR Partners enforcement action specifically rejected the idea that custom audiences escape the law merely because they are bundled with other services.

Does a service-provider contract solve the problem?

It can change the analysis, but only when both the contract and the conduct satisfy the CCPA. A compliant service provider or contractor is restricted from selling or sharing the data, using it outside the specified business purposes, or combining it with personal information received from other clients or collected through its own consumer interactions, subject to limited exceptions.

Consultants should not assume protection if they enrich a house file, reuse match results, pool data, build reusable models, retain audiences after an engagement, or use one client’s data to benefit another. The system must match the agreement.

What DROP requires of covered data brokers

  • Register annually with the California Privacy Protection Agency.
  • Access DROP at least once every 45 days beginning August 1, 2026.
  • Process and report matched deletion requests as required.
  • Direct service providers and contractors to delete covered information.
  • Maintain appropriate suppression so deleted consumers are not simply reacquired and reintroduced.

Consumers began submitting DROP requests on January 1, 2026. Independent data-broker compliance audits begin in 2028.

Liability can attach to the consultant—not just the data vendor

A consultant should separately analyze its own conduct. Buying data from a vendor that says it is compliant does not determine the consultant’s status. If the consultant meets the CCPA business threshold and sells an enhanced profile or audience outside a properly limited service-provider or contractor relationship, the consultant may have its own registration, deletion, and suppression obligations.

Failure to register can result in an administrative fine of $200 for each day the data broker fails to register, plus unpaid fees and agency costs. Failure to comply with a DROP deletion request can result in $200 per request for each day the broker fails to delete, plus costs. Other CCPA violations may carry separate administrative fines.

Six questions consultants should ask now

  1. Which exact fields came from a government source, and which were appended, inferred, scored, linked, or selected?
  2. Do we cross a CCPA business threshold, including the 100,000-consumer-or-household threshold?
  3. Do we make enhanced records or audiences available for money or other value, including inside a retainer?
  4. Are we operating under a compliant service-provider or contractor contract—and do our real systems follow it?
  5. Do we combine, retain, or reuse data or audiences across clients?
  6. Can we document current registration, DROP processing, deletion, downstream instructions, and suppression practices for every relevant vendor and internal system?

What to request from Voter.Vote or any data supplier

Request current written documentation concerning registration status, DROP processing, deletion and suppression procedures, downstream vendor controls, and the handling of government-source data versus commercially augmented data. Do not rely only on a general statement that “political data is exempt.”

Bottom line: householding and selecting “4 out of 5” voters are substantive data operations. They can create or reveal covered personal information and can expose a qualifying consultant to the Delete Act and DROP when the other data-broker elements are met.

Official resources: California DROP · CPPA Data Broker Registry

Last updated September 12, 2026.

Scroll to Top