What the California DROP Act Means for Sales Prospecting

Jun 29, 2026 | 5 minute read
Reading Time: 5 minutes

And What We’re Doing About It

If you’ve been following California’s evolving privacy landscape, you’ve probably heard about the Delete Act — and its enforcement mechanism, DROP (Delete Request and Opt-out Platform). As of 2026, this law is no longer on the horizon. It’s here. And if your sales or marketing team relies on contact-level data to reach prospective buyers, you need to understand what’s changing, what it means for you, and how Visual Visitor is staying ahead of it.

What Is the California DROP Act?

The California Delete Act (SB 362), signed in October 2023, creates a centralized privacy tool managed by the California Privacy Protection Agency (CPPA). For the first time, any California resident can submit a single deletion request through DROP at privacy.ca.gov and have that request automatically sent to every registered data broker simultaneously — without having to contact each one individually.

Prior to DROP, a consumer who wanted to opt out of data collection had to track down each data broker separately. Now, one request does it all.

The two dates that matter most:

  • January 1, 2026 — DROP went live. California residents can now submit deletion and opt-out requests.
  • August 1, 2026 — Data brokers must begin actively processing DROP requests on a 45-day cycle. Penalties of $200 per deletion request per day begin for non-compliance.

Who Does This Apply To?

Under California law, a data broker is defined as a business that knowingly collects and sells personal information about consumers with whom the business does not have a direct relationship. The definition is broader than most people assume.

The California Privacy Protection Agency has expanded how “direct relationship” is interpreted. It’s not enough that a consumer visited your website — they must have intentionally interacted with your business for the purpose of accessing your products or services. That means many B2B sales intelligence tools, lead generation platforms, contact enrichment providers, and website visitor identification services can fall within scope.

Key characteristics that may trigger data broker status:

  • Collecting personal data from third-party or public sources
  • Providing that data to businesses that have no prior relationship with the identified individual
  • Licensing personal contact information as a core business function
  • Retaining data about individuals across multiple third-party sources

If any of those describe your data vendors — or your own internal data practices — it’s worth a compliance review.

How This Affects Your Sales and Marketing Workflow

Here’s the practical reality: if a California resident submits a DROP request, any data broker holding their information must delete it within 45 days and can no longer sell or share it. That deletion obligation also flows downstream — meaning service providers and contractors who received that data must also delete it.

For sales and marketing teams, this creates several new risks:

  • Outreach to opted-out contacts. If someone’s information is deleted from a data source but it’s already sitting in your CRM, email sequence, or ad audience, continuing to contact them creates compliance exposure for your business — not just for the data vendor.
  • Data provenance gaps. As privacy regulation intensifies, buyers and procurement teams in regulated industries are starting to ask where contact data originated. Inability to answer that question can slow deals and erode trust.
  • Suppression failures across integrations. Contact data flows through many systems — CRM, marketing automation, ad platforms, sales engagement tools. If an opt-out is honored at the source but data has already been pushed across your stack, the suppression can break down.
  • California contacts carry elevated risk. Any California-based individual identified through a third-party data source currently represents the highest regulatory exposure in your pipeline. Applying additional care to outreach targeting California residents is a practical, near-term step.

What Visual Visitor Is Doing

Visual Visitor has always operated on a consent-based identification model — meaning the identification of website visitors is grounded in consent signals, not covert surveillance. As the DELETE Act enforcement window opens, we want to be transparent about how we approach these obligations:

We have assessed our data practices against the California data broker definition and the CPPA’s updated guidance;

  • We maintain registration status with the CPPA’s Data Broker Registry and have established a DROP account to process deletion requests on the required 45-day cycle;
  • We are building suppression workflows so that when a deletion request is processed, downstream clients receive timely notification to honor the removal across their own systems;
  • Our consent-based identification approach is designed to distinguish between data collected through direct, intentional consumer interactions versus passive or inferred data collection.

Steps Your Team Should Take Now

You don’t need to overhaul your entire tech stack, but a few proactive steps can meaningfully reduce your exposure:

  • Segment California contacts in your CRM. Know which contacts in your pipeline are California residents so you can apply appropriate caution.
  • Audit your data vendors. For every tool that provides contact data — visitor identification, lead enrichment, list providers — ask whether they have confirmed their DROP compliance and how they will notify you of deletion requests.
  • Map suppression across your stack. Identify every system that receives contact data from external sources (CRM, sales engagement, ad platforms, email tools) and confirm that opt-out signals propagate across all of them — not just at the source.
  • Review your privacy policy and opt-out mechanisms. Your website should have a clear, accessible opt-out mechanism for California residents. Under CCPA/CPRA, once someone opts out, you must wait at least 12 months before re-asking for consent.
  • Train your sales team. Reps should know what a DELETE Act opt-out means, how to recognize when a contact may be subject to one, and not to re-upload suppressed contacts through data enrichment workarounds.

The Bigger Picture

The California DELETE Act is part of a broader, accelerating trend toward consumer data rights. Only 9% of 522 registered data brokers were found to be fully compliant with transparency requirements in a May 2026 assessment, which means enforcement actions and reputational consequences are coming for a large portion of the industry. Businesses that treat compliance as a checkbox will struggle; those that build it into their data practices will earn a genuine competitive advantage with privacy-conscious buyers.

At Visual Visitor, we believe that transparent, consent-grounded prospecting isn’t just the compliant path — it’s the smarter business model. Prospects who engage with companies that respect their privacy convert better and retain longer. The DELETE Act is a forcing function, but the underlying principle is one we’ve always stood behind.

 

This post is intended for informational purposes only and does not constitute legal advice. Consult a qualified privacy attorney for guidance specific to your business.

References
1 Wikipedia

2 Califmatters.org

3 Crowell.com

4 themarkup.org

5 clarkhill.com

6 cppa.ca.gov

7 datagrail.io

8 cookie-script.com

9 mofo.com

10 leadrpro.com

11 jdsupra.com

12 DataGrail.io

13 Ben Isaacson – LinkedIn

14 freshfields.com

15 hunton.com

16 Clickpointsoftware.com

17 Visual Visitor

18 Visual Visitor – LinkedIn

19 privacy.ca.gov

20 CCPA.ca.gov

4 Ways Website Visitor Tracking Software Works

Did you know that 98% of the visitors to your website simply leave without ever contacting you? We help you identify who these visitors are in real-time. Sign Up Now

Visual Visitor Knows Who is
Visiting Your Website. Do You?

Start Your 14-day Free Trial

Sign Up Now