Data brokers
You collect and sell consumer information without a direct relationship. SB 362 requires you to process DROP deletion requests on a 45-day cycle — and keep suppressing those consumers going forward.
Drop Privacy is the compliance engine that turns California's Delete Act from a recurring scramble into a quiet, automated cycle. It matches the state deletion batch against your data, suppresses the right consumers, and keeps a tamper-evident record — without ever exposing personal information.
Drop Privacy is software for data brokers — not the state's DROP platform itself. If you sell consumer data you didn't collect directly from the consumer, and you're registered (or need to register) with the CPPA, you need a repeatable way to honor deletion requests every 45 days. That's what we built.
You collect and sell consumer information without a direct relationship. SB 362 requires you to process DROP deletion requests on a 45-day cycle — and keep suppressing those consumers going forward.
You need defensible proof — not a spreadsheet. Drop Privacy produces per-cycle reports, a hash-chained audit trail, and a printable attestation you can hand to an auditor or regulator.
You need something that scales and doesn't break every 45 days. Connect source tables, upload a CSV, or deploy the on-prem agent — the same automated cycle runs either way.
California now runs a single platform where any consumer can ask every registered data broker to delete their data in one click. Drop Privacy is the engine on your side of that exchange — it does the matching, the responding, and the record-keeping so your team doesn't have to build it from scratch.
Your lead tables are turned into a reverse hash index — built incrementally, never re-scanning. Matching happens on salted hashes, so raw PII stays inside your perimeter.
Each cycle downloads the outstanding CPPA DROP request file, matches every record against your index, and classifies it — deleted, exempt, opted-out, or not found.
It answers through the DROP API, suppresses matched consumers so their new leads aren't resold, and writes a hash-chained audit entry you can show a regulator.
Every 45 days Drop Privacy runs the same idempotent, resumable cycle from a background worker — never a web request, and safe to re-run.
Normalize and hash consumer identifiers into a reverse index, updated incrementally by a high-water mark.
Download the state deletion batch and look up every record's hashes against your index at scale.
Classify each record — deleted, exempt, opted-out, or not found — using rules you can configure per tenant.
Answer via the DROP API, suppress matched consumers forward, and seal a tamper-evident audit entry.
Connect your database tables, upload a CSV, or run everything inside your own network. Every path ends in a matched, deleted, attested cycle.
Map your columns — name, DOB, email, phone, VIN, MAID, CTV ID — and we hash, index, and cycle them.
Send a big CSV of raw leads — or pre-hashed records to the DROP spec — and we import it at any scale.
Run indexing and cycles inside your own perimeter; only hashes and reports reach the dashboard.
Most ways of answering a deletion platform mean shipping consumer lists somewhere. Drop Privacy is built the opposite way.
This isn't a one-time project. Once consumer requests are accessible, every registered broker must keep deleting — on the clock, on a cycle, with penalties for falling behind.
Doing this by hand doesn't scale. Manual matching against hundreds of millions of records — every 45 days, accurately, with an audit trail — is exactly the kind of work that quietly breaks. Drop Privacy makes the cycle boringly repeatable.
California's deletion batch can include name + date of birth + ZIP, email, phone, name + VIN, mobile ad IDs, and CTV IDs. Drop Privacy normalizes and hashes each type to the same spec the state uses — so matches are exact, not fuzzy guesses.
If a run stops mid-cycle, it picks up where it left off — never double-deletes or double-responds. Safe to re-run; corrections go through a dedicated amend path.
Built for hundreds of millions to billions of records. Incremental indexing and background workers keep cycle time predictable as your dataset grows.
Onboard a new broker as configuration, not a code fork. Each tenant gets isolated databases, custom rules, and branded reports.
A printable, themed attestation backed by a hash-chained log — ready to hand to an auditor or regulator.
Deleted consumers are remembered, so their newly imported leads are rejected at the door — not resold by accident.
Per-run and per-tenant reports: counts by status, coverage, rejects with reasons, and days left to respond.
The California Delete Act (SB 362) requires data brokers registered with the California Privacy Protection Agency (CPPA) to honor consumer deletion requests submitted through the state's single Delete Request and Opt-out Platform (DROP) — and to keep deleting on an ongoing 45-day cycle, not just once.
No. Drop Privacy matches salted, normalized hashes — not raw personal information. Consumer PII never leaves your systems; only hashes, statuses, and audit metadata cross the boundary. With the on-premise agent, even the hashing happens on your infrastructure.
Registered data brokers must process accessible deletion requests on a recurring cycle of at most 45 days, and continue suppressing matched consumers going forward. Drop Privacy runs that cycle automatically and tells you how many days you have left to respond.
Every state-changing action is written to a hash-chained, tamper-evident audit log (each row signed against the previous). That backs a proof-of-deletion lookup and a printable attestation you can hand to an auditor.
Yes. The engine is designed for hundreds of millions to billions of records — incremental indexing, keyset pagination, cached counts, and background workers — so cycle time stays predictable as your data grows.
Three paths: connect your source tables, upload CSVs, or deploy the on-prem agent inside your network. Drop Privacy runs on a container host or a plain PHP host — your choice. Engine work runs from a background worker or cron, never a web request. No provider lock-in.
Most teams see a full cycle on sample data in a single demo session. Production onboarding depends on volume and data path — table mapping or CSV import is usually days, not months; the on-prem agent adds a short install step. We'll give you a realistic timeline on the first call.
DROP (Delete Request and Opt-out Platform) is the state-run system where consumers submit deletion requests. Drop Privacy is the compliance software on your side — it downloads the state's batch, matches it against your data, responds through the DROP API, and keeps the audit record. We are not affiliated with the California Privacy Protection Agency.
Enterprise pricing based on data volume, deployment model (hosted vs on-prem agent), and hash-index size. Request a demo and we'll scope it to your environment — no self-serve checkout, because every broker's data shape is different.
See Drop Privacy run a full cycle against sample data — matching, deciding, responding, and producing a proof-of-deletion attestation — in under 30 minutes.