Skip to content
← BlogCompliance8 min read

A new California deadline just made 'where did this list come from' a real question

California's Delete Act requires data brokers to honor bulk deletion requests from August 1, 2026 — a good moment to check where your list came from.

By Norbelys Chirinos, Co-founder

Founder-reviewed ·How we research and correct articles

California’s Delete Act set up a single portal — the Delete Request and Opt-Out Platform, or DROP — where any California resident can submit one request and have it forwarded to every data broker registered with the state at once. DROP itself went live January 1, 2026. The date that actually bites is August 1, 2026: registered data brokers must begin retrieving and processing deletion requests through the platform on a recurring basis from that point on, with real financial exposure — reported at $200 per request per day for non-compliance — for brokers that don’t.

If you’ve never bought, rented, or appended a B2B contact list, this is background noise. If you have — and a large share of cold-email programs have, at some point, even just to fill out a segment — this is the week to actually trace where that data came from, because the company selling it to you may now be legally required to delete records it’s been holding, including some it may have already sold you.

Why a data-broker law touches a cold-email list

The Delete Act regulates data brokers — businesses whose core function is buying, selling, or licensing personal information about people they have no direct relationship with. A meaningful slice of the vendors that sell “500,000 verified B2B contacts” style lists fit that description exactly. The law doesn’t reach back and delete data that’s already sitting in your CRM the moment a broker processes a deletion request on their end — but it does mean the pipeline that fed your list is now under active regulatory pressure to prune itself, and the provenance question you should already have been asking gets a lot more concrete this year.

How DROP actually works, in practice

The mechanism itself is straightforward, which is part of why it’s likely to be effective: instead of a California resident having to track down and individually contact every data broker who might hold their information — historically the single biggest reason deletion rights went unused, since most people have no idea which of the hundreds of registered brokers actually has their record — DROP lets them submit one request that fans out to every broker registered with the state. Registered brokers are required to check the platform periodically and act on any request that names them. The reported $200-per-request-per-day exposure for non-compliance is meaningful specifically because it scales with volume: a broker sitting on stale deletion requests across a large user base accumulates exposure fast, which is exactly the incentive structure meant to stop “we’ll get to it eventually” from being a viable strategy.

That incentive structure is also why this is a genuinely different kind of pressure than a one-time fine. A company that gets fined once for a specific violation has an obvious end point. A company facing a recurring, compounding penalty for requests it hasn’t processed has an ongoing reason to actually build the deletion pipeline properly rather than treat compliance as a project that’s “mostly done.”

What actually changes for a cold-email program

A practical way to use this deadline

  1. Ask your data vendor, in writing, whether they're a registered California data broker

    If they are, ask how they handle DROP deletion requests and how quickly a deletion propagates to data they've already licensed to customers like you. A vendor that can't answer this clearly is a vendor whose entire product is now under more regulatory pressure than you may have assumed.

  2. Separate 'purchased/appended' contacts from 'first-party' contacts in your own list

    First-party data — someone who filled out a form, replied to you before, or is a genuine warm lead from your own research — carries none of this risk. Purchased and appended records are exactly the category a deletion request could reach back and invalidate. Knowing which bucket a given contact sits in matters more after this deadline than before it.

  3. Build re-verification into any purchased or appended segment before you send to it

    A list bought six months ago is already stale by normal decay rates; a list bought from a vendor now under active deletion-request pressure has an extra reason to be re-checked before your next send, not assumed valid because it worked last quarter.

  4. Treat an unsubscribe or a deletion request from any source as final, immediately

    Whether the request comes through your own unsubscribe link or indirectly because a vendor purged a record under DROP, the safe default is the same: remove and suppress, don't quietly keep sending because the removal came from an unfamiliar channel.

The broader pattern this fits into

This is the same direction nearly every privacy regime has been moving for the last several years — GDPR’s right to erasure, CCPA/CPRA’s own deletion rights, and now a dedicated mechanism specifically for the brokers sitting between a person and the companies that end up emailing them. Data minimization — holding only what you actually need, for only as long as you need it — used to be a best practice. It’s increasingly the only strategy that doesn’t leave you exposed every time a regulator adds a new enforcement mechanism to a pipeline you don’t control.

First-party contactsPurchased / appended contacts
Consent basisDirect interaction with your companyDepends entirely on the vendor's own compliance
Exposure to a broker-level deletion request
Recommended handling after Aug 1, 2026Standard hygiene and suppression practicesRe-verify before sending; confirm vendor's DROP compliance

Where the responsibility actually sits

There’s a temptation to read all of this as “the broker’s problem, not mine” — you bought data in good faith, the broker’s compliance obligations are the broker’s business, and if a record you were sold turns out to have been deleted somewhere upstream, that’s an administrative footnote rather than something you need to act on. That reading holds up right up until a complaint, an audit, or a regulator asks a much simpler question: on what basis do you still have this person’s information, and can you show it. “A vendor sold it to us and we’ve never checked whether they’re still allowed to hold it” is a weak answer under most current privacy frameworks, and it’s about to get weaker as broker-level deletion becomes a routine, ongoing process rather than a rare event.

This doesn’t mean every purchased or appended list is suddenly unusable. It means the standard for what “usable” means has moved from “we paid for it” to “we can account for where it came from and we’re prepared to remove it the moment that basis disappears.” That’s a solvable operational problem, not a reason to abandon list-building entirely — but it does mean the spreadsheet-and-goodwill approach to tracking list provenance is running out of runway.

Frequently asked questions

Does the August 1, 2026 deadline apply to companies outside California?

The obligation falls on data brokers registered under California's law, regardless of where they're headquartered, if they meet the state's definition of a data broker doing business that reaches California residents. A company simply buying a list from such a broker isn't itself subject to the DROP deletion-processing deadline, but is affected indirectly if the broker's records include people who submit deletion requests.

How would I even know if a contact in my list was deleted at the source?

In most cases you wouldn't find out proactively — the broker isn't obligated to notify every downstream buyer of every deletion. This is exactly why re-verification of purchased or appended segments before a send matters more now: it catches addresses that have gone bad or been withdrawn, regardless of why.

Is this the same as CCPA's existing right to delete?

It's related but distinct. CCPA/CPRA already gives California residents a right to request deletion from any business, including data brokers, on an individual basis. The Delete Act and DROP specifically build the bulk, one-request-reaches-every-broker mechanism that makes exercising that right practical at scale instead of requiring hundreds of separate individual requests.

Where Norbelys fits

However a contact ends up in your list, Norbelys enforces the same discipline on every one of them: verification before a send goes out, and permanent suppression the moment someone unsubscribes, bounces, or is removed for any reason — including a deletion request that reaches you indirectly through a vendor. That’s not a setting you have to remember to turn on for “the purchased segment” versus “the warm leads”; it’s the same default behavior across your entire audience, because provenance shouldn’t determine whether someone’s opt-out actually sticks.

If this deadline is prompting a harder look at where your list came from, that’s exactly the moment to move to a platform where suppression, verification, and consent state are enforced automatically rather than tracked in a spreadsheet next to the vendor invoice. See Norbelys’s plans and start building your next list on infrastructure that treats every contact’s history as permanent, not optional.