The California Delete Act Is Live: What It Means for First-Party Attribution in E-commerce

The California Delete Act Is Live

If your ecommerce brand leans on first-party attribution ecommerce data instead of purchased audiences, the California Delete Act’s enforcement start doesn’t touch your stack. If you’re still licensing third-party segments or leaning on broker-sourced lists, enforcement isn’t a future deadline anymore. It started August 1, 2026, and it’s already producing fines.

Here’s what the Delete Act’s DROP system actually requires, who it applies to, and why the brands least affected by it are the ones that already built their measurement on first-party data. 

Let’s dive into this…

What DROP Actually Requires, and Who It Applies To

The Delete Request and Opt-Out Platform, or DROP, is a state-run tool created under California’s Delete Act (SB 362) that lets a California resident submit one deletion request that applies to every registered data broker in the state at once, rather than contacting each broker individually. 

Consumers have been able to submit requests through DROP since January 1, 2026, and as of that date the CalPrivacy registry listed over 545 registered data brokers, names most marketers would recognize: Experian, Equifax, Acxiom, LiveRamp, ZoomInfo, Oracle, and Epsilon among them.

August 1, 2026 is when the obligation shifted from registration to action. 

Registered data brokers must now log into DROP at least every 45 days, match consumer deletion requests against their own records, and delete the matching personal information, including behavioral inferences, unless a specific legal exemption applies. 

There’s no grace period and no cure window. 

A broker that misses a deletion cycle faces a $200 per-consumer, per-day fine, and with more than 260,000 requests already queued at the start of enforcement, that penalty structure adds up fast for any broker that falls behind.

The part worth sitting with: the Delete Act’s definition of “data broker” is broader than most brands assume. 

  • It covers any business that knowingly sells or shares personal information about consumers it doesn’t have a direct relationship with, 
  • and CalPrivacy has already applied that definition to companies that didn’t think of themselves as brokers at all. 

A marketing firm called ROR Partners was fined $56,600 for building detailed audience segments, like lists of frequent health club attendees, from purchased data and selling access to those segments to its own clients. 

If your brand or agency licenses, appends, or resells audience data the way ROR Partners did, the Delete Act’s obligations may already apply to you directly, not just to the brokers you buy from.

Third-Party Broker Data vs. the Data You Already Own

Broker-sourced third-party data is information a company collects about people it has no direct relationship with, then aggregates, segments, and sells to advertisers for targeting. 

It comes from public records, purchased datasets, and behavioral tracking across sites and apps the consumer never chose to interact with your brand through. 

That’s the data category the Delete Act targets, and it’s also the category that’s been eroding in quality and reach for years as match rates decline and cookies keep getting harder to rely on.

First-party data is different in kind, not just in source. 

It’s information a customer generates through a direct interaction with your own store: a click on your own ad, a purchase on your own site, a signup through your own form. 

The distinction between first, second, and third-party data isn’t a technicality, it’s the difference between data your brand collected because a customer chose to engage with you, and data a broker assembled about someone whether they engaged with you or not.

First-party data 101 for ecommerce covers the full breakdown if your team is still mapping out what counts as which category.

Why This Doesn’t Touch Your CRM or Click-Based Attribution

Click-based, first-party attribution never depended on the broker ecosystem the Delete Act regulates. It ties a click to a conversion on your own domain, using data your own store generated. 

There’s no purchased segment, no appended demographic file, and no third-party identity graph sitting between the click and the sale. 

That’s precisely why first-party attribution isn’t a future problem for ecommerce brands, it’s already the more durable foundation, and DROP enforcement just made the alternative more legally exposed on top of already being less accurate.

There’s one caveat worth naming plainly.

Uploading your own customer list to an ad platform to build a lookalike audience is not the same as pure first-party attribution, even though the underlying list came from your own CRM.

Regulators increasingly treat that upload as “sharing” personal information for cross-context behavioral advertising, which triggers its own opt-out obligations under CCPA regardless of whether the Delete Act itself applies to you. 

Keeping your measurement first-party doesn’t automatically mean every use of your customer data is exempt from every privacy obligation.

The Audit: Where Broker Data Might Still Be Sitting in Your Stack

Most brands don’t have a line item called “broker data.” It shows up embedded in tools and workflows that were set up years ago and never revisited. Worth checking this week:

  • Any lookalike or interest-based audience built from a purchased or appended list rather than your own customer data
  • Demographic or firmographic enrichment services layered onto your CRM records
  • Retargeting pixels or platforms that receive hashed customer lists for cross-context targeting
  • Vendor contracts with data enrichment, intent-data, or audience-segment providers, and whether those vendors are registered data brokers
  • Any internal practice of selling or sharing your own customer segments with brand partners or affiliates

If a vendor in your stack turns out to be a registered data broker, or if your own brand’s data-sharing practices fit the Delete Act’s definition, the DROP obligations flow through that relationship regardless of whether your team ever thought about it in those terms. 

This is the same audit discipline that matters for staying compliant with CCPA and GDPR more broadly, not just for this one law.

The Broader 2026 Pattern

The Delete Act isn’t an isolated event. 

Consumer deletion requests through DROP were projected to reach 500,000 to 1 million by August, and California’s own CCPA regulations expanded again in January 2026 with new rules around automated decision-making and mandatory risk assessments. 

Three more states, Indiana, Kentucky, and Rhode Island, added comprehensive privacy laws of their own the same month, bringing the total to nineteen states with active legislation.

None of these laws move in the direction of loosening restrictions on inferred or purchased data. Every one of them tightens it.

That’s the pattern worth planning around, not any single law. A measurement strategy built on first-party, click-based data was never waiting on this specific deadline to be the right call. 

It just got harder to justify the alternative.

Run the audit above, flag anything in your stack that depends on broker data or lookalike uploads, and build your reporting on data your own store generated in the first place. If you want to see what independent, click-only attribution looks like without a single broker-sourced segment anywhere in the pipeline, book a live AdBeacon demo.

—-

FAQ

What is the California Delete Act’s DROP system?

DROP is the Delete Request and Opt-Out Platform, a state-run tool created under California’s Delete Act that lets a California resident submit one deletion request covering every registered data broker in the state, instead of contacting each broker separately.

When did DROP enforcement actually start?

Consumers could submit requests through DROP starting January 1, 2026. Data brokers became required to process those requests starting August 1, 2026, with no grace period.

Does the Delete Act apply to my ecommerce brand if I don’t sell data?

It depends on what your marketing stack does with customer data. The Delete Act’s data broker definition covers any business that sells or shares personal information about people it has no direct relationship with, which can include audience-segment sales, list enrichment, or reselling customer data to partners, even for a business that doesn’t consider itself a broker.

Does the Delete Act affect my own CRM or first-party click attribution?

No. Click-based attribution built on your own store’s data, tied to a click your own ad generated and a conversion on your own domain, was never part of the broker ecosystem the Delete Act regulates.

Is uploading my customer list to build a lookalike audience covered by the Delete Act?

The Delete Act itself targets registered data brokers, but uploading a customer list for lookalike targeting is commonly treated as “sharing” personal information under CCPA more broadly, which carries its own opt-out obligations separate from Delete Act broker status.

Sources

This website uses cookies

We use cookies to personalize content, provide social media features, and analyze our traffic. We also share information about your use of our site with our analytics partners. You can change your preferences at any time. For more information, please see our Privacy Policy and Cookie Policy. Privacy Policy