What to keep as your DROP audit record
Registered California data brokers now run a deletion cycle against the state's Delete Request and Opt-out Platform (DROP) at least once every 45 days. The law says less about record keeping than you might expect, and that gap is where an audit will find you. Below, what the Delete Act and the DROP regulation actually require is kept separate from what we suggest. This is general information, not legal advice.
What the law and the regulation require you to keep
The written obligations are narrow. Each is quoted or closely paraphrased, with the section cited.
The cycle. Civil Code section 1798.99.86(c)(1) requires you, beginning August 1, 2026, to access the deletion mechanism at least once every 45 days and, within 45 days after receiving a request, to process all deletion requests and delete the related personal information. Section 1798.99.86(d)(1) adds the continuing duty to keep deleting that consumer's information at least once every 45 days. 11 CCR § 7612(a) restates the interval as once every 45 calendar days.
Status reports. § 7614(a) requires you to report, at each access session, the status of every request received in the previous session. § 7614(b) sets the content: the transaction identifier and one response code for each (record deleted, record opted out of sale, record exempted, record not found). The regulation does not say how long to keep what you uploaded.
Deletion lists for non-matches. § 7613(c) requires you to "save and maintain the consumer deletion list" for requests that did not match your records, solely to check newly collected records before selling or sharing them. § 7613(b)(1)(B) requires you to keep the minimum personal information needed to keep honoring a request. These are the only records the regulation affirmatively tells you to retain, and § 7616(a) limits their use to compliance with section 1798.99.86.
The independent audit. Section 1798.99.86(e)(1) requires an audit by an independent third party beginning January 1, 2028 and every three years after. Under (e)(2) and (e)(3) you must submit the report to the Agency within five business days of a written request and maintain the report and related materials for at least six years. § 7612(c)(1) lets you request a complete re-download of a list "for purposes of ensuring compliance with this Chapter, reconciling internal records, or completing the audit."
Annual metrics. Section 1798.99.85(a) requires you, by July 1 each year, to compile the number of requests received, complied with in whole or in part, and denied, plus the median and mean days to respond, and publish them in your privacy policy. That needs per-cycle counts.
Neither text contains a general clause requiring you to keep records of each DROP cycle for a set period.
What a regulator would plausibly ask for
This is practical guidance, not a requirement in the text. An auditor under section 1798.99.86(e), or Agency staff reviewing a complaint, needs to reconstruct whether each cycle happened on time and whether each request got the right response. We suggest they will want:
- Proof of when each download occurred, since both 45-day clocks run from it.
- The files you received, including the Removed CSV that DROP adds when identifiers are withdrawn.
- The exact
Id,Statusfiles you uploaded and DROP's acceptance response for each. - Evidence that the § 7613(a)(1) standardization and hashing rules were applied, since a matching error produces a wrong status code.
- The direction you gave service providers and contractors under § 7613(d).
Checklist: fields to capture per cycle
We suggest recording the following for every access session. Items marked "from DROP" are returned by the state's system and cost nothing to capture.
- Registration and DROP account identifier, and the lists selected (§ 7610(a)(3)).
- Download timestamp and the due date 45 days out.
- ZIP file name, from DROP (it carries the date and your broker number, for example
20260312_4821_DROP.zip), each CSV inside it, and row count per list. - The version of the state's technical specification your matching followed. It has been revised more than once; a reviewer will ask which rules governed a batch.
- Match counts by outcome: deleted, exempted, opted out, not found.
- Upload timestamp, endpoint used (
uploadoramend), and each uploaded file name. - DROP's upload response, from DROP:
acceptedCount,rejectedCount, each accepted file's name and size in bytes, and each rejection message. - DROP's confirmation emails after acceptance and after processing, any record-level error email, and what you resubmitted.
- Who performed or approved each step.
- Any § 7612(b)(1) notice to the Agency that an automated connection failed.
Using a third party
You may read that no one but the broker may touch DROP. The regulation does not say that. § 7610(a)(1)(A) requires you to restrict credentials to "persons authorized to act on the data broker's behalf," and (a)(1)(B) restricts access to the DROP and information derived from it to the same persons. § 7610(a)(1)(D) makes you responsible for all actions taken through your account, and (a)(1)(C) requires you to inform the Agency immediately of unauthorized use or a breach. If a third party runs your cycles, we suggest your record include the written authorization and the § 7616(b) security measures applied to the state's data. Responsibility stays with you.
Retention
The only stated period is six years for audit reports and materials, section 1798.99.86(e)(3). The first audit falls in 2028; the duties it examines began August 1, 2026. Non-match lists must be kept while the request stands (§ 7613(c)). We suggest treating per-cycle records as audit materials, kept at least six years from the audit that relies on them, and keeping non-match lists until the consumer amends or cancels.
What DropClerk does
DropClerk writes this record automatically for every cycle: who acted, when, which registration and cycle, the file names, row and match counts, the specification version applied, and the state's upload response, exportable as CSV. Your first cycle is free.
Sources
- California Civil Code §§ 1798.99.85 and 1798.99.86 (Delete Act, SB 362): https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=CIV&division=3.&title=1.81.48.&part=4.&chapter=&article=
- California Code of Regulations, title 11, §§ 7610, 7612, 7613, 7614, 7616: https://cppa.ca.gov/regulations/pdf/data_broker_drop_reg.pdf
- CalPrivacy, DROP technical specifications (Integration workflow; API operations): https://privacy.ca.gov/drop-for-data-brokers/ and https://privacy.ca.gov/drop-for-data-brokers/technical-specifications/api-operations/