HomeIntelligenceBrief
BREACH BRIEF🟡 Medium Advisory

California’s DROP Platform Enables One‑Click Deletion Requests to All Registered Data Brokers

California launched DROP, a centralized portal that routes a single deletion request to every registered data broker, giving residents a 90‑day deadline for erasure. The initiative forces data‑driven businesses to formalize DSAR processes, a key SOC 2 privacy control.

LiveThreat™ Intelligence · 📅 August 04, 2026· 📰 malwarebytes.com
🟡
Severity
Medium
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
malwarebytes.com

California’s DROP Platform Gives Residents a One‑Stop Way to Delete Their Data from Brokers

What Happened — California’s new Delete Request and Opt‑out Platform (DROP) lets any state resident submit a single deletion request that is automatically routed to every data broker registered with the California Privacy Protection Agency. Brokers have 90 days to erase the consumer’s records once the request is received.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates how a regulator can enforce data‑subject‑right obligations that map directly to SOC 2 CC6.1 (Privacy) and GDPR/CCPA‑style controls.
  • Provides a concrete, auditable workflow (request ID, status tracking, 90‑day deadline) that can be captured as evidence of “right‑to‑erasure” compliance.
  • Highlights the need for organizations that buy or sell third‑party data to maintain up‑to‑date DSAR processes and consent‑management tooling—exactly the scenario CookiePLUS is built to support.

Who Is Affected – Data‑broker operators, any SaaS or advertising platforms that ingest brokered data, and privacy‑officers at enterprises that rely on third‑party data for marketing or analytics.

Recommended Actions

  • Map the DROP request flow to your SOC 2 privacy controls (CC6.1) and record the process as audit evidence.
  • Verify that all third‑party data sources you ingest have a documented DSAR response procedure; if not, mandate a vendor‑risk assessment.
  • Deploy a consent‑management/DSAR automation tool (e.g., CookiePLUS) to capture request IDs, track deadlines, and generate compliance reports.

Source: Malwarebytes Labs – Californians can tell data brokers to DROP their information

Technical Notes – DROP is a state‑run web portal; it requires users to verify residency via email/phone or Login.gov. The platform does not expose a vulnerability but creates a statutory “right‑to‑erasure” mechanism that data brokers must honor under the California Delete Act. No CVEs or exploit details are involved.

📰 Original Source
https://www.malwarebytes.com/blog/news/2026/08/californians-can-tell-data-brokers-to-drop-their-information

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

Data exposure is where consent and DSAR readiness get tested.

When personal data leaks, regulators ask what consent you held and how fast you can answer a subject request. The Verisq AI Trust Operations platform, with CookiePLUS, keeps that posture audit-ready under GDPR and CCPA.

Explore the Verisq AI Trust Operations platform →