DropWatch
California Delete Act · DROP enforcement is live

Miss one 45-day DROP pull and the fine is $200 per request, per day.

Since August 1, 2026, every registered data broker must pull the DROP deletion list at least every 45 days and resolve each request within 90 days. No revenue threshold — a solo email-append shop is as much a broker as a giant. Enterprise suites start at $10k/yr and ignore this segment. DropWatch is the command center built for the 600+ small brokers they price out.

Tamper-evident, append-only action ledger One-click audit evidence pack for the 2028 audits No plaintext PII stored — suppression list is SHA-256 hashes only

Operational compliance software, not legal advice. No credit card to try the quiz.

654+brokers on the CA registry
500k+Californians registered in DROP
$45,000,000exposure: 5,000-request backlog, 45 days
2028independent audits begin — evidence packs ready now
How it works

Four workflows. Zero spreadsheets.

1

Know if you're a broker

The 8-question self-assessment scores your broker risk the way a regulator would — including the "accidental broker" traps in lead-gen, list brokerage, and B2B contact data.

2

Track every registration

CA, TX, OR, VT — plus CT and NJ on the 2027 law radar. Fees, renewal countdowns, per-state penalty exposure, readiness checklists.

3

Run the 45-day cadence

Record each DROP pull, import the deletion-list CSV with duplicate detection, and work every request to deleted / suppressed / exception inside its 90-day window.

4

Prove it in an audit

Every action lands in an append-only ledger. One click downloads the evidence ZIP — ledger, pull cycles, determinations, hashed suppression list — for the 2028 audits.

Why DropWatch

The enterprise suites don't model your job.

OneTrust, Transcend, and DataGrail are built for enterprise privacy teams: data mapping, 100+ integrations, DSAR orchestration. None of them has a purpose-built 45-day DROP pull workflow, a multi-state broker registration tracker, or per-request penalty math — because their buyers aren't small brokers.

DropWatchEnterprise suites
Built forSmall registered brokersEnterprise privacy teams
Price$149–$299/moCustom · ~$3k–$10k+/yr to start
DROP 45-day pull cadencepurpose-builtnot modeled
§7614 report-back exportper-cycle CSV + filed trackingno
Unverifiable-request opt-out pathdisposition + vendor-notice logno
Broker registration tracker6 states + law radarnot their unit of analysis
Per-request penalty exposure$200/req/day, liveno
One-click audit evidence packZIP for 2028 auditsgeneric exports
Suppression list (hashed)SHA-256, with lookupno

Honest note: the enterprise platforms lead on automated data mapping and integrations. If you have a privacy engineering team, they're the right buy. DropWatch wins the broker-specific operational cadence they structurally won't build for a $149/mo segment.

Pricing

One broken DROP cycle costs more than a decade of DropWatch.

Pro

$299/mo

For growing brokerages: everything in Starter plus team seats, priority support, and onboarding help.

  • Everything in Starter
  • Up to 5 team seats
  • Deletion-request CSV import with duplicate detection
  • Priority email support
  • Assisted onboarding call
Choose Pro

Annual billing on request. Cancel anytime — your ledger and evidence pack export before you leave.

FAQ

Asked by every broker.

Are we even a data broker?

Probably, if you sell or share personal information of people with no direct relationship to your business — lead-gen, list brokerage, email append/enrichment, B2B contact databases, ad-tech. California has no revenue threshold. Take the quiz.

What happens if we ignore DROP?

$200 per unprocessed deletion request per day, uncapped, with no cure period — plus $200/day for failing to register at all. CalPrivacy's enforcement strike force has already fined unregistered brokers $35k–$55k in settlements. A 5,000-request backlog at 45 days is $45M of exposure.

Does DropWatch store our customers' personal data?

No. The suppression list stores only SHA-256 hashes — minimum-necessary identifiers. Deletion requests reference hashed identifiers, never plaintext.

What about Connecticut and New Jersey?

CT's $2,500/yr registration duty starts Jan 1, 2027 (PA 26-64), with a state deletion mechanism due 2028. NJ's tiered-fee registry ($5k–$1.5M/yr) is expected spring 2027. Both are tracked on the law radar with readiness checklists.

Is this legal advice?

No. DropWatch is an operational compliance tool. Verify your obligations with privacy counsel.

Can we cancel?

Yes, anytime, with one click from Billing. Your audit ledger and evidence pack export before you leave — your compliance proof is never hostage to a subscription.

The next 45-day window is already running.

Set up in two minutes. Your first pull reminder is on us.

Get compliant — $149/mo