Blog, Business Management, Industry News, Regulations

California’s DELETE Act Enforcement Began August 1: What i-SIGMA Members Need to Know

4 min read

California’s DELETE Act reached a major milestone on August 1, and member organizations that operate in California or handle data tied to California residents should take note. i-SIGMA is issuing this alert to help you understand the deadline, the ongoing obligations that follow, and the steps to review your compliance posture before enforcement ramps up.

What Changes Took Place on August 1

Starting August 1, nearly 600 registered data brokers in California must begin deleting consumer personal information. The law creates a single, statewide deletion system. Instead of contacting each company individually, California residents can submit one deletion request through the state portal at privacy.ca.gov. Registered data brokers are then required to honor those requests.

The scope of covered data is broad. It includes details such as where a person lives, their family members, relationship status, and employment history. For years, this information has been collected, packaged, and resold across the industry. The DELETE Act shifts that dynamic and gives consumers a direct way to reclaim control.

The 45-Day Rule You Can’t Overlook

The August 1 deadline is not a one-time event. After the initial round of deletions, data brokers must delete any newly collected data on a rolling 45-day cycle. This means compliance is an ongoing operational requirement, not a single project you complete and set aside.

Organizations will need repeatable processes, clear internal ownership, and reliable recordkeeping to meet this recurring obligation. If your current workflows treat deletion as a one-off task, now is the time to rethink that approach.

Who Enforces It, and What Happens If You Fall Short

Two authorities share enforcement responsibility: the California Privacy Protection Agency (CPPA) and the California Attorney General. The law grants the Attorney General power to pursue companies that fail to comply.

The penalty structure deserves your close attention. Fines under the DELETE Act are uncapped. Rather than a fixed amount you pay once, penalties can compound based on the number of data uses and the number of California residents affected. One expert compared it to a parking meter that keeps running. For organizations handling data at scale, exposure can grow quickly if deletion requirements are missed.

What This Means for Your Organization

If your organization qualifies as a data broker under California law, or if you support clients who do, this deadline is directly relevant to your operations. Even companies that do not register in California may still be subject to the law’s reach. That broad application is part of what sets California’s approach apart from other states.

For i-SIGMA members, the message is clear: secure information governance now extends beyond protecting data to proving you can delete it accurately and on schedule. This is squarely within the discipline our members practice every day, and it raises the bar for documentation, verification, and process discipline.

Your Next Steps

We encourage every member organization to take the following actions before enforcement pressure builds:

  • Confirm your status. Determine whether your organization or your clients meet the definition of a data broker under California law.
  • Review your registration. If you are a covered data broker, verify that your registration and data registry disclosures are accurate and current.
  • Build a repeatable deletion process. Establish workflows that can meet the initial deadline and the ongoing 45-day cycle.
  • Assign clear ownership. Designate who is responsible for receiving, processing, and documenting deletion requests.
  • Strengthen your records. Maintain evidence of compliance, since documentation will matter if enforcement questions arise.

i-SIGMA Is Here to Support You

The DELETE Act reflects a broader trend toward stronger consumer data rights, and California rarely stands alone for long. Getting your processes right now positions your organization well for similar requirements that may follow in other jurisdictions.

Review your compliance posture today. If you have questions about how the DELETE Act intersects with secure information governance best practices, reach out to i-SIGMA. We will continue to monitor developments and keep you informed as enforcement gets underway.

Stay ahead of the curve

Get the latest insights and resources delivered directly to your inbox.

    loading...