Today is the day California’s Delete Act stops being a compliance deadline on a calendar and starts being an enforcement reality. As of August 1, 2026, every one of the more than 600 data brokers registered with the California Privacy Protection Agency must log into the state’s Delete Request and Opt-Out Platform, known as DROP, at least once every 45 days, retrieve any pending consumer deletion requests, and erase the personal information tied to them. The platform went live on January 1 with roughly 260,000 requests already queued up and waiting. Brokers that miss a cycle face fines of $200 per deletion request per day, a penalty structure that scales into real money fast when a single broker is sitting on tens of thousands of unprocessed requests at once.
What DROP Actually Forces Brokers to Delete
DROP lets a California resident file one request that fans out to every registered broker simultaneously, replacing what used to be a process of contacting each company individually. The deletion obligation is broader than most people assume. It does not just cover the raw contact record. It reaches the inferences built on top of it, the algorithmically generated tags that quietly label someone as financially vulnerable, likely pregnant, politically aligned, or dealing with a particular health condition. Those inferences are often the actual product a data broker sells, and as of today they are squarely in scope for deletion alongside the underlying name, email address, and phone number.
Why This Is an Email Marketing Story, Not Just a Privacy One
Data brokers are the plumbing behind a large share of the acquired, appended, and cold-outreach email lists that marketing teams still buy or license. When a broker processes a wave of deletion requests, the addresses on those lists do not just become privacy-compliant. They stop existing, silently, on the broker’s side, while a marketing platform somewhere still has them loaded into a campaign segment. Nobody sends a notification to the marketer whose list just lost a chunk of its entries to a deletion cycle it never saw happen.
The practical result over the next several weeks is a slow but real degradation of list quality for any program still relying on broker-sourced contacts. Addresses that were already marginal, purchased rather than opted in, scraped rather than confirmed, are exactly the addresses most likely to sit on lists brokers are now required to scrub. Continuing to mail them does not just waste send volume. It actively damages sender reputation.
The Deliverability Bill Comes Due Fast
Gmail, Yahoo, and Microsoft all enforce hard thresholds on spam complaint rates for bulk senders, with 0.3% treated as the line past which authentication passing no longer saves a sending domain from filtering or outright rejection. Mail sent to a list built substantially on broker data tends to run high on exactly the metrics mailbox providers watch most closely: low engagement, elevated complaint rates, and a growing share of addresses that bounce or have gone cold. A list quietly thinned by a regulatory deletion cycle does not become safer to mail. It becomes a smaller pool of the same low-engagement addresses, with the same reputation risk concentrated into fewer sends.
Authentication Was Never the Fix for a Permission Problem
It is worth being precise about what SPF, DKIM, and DMARC actually protect against, because this is not one of those situations. Authentication proves that a message genuinely came from the domain it claims to represent. It says nothing about whether the recipient ever agreed to receive it. A perfectly aligned DMARC record with a policy of reject will not stop a mailbox provider from penalizing a domain that keeps sending to addresses harvested through a data broker, because the signal that gets a sender throttled or blocked is engagement and complaint behavior, not authentication failure. Authentication and permission solve different problems, and the Delete Act’s enforcement wave is squarely a permission problem wearing a privacy-law disguise.
What This Means for Your Program
Audit where every segment in your sending platform actually came from. Lists built from appended, purchased, or broker-licensed data are the ones most exposed to silent attrition as DROP processing continues, and they deserve a harder look regardless of the regulation.
Treat a sudden rise in hard bounces or unknown-user responses as a signal, not noise. A cluster of bounces appearing across a specific list segment in the weeks after August 1 is a reasonable first place to check for broker-sourced records that have just been deleted at the source.
Prioritize first-party, confirmed-opt-in acquisition over broker-sourced lists going forward. Addresses collected directly, with a clear record of consent, are not subject to this kind of invisible churn and consistently perform better against the engagement thresholds mailbox providers already enforce.
Keep your own authentication at full strength regardless. It will not fix a permission problem, but it remains the baseline that protects a legitimately built list from being undermined by anyone spoofing the domain around it.
The Takeaway
The Delete Act was written as a privacy law, and today’s enforcement deadline is being covered as a privacy story. For anyone running an email program, it is also a data quality event with a clock attached. Lists that depend on data broker sourcing are about to get quietly smaller and, in the segments that remain, no more engaged than they were before. The response is not a technical patch. It is the same discipline that good deliverability has always demanded: build lists on real consent, and let authentication do the job it was actually designed for.
Excello Mail gives you continuous visibility into your DMARC authentication health and every source sending under your domain, so the reputation you build on a genuinely opted-in list stays protected. Sign up for free to Excello Mail and keep your sending identity as clean as the list behind it.