Guide

The California Delete Act and B2B data

nodilist2026-10-0310 min read

California's Delete Act (SB 362) makes every data broker register each year with the California Privacy Protection Agency and, since 1 August 2026, check the state's deletion platform (DROP) at least once every 45 days and delete the data of people who asked. It covers business contact data too: a doctor, dentist or office manager in California is a "consumer" under the state's privacy law, and the law's temporary exemption for business-to-business data stopped applying on 1 January 2023.

What is a data broker under California law?

A data broker is "a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship" (Cal. Civ. Code 1798.99.80(c)). Three terms in that sentence take their meaning from the California Consumer Privacy Act (CCPA).

  • Business. A for-profit company that does business in California and meets one of three tests: more than $25 million in annual gross revenue (adjusted for inflation), buying, selling or sharing the personal information of 100,000 or more consumers or households a year, or getting 50% or more of its annual revenue from selling or sharing consumers' personal information (Cal. Civ. Code 1798.140(d)). The third test has no size floor, so a small company whose main product is contact data can qualify.
  • Consumer. "A natural person who is a California resident" (1798.140(i)). The definition doesn't distinguish home life from work.
  • Personal information. Information that identifies or could reasonably be linked with a particular consumer, including a real name, postal address and email address, and "professional or employment-related information" (1798.140(v)(1)).

The statute excludes entities to the extent they are covered by the Fair Credit Reporting Act, the Gramm-Leach-Bliley Act or California's Insurance Information and Privacy Protection Act, and certain health-data processing that the CCPA already exempts (1798.99.80(c)). There is no exclusion for business-to-business data.

Why B2B contact data is covered

B2B contact data is covered because the people in it are consumers under the CCPA. From 2020 to 2022, the CCPA held back most of its obligations for personal information "reflecting a written or verbal communication or a transaction" between a business and a person acting for another company, such as an employee, owner or contractor (Cal. Civ. Code 1798.145(n)). That subdivision, and the matching one for employee data, became inoperative on 1 January 2023 by their own terms. The California Attorney General's CCPA page says both exemptions "expired on December 31, 2022" (California AG, FAQ 11).

Here is how that applies to common kinds of rows:

  • Sole proprietors and solo practitioners. A one-dentist practice's name, address, phone and email can be the dentist's own, so a row about the office is also data about a person.
  • Named contacts at larger businesses. A practice manager's name or a named inbox such as jane@practice.com is personal information about that person, even though it's used only for work.
  • Shared inboxes at organizations. An address such as office@ at a multi-dentist group is harder to link to one person. Whether it is personal information depends on the facts.

The CCPA also says personal information doesn't include "publicly available information", which it defines to include information lawfully made available from government records and information a business has a reasonable basis to believe the consumer lawfully made available to the general public (1798.140(v)(2)). How far that exclusion reaches for a list compiled from registers and websites is a question for counsel, not something this guide settles.

What the Delete Act requires of data brokers

Under the registration law as amended by the Delete Act (SB 362, 2023) and SB 361 (in force from 1 January 2026), a data broker has five duties.

DutyWhat the law saysSource
Register every yearRegister with the California Privacy Protection Agency on or before 31 January following each year the business met the definition. Pay the agency's fee and disclose its contact details, request metrics, and whether it collects data such as names, emails, phone numbers, precise geolocation or data on minors1798.99.82
Process DROP deletionsFrom 1 August 2026, access the deletion mechanism at least once every 45 days, and within 45 days delete the personal information of the consumers who asked1798.99.86(c)
Keep them deletedAfter deleting a consumer's data, keep deleting it at least every 45 days and don't sell or share new personal information about that consumer, unless the consumer requests otherwise or an exemption applies1798.99.86(d)
Publish request numbersBy 1 July each year, publish in the privacy policy how many deletion, access and opt-out requests were received, complied with and denied, with the median and mean days to respond1798.99.85
Pass an auditFrom 1 January 2028, and every three years after that, undergo an independent audit of DROP compliance, and keep the report for at least six years1798.99.86(e)

Two details matter for B2B sellers. When a DROP request can't be verified, the broker must still treat it as an opt-out of sale or sharing within 45 days. And the broker must tell its service providers and contractors to delete the same data (1798.99.86(c)(1)).

Key dates and fees

The dates below come from the statute and the agency's data broker page, both read on 3 October 2026.

DateWhat happensSource
1 January 2024SB 362 takes effect1798.99.80
1 January 2026DROP regulations and SB 361's wider registration disclosures take effect. Consumers can file DROP requests from January 2026CPPA, DROP regulations; CalPrivacy, DROP for data brokers; 1798.99.82
1 to 31 January 2026Registration window for brokers active in 2025. The 2026 fee is $6,000 plus a processing fee for electronic paymentCPPA, Information for Data Brokers
1 August 2026Brokers must start processing DROP deletion lists, at least once every 45 days. A business that starts brokering after this date must create a DROP account before it starts1798.99.86(c); CPPA
1 July each yearRequest metrics due in the privacy policy1798.99.85
1 January 2028First independent audits; then every three years1798.99.86(e)
1 January 2029Registrations must say whether the broker has had an audit1798.99.82(b)(2)(U)

Fines are set in the statute: $200 for each day a broker fails to register, plus the unpaid fees and the agency's costs, and $200 for each deletion request for each day a broker fails to delete as required (1798.99.82(c) and (d)). The agency publishes the current registry of data brokers on its data broker page.

How much of a provider register is about individuals

Most of the US register that healthcare lists start from describes individual people, not companies. In the CMS NPPES file of 2026-09-14, active dental and physician registrations split like this:

Register (CMS NPPES)Individual registrationsOrganization registrationsCalifornia, registered practice addresses
Dentists~273,000~137,000~33,000 (15% of the US)
Physicians~1,253,000~367,000~53,000 (11% of the US)

Counts are rounded.

An individual registration (a Type 1 NPI) belongs to a person: a dentist or doctor registers under their own name, often at the practice address. Organization registrations belong to practices, groups and clinics. The California column counts distinct practice addresses in the register, including stale and duplicate ones, so it is an upper bound on offices. The exact counts are in dentists-register-2026-10.csv and physicians-register-2026-10.csv.

What these numbers don't show. A registration count isn't a count of people on any list, and an organization registration can still lead to one person when the practice is solo. They show that a list built from this register starts from records about individuals. Whether a given list's rows are personal information depends on what each row holds, so ask the vendor which columns can identify a person.

What to ask a list vendor

If you buy B2B contact data that includes Californians, ask the vendor these questions before you pay.

  1. Does the file include data about individuals? Ask which columns can identify a person: names, named inboxes, mobile numbers, or an identifier like an NPI that belongs to a person.
  2. Where does each record come from? A source per record, such as a register file date or the URL where an email was published, lets you check it and answer a complaint.
  3. How do you handle DROP and other deletion requests? Since 1 August 2026, a registered broker must process DROP lists at least every 45 days. Ask how often they do it and whether deleted people are suppressed in every later file.
  4. Is the suppression list applied to my order? Data built weeks ago can include someone who has since asked to be deleted. Ask whether deletions are applied when your file is built.
  5. Will you tell me about deletions after delivery? Ask whether the vendor passes on deletion requests for records you already received, and what you must do with them.
  6. Can I check the registration myself? Look the company up in the agency's data broker registry rather than relying on a claim.

The registration and DROP duties fall on brokers, the businesses that sell. Buying a list to contact prospects doesn't, by itself, match the definition's "sells to third parties". Reselling it is different. Under the CCPA, a third party may not sell or share personal information that was sold to it "unless the consumer has received explicit notice and is provided an opportunity to exercise the right to opt-out" (Cal. Civ. Code 1798.115(d)). If your company is itself a CCPA business, the personal information you buy is covered by your own CCPA obligations.

How nodilist handles removal requests

Anyone can ask us to remove a practice, a name or an email, from any state, free and without ID, through data removal. Each row of our lists will be one office. The dentist list will carry the emails offices publish on their own websites, which are shared inboxes such as office@ and, where a practice publishes one, a named inbox at the practice's own domain. It will have no column for a person's name, and each email will carry the URL of the page where it was published. For a solo practice, the office name or NPI can be the practitioner's own.

A removal goes on a suppression list. Every file we build will be checked against that list, so a removed record stays out even if it reappears in NPPES or on a website. If a buyer already received the record, we tell them to delete it. The details are on the data removal page and in our privacy policy.

What this guide can't tell you

  • Whether a particular company is a data broker. That depends on its revenue, what it sells and to whom, and how the "publicly available" exclusion applies to its data.
  • What other states require. Several states have their own data broker or privacy laws with different definitions, and this guide covers California only.
  • Future fees and dates. The agency sets registration and access fees each year, and the legislature amended the law in 2025. Check the agency's data broker page for current figures.

This is general information, not legal advice.

Questions

Is the California Delete Act the same as the CCPA?

No. The Delete Act (SB 362) amended California's data broker registration law, which sits beside the CCPA in the Civil Code. It borrows the CCPA's definitions of business, consumer and personal information, and says it doesn't change how the CCPA works (Cal. Civ. Code 1798.99.80 and 1798.99.88).

What is DROP?

DROP, the Delete Request and Opt-out Platform, is the California Privacy Protection Agency's website where a California resident can send one deletion request to every registered data broker. The statute requires that consumers can use it free of charge (Cal. Civ. Code 1798.99.86(b)).

Does the Delete Act apply to companies outside California?

It can. The definition uses the CCPA's "business": a company that does business in California and meets one of the size or revenue tests. It doesn't require an office in California. The duties concern personal information about California residents (Cal. Civ. Code 1798.140(d) and 1798.99.80(c)).

Is a business email address personal information?

It can be. The CCPA lists email addresses and professional information as personal information when they can be linked to a particular person, and the B2B exemption no longer applies. A named inbox usually can be linked to its owner. A shared inbox at a large organization usually can't.

When did the CCPA's B2B exemption end?

The exemption in Civil Code 1798.145(n) became inoperative on 1 January 2023. The California Attorney General describes it as having expired on 31 December 2022.

Sources

  1. California Civil Code 1798.99.80, data broker definition (amended by SB 362, Stats. 2023, Ch. 709, effective 1 Jan 2024), https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.99.80. (accessed 2026-10-03)
  2. California Civil Code 1798.99.82, registration, disclosures and fines (amended by SB 361, Stats. 2025, Ch. 466, effective 1 Jan 2026), https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.99.82. (accessed 2026-10-03)
  3. California Civil Code 1798.99.85, request metrics in the privacy policy, https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.99.85. (accessed 2026-10-03)
  4. California Civil Code 1798.99.86, accessible deletion mechanism, 45-day processing and audits (amended by SB 361, effective 1 Jan 2026), https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.99.86. (accessed 2026-10-03)
  5. California Civil Code 1798.140, CCPA definitions of business, consumer and personal information (amended by AB 1170, effective 1 Jan 2026), https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.140. (accessed 2026-10-03)
  6. California Civil Code 1798.145, CCPA exemptions, subdivisions (m) and (n) inoperative 1 Jan 2023, https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.145. (accessed 2026-10-03)
  7. California Civil Code 1798.115, resale of personal information by a third party, https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.115. (accessed 2026-10-03)
  8. California Privacy Protection Agency, Information for Data Brokers, https://cppa.ca.gov/data_brokers/ (accessed 2026-10-03)
  9. California Privacy Protection Agency (CalPrivacy), DROP for data brokers, https://privacy.ca.gov/data-brokers/ (accessed 2026-10-03)
  10. California Privacy Protection Agency, Accessible Deletion Mechanism (DROP) System Requirements, regulations effective 1 Jan 2026, https://cppa.ca.gov/regulations/drop.html (accessed 2026-10-03)
  11. California Attorney General, California Consumer Privacy Act (CCPA), FAQ 11, https://oag.ca.gov/privacy/ccpa (accessed 2026-10-03)
  12. CMS NPPES Data Dissemination V.2, file dated 14 Sep 2026, https://download.cms.gov/nppes/NPI_Files.html (register counts in /data/dentists-register-2026-10.csv and /data/physicians-register-2026-10.csv)