Skip to content
RiskTemplates · The Daily Brief Friday, July 31, 2026
Wire The Exodus OFAC Settlement: What a $3.1M Crypto Wallet Enforcement Action Teaches About Sanctions Compliance Programs JUL 30

Feature Data Privacy

California's DELETE Act: The August 1, 2026 DROP Deadline and the GLBA Exemption Test Every Fintech Needs to Pass

California's DELETE Act requires data brokers to process consumer deletion requests through the DROP system starting August 1, 2026. The penalty is $200 per request per day. Most GLBA-covered financial institutions are exempt — but many fintechs aren't sure which category they're in. Here's how to run the analysis.

By Rebecca Leung · July 28, 2026 ·
Table of Contents

TL;DR

  • California’s DELETE Act requires registered data brokers to process consumer deletion requests through the DROP system starting August 1, 2026 — the penalty is $200 per deletion request per day with no mandatory cure period
  • “Financial institutions subject to the GLBA” are exempt from the data broker definition — but that exemption requires confirming your fintech actually qualifies as a GLBA-covered financial institution
  • Many fintechs operate in financial services without meeting the GLBA financial institution definition: data aggregators, lead generators, and analytics companies in fintech are often NOT GLBA-covered
  • The analysis every fintech needs to run today: (1) Are we GLBA-covered? (2) If not, do we collect and sell personal data about consumers we don’t have a direct relationship with? (3) Should we be registered as a California data broker?

August 1 Is Not a Grace Period

California’s DROP system — the Delete Request and Opt-Out Platform — launched January 1, 2026, as a centralized consumer portal. Starting August 1, 2026, that launch phase ends and the compliance obligation begins: registered data brokers must access the platform at least once every 45 days to retrieve deletion requests and process them.

The penalty for non-compliance: $200 per deletion request for each day the data broker fails to delete the personal information as required by the Delete Act. And unlike some regulatory frameworks, California’s attorney general is not required to offer an opportunity to cure before pursuing enforcement. The California Privacy Protection Agency has made clear that August 1 is a firm compliance deadline, not the beginning of a grace period.

For organizations that are clearly registered data brokers and clearly not GLBA-covered, this deadline has been visible for over a year. The harder question — and the one many fintechs haven’t fully worked through — is whether the GLBA exemption actually applies to them.

What the DROP System Does

DROP is a consumer-facing tool. A California resident submits one deletion request through the CPPA’s portal. That request is distributed to every registered data broker in the system. Starting August 1, data brokers must:

  1. Access the platform at least once every 45 days
  2. Retrieve all pending deletion requests
  3. Search their records for each requesting consumer
  4. Delete all associated personal information — including inferences — where a match is found
  5. Report request status back through the system
  6. Maintain documentation of retrieval and deletion actions

The scope of “delete” is broader than some organizations expect: it includes derived data and inferences, not just raw personal information collected about the consumer. A data broker that compiled a behavioral profile from aggregated third-party data sources would need to delete the profile as well as the underlying data.

Who Is (and Isn’t) a Data Broker Under the Delete Act

The California Delete Act defines a “data broker” as a business that knowingly collects and sells or shares personal information of a consumer with whom the business does not have a direct relationship.

The operative element is the absence of a direct consumer relationship. This matters for how the test applies to different business models:

Business ModelDirect Relationship?Data Broker?
Neobank with account holdersYes — the bank has a direct relationship with account holdersNo
GLBA-covered financial institutionYes — and separately exempted by statuteNo
Data aggregator selling financial profilesNo — the consumer didn’t interact directly with the aggregatorYes (if not GLBA-covered)
Lead generation company in financial servicesNo — collecting data about consumers who didn’t contact themYes (if not GLBA-covered)
Credit bureau / consumer reporting agencySeparately exempted by FCRANo
Marketing analytics platformNo — consumers may not know the company existsPotentially yes
Fintech using third-party data for underwritingDepends on the specific data use and whether it involves resaleMay be yes

The statute also exempts HIPAA covered entities and business associates, FCRA consumer reporting agencies, and state and local government agencies. For financial services, the primary exemption is the GLBA.

The GLBA Exemption: Who Actually Qualifies

The Delete Act exempts “financial institutions subject to the GLBA” from the data broker definition. This sounds broad — financial services companies assume they’re covered — but it has a specific legal meaning.

A “financial institution” under GLBA is a company that is “significantly engaged in financial activities.” The Federal Trade Commission’s Safeguards Rule and Privacy Rule cover:

  • Banks, savings associations, and credit unions
  • Mortgage companies and brokers
  • Securities broker-dealers and investment advisers
  • Insurance companies
  • Payday lenders and consumer finance companies
  • Tax preparers
  • Travel agencies in connection with financial services
  • Companies providing financial data processing

What’s notably not on that list: pure technology companies, SaaS platforms, data analytics firms, and marketing platforms — even if their customers are financial services companies. A company that provides software to banks isn’t itself a GLBA financial institution. A company that sells marketing data to credit card companies isn’t GLBA-covered by virtue of its customers.

The question your legal team needs to answer: Does your company meet the statutory definition of a GLBA financial institution, or do you operate in financial services adjacent capacity?

The failure mode: a fintech assumes it’s GLBA-covered because it handles financial data, partners with banks, or calls itself a “fintech.” None of those facts determine GLBA coverage. What determines it is whether the company itself is “significantly engaged in financial activities” as defined by GLBA.

The Three Categories of Fintechs and What Each Should Do

Category 1: Clearly GLBA-covered financial institutions. Banks, credit unions, licensed mortgage companies, registered investment advisers, insurance companies, licensed consumer lending companies. These entities are specifically exempt from the data broker definition under California’s Delete Act. You should document this determination in your privacy compliance records. You’re not required to register as a data broker or access DROP — but you do have CCPA obligations for non-GLBA data, which is a separate analysis.

Category 2: Clearly not GLBA-covered and clearly data brokers. Data aggregators that compile consumer financial profiles and sell them. Lead generation companies that collect consumer information without a direct consumer relationship. Marketing analytics companies. Financial data resellers. If this describes your business and you’re not registered, you’re out of compliance as of August 1. The path forward: register with the CPPA, implement DROP access protocols before August 1, and build deletion request workflows into your data infrastructure.

Category 3: Uncertain — fintechs in the gray zone. This is the most common and most unresolved position. You’re a fintech that handles financial data, potentially has some GLBA-like obligations under your bank partner’s program agreement, but hasn’t formally determined whether you’re a GLBA financial institution. Or you have multiple business lines, some of which look like financial institution activity and some of which look like data services.

For Category 3 companies, the analysis cannot be deferred past August 1. The risk of getting this wrong runs in both directions: if you’re a data broker and you don’t comply, you’re accumulating $200-per-request-per-day liability. If you’re exempt and you spend resources on DROP infrastructure you don’t need, that’s a resource waste with no upside. Get a definitive legal determination.

What the Data Mapping Exercise Looks Like

Whether you’re working through the GLBA determination or confirming your data broker obligations, the underlying exercise is the same: map your data flows to understand what personal information you collect, from whom, and what you do with it.

For DELETE Act compliance specifically, you need to answer:

  • What personal information do we collect about individuals who are NOT our direct customers or end users?
  • Do we sell or share that information with third parties?
  • If yes, are we registered as a California data broker?
  • Do we have technical infrastructure to receive, process, and respond to deletion requests through DROP?

The data mapping tool inside a privacy compliance program gives you the inventory. The legal determination gives you the categorization. Together they tell you whether DROP access is an obligation starting August 1 or not.

So What?

California’s DELETE Act and the DROP system aren’t new — the law passed in 2023, the regulations finalized in late 2025, and the DROP portal launched January 1, 2026. August 1, 2026 is when the compliance obligation becomes operational and the penalty clock starts.

Most GLBA-covered financial institutions have correctly identified the exemption and have not registered as data brokers. The exposure sits in the middle tier: fintechs that haven’t done the formal GLBA determination, companies with mixed business models, and data-adjacent services that assumed “financial services” was synonymous with “GLBA-covered.”

If you haven’t confirmed your status, that confirmation needs to happen in the next three days — not because legal work can be completed in three days, but because knowing whether you should have registered months ago is the first step toward managing whatever liability may exist. The attorney general isn’t required to offer a cure period, but an organization that identifies a compliance gap, registers promptly, and builds DROP access demonstrates good faith in a way that an organization that ignores the deadline cannot.

For privacy compliance programs managing multiple overlapping state laws — and fintechs are managing an increasing number of them — the data broker determination should be a standing element of your annual privacy risk assessment, not a one-time analysis. State definitions of “data broker” are evolving. The GLBA exemption landscape is also shifting as Montana and Connecticut have already modified their entity-level exemptions. Document the determination now, and build a review cadence that catches when the facts or law change.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is the DROP system and who operates it?
DROP stands for Delete Request and Opt-Out Platform. It's a centralized portal operated by the California Privacy Protection Agency (CPPA, formerly CalPrivacy) that consumers can use to submit a single deletion request to all registered data brokers. Starting August 1, 2026, registered data brokers must access the platform at least once every 45 days to retrieve and process deletion requests.
Is my fintech automatically exempt from the Delete Act because we handle financial data?
Not automatically. The Delete Act exempts 'financial institutions subject to the GLBA' from the data broker definition. Whether your fintech qualifies as a GLBA-covered financial institution depends on your specific business activities — not just the fact that you operate in financial services. Non-bank technology companies, data aggregators, and lead generators in fintech may not qualify for the exemption.
What are the penalties for failing to comply with DROP?
A data broker that fails to process deletion requests through DROP faces a fine of $200 per deletion request for each day the data broker fails to delete the personal information as required. California's attorney general is not required to provide an opportunity to cure before initiating enforcement. The fines can accumulate quickly given that DROP processes requests from all California consumers.
What defines a 'data broker' under California's Delete Act?
A data broker is a business that knowingly collects and sells or shares personal information of California consumers with whom the business does not have a direct relationship. The key element is no direct consumer relationship — if you have a direct relationship with the individuals whose data you collect, you're not a data broker for purposes of that data. GLBA-covered financial institutions, HIPAA covered entities, and FCRA consumer reporting agencies are specifically exempt.
Does the GLBA exemption protect data collected outside of GLBA-covered activities?
Under the California Consumer Privacy Act (CCPA), data collected by GLBA-covered entities that falls outside GLBA coverage — marketing data, web analytics, employee data, prospective customer data — is generally not protected by the GLBA exemption and may be subject to CCPA consumer rights. However, for purposes of the Delete Act and data broker registration specifically, the exemption is entity-level for GLBA financial institutions.
If we're registered as a California data broker, what do we need to do starting August 1?
Access the DROP platform at minimum every 45 days to retrieve deletion requests. For each request where a consumer's personal information matches your records, delete all associated data — including inferences — unless a legal exemption applies. Report the request status back through the system. Maintain documentation of your retrieval and deletion actions.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Data Privacy Compliance Kit

Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.