Feature Data Privacy
California's DELETE Act: The August 1, 2026 DROP Deadline and the GLBA Exemption Test Every Fintech Needs to Pass
California's DELETE Act requires data brokers to process consumer deletion requests through the DROP system starting August 1, 2026. The penalty is $200 per request per day. Most GLBA-covered financial institutions are exempt — but many fintechs aren't sure which category they're in. Here's how to run the analysis.
Table of Contents
TL;DR
- California’s DELETE Act requires registered data brokers to process consumer deletion requests through the DROP system starting August 1, 2026 — the penalty is $200 per deletion request per day with no mandatory cure period
- “Financial institutions subject to the GLBA” are exempt from the data broker definition — but that exemption requires confirming your fintech actually qualifies as a GLBA-covered financial institution
- Many fintechs operate in financial services without meeting the GLBA financial institution definition: data aggregators, lead generators, and analytics companies in fintech are often NOT GLBA-covered
- The analysis every fintech needs to run today: (1) Are we GLBA-covered? (2) If not, do we collect and sell personal data about consumers we don’t have a direct relationship with? (3) Should we be registered as a California data broker?
August 1 Is Not a Grace Period
California’s DROP system — the Delete Request and Opt-Out Platform — launched January 1, 2026, as a centralized consumer portal. Starting August 1, 2026, that launch phase ends and the compliance obligation begins: registered data brokers must access the platform at least once every 45 days to retrieve deletion requests and process them.
The penalty for non-compliance: $200 per deletion request for each day the data broker fails to delete the personal information as required by the Delete Act. And unlike some regulatory frameworks, California’s attorney general is not required to offer an opportunity to cure before pursuing enforcement. The California Privacy Protection Agency has made clear that August 1 is a firm compliance deadline, not the beginning of a grace period.
For organizations that are clearly registered data brokers and clearly not GLBA-covered, this deadline has been visible for over a year. The harder question — and the one many fintechs haven’t fully worked through — is whether the GLBA exemption actually applies to them.
What the DROP System Does
DROP is a consumer-facing tool. A California resident submits one deletion request through the CPPA’s portal. That request is distributed to every registered data broker in the system. Starting August 1, data brokers must:
- Access the platform at least once every 45 days
- Retrieve all pending deletion requests
- Search their records for each requesting consumer
- Delete all associated personal information — including inferences — where a match is found
- Report request status back through the system
- Maintain documentation of retrieval and deletion actions
The scope of “delete” is broader than some organizations expect: it includes derived data and inferences, not just raw personal information collected about the consumer. A data broker that compiled a behavioral profile from aggregated third-party data sources would need to delete the profile as well as the underlying data.
Who Is (and Isn’t) a Data Broker Under the Delete Act
The California Delete Act defines a “data broker” as a business that knowingly collects and sells or shares personal information of a consumer with whom the business does not have a direct relationship.
The operative element is the absence of a direct consumer relationship. This matters for how the test applies to different business models:
| Business Model | Direct Relationship? | Data Broker? |
|---|---|---|
| Neobank with account holders | Yes — the bank has a direct relationship with account holders | No |
| GLBA-covered financial institution | Yes — and separately exempted by statute | No |
| Data aggregator selling financial profiles | No — the consumer didn’t interact directly with the aggregator | Yes (if not GLBA-covered) |
| Lead generation company in financial services | No — collecting data about consumers who didn’t contact them | Yes (if not GLBA-covered) |
| Credit bureau / consumer reporting agency | Separately exempted by FCRA | No |
| Marketing analytics platform | No — consumers may not know the company exists | Potentially yes |
| Fintech using third-party data for underwriting | Depends on the specific data use and whether it involves resale | May be yes |
The statute also exempts HIPAA covered entities and business associates, FCRA consumer reporting agencies, and state and local government agencies. For financial services, the primary exemption is the GLBA.
The GLBA Exemption: Who Actually Qualifies
The Delete Act exempts “financial institutions subject to the GLBA” from the data broker definition. This sounds broad — financial services companies assume they’re covered — but it has a specific legal meaning.
A “financial institution” under GLBA is a company that is “significantly engaged in financial activities.” The Federal Trade Commission’s Safeguards Rule and Privacy Rule cover:
- Banks, savings associations, and credit unions
- Mortgage companies and brokers
- Securities broker-dealers and investment advisers
- Insurance companies
- Payday lenders and consumer finance companies
- Tax preparers
- Travel agencies in connection with financial services
- Companies providing financial data processing
What’s notably not on that list: pure technology companies, SaaS platforms, data analytics firms, and marketing platforms — even if their customers are financial services companies. A company that provides software to banks isn’t itself a GLBA financial institution. A company that sells marketing data to credit card companies isn’t GLBA-covered by virtue of its customers.
The question your legal team needs to answer: Does your company meet the statutory definition of a GLBA financial institution, or do you operate in financial services adjacent capacity?
The failure mode: a fintech assumes it’s GLBA-covered because it handles financial data, partners with banks, or calls itself a “fintech.” None of those facts determine GLBA coverage. What determines it is whether the company itself is “significantly engaged in financial activities” as defined by GLBA.
The Three Categories of Fintechs and What Each Should Do
Category 1: Clearly GLBA-covered financial institutions. Banks, credit unions, licensed mortgage companies, registered investment advisers, insurance companies, licensed consumer lending companies. These entities are specifically exempt from the data broker definition under California’s Delete Act. You should document this determination in your privacy compliance records. You’re not required to register as a data broker or access DROP — but you do have CCPA obligations for non-GLBA data, which is a separate analysis.
Category 2: Clearly not GLBA-covered and clearly data brokers. Data aggregators that compile consumer financial profiles and sell them. Lead generation companies that collect consumer information without a direct consumer relationship. Marketing analytics companies. Financial data resellers. If this describes your business and you’re not registered, you’re out of compliance as of August 1. The path forward: register with the CPPA, implement DROP access protocols before August 1, and build deletion request workflows into your data infrastructure.
Category 3: Uncertain — fintechs in the gray zone. This is the most common and most unresolved position. You’re a fintech that handles financial data, potentially has some GLBA-like obligations under your bank partner’s program agreement, but hasn’t formally determined whether you’re a GLBA financial institution. Or you have multiple business lines, some of which look like financial institution activity and some of which look like data services.
For Category 3 companies, the analysis cannot be deferred past August 1. The risk of getting this wrong runs in both directions: if you’re a data broker and you don’t comply, you’re accumulating $200-per-request-per-day liability. If you’re exempt and you spend resources on DROP infrastructure you don’t need, that’s a resource waste with no upside. Get a definitive legal determination.
What the Data Mapping Exercise Looks Like
Whether you’re working through the GLBA determination or confirming your data broker obligations, the underlying exercise is the same: map your data flows to understand what personal information you collect, from whom, and what you do with it.
For DELETE Act compliance specifically, you need to answer:
- What personal information do we collect about individuals who are NOT our direct customers or end users?
- Do we sell or share that information with third parties?
- If yes, are we registered as a California data broker?
- Do we have technical infrastructure to receive, process, and respond to deletion requests through DROP?
The data mapping tool inside a privacy compliance program gives you the inventory. The legal determination gives you the categorization. Together they tell you whether DROP access is an obligation starting August 1 or not.
So What?
California’s DELETE Act and the DROP system aren’t new — the law passed in 2023, the regulations finalized in late 2025, and the DROP portal launched January 1, 2026. August 1, 2026 is when the compliance obligation becomes operational and the penalty clock starts.
Most GLBA-covered financial institutions have correctly identified the exemption and have not registered as data brokers. The exposure sits in the middle tier: fintechs that haven’t done the formal GLBA determination, companies with mixed business models, and data-adjacent services that assumed “financial services” was synonymous with “GLBA-covered.”
If you haven’t confirmed your status, that confirmation needs to happen in the next three days — not because legal work can be completed in three days, but because knowing whether you should have registered months ago is the first step toward managing whatever liability may exist. The attorney general isn’t required to offer a cure period, but an organization that identifies a compliance gap, registers promptly, and builds DROP access demonstrates good faith in a way that an organization that ignores the deadline cannot.
For privacy compliance programs managing multiple overlapping state laws — and fintechs are managing an increasing number of them — the data broker determination should be a standing element of your annual privacy risk assessment, not a one-time analysis. State definitions of “data broker” are evolving. The GLBA exemption landscape is also shifting as Montana and Connecticut have already modified their entity-level exemptions. Document the determination now, and build a review cadence that catches when the facts or law change.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is the DROP system and who operates it?
Is my fintech automatically exempt from the Delete Act because we handle financial data?
What are the penalties for failing to comply with DROP?
What defines a 'data broker' under California's Delete Act?
Does the GLBA exemption protect data collected outside of GLBA-covered activities?
If we're registered as a California data broker, what do we need to do starting August 1?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Keep reading
Related posts.
Data Privacy
New Jersey's A5328 Is the Costliest Data Broker Law in the Country — and It's Already in Effect for Sensitive Data
New Jersey signed A5328 on June 30, 2026, banning the sale of sensitive financial and personal data immediately and creating registration fees up to $1.5 million. GLBA covers some fintechs — but 'financial services' doesn't automatically mean exempt. Here's the analysis every fintech and data aggregator needs to run now.
Jul 29, 2026
Data Privacy
Privacy Impact Assessment for Mixed GLBA and Non-GLBA Data: Scope the Data, Not the Entity
Use a data privacy impact assessment template to separate GLBA and non-GLBA processing by data flow, purpose, person, use, and state-law scope.
Jul 25, 2026
Data Privacy
Oregon's Privacy Law Has a Feature No Other State Has — and Financial Services Companies Are Probably in Scope
The Oregon Consumer Privacy Act's 30-day cure period ended January 1, 2026. The AG can now sue without notice. More importantly for financial services: the GLBA exemption is narrower than most assume, fintechs have significant exposure on non-NPI data, and Oregon requires something no other state does — a list of the specific named third parties that received consumer data.
Jul 17, 2026