The state’s new DROP platform goes fully operational on August 1, 2026. Here is what it requires, and how HealthLink Dimensions built for it ahead of the deadline.
By: Nathan Lenyszyn, Chief Marketing Officer, HealthLink Dimensions
What Changes on August 1
On August 1, 2026, California’s Delete Act hits its real deadline. From that date, every data broker registered in the state must retrieve and honor consumer deletion requests submitted through the Delete Request and Opt-out Platform (DROP), a centralized system run by the CalPrivacy. A consumer files one request, and it reaches every registered data broker in California at the same time.
Residents have been filing DROP requests since January 1, 2026, so a queue is already waiting. Each request does double duty as a deletion request and a do-not-sell-or-share opt-out. The law has teeth: daily fines for brokers that miss the deadline, and a regulator that has made clear it intends to enforce.
Here is the part that matters for healthcare marketers: clinicians are consumers too. A physician, nurse practitioner, or physician assistant in California can file a DROP request like anyone else. When they do, that choice needs to follow their data wherever it has traveled, including into the files and platforms of companies that license healthcare professional (HCP) data.
What does the Delete Act Require of Data Brokers?
Starting August 1, 2026, registered data brokers must access DROP at least every 45 days, process verified deletion requests, honor opt-outs of sale and sharing, report request status back to the state, and maintain an ongoing suppression list that screens newly acquired records, so a deleted consumer’s information is never sold or shared again. Brokers must also direct their service providers and contractors to honor the same requests.
The duty does not stop there. Under the California Consumer Privacy Act (CCPA), a business that deletes personal information must also notify the third parties it sold or shared that information with, so they can delete it too. DROP did not invent that duty. It made the duty centralized, frequent, and auditable. Any organization that licenses third-party data now has a practical question to answer: when a person in that dataset exercises their rights, how will you find out, and what will you do about it?
For many data users, the honest answer today is that they would not find out. Their supplier has no mechanism, no cadence, and no contract language covering the scenario. Much of the industry has been slow to engage with this deadline, and the risk lands on their customers.
How HealthLink Dimensions Built for DROP
HealthLink Dimensions is a registered data broker in California, Texas, Oregon, and Vermont, and we take the obligations that come with registration seriously. We built our DROP program ahead of the August 1 deadline on one idea: a clinician’s privacy choice should be honored everywhere their data lives, quickly and verifiably.
In practice, that means we retrieve requests from the state platform on a recurring cadence, verify them, and act on them in our own database. Deleted and opted-out records are permanently suppressed so they cannot come back in through new data sources, and every new delivery is screened against that suppression list before it leaves our building. Customers receive data that is already clean.
Privacy & Compliance is one of the three commitments we make on every engagement, alongside Product Excellence and Superior Service. The same posture is why we maintain Network Advertising Initiative (NAI) membership and SOC 2 Type II attestation. We would rather be early on a new obligation than explain later why we were not.
What HealthLink Customers Should Expect
Customers do not need to build anything. In late July, HealthLink customers will receive two things: an updated Data Protection Agreement (DPA) to execute electronically, and access to a secure file feed that delivers verified deletion and opt-out requests affecting data they have licensed from us.
The DPA is deliberately simple. It records that each party runs its own business and follows privacy law independently, and that when we pass a verified privacy request downstream, the customer honors it within an agreed window. It does not change commercial terms. What it adds is a signed, regulator-ready answer to a question customers are hearing more often from their own clients and auditors: how do you handle deletion requests in licensed data?
The feed works like the deliveries you already receive from us. Through a secure file transfer (SFTP) account, customers download a comma-separated values (CSV) file containing hashed identifiers only, never clear-text personal information, along with header definitions that explain every field. Your team matches the hashed values against HealthLink-sourced records, removes or suppresses the matches, and confirms. We monitor the state platform and verify every request, so customers get one clean, actionable file instead of building a compliance function of their own.
A data partner should remove risk from your profile, not add to it. Compliance handled well is what makes licensed data safe to put to work.
Privacy That Holds Up Across the Entire HCP Data Lifecycle
The Delete Act is one deadline. The discipline behind it applies to everything we do. Accurate, permissioned, verifiable data is the foundation under Profile, our HCP database and profiling foundation; Enrich, which validates and appends customer data; Engage, which powers compliant multichannel HCP outreach; and Pulse, which turns market signals into insight. Whichever pillar a customer starts with, the same privacy architecture sits underneath.
A lot of the industry is hoping this deadline applies to someone else. We planned for it, built for it, and put it in writing for our customers. If you want to see the mechanics, ask us for the sample suppression file. We are happy to show our work.
Frequently Asked Questions
What is California’s Delete Act?
The Delete Act (SB 362) is a California law that lets residents request deletion of their personal information from all registered data brokers through a single request. It directed the CPPA to build a single deletion mechanism, DROP is that platform, and brokers must retrieve and process those requests on a recurring cadence beginning August 1, 2026.
What is the DROP platform?
DROP, the Delete Request and Opt-out Platform, is the CPPA’s centralized system for consumer deletion requests. Consumers file once, and every registered data broker must check the platform at least every 45 days, act on verified requests, and report status back. Each request also functions as a do-not-sell-or-share opt-out.
Does the Delete Act affect companies that are not data brokers?
Yes, indirectly. Deletion requests follow the data downstream, so companies that license data from a broker are expected to honor requests the broker passes along. Data users should ask their suppliers how verified deletion and opt-out requests will reach them, on what cadence, and under what contract language.
What is HealthLink Dimensions doing about the Delete Act?
HealthLink retrieves and verifies DROP requests, honors them in its own database, permanently suppresses affected records, and screens every outbound delivery against the suppression list. Customers execute a short Data Protection Agreement and receive a secure feed of verified deletion and opt-out requests affecting data they have licensed.
What should HCP data users do before August 1, 2026?
Ask every data supplier three questions: are you a registered data broker where the law requires it, how will verified deletion requests reach us, and what agreement covers our obligation to act on them? If a supplier has no answer, that risk sits with you.
About HealthLink Dimensions
HealthLink Dimensions is the trusted HCP data partner for healthcare marketing agencies and the life sciences, hospital, health plan, and continuing medical education (CME) organizations they serve. Our four connected pillars, Profile, Enrich, Engage, and Pulse, deliver identity-resolved HCP data, clinically relevant audiences, monthly-verification for deliverability, and closed-loop measurement. Every engagement is built on three commitments: Product Excellence, Superior Service, and Privacy & Compliance. Data to Insight. One Trusted Partner.

.png)
