CPPA Board to Weigh Data Broker Fee Adjustments and DROP Compliance Audit Rules

Table of Contents

The California Privacy Protection Agency Board will consider changes to data broker registration and access fees along with a package of proposed regulations governing compliance audits under the Delete Request and Opt-out Platform when it meets in San Francisco on August 6–7, 2026. The agenda also includes the first annual update from the Agency’s Audits Division, which recently launched its initial examination of gig platforms’ adherence to the California Consumer Privacy Act.

These items form the core of the second day’s proceedings and signal the Agency’s continued effort to operationalize the California Delete Act’s data broker requirements while expanding its enforcement toolkit.

Fee Adjustments Under Review

Board members are scheduled to discuss and potentially act on amendments to Regulation Sections 7600 and 7611. The proposed changes would adjust the fees data brokers pay to register with the Agency and to access the Delete Request and Opt-out Platform, commonly known as DROP. Fee levels directly affect the cost of doing business for companies that collect and sell or share personal information, and any upward or downward revision will influence the Agency’s ability to fund ongoing administration of the registry and platform.

The Delete Act requires data brokers to register annually and to process deletion requests funneled through the centralized DROP system. As the platform matures, the Agency is recalibrating the financial structure that supports it. Stakeholders will watch whether the Board advances specific fee figures or directs staff to refine the proposal before formal adoption.

DROP Compliance Audit Regulations

A more substantial rulemaking item involves proposed amendments to Sections 7601–7622 and the possible adoption of new Sections 7630–7633. These provisions address how the Agency will conduct compliance audits of data brokers’ use of DROP. If advanced, the package would move into formal rulemaking, opening a public comment period and setting the stage for enforceable audit standards.

The draft rules are expected to clarify the scope of audits, documentation requirements, response timelines, and potential consequences for deficiencies. For data brokers, the regulations will determine how thoroughly their deletion and opt-out processes are examined and what evidence they must be prepared to produce. Clear standards can reduce uncertainty; vague or overly burdensome ones risk increasing compliance costs without corresponding consumer benefit.

Agency staff from the Legal Division, including General Counsel Philip Laird and supporting attorneys, are slated to present the materials and recommendations. The Board’s decision on whether to advance the package will shape the next phase of Delete Act implementation.

Audits Division Reports First Activity

Sabrina Boyson Ross, Chief Privacy Auditor, will deliver the Audits Division’s first annual update. The division has already initiated its inaugural audit focused on gig platforms’ compliance with the CCPA. That examination marks the Agency’s shift from primarily rulemaking and registration activities into active, systematic review of regulated entities’ practices.

The update is expected to outline the division’s methodology, early findings or process observations, and plans for future audits. Because the first target set involves platforms that handle large volumes of worker and consumer data, the results could influence both industry practices and the Agency’s prioritization of subsequent sectors—including data brokers subject to DROP obligations.

Broader Meeting Context

While the data broker and audit items dominate interest among privacy practitioners, the two-day agenda also covers related topics. On August 6 the Board will receive an informational briefing on the history, legal framework, and technology of opt-out preference signals, followed by a preliminary rulemaking update and recommendations on those signals. Other sessions address administrative and public affairs updates, a legislative report, and routine governance matters.

The meeting will be held in person at the California Public Utilities Commission Auditorium in San Francisco and livestreamed via Zoom. Public comment is permitted on each agenda item, subject to time limits set by the Chair.

Implications for Regulated Entities

Data brokers should monitor the fee discussion closely; any increase will raise ongoing operational costs, while adjustments tied more tightly to actual Agency expenses could improve predictability. The proposed DROP audit regulations, if advanced, will create a clearer roadmap for what “compliance” looks like under the Delete Act and will likely require brokers to strengthen internal documentation, logging, and response capabilities.

More broadly, the Audits Division’s first annual report and its gig-platform examination signal that the CPPA is moving beyond registration and education into sustained oversight. Companies subject to the CCPA and the Delete Act should treat the August meeting as an early indicator of where examination resources will be directed in the coming year.

Final Board actions on the fee amendments and the DROP audit rulemaking package will determine the immediate next steps. Interested parties can follow the proceedings through the Agency’s public livestream and will have further opportunity to comment once any formal rulemaking is initiated.

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.