California's Delete Act (Senate Bill 362) establishes a deletion request mechanism that allows California consumers to demand the deletion of their personal information from all registered data brokers through a single submission to the California Privacy Protection Agency (CPPA). The law becomes enforceable beginning in 2026. For SaaS organizations that collect, process, or sell California consumer data, the question is not whether the law exists but whether your company meets the statutory definition of a data broker and what that classification requires.

This article describes the Delete Act's requirements, what constitutes a data broker under California law, the registration and deletion obligations that begin in 2026, and the operational assessments SaaS leadership must complete.

What the Delete Act Creates

The Delete Act amends California Civil Code Section 1798.99.82 to establish a statewide deletion mechanism administered by the CPPA. Beginning on or after January 1, 2026, California consumers may submit a single deletion request through the CPPA's platform. The CPPA then transmits that request to all entities registered as data brokers. Each registered data broker must process the request within the timeframes specified by the California Consumer Privacy Act (CCPA) and its regulations.

The mechanism is intended to replace the impractical burden of consumers contacting dozens or hundreds of data brokers individually. For organizations classified as data brokers, it creates a centralized channel through which deletion requests arrive, continuous monitoring obligations, and technical integration requirements that many SaaS platforms have not yet scoped.

What Constitutes a Data Broker

California law defines a data broker as a business that knowingly collects and sells to third parties the personal information of consumers with whom the business does not have a direct relationship. The definition is found in California Civil Code Section 1798.99.80(a). Several exclusions apply, including for consumer reporting agencies subject to the Fair Credit Reporting Act, financial institutions subject to the Gramm-Leach-Bliley Act, and entities subject to certain other federal privacy regimes.

The defining element is not volume or sector. It is whether the business collects personal information about consumers it does not directly interact with and subsequently sells that information. Many SaaS organizations assume they are exempt because they serve enterprise customers. That assumption is incorrect if the platform collects data about end users and monetizes it through sales to third parties who are not service providers or contractors under the CCPA.

Product leadership must evaluate three elements:

  • Does the platform collect personal information about California consumers with whom the business has no direct contractual relationship?
  • Is any of that information sold, as "sale" is defined under CCPA (which includes exchanges for valuable consideration, not merely monetary payment)?
  • Does any statutory exclusion apply that removes the organization from the data broker definition?

These are legal determinations, not technical ones. They require involvement from general counsel, not only from engineering or product management.

Registration and Compliance Obligations Beginning in 2026

Entities that meet the data broker definition must register annually with the CPPA and pay a registration fee. The registration requirement has existed since 2020; the Delete Act adds the centralized deletion mechanism and the requirement to process CPPA-transmitted deletion requests.

From 2026 onward, registered data brokers must:

  • Monitor the CPPA platform for incoming deletion requests
  • Process those requests within the timeframes required by CCPA regulations (typically 45 days, extendable to 90 days with notice)
  • Maintain systems capable of matching consumer-submitted identifiers to records held by the organization
  • Provide confirmation of deletion where required by the regulations
  • Maintain accurate registration information, including contact details and a description of data collection and sale practices

The CPPA has not yet published final technical specifications for how deletion requests will be transmitted or how data brokers must integrate with the centralized platform. That uncertainty does not eliminate the obligation to prepare. Organizations that wait for final technical guidance before assessing their classification risk insufficient lead time for infrastructure changes, vendor contract reviews, and process documentation.

What SaaS Providers Must Assess Now

The Delete Act does not change the substantive privacy obligations under the CCPA. It changes the operational mechanism through which consumers exercise deletion rights against data brokers. The consequences for SaaS organizations are operational, reputational, and strategic.

General counsel must determine, with input from product and engineering leadership, whether the organization meets the statutory data broker definition. This requires mapping:

  • All data flows involving California consumer personal information
  • All data sales, exchanges, or other monetization arrangements that meet the CCPA definition of "sale"
  • The nature of the organization's relationship with the data subjects whose information is processed
  • Whether any statutory exclusion applies

This analysis should be documented, reviewed annually, and updated whenever material changes occur in product offerings, data partnerships, or monetization models.

Technical Infrastructure for Deletion Processing

If the organization is classified as a data broker, engineering leadership must ensure systems can:

  • Receive and parse deletion requests from the CPPA platform in the format specified by the agency
  • Match consumer-submitted identifiers (email, phone, name, address, device identifiers) to internal records with sufficient accuracy
  • Execute deletion across all systems that store or process the identified consumer's personal information
  • Generate confirmation records suitable for regulatory examination
  • Handle requests at a volume that may exceed historical direct-to-business deletion request volumes

Many SaaS platforms process CCPA deletion requests manually or semi-manually through support ticket workflows. That approach may not scale when the CPPA begins transmitting requests on behalf of consumers using the centralized mechanism.

Vendor and Service Provider Contract Reviews

Organizations that provide data to third parties must examine whether those arrangements constitute sales under the CCPA or whether the recipients qualify as service providers or contractors. The distinction determines whether the organization is selling personal information and thus whether it may meet the data broker definition. Procurement and legal teams must review data-sharing agreements and document the classification of each recipient.

Privacy Policy and Public-Facing Disclosures

Data brokers must disclose specific information in their registration with the CPPA, including categories of data collected and the purposes for collection and sale. These disclosures must align with the organization's privacy policy and other public statements. Compliance leadership should audit existing privacy policy language to ensure consistency and completeness before registration is required.

Who Inside the Organization Is Accountable

The Delete Act creates obligations that span legal, product, engineering, compliance, and customer operations. No single function owns the outcome. General counsel determines classification and regulatory position. Engineering builds the technical capability to process deletions. Product management decides whether to change data practices to avoid classification as a data broker. Compliance monitors ongoing registration and request processing. Customer operations may handle escalations or exceptions.

This distributed accountability creates a coordination problem. Executives describe the same pattern: each function understands its piece, but no single leader owns the cross-functional decision sequence, the timeline, or the operational readiness assessment. Work stalls because no one has the authority to set priorities across teams, resolve conflicts between product goals and compliance requirements, or decide when the organization is prepared to register or to certify that it is not required to do so.

Adequate ownership requires a named executive accountable for:

  • Coordinating the classification determination and documenting the rationale
  • Driving the technical build or vendor procurement required for deletion processing
  • Establishing the monitoring and response process once the CPPA platform is operational
  • Reporting readiness to the board or chief executive with sufficient detail to support informed oversight

In organizations without a dedicated chief privacy officer or chief information security officer, this accountability often lands on the general counsel by default. That placement is workable only if legal leadership has the technical fluency, project authority, and cross-functional influence to drive execution rather than merely advising on requirements.

How This Relates to Regulatory and Framework Readiness

The Delete Act is one data point in a regulatory environment that is fragmenting by jurisdiction, sector, and data type. California, Colorado, Connecticut, Utah, Virginia, and other states have enacted comprehensive privacy laws with overlapping but non-identical requirements. Federal privacy legislation remains under consideration. Sector-specific rules continue to evolve. Organizations that treat each new law as a discrete compliance project accumulate technical debt, conflicting processes, and gaps where no one is responsible.

Regulatory and framework readiness is the practice of building governance, risk management, and operational capabilities that generalize across obligations rather than optimizing for a single statute. It begins with establishing who is accountable for privacy and data protection as a strategic function, not merely as a legal checklist. It continues with adopting structured approaches such as the [NIST Privacy Framework](https://www.nist.gov/privacy-framework) to identify and manage privacy risks in a way that connects to enterprise risk management and business objectives.

Organizations with mature [vCISO leadership](/vciso/) have an executive who coordinates privacy, security, and compliance strategy across functions, translates regulatory obligations into operational requirements, and reports progress to the board in business terms. That leader does not replace general counsel or the chief information officer; they provide the connective tissue that prevents regulatory obligations from being addressed in isolation.

Practical Next Steps for Leadership

SaaS executives preparing for the Delete Act should complete the following sequence:

**First, determine classification.** General counsel, with input from product and engineering leadership, should document whether the organization meets the statutory definition of a data broker. This requires mapping data flows, identifying sales as defined by the CCPA, and applying any statutory exclusions. The determination should be reviewed by outside privacy counsel if internal expertise is insufficient.

**Second, assign executive ownership.** Designate a single executive accountable for coordinating the technical, operational, and legal workstreams required for compliance or for certifying that the organization is not subject to the registration requirement. This leader should have authority to set priorities across legal, engineering, and product teams.

**Third, assess technical readiness.** If the organization is classified as a data broker, engineering leadership should evaluate whether existing systems can receive, match, and execute deletion requests at the expected volume and within the regulatory timeframes. Identify gaps and estimate the lead time required to close them.

**Fourth, monitor CPPA guidance.** The CPPA will publish technical specifications and operational guidance for the centralized deletion mechanism. Compliance leadership should monitor agency communications and participate in public comment periods where the organization's input may shape implementation details.

**Fifth, integrate into broader privacy governance.** The Delete Act should not be treated as a standalone project. It is one obligation within a larger body of privacy regulation. Organizations that establish structured privacy governance, adopt frameworks such as the NIST Privacy Framework, and assign clear executive accountability are better positioned to respond efficiently as requirements evolve.

Heights Consulting Group provides fractional vCISO leadership that coordinates privacy, security, and compliance strategy for regulated and risk-sensitive organizations. If your executive team lacks a single owner for this work, or if the distributed accountability model is creating gaps, a confidential consultation can clarify what adequate ownership looks like and how to establish it. Reach out through the [contact page](/contact/) to begin that conversation.

Sources

  1. Cybersecurity Framework | NIST , www.nist.gov
  2. Privacy and Security | Federal Trade Commission , www.ftc.gov
  3. Privacy Framework | NIST , www.nist.gov

Related service: Regulatory and Framework Readiness

Readiness for the frameworks and regulations that genuinely apply to you, NIST CSF, ISO 27001, SOC 2, CMMC, HIPAA, PCI DSS and SOX-related IT controls, with the evidence maintained between assessments.

Read about Regulatory and Framework Readiness