
California privacy regulators are rapidly shifting compliance expectations from passive policy commitments to mandatory technical proof and proactive oversight. Privacy, legal, and compliance professionals must immediately prepare for independent deletion audits, technical verification across vendor networks, and rising data broker registration fees.
The California Privacy Protection Agency (CalPrivacy) is significantly expanding its regulatory oversight framework through new audit initiatives and updated operational fee structures under the California Consumer Privacy Act and the Delete Act. CalPrivacy’s newly staffed Audits Division, led by Chief Auditor Sabrina Boyson Ross, launched its first formal sectoral audit targeting gig economy platforms while preparing to examine automated decision-making technologies and cybersecurity practices. The Audits Division conducts proactive fact-finding, document requests, staff interviews, and technical testing to publish sector-wide trend reports and identify compliance vulnerabilities.
Simultaneously, CalPrivacy initiated formal rulemaking on draft regulations establishing independent triennial compliance audits for data brokers participating in the Delete Request and Opt-Out Platform (DROP), ahead of a January 1, 2028 enforcement deadline. Under preliminary proposals, data brokers can no longer rely on policy attestations. Independent auditors will examine deletion logs, status reports, data maps, and technical system testing across nine focus areas to verify that erasure requests reach primary databases, downstream service providers, and derived profiling data. To cover increasing platform infrastructure, staffing, and residency verification expenses, the board approved raising annual data broker fees by 58%, from $3,500 to $9,500 starting in 2027.
Fahad Diwan, JD, FIP, CIPP/M, CIPP/C, Director of Product, Privacy, Exterro
For years, privacy compliance lived largely on paper, supported by policy statements, vendor attestations, and goodwill. California’s aggressive new enforcement push makes one thing clear: the era of "trust me" compliance is over. With CalPrivacy launching active technical audits and mandating independent verification for deletion requests, regulators aren't just reading your policies; they’re inspecting your technical architecture.If your deletion process relies on manual ticketing or fails to cascade down to third-party vendors, legacy archives, and derived AI datasets, you are exposed. Compliance now demands technical proof of execution, automated data lineage, and defensible audit logs across your entire data ecosystem.
Prepare for mandatory California deletion audits by establishing automated data mapping and technical verification tools. Ensure complete visibility into consumer records across all environments with Exterro’s data governance software.