The 2028 Delete Act audit: what to keep now
Starting January 1, 2028, every broker subject to DROP faces a triennial independent third-party audit of its compliance, required under §1798.99.86(e). That date is closer than the cycles running today make it feel, and the audit won’t be looking at 2028 practices. It will be looking at whatever record trail exists reaching back through it, because the retention window the Delete Act sets is six years.
What the audit expects to find
The CPPA’s August 6-7, 2026 board meeting advanced draft audit regulations to formal rulemaking (Agenda Item 10, new Article 5, §§7630-7633), with a 45-day public comment period. The draft is specific: any broker that meets the data-broker definition at any point between August 1, 2026 and December 31, 2027 must file its first DROP audit report by November 1, 2028, covering an audit period running August 1, 2026 to August 1, 2028. Reports recur every three years after that, performed by an independent qualified third-party auditor, and the broker’s own executive has to certify the report under penalty of perjury. This is still a draft, not an adopted regulation, but it means the records being made right now, from the very first cycles run in August 2026, are the audit file the drafted rule describes.
Two mechanics matter alongside that draft timeline: the six-year record retention requirement, and a production duty, meaning records have to be handed to CPPA within five business days of a request. Starting January 1, 2029, a third mechanic kicks in: the state’s public registry itself discloses each broker’s audit status (§1798.99.82(b)(2)(U)), so the outcome stops being a private compliance file and becomes something a broker’s own customers can look up. A broker that treats “audit-ready” as something to build in 2027 is proposing to fill a six-year retention window, and an audit period that already started in August 2026, with roughly one year of actual records.
Why this can’t be caught up later
Evidence has a property paperwork doesn’t: it can’t be produced retroactively. A cycle run today without a timestamped record of it is a cycle the 2028 audit will find a gap where evidence should be, and there’s no way, in 2028, to go back and generate a 2026 download timestamp that didn’t get captured in 2026. Every cycle run between now and the audit without clean records behind it becomes audit debt that can’t be repaid, only disclosed as a gap.
Book a 20-minute call if it’s unclear whether a given cycle’s records would hold up to that kind of look-back.
What a defensible per-cycle record contains
Nobody knows the audit’s exact checklist yet, but the shape of a defensible record is already clear from what the cycle itself requires documenting:
- The download timestamp and the files pulled and uploaded for the cycle.
- Match counts and the disposition assigned to each matched record: deleted, exempted (with the exemption ground noted), or opted out.
- The vendor deletion directives sent that cycle, with proof they went out.
- Upload receipts confirming File 2 was received for the cycle.
- Any status correction filed through /data/amend, and confirmation it went in within 45 days of the correction being identified.
None of this is exotic. It’s the ordinary output of running the cycle correctly and writing down that it happened. The gap most brokers will have by 2028 isn’t a missing capability, it’s a missing habit.
The enforcement record so far
For context: fourteen enforcement actions since November 2024 have totaled $697,290, including three since August 2026, and every one of them is a registration case or a CCPA data-minimization case. Nobody has yet been fined over a DROP deletion cycle, because the deletion obligation only started August 1, 2026. A dedicated enforcement strike force was announced in November 2025 and exists specifically to police this space going forward. The audit requirement, now drafted rather than hypothetical, is the mechanism most likely to turn “no deletion-cycle fine yet” into the first one, on a lag most brokers aren’t currently planning around.
Related: For the cycle mechanics behind the records an audit will read, see The 45-day DROP cycle, operationally. For the same cycle scaled to a 3-to-40-person shop, see DROP compliance for small data brokers. For whether a matching tool alone covers the recordkeeping duty, see DROP compliance: software vs. a service.
Common questions
Who actually performs the audit?
An independent third party. The detailed audit regulations advanced to formal rulemaking at the CPPA's August 6-7, 2026 board meeting (draft Article 5, §§7630-7633, now in a 45-day public comment period). They are drafted, not adopted. CalPrivacy named its first Chief Privacy Auditor, Sabrina Boyson Ross, in February 2026, an earlier sign the rulemaking was moving; the August draft is the first real look at what it will require.
If a broker uses compliance software to run its cycles, does that cover the audit obligation?
No. The obligation to run the cycle and keep the records belongs to the broker regardless of which tool did the matching: software doesn't stand in for the broker at audit time, and a license agreement that disclaims liability doesn't transfer the recordkeeping duty to whoever wrote the code.
When is the first audit report due, and what period does it cover?
Under the draft text, any broker that met the data-broker definition at any point between August 1, 2026 and December 31, 2027 must complete its first DROP audit report by November 1, 2028. That report covers an audit period running from August 1, 2026 through August 1, 2028, then recurs every three years.
Can a broker fix gaps from 2026 once the draft rules are finalized?
No. The audit period the draft text sets, August 1, 2026 through August 1, 2028, has already started. A cycle run without a record of it today is a gap the 2028 report will find, and there is no mechanism to generate a 2026 download timestamp or match count in 2028 that wasn't captured at the time.