The 2028 Delete Act audit: what to keep now

Reviewed August 2026

Starting January 1, 2028, every broker subject to DROP faces a triennial independent third-party audit of its compliance, required under §1798.99.86(e). That date is closer than the cycles running today make it feel, and the audit won’t be looking at 2028 practices. It will be looking at whatever record trail exists reaching back through it, because the retention window the Delete Act sets is six years.

What the audit expects to find

Two mechanics matter more than the audit’s exact procedure, which isn’t written yet: the six-year record retention requirement, and a production duty, meaning records have to be handed to CPPA within five business days of a request. Starting January 1, 2029, a third mechanic kicks in: the state’s public registry itself discloses each broker’s audit status (§1798.99.82(b)(2)(U)), so the outcome stops being a private compliance file and becomes something a broker’s own customers can look up. A broker that treats “audit-ready” as something to build in 2027 is proposing to fill a six-year retention window with roughly one year of actual records.

The audit regulations themselves are still being written. CalPrivacy named its first Chief Privacy Auditor, Sabrina Boyson Ross, in February 2026, a sign the rulemaking process is underway, not a sign it’s settled. That’s arguably the harder position for a broker to be in, not the easier one: there’s no checklist yet to satisfy, only the underlying six-year retention and five-business-day production duties, which are already in force regardless of what the detailed audit rules eventually say.

Why this can’t be caught up later

Evidence has a property paperwork doesn’t: it can’t be produced retroactively. A cycle run today without a timestamped record of it is a cycle the 2028 audit will find a gap where evidence should be, and there’s no way, in 2028, to go back and generate a 2026 download timestamp that didn’t get captured in 2026. Every cycle run between now and the audit without clean records behind it becomes audit debt that can’t be repaid, only disclosed as a gap.

Book a 20-minute call if it’s unclear whether a given cycle’s records would hold up to that kind of look-back.

What a defensible per-cycle record contains

Nobody knows the audit’s exact checklist yet, but the shape of a defensible record is already clear from what the cycle itself requires documenting:

  • The download timestamp and the files pulled and uploaded for the cycle.
  • Match counts and the disposition assigned to each matched record: deleted, exempted (with the exemption ground noted), or opted out.
  • The vendor deletion directives sent that cycle, with proof they went out.
  • Upload receipts confirming File 2 was received for the cycle.
  • Any status correction filed through /data/amend, and confirmation it went in within 45 days of the correction being identified.

None of this is exotic. It’s the ordinary output of running the cycle correctly and writing down that it happened. The gap most brokers will have by 2028 isn’t a missing capability, it’s a missing habit.

The enforcement record so far

For context: eleven enforcement actions since November 2024 have totaled $492,000, and every one of them is a registration case. Nobody has yet been fined over a DROP deletion cycle, because the deletion obligation only started August 1, 2026. A dedicated enforcement strike force was announced in November 2025 and exists specifically to police this space going forward. The audit requirement is the mechanism most likely to turn “no deletion-cycle fine yet” into the first one, on a three-year lag most brokers aren’t currently planning around.

Related: For the cycle mechanics behind the records an audit will read, see The 45-day DROP cycle, operationally.

Common questions

Who actually performs the audit?

An independent third party. The audit regulations that will define the process in detail haven't been written yet. CalPrivacy named its first Chief Privacy Auditor, Sabrina Boyson Ross, in February 2026, which is the clearest sign so far that rulemaking is moving, not that it's finished.

If a broker uses compliance software to run its cycles, does that cover the audit obligation?

No. The obligation to run the cycle and keep the records belongs to the broker regardless of which tool did the matching: software doesn't stand in for the broker at audit time, and a license agreement that disclaims liability doesn't transfer the recordkeeping duty to whoever wrote the code.