MCStanding runs the California DELETE Act's 45-day DROP cycle, screens every file you acquire against consumers who already asked to be deleted, and produces evidence an auditor can verify on their own machine. Across eleven jurisdictions, without your customer data ever leaving your browser.
New Jersey has prohibited selling or licensing sensitive data outright since 30 June 2026, at $50,000 per record. California runs its own meter at $200 per request per day with no cure period, and has already fined LocateSmarter LLC $116,490 on 11 August 2026 and Cybba Inc. $52,400 two days later — every action, with links to the orders.
Since 1 August 2026, every registered data broker must access California's Delete Request and Opt-out Platform (DROP) at least once every 45 days, download the consumer deletion list, match it against their own records, act on every request, and report an outcome for each one. There is no cure period, and brokers are forbidden from verifying the requester.
Penalties accrue at $200 per request, per day, uncapped. Registration with CalPrivacy costs $6,000 a year and is due between 1 and 31 January. From 1 January 2028 an independent third-party audit is required every three years, with records retained six years and produced within five business days of a written request.
DROP compliance fails quietly. Identifiers are matched as SHA-256 hashes, so if your normalisation is wrong by a single rule, every hash you generate is wrong, every match misses, and you report "not found" for consumers who are sitting in your database. The platform accepts it. Nobody objects. The discrepancy surfaces at the audit, with the penalty compounded.
Brokers must ensure deleted consumers stay deleted. Someone removed in July who reappears in a list purchased in September must not be re-ingested — and re-acquisition is invisible, because the cycle that processed them was correct and the outcome reported was correct.
MCStanding builds a hash-only suppression list from everything you have already processed and screens each inbound file against it before the data reaches your systems, returning a cleaned file and a report of what was blocked. It is the operation you run on every acquisition, not once every 45 days.
| Type | Jurisdiction | Notes |
|---|---|---|
| Registry and deletion platform | California — DELETE Act / DROP | $6,000/yr, Jan 1–31, $200 per request per day |
| Registry | Connecticut | Effective 1 Oct 2026; registration from 1 Jan 2027; own deletion mechanism 2028 |
| Registry | Texas · Oregon · Vermont | Registration and disclosure duties |
| Individual erasure | EU GDPR · UK GDPR | One month, extendable; Article 19 downstream notice |
| Individual erasure | Brazil LGPD | 15 days — the tightest clock |
| Individual erasure | Canada PIPEDA · Québec Law 25 | 30 days; Law 25 adds de-indexation |
Erasure regimes attach to processing, not to broker status — a business can fail every prong of the US broker definition and still owe a one-month GDPR erasure response. Every date, fee and penalty in the software carries its statutory citation so you or your counsel can check it.
DROP publishes deletion requests as hashes rather than plaintext, which makes matching a deterministic offline computation. It never required a cloud platform.
Every alternative in this category is a hosted service, so complying means sending your customer
database to a third party. MCStanding does the same computation locally. The site sends
connect-src 'none', meaning the page cannot open a network connection at all — your
security team can confirm that from the response headers in about ten seconds, without reading any
code or taking our word for it.
Open the app and choose "See a worked example". A fictional broker with a real history loads in about a minute, deliberately including problems worth finding. No account, no card, nothing to install and nothing uploaded.