HeyDrop
Try HeyDrop Menu

Your Prospect List Now Has an Off Switch

What switched on this month

On the first of August, a piece of California infrastructure that had been sitting quietly since New Year started issuing instructions to the companies that sell contact data. The California Privacy Protection Agency runs a system called DROP, the Deletion Request and Opt-Out Platform, and the obligation it now carries is short: from August 1, 2026, registered data brokers must access the deletion mechanism at least once every 45 days and process the consumer deletion requests waiting in it.

One request, filed once, reaches every broker registered with the state. It came out of the Delete Act, signed in October 2023, Californians have been able to file since January 1, 2026, and noncompliance runs at $200 per request, per day. By the time that processing obligation arrived, more than 300,000 California residents had already submitted deletion requests.

Three hundred thousand people queued up to be removed from lists they never knowingly joined, during a window when nobody was obliged to do anything about it. That is the part worth sitting with.

The definition that should interest anyone running outbound

The Delete Act defines a data broker as a business that knowingly collects and sells the personal information of a California resident with whom the business does not have a direct relationship. The absence of a relationship is not incidental here. It is the thing being regulated.

The second half gets missed constantly. Business contact information is not carved out of any of this. The CCPA exemption that once covered B2B data expired on January 1, 2023. A work email, a direct dial and a job title belonging to a California resident have been personal information for more than three years.

Put the two together and the shape is clear. Professional contact data is regulated data, and the regulator has just finished building a single button that removes a person from every list sold in the state.

You are probably not a data broker. Your suppliers are.

Worth being precise, because the alarmed version of this is wrong. A company that buys contact data to sell its own product is not selling that data onward, so it is generally not a broker at all. Nothing about running outbound became unlawful in August.

The change landed one step upstream, which is a worse place for it. The vendor you license from is squarely in scope. Which means the asset you are renting now has a deletion cycle attached to it that you cannot see, did not trigger and cannot appeal.

What that looks like from your desk is nothing at all. No notice arrives. No record turns red. Every 45 days a batch of people leaves the source your data comes from, and the only symptom you get is a slow, unexplained decline in a list that used to work.

A second decay curve underneath the one you knew about

Contact data already rots. People change jobs, titles and numbers, and sales teams have priced that in for years by rebuying. This adds a second curve underneath the first, with two properties the original lacks. It costs the person opting out nothing, and it is one action covering every supplier at once. Whoever leaves your vendor’s database has left your next vendor’s database on the same day, so switching providers buys you nothing.

Direct relationship is the whole game

The statute drew its line in an interesting place, and it happens to be the line good salespeople already recognize instinctively. Did this person give you their details, or did you acquire them from somebody who never met them?

A contact who handed over their information in a meeting sits on the other side of that line. They know who you are. They can still ask you to delete their record, and you should honor it, but they are not deleting you by accident while removing themselves from databases they never chose. Everything about that contact is stronger: it was accurate on the day you got it, it arrives with context, and it belongs to a conversation instead of a purchase.

Which puts real weight on a moment most teams treat casually. The exchange at the end of a meeting takes about ten seconds, and it either happens or it quietly does not. If it depends on a paper card going into a jacket pocket, or on somebody typing an email address into a phone while standing up and putting a coat on, it fails often, and every failure sends you back to buying that same person’s details from a third party. A card that shares by QR code, NFC tap, AirDrop or a plain link, and that can sit in Apple Wallet or Google Wallet with nothing for the other person to install, survives that window because it needs one action from them and no typing from either side. If you build your pipeline in meetings and at events, get the HeyDrop app and stop rebuying contacts you have already met in person.

The reverse direction counts for as much. An AI contact scanner that reads paper cards and conference badges into structured contacts turns the stack in the bottom of your bag into first-party records with a known origin, rather than a pile you will eventually give up on and replace with purchased data covering the same people.

Make capture a system, not a personal habit

One rep doing this well is a habit. A team doing it inconsistently produces something worse than no data at all: records with no provenance, so when a deletion request does land nobody can say where the contact came from or whether the company is entitled to hold it.

That is an operations problem before it is a sales problem. Running the team’s cards from one admin panel means every rep captures the same way, joiners and leavers are handled centrally instead of inside a dozen personal phones, and what the team collects comes back in one shape, exporting to CSV or Excel as a CRM-ready record rather than a photo of a business card in somebody’s camera roll. If your first-party contact data currently lives scattered across handsets, set your team up on HeyDrop before you are asked to prove where a record came from.

Five things worth doing before the next cycle closes

Ask your data vendor how they are processing DROP, in writing. Specifically: how often they suppress, and whether deleted people disappear from the exports you already hold or only from future ones. The answer to the second question decides whether your existing lists are quietly non-compliant.

Stop reporting list size as a metric. A number that only ever goes up is now actively misleading, because the underlying population is being removed on a schedule you do not control.

Add a provenance field to the CRM. Event, inbound, referral, purchased, and the date. It takes an afternoon and it is the first thing you will want the day a deletion request arrives.

Convert your warmest purchased records now. Get a reply, get a meeting, get them to save your details. Move them across the line from bought to given while they are still in the database.

Instrument the in-person moments you already pay for. You are funding the flights, the booth and the dinners anyway. The contacts collected there are the only ones nobody else can delete out from under you, and they are usually the ones captured worst.

The category quietly changed

For most of the last decade, data in B2B sales meant something you bought. It was a line item, it was renewable, and the only real question was which vendor had better coverage. California has now drawn a legal boundary around that category and fitted a switch to the outside of it, and three hundred thousand people found the switch before it was even connected.

Everything you gathered yourself sits on the other side of that boundary. It is smaller than the list you can buy, it takes actual work to build, and it is the only part of a contact database that nobody else gets to turn off.

This article and its accompanying image were generated with the assistance of AI.

Ready to go digital?

Create your professional digital business card in under 2 minutes. Free forever plan available.

Try HeyDrop Free →