California’s DROP Is Now in Effect: What It Means for B2B Sales Data and Prospecting Lists
- Jon Elhardt

- 11 minutes ago
- 7 min read

For years, buying B2B contact data followed a familiar pattern. A sales team purchased a list, imported it into its CRM, and began calling or emailing the people on it.
California’s new privacy system does not make that process illegal. It does, however, give sales leaders another reason to ask where their prospect data came from, how recently it was verified, and whether their data providers can keep it current.
On August 1, 2026, an important part of California’s Delete Act took effect. Registered data brokers must now begin processing deletion requests submitted through the state’s Delete Request and Opt-Out Platform, better known as DROP.
For businesses that depend on third-party contact data, this change may affect which records remain available, how often databases need to be updated, and what sales teams should expect from their data providers.
The short version is simple: DROP does not ban B2B prospecting, but it makes static, poorly documented prospect databases even more difficult to trust.
This article is intended for general informational purposes and does not constitute legal advice. Businesses should consult qualified legal counsel regarding their specific privacy obligations.
What Is California’s DROP System?
DROP stands for the Delete Request and Opt-Out Platform. It was created under California’s Delete Act to give residents a simpler way to request the deletion of personal information held by registered data brokers.
Previously, a California resident who wanted their information removed had to identify data brokers individually and submit separate requests to each one. That was difficult because many people did not know which companies had collected or sold their information.
Through DROP, residents can submit one request that is distributed to active data brokers registered with the state.
According to the California Privacy Protection Agency, residents have been able to submit DROP requests since January 1, 2026. Starting August 1, registered data brokers became responsible for retrieving and processing those requests.
The state requires data brokers to check DROP at least once every 45 days. If a resident’s information matches the broker’s records, the broker generally must delete the associated personal data, including inferences created from that data, unless a legal exception applies. The broker must also report how it handled the request.
This is not a one-time database cleanup. It creates an ongoing process for identifying people who have requested deletion and preventing their information from simply returning during the next data refresh.
Why Should B2B Sales Teams Care?
DROP is aimed directly at data brokers, not every company with a CRM.
Under California law, a data broker is generally a business that collects and sells
personal information about people with whom it does not have a direct relationship. A company storing information about its own customers is not automatically a data broker simply because it uses a CRM.
However, many sales organizations receive contact information from companies that may fall within the definition.
That is where the practical effect reaches B2B sales.
Professional contact information can still be personal information. A work email address, direct phone number, name, title, and employment history may describe a business prospect, but they also describe an individual.
California’s temporary exemption for certain B2B personal information expired at the beginning of 2023. As the International Association of Privacy Professionals explained, B2B personal information became subject to the broader CCPA and CPRA framework once that exemption ended.
That does not mean every business contact must be deleted. It means companies should stop treating B2B data as if privacy rules never apply simply because the information appears on a company website or LinkedIn profile.
What Could Change for Prospecting Lists?
The most immediate effect may be greater movement inside third-party databases.
If people use DROP to remove their information, some data providers may lose certain email addresses, phone numbers, personal details, or inferred attributes. Providers may also need to suppress those records during future updates.
A list purchased six months ago could therefore differ significantly from the version available today.
Of course, sales data already changes constantly. People switch jobs, earn
promotions, move to different departments, change phone numbers, and leave companies. Tendril has previously examined this problem in The Silent 60, which explains how much prospecting data arrives without a usable direct path to the decision-maker.
DROP adds another source of change. A record may no longer be available because the person exercised a privacy right, not simply because the information became outdated.
This creates several practical questions:
Does your provider maintain a suppression process for deletion and opt-out requests?
How frequently does it refresh previously purchased data?
Can it explain where its data came from?
Does it distinguish between confirmed information, inferred information, and guessed information?
What happens when a record must be deleted or restricted after it has been delivered to customers?
Sales leaders may not own the legal answers, but they should be part of the conversation. A data sourcing decision affects sales productivity, deliverability, brand reputation, and compliance at the same time.
If your team is unsure how much of its current list is accurate, Tendril Enrich can help review, clean, and human-verify your prospect data before your reps spend time working through it.
What DROP Does Not Mean

It is equally important to understand what has not changed.
DROP does not automatically erase every California resident from every CRM. It does not prohibit companies from keeping information obtained through a direct customer relationship when there is a valid reason to retain it. It also does not make all B2B prospecting illegal.
The direct DROP obligations apply to businesses that meet California’s definition of a data broker. Other privacy requirements may apply to companies using the data, but those obligations depend on the company, the information, how it was collected, and how it is being used.
This is why a blanket reaction such as “We can no longer prospect in California” would be inaccurate.
The better response is to understand your data supply chain and involve legal or privacy specialists when necessary.
How Sales and RevOps Teams Can Prepare
You do not need to become a privacy attorney to improve the way your company manages prospect data. A few operational steps can make your database more reliable and help your legal team understand how information moves through the business.
1. Map Where Your Prospect Data Comes From
Create a list of every source feeding contact information into your CRM
.
That may include:
Purchased databases
Data enrichment providers
Event and webinar registrations
Website forms
Partner referrals
Public company directories
Sales representatives’ manual research
CRM integrations and sales intelligence tools
Do not assume everyone internally knows which systems are adding or updating records. Many companies discover that several platforms are enriching the same contact fields without clear ownership.
2. Ask Providers Direct Questions
Sales technology evaluations usually focus on database size, accuracy,
integrations, and price. Privacy operations should now be part of that evaluation.
Ask providers whether they are registered as data brokers in California, how they process DROP requests, how often they refresh customer data, and what happens when a record is deleted after being delivered.
A provider should be able to explain its process clearly. Vague claims such as “fully compliant data” are not a substitute for a real answer.
3. Separate First-Party and Third-Party Data
Your CRM should make it possible to understand how a contact entered the system.
A person who submitted a demo request is different from someone added through a purchased list. A current customer is different from a prospect whose information came from a third-party database.
Recording the source of each contact helps teams apply the correct internal process and avoid treating every record the same way.
4. Replace Occasional Cleanups With Continuous Maintenance
A yearly CRM cleanup is no longer enough for an active outbound team.
Records change too quickly. Privacy requests, job changes, company restructuring, email bounces, and disconnected phone numbers continue throughout the year.
Data hygiene should be an operating process rather than a rescue project. Teams should regularly verify high-priority accounts, remove unusable records, document contact sources, and monitor whether information has changed.
For teams that want to see what human verification can uncover, Tendril offers free enrichment for up to 250 contacts, with cleaned and enriched results returned within 48 hours.
5. Connect Opt-Out Processes Across Your Sales Tools
An opt-out recorded in one platform should not disappear when data moves to another.
Review how your CRM, sales engagement platform, dialer, marketing automation system, and enrichment tools exchange suppression information. Otherwise, a record removed from one campaign may be reintroduced by another integration a week later.
HubSpot, Salesforce, Outreach, and other platforms can only enforce the information they receive. Clear system ownership matters just as much as the software itself.
6. Train Reps to Report Data Problems
Sales representatives are often the first people to discover that a record is wrong.
They learn when someone has changed roles, when a number belongs to a different employee, or when a prospect asks not to be contacted again. That information should not remain buried in call notes.
Create a simple way for reps to flag incorrect, outdated, or restricted records. Every correction makes the next campaign more accurate.
Better Data Is Not Only a Compliance Issue

Privacy changes often reach sales teams as a list of restrictions. But better data management also produces a better sales process.
When reps work from accurate, current information, they waste fewer calls, send fewer emails to dead addresses, and spend more time speaking with people who are actually relevant to the offer.
That protects more than compliance. It protects sender reputation, calling reputation, employee time, and the prospect’s experience with your company.
California’s DROP system is another reminder that a large database is not necessarily a valuable database. The number of records matters less than whether those records are current, usable, properly sourced, and connected to the right decision-makers.
Turn Your Prospect Data Into Real Conversations
Your sales team should not have to guess whether its contact data is accurate.
Tendril Enrich combines data mining, cleaning, and human verification to help companies identify the right prospects and correct incomplete or outdated records. When paired with Tendril Connect’s agent-assisted dialing, that cleaner data can be turned into more live conversations without forcing sales reps to spend their day navigating bad numbers, switchboards, and dead ends.
Request a Tendril demo to review your current outbound process, identify where unreliable data is costing your team time, and see how human-verified enrichment can help you build a more dependable path to the people you need to reach.





Comments