Privacy rights are becoming easier to exercise and more difficult to operationalize. Over the last several years, organizations have steadily adapted to growing volumes of data subject access requests (DSARs). Many privacy teams refined workflows, documented procedures, and invested in technology to keep pace with expanding regulatory requirements. At the same time, citizens have become more aware of their privacy rights, leading to a consistent increase in requests across industries.
Now, generative AI has dramatically lowered the barrier to submitting detailed privacy requests. Individuals no longer need to understand privacy law or spend hours drafting a request. In seconds, AI tools can generate lengthy, highly detailed DSRs covering multiple systems, communication channels, audit logs, metadata, and supporting explanations. What was once an occasional administrative process is quickly becoming a recurring operational challenge.
From the regulatory side, California's Delete Request and Opt-Out Platform (DROP) reinforces that same trend. Beginning August 1, 2026, registered data brokers must retrieve deletion requests from the state-operated platform every 45 days, fulfill those requests across their environments, and report their status back through DROP. Rather than responding to requests one at a time, organizations must prepare for recurring, large-scale deletion workflows.
The result? Privacy rights are becoming continuous operational processes, and technology increasingly defines how organizations deliver them.
Key Takeaways
- AI is making DSRs easier to generate, increasing both the volume and complexity of privacy requests.
- California DROP shifts deletion rights from individual interactions to recurring operational workflows for data brokers.
- Manual, case-by-case processes struggle to scale across fragmented systems, third parties, and growing request volumes.
- Privacy leaders should prepare for repeatable, auditable workflows that support defensible rights fulfillment across the entire data lifecycle.
AI Is Raising Expectations for Privacy Rights
Organizations have always received broad privacy requests, what's changing is how easily those requests can be created.
Modern AI assistants can produce comprehensive DSR templates that ask for personal information across email systems, collaboration platforms, customer support records, call recordings, HR systems, access logs, and countless other repositories. Many also request explanations of search methodologies, audit records, redactions, and decisions made during fulfillment.
The result is more, and more sophisticated, requests that require greater coordination across legal, privacy, IT, security, HR, and business teams.
Privacy teams are also seeing patterns that suggest greater automation. These include:
- nearly identical requests arriving within short timeframes;
- unusually formal language;
- exhaustive lists of statutory rights; and
- references spanning multiple jurisdictions all increase the operational effort needed during triage.
None of these characteristics invalidate a request, but they do reinforce the need for consistent intake, verification, scope management, and documentation throughout the fulfillment process.
As request complexity increases, organizations need processes that distinguish between understanding the request, determining an appropriate scope, documenting decisions, and executing searches that are reasonable, proportionate, and defensible.
California DROP Turns Individual Rights Into Recurring Operations
The Delete Request and Opt-Out Platform gives California residents a centralized mechanism to request deletion from registered data brokers through a single submission. Beginning August 1, data brokers must process DROP requests at least once every 45 days, retrieving new deletion requests, process them across relevant systems, delete associated personal information and inferences where required, and report completion status back through the platform.
Traditional DSR programs often begin when an individual contacts an organization directly. DROP introduces recurring batches of requests originating from a state-operated platform, creating standardized processing cycles that require repeatable execution rather than individual handling.
Organizations must identify individuals across multiple identifiers, match information within distributed systems, coordinate deletion across internal environments and downstream partners where appropriate, document outcomes, and maintain evidence that requests were processed correctly. The complexity sits largely behind the scenes, where identity matching, workflow orchestration, reporting, and auditability determine whether organizations can meet their obligations consistently.
Could Your Organization Qualify as a California Data Broker?
California's definition of a data broker reaches further than many organizations expect. If your business collects, enriches, licenses, or shares personal information beyond direct customer relationships, it's worth taking a closer look.
Take our five-minute interactive assessment to see whether your organization should evaluate its obligations under California's data broker framework.
Manual Privacy Operations Reach Their Limits
Many privacy programs evolved around relatively low volumes of requests managed through inboxes, spreadsheets, ticketing systems, or disconnected workflows.
That model becomes increasingly difficult to sustain as both regulatory obligations and individual expectations continue to expand.
One request may require searching structured databases, unstructured documents, messaging platforms, archived systems, cloud applications, and third-party environments. Another may require clarification because the scope is so broad that a proportionate search cannot begin without additional context. Meanwhile, organizations must continue verifying identities, tracking deadlines, documenting decisions, and maintaining complete audit records.
The recent increase in privacy requests has reinforced these operational pressures across the industry. Organizations report greater manual triage effort, increased verification workloads, more difficulty distinguishing legitimate requests, and growing pressure on privacy operations teams as request volumes continue to rise.
These challenges don't originate from a single regulation, they emerge when multiple trends converge, including growing consumer awareness, increasingly sophisticated requests, expanding regulatory expectations, and larger volumes arriving simultaneously.
Technology Is Becoming the Operating Model for DSRs
Compliant organizations increasingly need connected workflows that support request intake, identity verification, intelligent routing, data discovery, fulfillment, documentation, reporting, and ongoing evidence collection across complex data environments.
Technology also creates opportunities to improve consistency. AI-assisted capabilities can help identify relevant information across structured and unstructured repositories, reducing manual effort while supporting more comprehensive searches. Human review remains essential, particularly for complex requests, but automation enables privacy teams to focus their expertise where it delivers the greatest value.
For organizations preparing for California DROP, these capabilities become even more important. Recurring deletion obligations require repeatable execution, clear ownership, and the ability to demonstrate how requests were received, processed, fulfilled, and documented over time.
This is where DSR Automation supports privacy operations: rather than relying on disconnected manual processes, organizations can centralize request management, orchestrate fulfillment across systems, maintain audit trails, and build repeatable workflows that support growing volumes of privacy rights requests.
What Privacy Teams Should Do Next
California's DROP is arriving at the same time as individuals are becoming more empowered to exercise their privacy rights. Together, these two drivers reinforce the same message for privacy leaders. Successful privacy programs depend on repeatable processes, clear ownership, connected systems, and the ability to demonstrate consistent execution across every stage of the rights fulfillment lifecycle.
Understanding your obligations is only the first step. Preparing your people, processes, and technology for recurring deletion requests requires an operational plan.
Download the California DROP Readiness Checklist to assess your current workflows, identify operational gaps, and prepare your privacy program for AI-driven DSR volumes and recurring deletion obligations.
Learn how OneTrust DSR Automation helps organizations operationalize privacy rights through centralized request management, workflow orchestration, automated fulfillment, and auditable reporting across complex data environments.
Key Questions About AI, California DROP, and DSR Operations