Notes ·
California Can Finally Make Data Brokers Delete What They Know About Us
California’s Delete Request and Opt-out Platform, better known as DROP, reached its most important milestone on August 1, 2026. Registered data brokers must now begin processing the deletion requests Californians have submitted through the system.
DROP launched for consumers on January 1, but brokers were given until August to connect their systems and prepare for enforcement. A single request now reaches more than 600 registered data brokers. The Electronic Frontier Foundation counted 614 when it published its recent guide.
That replaces an absurd process where people had to identify data brokers individually, locate each company’s privacy form, verify their identity repeatedly and hope every request was honored.
I have used several of those individual opt-out forms before. They were better than nothing, but the burden was placed almost entirely on the person whose information had been collected and sold without a direct relationship in the first place.
DROP changes that balance.
When a broker finds a matching identifier, it must delete the consumer’s non-exempt personal information, including inferences created from that information. It must also direct its contractors and service providers to delete matching records.
That can include contact information, precise location, browsing activity and sensitive assumptions about a person’s health or political views. Public records, exempt information and information given directly to a company through a first-party relationship may remain outside the request.
Brokers must retrieve new requests at least once every 45 days and report what happened within 45 days of downloading them. California describes the initial consumer-facing deletion window as up to 90 days. Afterward, the broker must preserve enough identifiers to prevent newly collected information from being sold or shared again.
The enforcement mechanism has teeth. Failure to register costs $200 per day. Failure to delete information can cost $200 per deletion request for every day the broker remains out of compliance, plus the state’s investigation and enforcement costs. With hundreds of thousands of Californians already submitting requests, that could become expensive very quickly.
California has already used the Delete Act against brokers that failed to register.
As of August 3, I found 10 publicly announced cases where brokers were ordered or agreed to pay a combined $485,400 in administrative fines:
- Growbots: $35,400
- UpLead: $34,400
- Infillion: $54,200
- The Data Group: $46,600
- Key Marketing Advantage: $55,800
- National Public Data: $46,000
- Accurate Append: $55,400
- ROR Partners: $50,000
- Datamasters: $45,000
- S&P Global: $62,600
ROR Partners was also required to pay a $6,600 past-due registration fee, bringing the total ordered payments across those cases to $492,000.
An additional broker, Background Alert, avoided an immediate fine by agreeing to stop operating through 2028. It faces a $50,000 penalty if it violates that settlement, so I have not included that amount in the collected or ordered-fine total.
These were registration cases, not penalties for ignoring DROP deletion requests.
I found no public enforcement order yet against a broker for failing to process a DROP request or remove someone’s information. That is not evidence that every broker is complying. The requirement began only two days ago, and existing brokers have 45 days from August 1 to access DROP and process their first batch. The first meaningful deadline will arrive in September, with some consumer requests taking up to 90 days to complete.
That distinction matters. August 1 was the beginning of enforceable processing, not the date every broker was required to have already erased every record.
As well-intentioned as this law is, I do not like the language used around it.
Regular people are told to “request” deletion, “ask” companies to remove their information or politely submit an opt-out form. When the law protects corporate interests, the language is much stronger. Copyright owners send DMCA takedown notices and attorneys issue demand letters.
I do not want to ask a data broker, pretty please with sugar on top, to stop selling information it collected about me without a meaningful relationship or permission.
People should be able to demand deletion. Brokers should be required to act immediately, provide evidence that every copy and derived profile was removed, identify any claimed exemption and certify the result under penalty of perjury.
The information belongs to the person it describes. The company profiting from it should be the party asking for permission.
The larger test begins now. California has built the system and demonstrated that it will fine brokers that fail to register. The real measure of DROP will be whether the state audits deletion results, identifies brokers that falsely report records as missing or exempt, and uses the much larger per-request penalties when companies refuse to comply.
This is still a meaningful improvement. Privacy rights are not very useful when exercising them requires hundreds of forms and knowledge of companies most people have never heard of.
California has turned that process into one submission and placed the continuing responsibility closer to where it belongs: on the companies collecting, profiling and selling our information.