Since January 1, 2026, California residents have been able to submit a single deletion request through DROP — the Delete Request and Opt-Out Platform — that reaches every registered data broker in the state at once. The platform launched. The requests started flowing. By the time August arrived, more than 300,000 Californians had submitted DELETE requests through the system.
The problem through most of the year: data brokers weren’t legally required to act on those requests on any mandatory timetable. Compliance was expected but not enforced.
August 1 changed that.
What the Enforcement Deadline Actually Requires
Starting August 1, 2026, registered data brokers have specific legal obligations under the DELETE Act’s new rules:
- They must access the DROP platform at least once every 45 days
- They must process consumer deletion requests within that window
- Any request they cannot fulfill through deletion (because they can’t verify the person’s identity) must be treated as an opt-out from data sale and sharing — not ignored
- Non-compliance carries fines of $200 per day, per violation
The math on that last point is significant. One missed 45-day cycle — one data broker failing to check DROP for a single quarter — produces $1.5 billion in theoretical liability across the 600+ registered brokers. Not every broker will be fined, and enforcement has practical limits. But the financial stakes of non-compliance are now genuinely consequential.
What DROP Is and How It Works
DROP stands for Delete Request and Opt-Out Platform. It’s operated by the California Privacy Protection Agency (CPPA) — the state agency created specifically to enforce the CPPA and related California privacy laws.
The core function: instead of filing deletion requests individually with hundreds of data brokers (a process that would take weeks and require re-submission every few months), DROP lets Californians submit a single request that automatically reaches all registered brokers simultaneously.
To submit a request:
- Visit the CPPA’s DROP portal (accessible through the CPPA’s website)
- Complete an identity verification process — required to prevent fraudulent deletion requests
- Submit your request
From that point, every registered data broker in California is legally required to retrieve your request within their 45-day access cycle and process it — meaning they must delete your personal information from their databases, or opt you out of data sale if identity verification issues prevent full deletion.
Who Is a “Data Broker” Under This Law?
This matters, because the DELETE Act doesn’t cover every company that holds personal information.
The California DELETE Act defines data brokers as businesses that “knowingly collect and sell to third parties the personal information of a consumer with whom the business does not have a direct relationship.”
That definition excludes most companies you’ve dealt with directly. Google holds vast amounts of personal data, but users have a direct relationship with Google as a service provider — Google isn’t classified as a data broker for DELETE Act purposes in its primary role. The same logic applies to Facebook, Amazon, Apple, and most apps you’ve willingly signed up for. The data those companies collected in their capacity as service providers falls under their own privacy policies and CCPA’s separate opt-out mechanisms.
The companies covered by DROP are a different category: background check services like Spokeo, WhitePages, and BeenVerified; data aggregators that compile profiles from public records, credit files, and third-party purchases; marketing intelligence firms; financial data aggregators; people-search sites. These are businesses whose entire model is collecting and selling data about people they’ve never had a direct relationship with.
More than 600 such businesses are currently registered with the CPPA. That number is also probably low — there are companies operating as data brokers that haven’t registered, either through non-compliance or through good-faith uncertainty about whether they meet the definition.
What “Processing” Your Request Actually Involves
When a data broker processes your DROP request, the outcome depends on the type of broker.
People-search sites (Spokeo, WhitePages, BeenVerified, Whitepages, PeopleFinder, and dozens of similar services) are required to remove your public profile from their directories. Your name, home address, phone number, relative information, and any other compiled profile data should be removed from what appears in search results.
Background check companies provide information to landlords, employers, and other screeners. Deletion from these databases means your record should no longer appear in background check queries by your name. Some providers archive records for legal compliance purposes but are required to remove them from their commercial products.
Marketing data firms sell audience segments to advertisers — “35-45 year old homeowners with children interested in home improvement” built from individual-level records. Deletion means your record should be removed from these commercial audiences and your data should no longer be sold to advertising buyers.
Financial data aggregators compile spending behavior, credit patterns, and financial health indicators. Deletion here affects the data used in credit prescreening, insurance pricing, and financial product targeting.
The processing window: a broker that checks DROP on day 1 of a new cycle has up to 45 days before your request must be complete. For requests submitted shortly before a broker’s DROP check, that could mean roughly six weeks until your data is actually removed from active systems.
The Verification Hurdle
DROP requires identity verification before a deletion request can be submitted. This is designed to prevent fraudulent requests — a malicious actor filing deletion requests for someone else, effectively erasing their credit or background check records without consent.
The verification process uses information about the requester to confirm identity. For most people, this works. For some, it creates friction:
- People with recent address changes (military families, frequent movers) may have mismatches between current and historical records
- People with common names and limited credit history may have harder verification paths
- Some immigrant communities with limited public records footprint may find the verification system doesn’t confirm their identity cleanly
When DROP’s verification process can’t confirm identity sufficiently to process a full deletion, the request defaults to an opt-out rather than deletion — meaning the broker stops selling the data but may retain the record internally. This is better than nothing, but it’s a meaningful difference from full removal.
What DROP Can’t Do
DROP is a significant legal tool. It’s also specific in what it covers, and understanding its limits prevents false comfort.
It only covers registered brokers. The 600+ registered brokers represent a substantial portion of the data broker industry, but registration isn’t universal. Companies that should be registered but aren’t — either through non-compliance or definitional ambiguity — aren’t bound by DROP requests. The CPPA is responsible for enforcement against unregistered brokers, but that’s a separate process from the consumer opt-out system.
It doesn’t reach first-party data. The data Google, Meta, Apple, and the apps you’ve directly used have collected about you isn’t governed by the DELETE Act’s broker-specific provisions. Your rights regarding that data exist under CCPA’s separate mechanisms — the right to know, right to delete, and right to opt out of data sale that apply to first-party companies directly.
Deletion has to be repeated. Data brokers continuously collect new information from public records, property filings, court records, and social media. A deletion today doesn’t prevent your information from reappearing in broker databases when a new public record is filed. The CPPA recommends annual re-submission of DROP requests as a maintenance practice.
Not all data categories are included. Some data held by brokers — used for fraud prevention, legal compliance, or research purposes — may be exempt from deletion obligations under specific circumstances. The exemptions are narrow, but they exist.
The $21 Billion Problem This Addresses
Context for why this enforcement matters: a February 2026 report from the Senate Judiciary Committee found that data broker leaks and breaches cost Americans an estimated $21 billion annually through identity theft, targeted fraud, and financial account compromise.
Data brokers enable sophisticated fraud because they aggregate records from hundreds of sources into profiles that include: home address and address history, family member names and relationships, phone numbers (including historical numbers), employer and employment history, financial behavior indicators, and often photos or social media content pulled from public profiles.
With this profile data, a fraudster doesn’t need to guess who you are or what you care about. They can reference your neighborhood, name your family members, mention your actual service providers, and construct a call or message that passes the common tests people use to distinguish legitimate contact from scams. The 2026 fraud economy is built significantly on data broker databases.
DROP deletion doesn’t eliminate all of this — but removing your record from commercial data broker databases reduces the profile available to bad actors who purchase this data, and it reduces the likelihood of your information appearing in future breach datasets.
For People Outside California
California remains the only state with a centralized DELETE Act-style platform. Other privacy laws — Virginia’s VCDPA, Colorado’s CPA, Texas’s TDPSA — include data broker provisions and deletion rights, but none have built a DROP-equivalent platform.
For consumers in other states, the practical options are:
Individual broker opt-outs. Most major data brokers maintain individual removal pages. The work of finding and completing these is substantial — there are hundreds of brokers, each with its own process, and removal needs to be repeated every few months. But it’s possible.
Commercial data removal services. Services like DeleteMe, Kanary, and Incogni automate individual broker opt-outs for a subscription fee, typically in the $100-150 per year range. They handle the ongoing re-submission that manual opt-outs require.
Minimal exposure as prevention. The most effective long-term strategy is limiting what enters data broker databases in the first place — opting out of voter registration lists being made public (where state law allows), using alternate contact information for retail loyalty programs, being selective about what public records your activities generate.
What This Means for Personal Data Privacy Broadly
The DELETE Act’s enforcement mechanism is one concrete piece of a larger shift in how personal data is regulated. The California Privacy Protection Agency launched a dedicated “Data Broker Strike Force” in early 2026 to pursue unregistered brokers — meaning the enforcement posture is actively expanding, not limited to the 600+ who registered voluntarily.
For California residents, submitting a DROP request today is worthwhile. The process takes about fifteen minutes, reaches all registered brokers simultaneously, and requires re-submission annually rather than continuously. For a $0 cost, the risk reduction is meaningful.
For users in other states, the advocacy question is becoming concrete: twenty states have introduced or passed privacy legislation that includes data broker provisions. The DROP model — a centralized platform making the opt-out process practical rather than theoretical — is what consumer advocates are pushing for in those states. How the California enforcement works in practice over the next 18 months will inform what other states build.
Storing Personal Data You Actually Control
The broader issue that DROP addresses — personal information circulating in systems you didn’t choose and can’t directly access — reflects a fundamental asymmetry in data ownership. You generate the information. Companies aggregate it. You have, in California, a legal mechanism to request deletion. But the cycle continues as new information is generated and collected.
The most durable approach to this asymmetry isn’t just deletion requests — it’s being deliberate about what you generate and where you store the personal files you do control. Tax records, identity documents, health files, personal communications — these don’t belong in general cloud storage platforms designed to analyze and process content.
daftei provides storage where files are encrypted in transit (TLS 1.3) and at rest (AES-256), where the business model doesn’t depend on analyzing what you store, and where account deletion includes a 30-day grace window followed by permanent, irreversible erasure — not indefinite backend retention dressed up as deletion.
That’s a different relationship with personal data than what data brokers offer. DROP gives you a tool to push back against the broker side of that relationship. Deliberate storage choices limit what enters the ecosystem in the first place.
Both matter.