California’s DROP platform creates a centralized system for residents to request deletion of personal information held by registered data brokers.
California’s DROP privacy platform is now entering its enforcement phase, requiring registered data brokers to process centralized deletion requests from residents beginning August 1, 2026.
For years, Americans concerned about their personal information being bought and sold faced an exhausting problem: even if you wanted your data deleted, you often had to track down individual companies and submit separate requests.
California is attempting to change that model.
The state’s Delete Request and Opt-Out Platform, or DROP, allows California residents to submit a single verified request directing registered data brokers to delete personal information associated with them. The platform opened to consumers on January 1, 2026, and as of August 1, 2026, registered data brokers are required to begin retrieving and processing those requests.
That makes California’s new privacy system more than another opt-out website. It places an ongoing legal obligation on covered data brokers.
What Exactly Is DROP?
DROP was created by the California Privacy Protection Agency, or CalPrivacy, as part of the state’s Delete Act, which originated with Senate Bill 362.
The law required California to establish an “accessible deletion mechanism” allowing a consumer to make one verifiable request asking registered data brokers holding information about that person to delete it. Consumers can also choose to exclude particular brokers from their request.
The significance is simplicity.
Instead of finding potentially hundreds of companies, navigating their privacy pages and completing individual deletion procedures, an eligible California resident can initiate the process through one state-run system.
CalPrivacy describes DROP as a first-of-its-kind state-hosted platform.
The August 1 Deadline Changes Everything
Californians have been able to submit DROP requests since January.
But August 1, 2026 is when the major obligation for data brokers kicked in.
Covered data brokers must access DROP at least once every 45 days and process applicable deletion requests. The statute generally requires brokers to process requests within 45 days after receiving them through the mechanism, subject to specified exceptions.
And it isn’t necessarily a one-and-done deletion.
After a consumer’s information has been deleted, covered brokers generally must continue deleting newly acquired personal information associated with that consumer at least once every 45 days, unless an exception applies or the consumer changes the request. The law also generally prohibits the broker from subsequently selling or sharing newly obtained information about that consumer.
That ongoing requirement may ultimately be one of the most powerful parts of the law.
What Is a Data Broker?
California law generally defines a data broker as a business that knowingly collects and sells personal information about consumers with whom it does not have a direct relationship.
There are important statutory exclusions, including certain entities or activities covered by laws such as the Fair Credit Reporting Act and Gramm-Leach-Bliley Act, among others.
Data brokers can possess surprisingly detailed information.
CalPrivacy says information collected and sold by brokers can include things such as Social Security numbers, precise geolocation information, health-related information and browsing history.
And many consumers may have little idea which companies possess that information.
That is precisely the problem DROP was designed to address.
Does This Delete Your Information From the Entire Internet?
No — and that’s an important distinction.
DROP isn’t a universal internet “delete me” button.
The system applies to businesses covered by California’s definition of a registered data broker. Other organizations and information may fall outside the law or qualify for statutory exemptions.
That means submitting a DROP request doesn’t automatically erase your Facebook account, remove government records, wipe banking records or make every reference to you disappear from the internet.
It targets the specific data-broker ecosystem governed by California’s Delete Act.
What Happens When a Broker Can’t Verify You?
There’s another interesting protection built into the law.
If a data broker cannot verify a deletion request, the statute generally requires the broker to treat the request as an opt-out from the sale or sharing of the consumer’s personal information, subject to applicable limitations.
In other words, a failed identity match doesn’t necessarily mean the request simply disappears.
California Is Putting Real Enforcement Behind Privacy
DROP also fits into a larger California effort to regulate the data-broker industry.
Companies meeting California’s definition of a data broker must register annually with CalPrivacy. The agency has already pursued enforcement actions against companies over registration requirements.
The requirements will become even more substantial.
Beginning January 1, 2028, covered data brokers must undergo an independent third-party compliance audit every three years.
That creates a combination of centralized consumer requests, recurring deletion obligations, registration requirements, regulatory enforcement and eventual independent audits.
Could California’s Model Spread?
That’s now the larger question.
California has repeatedly influenced how companies handle consumer privacy because businesses operating nationally often find it easier to build systems around strict state requirements than maintain completely different infrastructure for every jurisdiction.
DROP takes that idea another step.
Rather than telling consumers they have a privacy right and then forcing them to chase hundreds of companies to exercise it, California has created centralized infrastructure designed to make that right considerably easier to use.
Whether other states eventually adopt similar one-request deletion systems remains to be seen.
But the concept could fundamentally alter the privacy debate.
For years, consumers have essentially been asked to manage an industry they cannot see: find out who has your information, determine how they obtained it, locate their privacy process and then ask each company individually to stop selling or delete it.
California’s answer is much simpler:
Make one request — and put the compliance burden on the data brokers.
For California residents concerned about how much of their personal information is circulating through the data economy, August 2026 marks a significant shift in who controls that information.
Official resources: California Data Broker Registry and DROP information | CalPrivacy data broker guidance
Sources: California Privacy Protection Agency (CalPrivacy); California Delete Act/SB 362; California Civil Code §§ 1798.99.80–1798.99.89.