Skip to content
TrustList
News

California's DROP passes 550,000 sign-ups as data brokers process deletions

Editorial

By TrustList Editorial

Deletion processing began on 1 August; brokers have up to 90 days to report each result, and the fine for failing to delete is $200 a day per consumer.

About California's DROP passes 550,000 sign-ups as data brokers process deletions

California's DROP passes 550,000 sign-ups as data brokers process deletions

6 October 2026: More than 550,000 Californians had signed up to the Delete Request and Opt-out Platform, known as DROP, by the beginning of October, according to CalPrivacy, the state's privacy regulator. Any company that sells or shares personal data and is registered as a data broker in California now has live deletion requests to work through.

Not yet independently verified. Single source: the regulator's own FAQ post. The sign-up and deletion figures are CalPrivacy's and have not been checked against broker records. We will update this when it can be confirmed, and remove this note.

DROP lets a California resident ask all of the more than 650 registered data brokers to delete their personal information in one request. CalPrivacy says brokers started processing requests on 1 August. In the first three months, it reports, 99% of consumers had their information deleted by at least one broker and 70% by 100 or more.

Brokers report the result of each record back to DROP, and the agency says that can take up to 90 days from the moment a consumer submits a request. Each result appears to the consumer as one of five statuses: deleted, exempt, opted out, record not found or pending. The agency notes that "record not found" is a normal outcome, because not every broker holds data on every person, and that some data, such as information a person gave a broker directly, can be exempt under the Delete Act.

The obligation does not end after one pass. CalPrivacy says a consumer needs to submit a request only once, and brokers must honour it on an ongoing basis, checking newly acquired data against the stored requests. A "record not found" result today could therefore turn into "deleted" a year from now.

Matching works on hashed identifiers. DROP collects a name, phone number and email address, plus optional mobile advertising IDs and vehicle identification numbers, because names alone often cannot find a specific record. The agency says the data is hashed on entry so that no one in state government can read it, and brokers use the same hashing method to find matches.

On penalties, the agency is direct: the fine is $200 a day per consumer for failure to delete information as required, plus CalPrivacy's cost of investigation and administrative enforcement action.

Teams that buy or resell consumer data from California residents, or enrich their own records with it, should check how their suppliers handle the ongoing matching step, since a purchased list can reintroduce a record that was already deleted.

Sources

Categories & features

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy