Privacy law update
California’s DROP Has Entered Its Processing Phase
California data brokers began processing DROP deletion requests on August 1, 2026. Here is what the tool does, who may use it, and where its limits remain.

Deleting personal information from the data-broker market has traditionally required people to identify companies they may never have heard of, find each company’s request process, and repeat the same work. California’s Delete Request and Opt-out Platform, known as DROP, is designed to replace much of that repetition with one state-run request.
The timing matters. Californians have been able to submit DROP requests since January 1, 2026, but August 1 marked a second stage: registered data brokers became legally required to retrieve and process those requests. That makes DROP an active privacy tool rather than only a promise of future relief.
Who can use DROP
DROP is for California residents. The state’s official DROP overview says eligibility is verified through the California Identity Gateway. A person does not need to create an Identity Gateway account, and the state says the information used for that eligibility check is not retained by DROP. A Florida resident does not gain California residency—or access to this California-specific mechanism—simply by visiting a California website or dealing with a California business.
The program implements California’s Delete Act, enacted as Senate Bill 362 in 2023. The law defines a data broker generally as a business that knowingly collects and sells personal information about a consumer with whom it has no direct relationship. It excludes certain entities to the extent they are covered by laws including the Fair Credit Reporting Act, the Gramm-Leach-Bliley Act, specified insurance privacy law, or particular health-information exemptions.
What one request can do
A DROP request goes to all active data brokers in the system unless the consumer chooses to exclude particular brokers. The official consumer instructions say a request may be submitted with only a name, date of birth, and ZIP code. People may add information such as email addresses, phone numbers, mobile advertising identifiers, connected-TV identifiers, or a vehicle identification number to improve the chance of a match. Providing more information is optional, but a broker cannot delete a record it cannot reliably connect to the requester.
When a broker finds a match, the Delete Act generally requires it to delete associated non-exempt personal information and direct relevant service providers or contractors to do the same. That obligation can include inferences derived from the consumer’s data. The law also requires continuing attention: after deletion, the broker generally must recheck at least every 45 days and delete newly acquired matching information, unless an exception applies or the consumer changes the request.
Why a request may not show “deleted”
DROP is not an instant erase button. California says consumers may wait up to 90 days for status information while brokers complete their initial processing cycle. The platform can report several outcomes, including Deleted, Exempted, Opted-out, Record not found, and Pending.
Those labels deserve a careful reading. “Record not found” may mean the broker has no information about the person, or that the submitted details were not enough to produce a match. “Exempted” means the broker identified information it is legally permitted to retain. When a deletion request cannot be verified, the statute generally directs the broker to process it as an opt-out of sale or sharing instead, subject to the law’s limits.
A requester does not need to start over every 45 days. The state explains that brokers must retain the request and continue taking steps to keep matching information out of their systems. Consumers can also return to their profile to add updated identifiers if an email address, phone number, device, vehicle, or name changes.
What DROP does not reach
The mechanism is aimed at registered data brokers, not every organization that holds personal information. Data provided directly to a business with which a person has a relationship may fall outside a DROP request. Publicly available information and data covered by statutory exemptions may also remain. DROP therefore should not be presented as a universal deletion system or a guarantee that every trace of someone’s information will disappear.
Its larger value is structural. A privacy right is difficult to use when exercising it requires dozens or hundreds of separate requests. By creating one entry point, a reusable request, visible status information, and recurring deletion duties, California has reduced some of that friction. The design is also a useful privacy-advocacy lesson: meaningful rights need practical delivery systems, not only language in a statute.
This article provides general educational information, not legal advice. It describes California law and official guidance checked on September 26, 2026; it does not suggest that California-specific rights apply to residents of other states.