California’s central data broker deletion mechanism is DROP, the state-run Data broker Requests and Opt-out Platform. It lets a verified California resident send one deletion request to covered data brokers and review the outcomes those brokers report.
The law and the platform have different names
The DELETE Act is the statute enacted through SB 362. It amended California’s data-broker registration law and required the California Privacy Protection Agency (CPPA), operating publicly as CalPrivacy, to establish an accessible deletion mechanism. DROP is the Data broker Requests and Opt-out Platform that implements that mechanism. Later SB 361 amendments revised parts of the statutory framework without changing that basic relationship.
This naming distinction prevents two common errors. A person uses DROP, not “the DELETE Act website,” to submit the centralized request. A broker’s legal duties arise from the current statute and regulations, not from the platform name alone. The broader California DELETE Act overview places both components in context.
The mechanism is also narrower than a universal privacy portal. Civil Code section 1798.99.80 defines a data broker as a business that knowingly collects and sells to third parties personal information about a consumer with whom it lacks a direct relationship, subject to listed exclusions. An everyday description of what a data broker is is useful background, but the statutory definition controls which businesses must participate.
What makes the mechanism central
Section 1798.99.86 of the current California Civil Code requires a single verifiable consumer request that can reach every covered data broker maintaining personal information about the consumer. It also allows the consumer to exclude selected brokers, submit information in privacy-protecting ways, use an Agency-operated internet service, and check request status. The statute prohibits charging the consumer to make the request and requires support for authorized agents, language access, and accessibility for people with disabilities.
Centralization changes the route, not the legal limits. DROP transmits a request through one state system, but each broker still performs its own matching and applies the statutory rules to its own records. The mechanism therefore does not create one shared broker database, produce a copy of every profile, or make the Agency decide whether each stored item must be erased.
California residents could submit requests when DROP launched on January 1, 2026. Beginning August 1, 2026, covered brokers became responsible for accessing the mechanism at least once every 45 days and processing received requests under the statutory cycle. The official DROP workflow cautions that status timing varies and that a reported result depends on the particular broker.
How a DROP request moves through the system
The mechanism separates eligibility, request creation, matching, deletion, and reporting. Treating these as distinct stages makes status results easier to interpret.
| Stage | Responsible party | What the stage establishes | What it does not establish |
|---|---|---|---|
| Residency verification | CPPA through the state eligibility process | The consumer qualifies to submit through DROP under section 7620. | That every identifier belongs to one unique broker record. |
| Request creation | Consumer or authorized agent | The profile supplies identifiers for comparison and defines which active brokers receive the request. | That every listed broker has information about the consumer. |
| Record matching | Each participating data broker | Hashed, standardized identifiers correspond to records in that broker’s systems under section 7613. | That another broker will find the same match. |
| Processing | Data broker and its service providers or contractors | Covered matched information is deleted or another legally defined outcome is applied. | That exempt or first-party information was erased. |
| Status reporting | Each data broker through DROP | The broker reports a defined response code under section 7614. | Independent confirmation that no relevant information exists anywhere else. |
Eligibility and request information
Under sections 7620–7622 of the effective regulations, the Agency verifies California residency before submission. A consumer who cannot be verified cannot submit at that point and may use the regulation’s review process. This eligibility decision is separate from the identifiers later compared with broker records.
CalPrivacy’s consumer instructions say a request can be submitted with name, date of birth, and ZIP code. A consumer may also provide email addresses, phone numbers, mobile advertising identifiers, connected-TV identifiers, and vehicle identification numbers. Optional identifiers may help a broker find a corresponding record, but supplying more information is not a guarantee of a match or deletion.
Submitting the request authorizes disclosure of its personal information to brokers for processing until cancellation, as section 7620 provides. The regulations separately prohibit a broker from selling or sharing information received from the Agency, restrict its use to compliance, require reasonable security, and prohibit contacting the consumer to verify the DROP request.
Broker matching and deletion
The DROP processing regulations require brokers to standardize comparable data in their records, apply the same hashing method used for the relevant deletion list, and compare the resulting identifiers. When a match is found, the broker must address the personal information associated with that matched identifier, rather than delete only the identifier supplied in the request.
For covered matched data, deletion may consist of permanent erasure, deidentification, or aggregation under section 7613. The rule permits delayed removal from an archive or backup until that system is restored to an active system or accessed for a sale, disclosure, or other commercial purpose. It also requires the broker to direct associated service providers and contractors to delete relevant information as required by the statute.
The request has a continuing component. Under Civil Code section 1798.99.86(d), after completing deletion a broker must reapply deletion to the consumer’s personal information at least once every 45 days and must not sell or share newly obtained personal information, unless the consumer requests otherwise or a stated exception permits the activity. For an initial nonmatch, the regulations require retaining the request list for future comparison for the limited compliance purpose.
How to read DROP status results
The effective regulations define four broker response codes, while the consumer interface also displays a pending state. Each result answers a limited question about that broker’s processing:
- Deleted means the broker matched an identifier and reported deleting the associated personal information required by the mechanism.
- Opted out means an identifier mapped to multiple consumers, so the broker could not verify one unique deletion target and instead applied an opt-out of sale or sharing to the associated consumers.
- Exempted means the broker matched a record but reported that all related information was exempt from deletion.
- Record not found means the broker found no match after applying the prescribed comparison process. It can reflect absence of a record or insufficient matching information.
- Pending means the broker has not yet reported a completed outcome through DROP; it is not itself evidence of noncompliance.
A status is a broker report within the platform, not a government certificate of complete erasure. The Agency’s status explanation likewise notes that results vary by broker and that some information may be legally retained.
What the central request does not cover
The statute incorporates deletion exceptions from other California privacy provisions. Information retained under an applicable exception may be used only for the permitted purpose rather than for an unrelated purpose such as marketing, according to section 1798.99.86(c). Whether an exception applies depends on the information, activity, entity, and facts; a DROP status alone does not resolve a broader legal dispute.
DROP also distinguishes broker-held information from first-party information. CalPrivacy explains that information given directly to a business is not subject to deletion through DROP merely because that business holds it. If a data broker obtained the same information outside a direct relationship, the broker-held copy may be within the mechanism. The source and relationship therefore matter more than the data field by itself.
A DROP submission is one specialized type of consumer request, not a request to know, correct, or obtain a copy of information. A direct request under the broader California privacy-law framework may be relevant when the consumer’s objective or the business relationship falls outside DROP. Coverage and exceptions must still be assessed under the current official texts.
Practical checklist for using the mechanism carefully
- Begin with the official CalPrivacy DROP instructions and confirm that the submission route remains on a California government service.
- Treat California residency verification as an eligibility step, not proof that a broker holds a matching profile.
- Provide accurate identifiers that you are comfortable submitting; do not add guessed, outdated, or another person’s information.
- Review the broker selection before submission if there is a reason to exclude a particular broker, as the statute permits.
- Save the DROP ID securely. The Agency says it is used to check status and should not be shared.
- Read each broker result according to its defined meaning; do not interpret “record not found” as proof that the broker never had information.
- Consider whether a separate direct request is needed for access, correction, first-party data, or another right that DROP does not exercise.
- Preserve neutral records of the submission and displayed statuses if a later complaint or legal consultation becomes necessary.
California’s central mechanism reduces the need to locate a separate deletion channel for every participating data broker, but it does not remove the importance of legal coverage, accurate matching, exceptions, and careful interpretation of broker reports. This article provides general information, not legal advice.
Frequently asked questions
What is California's central data broker deletion mechanism?
It is DROP, the state-operated platform through which an eligible California resident can submit one deletion request for covered personal information held by data brokers subject to the mechanism.
Is DROP the same thing as the California DELETE Act?
No. The DELETE Act is the law enacted through SB 362. DROP is the Data broker Requests and Opt-out Platform established to implement the law's centralized deletion mechanism.
Does one DROP request guarantee that every record will be deleted?
No. Results depend on legal coverage, the identifiers available for matching, the records held by each broker, statutory exceptions, and whether information was collected in a covered broker relationship.
Can a California resident exclude a data broker from a DROP request?
Yes. The current statute and official workflow allow a consumer to exclude selected data brokers, so an excluded broker does not receive that request.
Is a DROP request the same as a direct CCPA privacy request?
No. DROP centralizes deletion requests to covered data brokers. A direct CCPA request goes to a particular business and may seek access, correction, deletion, opt-out, or another applicable right.
Primary sources
- California Legislature — current Civil Code sections 1798.99.80–1798.99.89
- California Legislature — SB 362, the DELETE Act
- California Legislature — SB 361 data broker amendments
- California Privacy Protection Agency — DROP regulations effective January 1, 2026
- CalPrivacy — How DROP works
- CalPrivacy — Personal information and data brokers
This article provides general information, not legal advice.