trustifo

Privacy reference

How California's DROP Platform Handles Consumer Deletion Requests

A source-linked guide to submitting a California DROP request, record matching, broker responses, status codes, limits, and practical follow-up.

California’s DROP platform lets a California resident send one deletion request to registered data brokers. The platform verifies eligibility, converts submitted identifiers for matching, distributes request lists, and later displays each broker’s reported result; deletion is not guaranteed in every case.

DROP and the DELETE Act are different things

The DELETE Act is the California statute enacted as SB 362. DROP is the Data broker Requests and Opt-out Platform created to implement the statute’s centralized request mechanism. The law required the California Privacy Protection Agency (CPPA), now operating publicly as CalPrivacy, to establish a system through which one verifiable request can reach every covered data broker, while allowing a consumer to exclude selected brokers. The enacted DELETE Act and the later SB 361 amendments supply the controlling statutory language.

DROP opened to consumers on January 1, 2026. As of this article’s publication date, brokers are scheduled to begin accessing and processing requests on August 1, 2026. The Agency’s consumer timeline explains that requests submitted before broker processing begins remain pending. For a broader account of the legislation, see the DELETE Act and DROP overview.

DROP is narrower than a general request portal for every company that holds personal information. It concerns registered data brokers and information within the covered broker relationship. The legal definition is more specific than the ordinary meaning of the term; the separate data broker explainer describes why the source of data and the relationship with the consumer matter.

How a consumer request moves through DROP

DROP separates the consumer-facing submission from the broker’s later matching and response. A consumer does not identify and contact each broker individually. Instead, the platform creates a continuing request that current and future registered brokers must account for unless the consumer narrows or cancels it, as described in the Agency’s official workflow.

StageWhat happensWhat the consumer should understand
EligibilityCalifornia residency is checked through the California Identity Gateway.Eligibility verification is separate from broker record matching.
ProfileThe consumer supplies required identifiers and may add optional identifiers.More identifiers can support matching, but each disclosure should be deliberate.
SubmissionDROP issues a confirmation and a DROP ID.The DROP ID is needed to return and check results.
Broker processingBrokers retrieve hashed request lists, compare them with standardized and hashed records, and take the required action.A result depends on whether the supplied identifier matches the broker’s data.
Status reportingEach broker reports a defined response code through DROP.“Not found,” “exempted,” and “opted out” do not mean the same thing as deletion.

1. Residency verification and profile creation

Only a California resident is eligible to submit a DROP request. The Agency says residency verification is managed through the California Identity Gateway and can be completed by entering basic information or using Login.gov. It also states that a California Identity Gateway account is not required and that DROP does not retain the information used by that gateway for the eligibility check. These operational statements appear in the Agency’s DROP eligibility instructions.

After verification, the consumer creates a request profile. According to the Agency’s profile instructions, the minimum fields are name, date of birth, and ZIP code. A consumer may also provide names previously used, email addresses, phone numbers, mobile advertising identifiers, connected-TV identifiers, and vehicle identification numbers. Except for date of birth, the system can accept multiple values in the listed categories. These are matching inputs, not a representation that every broker holds every type of identifier.

2. Submission and the DROP ID

The consumer reviews the profile and submits the request. DROP then supplies a DROP ID, which the Agency tells consumers to save for status checks. The ID should be treated as a private control credential: it is useful for returning to the request, but it does not prove that any particular broker had a record or completed deletion. The Agency’s post-submission guidance also allows consumers to return to the profile and add information when details change or when more matching data may be useful.

This submission is a particular type of consumer request, not a general instruction covering all possible privacy rights. It seeks deletion from data brokers through DROP and supports an opt-out result in the cases defined by the DROP regulations. It does not itself request access, correction, or an explanation of the specific data a broker holds.

3. Hash-based matching by brokers

Consumers do not send ordinary readable request profiles separately to every broker. DROP places identifiers into defined consumer deletion lists in hashed form. Before comparing those values, a broker must standardize comparable fields in its own records and apply the same hashing method. The CPPA’s effective DROP regulations specify normalization rules and matching requirements; the Agency’s processing overview summarizes the download, standardization, hashing, matching, deletion, and reporting cycle.

Hashing supports comparison without putting the consumer’s raw identifier into a broker download. It does not make matching certain. A broker may hold an old email address, a different name format, an identifier shared by several people, or no corresponding record. Conversely, when an identifier produces a valid match, the regulations require the broker to address personal information associated with the matched identifier, rather than merely deleting the identifier supplied by the consumer.

4. Processing and continuing effect

Beginning August 1, 2026, the amended statute requires a data broker to access the mechanism at least once every 45 days and process a received deletion request within 45 days. That structure can make a consumer-facing status take up to 90 days to appear, depending on when the broker retrieves the request and reports at a later access session. The current timing appears in Civil Code section 1798.99.86 as amended by SB 361 and is explained in the Agency’s broker processing cycle.

The obligation is designed to continue after an initial match. Subject to the statute’s exceptions and the consumer’s later choices, a broker must address newly collected personal information on the recurring cycle and must not sell or share newly collected information covered by the request. The amended statutory text also directs brokers to pass the required deletion or opt-out action to associated service providers and contractors.

How to read DROP status results

The status page is a broker-by-broker record of reported outcomes, not a certification that no copy of the consumer’s information exists anywhere. The final regulations define four broker response codes, while the consumer interface may show a request as pending before a broker reports:

  • Record deleted. The broker matched an identifier and deleted associated non-exempt personal information as required.
  • Record opted out of sale. The identifier matched multiple consumers, so the broker could not verify one consumer for deletion and instead opted all associated consumers out of sale or sharing.
  • Record exempted. The broker matched the identifier, but all information associated with that consumer was exempt from deletion under the cited provisions.
  • Record not found. The broker completed the prescribed comparison and found no match in its records.
  • Pending. The broker has not yet supplied a final response for that request.

“Record not found” should be interpreted cautiously. The Agency says it may mean the broker has no information about the consumer or could not locate a match using the submitted information. A consumer can review the Agency’s status explanations and consider adding an accurate current or former identifier. The status does not establish that a visible record belongs to the same legal entity, uses the same matching fields, or falls within DROP.

What DROP may not delete

DROP does not erase every item a business possesses. The amended statute preserves the deletion exceptions incorporated from the CCPA and restricts retained information to the permitted purpose rather than marketing. The Agency’s consumer explanation of covered and excluded information identifies first-party data, publicly available information, and legally exempt information as categories that may remain.

First-party data is especially important. The Agency explains that information collected through a direct interaction remains with the first-party business, even when data brokers that obtained the information must process a covered DROP request. A separate request under the California privacy law framework may be appropriate, depending on the business, information, purpose, and applicable exceptions. DROP does not decide those coverage questions for the consumer.

Deletion also differs from access and correction. DROP’s defined status codes tell the consumer what outcome the broker reported; they do not provide a copy of the record, identify every source, or correct an inaccurate field. A person who needs those outcomes may have to use the business’s direct privacy channel under the rights that apply to that situation.

Practical checklist for consumers

Use the official state site and keep the request narrow enough to manage:

  1. Confirm that the page is within the official privacy.ca.gov DROP service before entering identifiers.
  2. Provide the required profile information accurately; add optional identifiers only when their matching value justifies the added disclosure.
  3. Review old names, email addresses, and phone numbers that a broker might reasonably hold, without adding unrelated sensitive information.
  4. Save the DROP ID in a secure place and record the submission date.
  5. Expect a pending result before broker processing begins, and allow for the official processing and reporting cycle after August 1, 2026.
  6. Read each broker’s status separately instead of treating one result as representative of all brokers.
  7. If a result is “record not found,” verify the broker’s legal identity and consider whether an accurate additional identifier could improve matching.
  8. Use a direct business request when the objective is access, correction, first-party deletion, or another right outside DROP’s function.

This checklist summarizes the Agency’s consumer instructions and does not replace the statute, regulations, or current instructions shown inside DROP. Platform wording and implementation guidance can change; the official service should control when it differs from this guide.

Limits of this guide

DROP creates a centralized route, but the result still depends on residency, statutory coverage, exemptions, identifiers, matching, and the records each broker maintains. A status is evidence of what a broker reported through the platform, not a guarantee of complete erasure across government sources, first-party businesses, search engines, or entities outside the California data-broker system.

This material provides general information, not legal advice. For a dispute about coverage, an exemption, verification, or compliance, consult the current statutory and regulatory text and consider advice from a qualified legal professional.

Frequently asked questions

Who may submit a consumer deletion request through DROP?

DROP is available to California residents. The platform verifies residency before a person creates and submits a deletion request.

Does a DROP request guarantee that every broker will delete a record?

No. A broker may find no matching record, find an ambiguous match that results in an opt-out, or determine that all matched information is exempt from deletion.

What information is required to create a DROP request?

The Agency says a consumer needs a name, date of birth, and ZIP code. Email addresses, phone numbers, and several device or vehicle identifiers are optional.

How can a consumer review the result of a DROP request?

The confirmation page provides a DROP ID. The consumer uses that identifier to return to the official platform and check broker-reported statuses.

Does DROP replace direct privacy requests to a business?

No. DROP addresses covered information maintained by registered data brokers. A direct request may still be relevant for first-party data, another privacy right, or a business outside DROP's scope.

Primary sources

This article provides general information, not legal advice.