Last verified: September 2026.
California gives residents the strongest data-deletion rights in the United States. Between the California Consumer Privacy Act (CCPA, strengthened by the CPRA) and the DELETE Act's new DROP platform, you can now force hundreds of data brokers to delete your information through a single free request — and demand deletion directly from any other covered business. This guide explains exactly what each right does, how to use them, and where the gaps are.
Your rights under CCPA/CPRA
The CCPA took effect January 1, 2020, and was expanded by the CPRA ballot measure (effective January 1, 2023). If you're a California resident, you have these rights against covered businesses (official CCPA overview, California DOJ):
| Right | What it lets you do |
|---|---|
| Right to know / access | Demand what personal information a business collected, where it came from, and who it was sold or shared with |
| Right to delete | Demand the business delete personal information it collected from you (with exceptions for legal, security, and transactional needs) |
| Right to opt out of sale/sharing | Stop the business from selling your data or sharing it for cross-context behavioral advertising |
| Right to correct | Require the business to fix inaccurate personal information |
| Right to limit sensitive PI | Restrict use of sensitive personal information (SSN, precise location, biometrics, account credentials) to what's necessary |
| Right to non-discrimination | A business can't charge you more or degrade service because you exercised these rights |
Two things to know about scope: the CCPA generally covers for-profit businesses above certain size/data thresholds (roughly $26.6M+ revenue, 100,000+ consumers, or 50%+ of revenue from selling/sharing PI), and businesses must honor the Global Privacy Control browser signal as an automatic opt-out of sale/sharing.
The California data-broker registry
California requires data brokers — businesses that knowingly collect and sell personal information about consumers they have no direct relationship with — to register with the California Privacy Protection Agency (CPPA). The registry is public, so you can look up which companies legally classify themselves as brokers. More than 500 brokers are registered as of 2026, and the CPPA has begun fining companies that fail to register: early enforcement actions included LocateSmarter ($116,490), S&P Global ($62,600), and Cybba ($52,400), largely for registration failures. Failure to register costs $200 per day.
The DELETE Act and DROP: one request, 500+ brokers
The DELETE Act (SB 362, signed October 2023) created the Delete Request and Opt-Out Platform (DROP) — the first centralized deletion mechanism of its kind in the US, run by the CPPA (official DROP explainer).
Timeline:
| Date | Milestone |
|---|---|
| Jan 1, 2026 | DROP opened to California consumers; 155,000+ signed up within the first weeks |
| Mid-2026 | 300,000+ accounts and 475,000+ deletion requests submitted |
| Aug 1, 2026 | Data brokers must begin processing DROP requests, and must check the platform at least every 45 days thereafter |
| Jan 1, 2028 | Mandatory independent third-party audits of brokers begin (every 3 years) |
Once processing begins, brokers must delete matching records — including inferences — and report the status of each request. Requests a broker can't verify must still be honored as opt-outs of sale/sharing, and brokers must keep suppression lists so deleted records aren't re-added. Ignoring a request costs $200 per request, per day — a month of ignoring one request is $6,000; a hundred ignored requests accrue $20,000 a day.
How to use DROP, step by step
- Go to the DROP portal at privacy.ca.gov/drop.
- Verify California residency through the California Identity Gateway or Login.gov.
- Enter the identifiers you want deleted (names, emails, phone numbers, addresses) — the more identifiers you provide, the more records brokers can match.
- Submit. Your single request is broadcast to every registered data broker.
- Check back after August 2026 processing cycles begin, and re-verify annually — brokers re-check every 45 days, but new identifiers (a new phone, a moved address) warrant an updated request.
What DROP does NOT cover
DROP is powerful but narrow. It does not:
- Cover anyone who isn't a verified California resident
- Reach brokers that simply don't register — people-search sites that structure themselves to dodge the legal definition
- Reach non-broker businesses, public-records sources, or search results
- Give you proof a specific listing was deleted — no per-listing evidence artifact
- Prevent relisting in practice — suppression lists are required, but brokers re-ingest data from fresh sources constantly, and verifying compliance is on you
Filing direct CCPA requests
For businesses outside DROP — or to exercise rights DROP doesn't cover (access, correction, sensitive-PI limits) — file directly:
- Find the company's privacy policy and its "Do Not Sell or Share My Personal Information" link (required on the homepage of covered businesses).
- Submit a deletion or opt-out request through the designated method (webform, email, or toll-free number). For site-by-site walkthroughs, see our free opt-out guides for Spokeo, Whitepages, and BeenVerified — or the full 47-site index.
- Businesses have 45 days to respond (one 45-day extension allowed). Identity verification is allowed, but they can't demand a new account. See what to share and what to refuse during verification.
- If denied or ignored, refile strategically, then complain to the CPPA or the California AG.
Where MyPrivacyAgent fits
DROP covers registered brokers; your direct requests cover the rest — but nobody sends you proof. MyPrivacyAgent works nationwide (not just California), covers brokers outside the registry including hard-to-file sites, and — unlike DROP or any opt-out form — keeps per-listing proof: nothing is marked removed until a re-check finds the listing gone, and Patrol ($19.99/mo, see pricing) re-checks monthly and flags listings that come back so they can be re-filed. Start with the free exposure scan, or compare us honestly against DeleteMe, Incogni, and Optery in our best data removal services roundup. Not in California? See the Texas data removal guide.
FAQ
Is DROP free? Yes. Registering and submitting deletion requests through DROP is completely free for California residents.
Does DROP delete my data from Google? No. DROP routes requests to registered data brokers only. Search results and non-broker sites require separate requests.
What's the difference between a CCPA deletion request and DROP? DROP is one request broadcast to all registered brokers. A direct CCPA request goes to a specific business — and can also exercise access, correction, and sensitive-data rights DROP doesn't handle.
When do brokers actually have to delete my DROP request? Starting August 1, 2026, brokers must process DROP requests at least every 45 days. Requests filed earlier queue up for that first processing cycle.
Can a California data broker ignore my opt-out? Not legally. Unprocessed DROP requests cost $200 per request per day; ignored direct requests expose businesses to CPPA enforcement and fines.
Will my data stay deleted? Brokers must maintain suppression lists, but fresh data constantly flows in from new sources. Re-check your listings periodically — or use a service that patrols for relisting automatically.