Guide · Privacy law & practical steps

California Data Privacy Law: CCPA Opt-Out and the DELETE Act Explained (2026)

How to use your CCPA rights and California's new DROP platform to delete your data from 500+ registered brokers — plus what neither one covers, and how to get proof.

Last verified: September 2026.

California gives residents the strongest data-deletion rights in the United States. Between the California Consumer Privacy Act (CCPA, strengthened by the CPRA) and the DELETE Act's new DROP platform, you can now force hundreds of data brokers to delete your information through a single free request — and demand deletion directly from any other covered business. This guide explains exactly what each right does, how to use them, and where the gaps are.

Your rights under CCPA/CPRA

The CCPA took effect January 1, 2020, and was expanded by the CPRA ballot measure (effective January 1, 2023). If you're a California resident, you have these rights against covered businesses (official CCPA overview, California DOJ):

RightWhat it lets you do
Right to know / accessDemand what personal information a business collected, where it came from, and who it was sold or shared with
Right to deleteDemand the business delete personal information it collected from you (with exceptions for legal, security, and transactional needs)
Right to opt out of sale/sharingStop the business from selling your data or sharing it for cross-context behavioral advertising
Right to correctRequire the business to fix inaccurate personal information
Right to limit sensitive PIRestrict use of sensitive personal information (SSN, precise location, biometrics, account credentials) to what's necessary
Right to non-discriminationA business can't charge you more or degrade service because you exercised these rights

Two things to know about scope: the CCPA generally covers for-profit businesses above certain size/data thresholds (roughly $26.6M+ revenue, 100,000+ consumers, or 50%+ of revenue from selling/sharing PI), and businesses must honor the Global Privacy Control browser signal as an automatic opt-out of sale/sharing.

The California data-broker registry

California requires data brokers — businesses that knowingly collect and sell personal information about consumers they have no direct relationship with — to register with the California Privacy Protection Agency (CPPA). The registry is public, so you can look up which companies legally classify themselves as brokers. More than 500 brokers are registered as of 2026, and the CPPA has begun fining companies that fail to register: early enforcement actions included LocateSmarter ($116,490), S&P Global ($62,600), and Cybba ($52,400), largely for registration failures. Failure to register costs $200 per day.

The DELETE Act and DROP: one request, 500+ brokers

The DELETE Act (SB 362, signed October 2023) created the Delete Request and Opt-Out Platform (DROP) — the first centralized deletion mechanism of its kind in the US, run by the CPPA (official DROP explainer).

Timeline:

DateMilestone
Jan 1, 2026DROP opened to California consumers; 155,000+ signed up within the first weeks
Mid-2026300,000+ accounts and 475,000+ deletion requests submitted
Aug 1, 2026Data brokers must begin processing DROP requests, and must check the platform at least every 45 days thereafter
Jan 1, 2028Mandatory independent third-party audits of brokers begin (every 3 years)

Once processing begins, brokers must delete matching records — including inferences — and report the status of each request. Requests a broker can't verify must still be honored as opt-outs of sale/sharing, and brokers must keep suppression lists so deleted records aren't re-added. Ignoring a request costs $200 per request, per day — a month of ignoring one request is $6,000; a hundred ignored requests accrue $20,000 a day.

How to use DROP, step by step

  1. Go to the DROP portal at privacy.ca.gov/drop.
  2. Verify California residency through the California Identity Gateway or Login.gov.
  3. Enter the identifiers you want deleted (names, emails, phone numbers, addresses) — the more identifiers you provide, the more records brokers can match.
  4. Submit. Your single request is broadcast to every registered data broker.
  5. Check back after August 2026 processing cycles begin, and re-verify annually — brokers re-check every 45 days, but new identifiers (a new phone, a moved address) warrant an updated request.

What DROP does NOT cover

DROP is powerful but narrow. It does not:

  • Cover anyone who isn't a verified California resident
  • Reach brokers that simply don't register — people-search sites that structure themselves to dodge the legal definition
  • Reach non-broker businesses, public-records sources, or search results
  • Give you proof a specific listing was deleted — no per-listing evidence artifact
  • Prevent relisting in practice — suppression lists are required, but brokers re-ingest data from fresh sources constantly, and verifying compliance is on you

Filing direct CCPA requests

For businesses outside DROP — or to exercise rights DROP doesn't cover (access, correction, sensitive-PI limits) — file directly:

  1. Find the company's privacy policy and its "Do Not Sell or Share My Personal Information" link (required on the homepage of covered businesses).
  2. Submit a deletion or opt-out request through the designated method (webform, email, or toll-free number). For site-by-site walkthroughs, see our free opt-out guides for Spokeo, Whitepages, and BeenVerified — or the full 47-site index.
  3. Businesses have 45 days to respond (one 45-day extension allowed). Identity verification is allowed, but they can't demand a new account. See what to share and what to refuse during verification.
  4. If denied or ignored, refile strategically, then complain to the CPPA or the California AG.

Where MyPrivacyAgent fits

DROP covers registered brokers; your direct requests cover the rest — but nobody sends you proof. MyPrivacyAgent works nationwide (not just California), covers brokers outside the registry including hard-to-file sites, and — unlike DROP or any opt-out form — keeps per-listing proof: nothing is marked removed until a re-check finds the listing gone, and Patrol ($19.99/mo, see pricing) re-checks monthly and flags listings that come back so they can be re-filed. Start with the free exposure scan, or compare us honestly against DeleteMe, Incogni, and Optery in our best data removal services roundup. Not in California? See the Texas data removal guide.

FAQ

Is DROP free? Yes. Registering and submitting deletion requests through DROP is completely free for California residents.

Does DROP delete my data from Google? No. DROP routes requests to registered data brokers only. Search results and non-broker sites require separate requests.

What's the difference between a CCPA deletion request and DROP? DROP is one request broadcast to all registered brokers. A direct CCPA request goes to a specific business — and can also exercise access, correction, and sensitive-data rights DROP doesn't handle.

When do brokers actually have to delete my DROP request? Starting August 1, 2026, brokers must process DROP requests at least every 45 days. Requests filed earlier queue up for that first processing cycle.

Can a California data broker ignore my opt-out? Not legally. Unprocessed DROP requests cost $200 per request per day; ignored direct requests expose businesses to CPPA enforcement and fines.

Will my data stay deleted? Brokers must maintain suppression lists, but fresh data constantly flows in from new sources. Re-check your listings periodically — or use a service that patrols for relisting automatically.