Today the Delete Request and Opt-Out Platform — DROP — becomes operative for the industry it was built to constrain. If you are a California resident, this is the most useful thing that has happened to your privacy in a decade, and it takes about ten minutes to use.

What changed today

California’s Delete Act (SB 362) required the California Privacy Protection Agency to build a single, centralized deletion mechanism. Not a per-company opt-out. Not a form you fill out 600 times. One request, filed once with the state, that every registered data broker is legally obligated to honor.

The consumer side of DROP has been live since earlier in 2026. Today is the day the obligation attaches to the brokers.

The mechanics:

  • More than 600 registered data brokers must begin systematically processing deletion requests through DROP.
  • Brokers must access DROP at least once every 45 days.
  • Every request must be processed within 45 days of receipt.
  • Deletion is not one-and-done: brokers must continue honoring the request going forward, not simply drop the current record and re-acquire the person next quarter.

The number that makes this real

More than 300,000 Californians had already filed deletion requests through DROP before today’s deadline, all queued and waiting.

Now the penalty structure: $200 per consumer, per day that a request goes unprocessed.

Do that arithmetic on a broker that ignores one 45-day cycle across a queue in the hundreds of thousands, and the theoretical exposure runs to well over a billion dollars. Analysts have put the figure for a single missed cycle at roughly $1.5 billion against the volumes involved.

Nobody expects a fine at that magnitude. Theoretical maximums never survive contact with settlement negotiation. But the number does something important regardless of whether it is ever imposed: it makes ignoring DROP a bet-the-company decision rather than a cost-of-doing-business line item. That is a threshold most privacy law never reaches. The GDPR’s 4%-of-global-turnover ceiling is famous precisely because it crossed it.

Why this design is better than everything before it

Every prior consumer deletion right in American law shares the same fatal flaw: it requires the consumer to know who has their data.

You cannot send a deletion request to a company whose name you have never heard. The data broker industry’s core structural advantage has always been obscurity — you have no relationship with these firms, you never gave them anything directly, and most of them are named things like “Acxiom” and “LiveRamp” and “Datastream Group” that mean nothing to a normal person. The CCPA gave Californians a deletion right in 2020. Exercising it against the broker industry meant identifying and individually petitioning hundreds of companies you’d never heard of, each with its own deliberately tedious form.

DROP inverts the burden. The state maintains the registry. The consumer files once. The brokers come to the platform. The obscurity that protected the industry now works against it, because registration is mandatory and the registry is the distribution list.

This is the correct architecture, and it is the first time any US jurisdiction has built it.

What it does not do

Be precise about the limits, because the gap between what DROP covers and what people assume it covers is large.

It only reaches registered data brokers. A data broker under California law is a business that knowingly collects and sells personal information about consumers with whom it does not have a direct relationship. That “direct relationship” carve-out is load-bearing. Your bank, your insurer, your grocery loyalty program, your airline, and every app you have ever installed are not data brokers as to you — you have a direct relationship with them. DROP does not touch them.

It only covers California residents. There is no reciprocity, no national version, and no pending federal equivalent with a realistic path.

Registration is self-executing and under-inclusive. A company that meets the definition but does not register is not on the list, and therefore not checking DROP. CalPrivacy has been actively enforcing the registration requirement — that has been a steady stream of penalties through 2026 — but enforcement against the registered is easier than enforcement against the hidden.

Deletion is not the same as never being collected again. Brokers must honor the request going forward, but the flows that feed them — app SDKs, loyalty programs, public records, credit headers — do not stop. DROP drains the reservoir; it does not close the taps.

Do this today if you’re a Californian

The whole point of DROP is that it is cheap for you and expensive for them. Take the ten minutes.

  1. Go to privacy.ca.gov and file a DROP request. You will need to verify your identity — this is genuinely necessary, since an unverified deletion mechanism would be a tool for erasing other people’s records.

  2. File for every California resident in your household who wants it, including adult children and elderly parents who will not do it themselves. The people most harmed by broker data are usually the least likely to file.

  3. Then do the direct-relationship companies separately, because DROP will not. Your carrier, your bank’s marketing preferences, your loyalty programs, your credit bureaus’ pre-screen opt-out (optoutprescreen.com, which is free and covers all three bureaus).

  4. Keep the confirmation. If a broker keeps selling your data after a DROP request, the record of that request is the entire case.

  5. If you are not in California, the direct opt-outs still work: LexisNexis, Acxiom, Whitepages, Spokeo, Radaris, and the rest. They are worse in every way than DROP. Do them anyway, and note that this is a thing your state legislature could fix by copying a statute that already exists and already works.

Why this matters beyond California

State privacy law has produced twenty comprehensive statutes and a great deal of compliance paperwork, and comparatively little change in what actually happens to your data. The gap between rights on paper and rights exercised is enormous, and it is enormous by design — friction is the industry’s most effective defense, and it never has to argue against your rights in public if it can just make them tedious.

DROP is the first American privacy mechanism built specifically to eliminate that friction rather than to create another right nobody exercises. Three hundred thousand filed requests before the obligation even attached is evidence that the demand was always there.

Whether it works is the question the next 45 days answer. Watch for the first enforcement action — CalPrivacy has been aggressive with sectoral audits this year and has shown no reluctance to name names.

The pattern

The data broker industry has spent twenty years arguing that its practices are legal, disclosed, and consented to. All three claims depend on a consumer never being able to act on them at scale.

California just made acting on them a single form. The industry’s response over the next two months will tell you which of those three claims it actually believed.