Skip to content

Industry Insights & Analysis

California's DROP: The First-of-Its-Kind Data Deletion Platform That Could Reshape Global Privacy Standards

How California's DELETE Act and DROP platform are transforming data privacy enforcement

By Deepak Gupta·January 5, 2026·15 min read

Key Findings

  • California's DROP enables single deletion requests to 545+ registered data brokers
  • Non-compliant data brokers face penalties of $200 per day per violation
  • The platform could set a precedent for global privacy enforcement mechanisms
data privacyCalifornia DROPDELETE Actdata brokersprivacy regulationconsumer rights

Introduction: The Dawn of Consumer Data Control

On January 1, 2026, California quietly launched what privacy advocates are calling the most significant consumer data protection mechanism since the EU's GDPR. The Delete Request and Opt-out Platform, known as DROP, represents a fundamental shift in the balance of power between individuals and the multi-billion dollar data broker industry.

For decades, data brokers have operated in the shadows, collecting, aggregating, and selling personal information about hundreds of millions of consumers, often without their knowledge or meaningful consent. These companies know your home address, your income bracket, your health conditions, your political affiliations, and in many cases, far more intimate details about your life than your closest friends.

DROP changes this dynamic. For the first time, California residents can submit a single request that compels every registered data broker to delete their personal information and stop collecting it in the future. No more navigating dozens of different company websites. No more filling out endless opt-out forms. One request. Done.

As someone who has spent over 15 years building identity and access management systems, including scaling a CIAM platform to serve over 1 billion users globally, I've watched the data broker ecosystem evolve from both technical and business perspectives. What California has built with DROP represents a paradigm shift that other jurisdictions would be wise to study closely.


Understanding the Data Broker Problem

What Are Data Brokers?

Under California law, a data broker is defined as any business that "knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship." This definition is crucial, it means that the company collecting your data never interacted with you directly. You didn't sign up for their service. You didn't buy their product. You may not even know they exist.

The data broker industry has grown into a massive, largely invisible ecosystem. As of January 2026, 545 data brokers have registered with the California Privacy Protection Agency (CPPA), though industry analysts believe the true number of companies that should be registered is significantly higher. Privacy Rights Clearinghouse and the Electronic Frontier Foundation have identified hundreds of companies registered in other states that haven't registered in California.

The Scope of Personal Data Collection

The breadth of information data brokers collect is staggering. According to official disclosures, data brokers may hold any combination of the following about you:

Category Examples
Identification Data Full legal name, aliases, Social Security numbers, driver's license numbers, passport information
Contact Information Current and historical addresses, phone numbers, email addresses
Financial Data Income estimates, credit scores, purchase history, property records, bankruptcy filings
Demographic Information Age, gender, ethnicity, marital status, household composition
Behavioral Data Browsing history, search queries, app usage, location tracking data
Sensitive Categories Health conditions, political affiliations, religious beliefs, sexual orientation
Family Information Data about your children, parents, and other relatives

The Human Cost: Identity Theft and Beyond

The proliferation of personal data in broker databases has real-world consequences. According to the Identity Theft Resource Center, the first half of 2025 saw 1,732 publicly reported data compromises, approximately 5% ahead of 2024's record-breaking pace. These breaches affected over 165 million individuals in just six months.

The statistics paint a sobering picture:

  • Every 4.9 seconds, someone in the United States becomes a victim of identity theft
  • Over 51% of Americans have been scammed at some point in their lives
  • The average victim loses $730 in the past year alone
  • 24% of identity theft victims were also victims of a data breach

Data brokers are not merely passive repositories of this information. By aggregating data from multiple sources, they create comprehensive profiles that can be used for targeted scams, AI-powered impersonation attacks, and sophisticated social engineering campaigns. The rise of generative AI has made these threats even more acute, attackers can now use leaked personal information to create convincing deepfakes and personalized phishing attacks at scale.


How DROP Works: A Technical Overview

The Consumer Experience

DROP was designed with simplicity in mind. The process involves three straightforward steps:

Step 1 - Verify Eligibility Consumers must confirm California residency through the California Identity Gateway, the state's secure digital identity verification platform. This can be done by entering information directly or by using Login.gov credentials. Importantly, DROP does not retain this verification data.

Step 2 - Create a Profile Users provide identifying information that data brokers can use to locate their records. This might include name variations, email addresses, phone numbers, and date of birth. Consumers choose how much information to provide, more information increases the likelihood of comprehensive deletion.

Step 3 - Submit Request With a single submission, the deletion request is sent to all 545+ registered data brokers. Users can also exclude specific brokers if desired. The request remains active indefinitely, meaning brokers must continue deleting the consumer's data on an ongoing basis.

Submit Your DROP Request

The Data Broker Compliance Framework

From the data broker perspective, DROP creates new operational requirements:

Requirement Details
45-Day Check Cycle Starting August 1, 2026, data brokers must access DROP at least every 45 days to retrieve new deletion requests
Identity Matching Brokers must compare consumer information against their databases using unique identifiers
Comprehensive Deletion If a match is found, delete all associated personal data, including inferences
Status Reporting Report the status of each deletion request within 45 days of retrieval
Ongoing Compliance Continue deleting data at least every 45 days; cannot collect new data about requestors

Privacy-Preserving Architecture

A critical aspect of DROP's design is its privacy-preserving architecture. Consumer information submitted to DROP is stored in a hashed format, protecting it from unauthorized access. The platform is built to be "safe, secure, and protects your privacy" according to the CPPA.

Crucially, the information submitted to DROP is only used to complete deletion requests. It won't be sold or shared for any other purpose. This addresses a legitimate concern about centralized data deletion services: that they might themselves become another data aggregation point.


Evolution of California Privacy Law

DROP didn't emerge in a vacuum. It represents the culmination of nearly a decade of privacy legislation in California:

Year Legislation Impact
2018 CCPA Gave consumers rights to know, delete, and opt-out, but required individual requests
2019 AB 1202 Created first U.S. data broker registry
2020 CPRA Expanded CCPA; created California Privacy Protection Agency
2023 Delete Act (SB 362) Required creation of DROP; mandated data broker participation
2025 SB 361 Amendments Required additional disclosures in registration process

Enforcement Mechanisms and Penalties

The Delete Act includes significant enforcement mechanisms:

  • Registration Penalties: $200 per day for unregistered data brokers
  • Deletion Penalties: $200 per request per day for failure to process
  • Audit Requirements: Independent compliance audits every three years (starting January 2028)
  • Cost Recovery: CPPA can recover investigation costs and unpaid fees

Recent Enforcement Actions:

Date Company Penalty Violation
July 2025 Accurate Append Inc. (WA) $55,400 Failed to register
May 2025 National Public Data (FL) $46,000 Failed to register and pay fees
February 2025 Background Alert (CA) $50,000 Ordered to suspend operations

California in Context: The U.S. Data Broker Landscape

State-Level Approaches

California is not the only state to regulate data brokers, but it has gone significantly further than any other jurisdiction. Currently, four states have data broker registration laws:

State Year Annual Fee Penalties Unique Feature
Vermont 2018 $100 Up to $500/day First state registry
California 2019/2023 $6,600 $200/day DROP centralized deletion
Texas 2023 $300 Up to $10,000/year Conspicuous notice requirement
Oregon 2024 $600 Up to $10,000/year Opt-out declaration required

Additional states, including New Jersey, Delaware, Michigan, and Alaska, have data broker registration laws in development.

The Compliance Gap

A June 2025 analysis by Privacy Rights Clearinghouse and the EFF revealed significant compliance gaps across states:

  • 291 companies registered elsewhere but not in California
  • 524 companies registered elsewhere but not in Texas
  • 475 companies registered elsewhere but not in Oregon
  • 309 companies registered elsewhere but not in Vermont

While definitional differences between state laws may account for some discrepancies, this data suggests systematic underregistration that state enforcement agencies are now being urged to investigate.

The Case for Federal Legislation

The current patchwork of state laws creates challenges for both consumers and businesses. A data broker operating nationally must navigate different registration requirements, definitions, and deadlines across multiple jurisdictions. Consumers, meanwhile, receive wildly different protections depending on where they live.

Privacy advocates have long called for federal data broker legislation. The Consumer Financial Protection Bureau's March 2023 request for information about data brokers signaled potential federal interest in the space, but comprehensive legislation has yet to materialize. Until it does, California's DELETE Act represents the most robust model for other states considering similar protections.


Global Lessons: What Other Countries Can Learn

GDPR and the Right to Erasure

The European Union's General Data Protection Regulation (GDPR), in effect since 2018, includes a "right to erasure" (Article 17) that allows individuals to request deletion of their personal data. However, the GDPR approach differs significantly from California's DROP:

Aspect GDPR California DROP
Request Method Individual requests to each controller Single centralized request
Data Broker Registry None Mandatory public registry
Enforcement 30+ national DPAs Single dedicated agency (CPPA)
Ongoing Deletion Case-by-case Automatic 45-day cycles

The European Data Protection Board (EDPB) has made the right to erasure a priority for 2025. Thirty-two DPAs across Europe are participating in coordinated enforcement actions specifically focused on how controllers handle erasure requests. This suggests European regulators recognize gaps in the current framework, gaps that California's approach directly addresses.

Recommendations for Other Jurisdictions

Based on California's experience, jurisdictions considering similar legislation should consider the following principles:

  1. Create a Data Broker Registry First Before consumers can exercise deletion rights, they need to know who holds their data. A mandatory registry creates transparency and establishes the universe of companies subject to regulation.
  2. Build Centralized Infrastructure Individual opt-out requests are too burdensome for consumers. A government-operated platform that transmits requests to all registered brokers simultaneously makes the right to deletion practically exercisable.
  3. Mandate Ongoing Compliance One-time deletion isn't enough. Data brokers can re-acquire information from other sources. Requiring ongoing deletion cycles (45 days in California's case) ensures persistent protection.
  4. Include Meaningful Penalties Registration fees and daily fines for non-compliance create financial incentives for participation. Without enforcement teeth, regulation becomes advisory.
  5. Require Independent Audits Self-reported compliance is insufficient. Third-party audits verify that data brokers are actually deleting data as required.
  6. Protect Privacy in the Protection Mechanism The deletion platform itself must be designed with privacy at its core. Hashing consumer data and limiting its use to deletion requests prevents the platform from becoming another data aggregation point.

Security Implications: Beyond Privacy

Reducing the Attack Surface

From a cybersecurity perspective, DROP addresses a fundamental problem: every database containing personal information is a potential attack target. Data brokers, by definition, aggregate massive amounts of sensitive data, making them attractive targets for malicious actors.

When consumers use DROP to delete their information, they're effectively reducing their "attack surface", the total number of places where their data could be compromised. With 545+ data brokers currently registered in California, that represents hundreds of potential breach vectors that can be eliminated with a single request.

The AI Impersonation Threat

Generative AI has introduced new dimensions to identity-related threats. Personal data harvested from data brokers can fuel sophisticated impersonation attacks, including voice cloning, deepfake videos, and AI-generated phishing that incorporates intimate knowledge of the target's life.

Research indicates that 85% of U.S. consumers believe AI makes scam detection harder, and 62% have either been victims of AI-driven scams or know someone who has. By limiting the personal data available to potential attackers, DROP provides a proactive defense against these emerging threats.

Implications for Enterprise Security

For organizations, the proliferation of employee data across broker databases represents a significant security risk. Business email compromise (BEC) attacks, which accounted for 251 confirmed incidents in H1 2025, often rely on personal information to craft convincing social engineering campaigns.

Security-conscious organizations should consider encouraging California-based employees to use DROP as part of their personal security hygiene. Reducing the availability of employee personal data in commercial databases makes targeted attacks more difficult to execute.


Limitations and Considerations

What DROP Does Not Cover

It's important to understand DROP's scope limitations:

Limitation Details
Geographic Only available to California residents
Registered Brokers Only Only covers companies registered with CPPA
Data Broker Definition First-party data from companies you interact with is not covered
Legal Exemptions Some data may be exempt from deletion requirements
Processing Delay Requests submitted now won't be processed until August 1, 2026

Potential Trade-offs

Using DROP may affect certain online experiences. The CPPA notes that deletion may result in fewer targeted advertisements and reduced content personalization. For some users, this may be a welcome side effect; for others, it may represent a trade-off worth considering.

Additionally, data brokers may re-acquire information from other sources over time. While the ongoing deletion requirement addresses this partially, consumers should understand that DROP is not a permanent shield but rather a continuous protection mechanism.


Looking Ahead: The Future of Consumer Data Rights

DROP represents a significant step forward in consumer data protection, but it's likely just the beginning of a broader transformation in how societies approach personal data rights.

Several trends suggest where this space is heading:

  • State Expansion: Other states are watching California's implementation closely. Success could trigger a wave of similar legislation, potentially creating pressure for federal action.
  • International Adoption: Countries with existing privacy frameworks (particularly in the EU and Asia-Pacific) may incorporate centralized deletion mechanisms into their regulatory structures.
  • Technology Integration: Future iterations may include automated monitoring, real-time deletion verification, and integration with identity management systems.
  • AI and Data Rights: As AI systems increasingly rely on personal data for training, questions about data rights in machine learning contexts will become more pressing. DROP-like mechanisms may eventually extend to AI training data.

Conclusion: A Model Worth Emulating

California's DROP platform represents a genuine innovation in consumer privacy protection. By combining a comprehensive data broker registry with a centralized deletion mechanism, ongoing compliance requirements, and meaningful enforcement, California has created a framework that makes data deletion rights practically exercisable, not just theoretically available.

For California residents, the message is clear: if you haven't already, visit DROP and submit your deletion request. It's free, it takes minutes, and it provides ongoing protection against the 545+ data brokers currently collecting and selling your personal information.

For policymakers in other jurisdictions, DROP offers a proven template. The data broker problem is not unique to California, it's global. Every jurisdiction grappling with personal data protection would benefit from studying California's approach and adapting it to their own legal and cultural contexts.

The data broker industry has operated in the shadows for too long. DROP brings it into the light, and gives consumers, for the first time, a meaningful way to take back control of their personal information.


References & Resources

Official Resources

Resource URL
California DROP Portal https://privacy.ca.gov/drop/
Consumer Request Portal https://consumer.drop.privacy.ca.gov
California Privacy Protection Agency https://cppa.ca.gov
Data Broker Registry https://cppa.ca.gov/data_broker_registry/
Delete Act (SB 362) Full Text https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240SB362

Research & Data Sources

Organization URL
Identity Theft Resource Center https://www.idtheftcenter.org
Electronic Frontier Foundation https://www.eff.org
Privacy Rights Clearinghouse https://privacyrights.org
European Data Protection Board https://www.edpb.europa.eu
Federal Trade Commission https://www.ftc.gov

Disclaimer: This article is provided for informational purposes only and does not constitute legal advice. Readers should consult with qualified legal professionals regarding their specific situations. Information about DROP and related regulations was accurate as of publication date but may be subject to change.

More Research

Independent research and analysis from 15+ years of building in cybersecurity, AI, and SaaS

Cybersecurity Foundations

The AI Security Stack of 2026: Governance, Red Teaming, MLSecOps, Threat Detection, and Agentic Defense

How the five layers of AI security actually fit together — and what to build first

13 minRead →

Cybersecurity Foundations

Application Security 101: SAST, DAST, IAST, ASPM, SCA, and the Modern AppSec Stack

How the application security toolchain actually fits together, what each acronym does, and where to start

16 minRead →

Frontier AI Models

Grok AI Explained: xAI's Model Family, Capabilities, and Where It Fits

How Grok works, what makes it different from ChatGPT and Claude, and what it is actually good at

11 minRead →

AI Infrastructure & Hardware

NPU Explained: What a Neural Processing Unit Is, How It Differs From a CPU and GPU

How NPUs work, why every laptop and phone now has one, and what they actually accelerate

12 minRead →

Cybersecurity Foundations

Zero Trust Architecture Explained: SASE, SSE, ZTNA, and How the Pieces Actually Fit

The vendor-neutral guide to Zero Trust: what NIST 800-207 actually says, how SASE and SSE differ, where ZTNA fits, and what to build first

17 minRead →

Industry Research & Market Analysis

AI Receptionists for SMBs: Market Data, ROI, and Implementation Guide

How AI Receptionists Are Rewiring SMB Communication with 75% Fewer Missed Calls and 300% First-Year ROI

20 minRead →

Industry Research & Market Analysis

Generative Engine Optimization (GEO): Market Research & Industry Analysis 2026

A Deep Analysis of Monitoring & Content Platforms, Market Gaps, and Strategic Opportunities

25 minRead →

Industry Research & Market Analysis

CIAM Industry Research Report: M&A and Investment Analysis

Comprehensive Market Intelligence for Private Equity, Growth Equity, and Venture Capital Firms

35 minRead →

Authentication & Cryptography

The Complete Guide to Password Hashing: Argon2 vs Bcrypt vs Scrypt vs PBKDF2 (2026)

Benchmarking and comparing modern password hashing algorithms for secure credential storage

25 minRead →

Technical Implementation Guides

Model Context Protocol (MCP): Enterprise Adoption, Market Trends & Implementation

The Complete Guide to MCP, Architecture, Security, Authentication, and Strategic Deployment for Enterprises

35 minRead →

Strategic Frameworks & Playbooks

How Companies Can Achieve AEO and GEO: The Complete 2025 Guide

Optimizing content for AI search visibility through AEO and GEO strategies

18 minRead →

Industry Research & Market Analysis

The Complete Guide to AI-Powered Visual Content Creation

Comprehensive Analysis of AI Image Editing, Generation, and Restoration Platforms Serving 50M+ Creators

30 minRead →

Strategic Frameworks & Playbooks

The Complete Guide to Setting up your US Tech Startup

Foundational decisions for entity selection, banking, payments, and compliance

13 minRead →

Industry Research & Market Analysis

AI Voiceover & Text-to-Speech: A Comprehensive Analysis

Technology, Use Cases, and Market Landscape for AI Voice Synthesis in 2025

25 minRead →

Industry Research & Market Analysis

AI Chat with PDF: Complete Guide & Top Tools

Comprehensive Analysis of the AI Document Interaction Market, Leading Platforms, and Industry Applications

30 minRead →

Industry Insights & Analysis

How Model Context Protocol Servers Facilitate Real-Time Decision Making in AI

Understanding MCP servers' role in enabling AI systems to access live data for instantaneous decisions

6 minRead →

Buyer's Guides & Solution Comparisons

CIAM Security Buyers' Guide 2025: 25 Essential Solutions

Essential Capabilities for Securing Customer Identity and Access Management

30 minRead →

Buyer's Guides & Solution Comparisons

Know Your Customer (KYC) Buyers' Guide 2025

25 Essential Solutions for Customer Verification and Compliance

30 minRead →

Buyer's Guides & Solution Comparisons

Privileged Access Management (PAM) Buyers' Guide 2025

25 Essential Tools for Privileged Access Security

30 minRead →

Buyer's Guides & Solution Comparisons

Workplace Identity & Access Management (IAM) Buyers' Guide 2025

25 Essential IAM Tools and Strategies to Strengthen Your Security Posture

30 minRead →

Authentication & Cryptography

The Future of Hashing: Quantum Resistance and Beyond

How cryptographic hashing must evolve to withstand quantum computing threats

22 minRead →

Authentication & Cryptography

Data Integrity Verification: Implementing Checksums and Hash Verification

Practical guide to implementing checksums and hash verification for data integrity

20 minRead →

Industry Insights & Analysis

Akamai's Identity Cloud Shutdown: The Migration Crisis That's Reshaping Enterprise Authentication

How 1,000+ enterprises face forced migration from Akamai's Identity Cloud

13 minRead →

Buyer's Guides & Solution Comparisons

Best IAM Solutions 2025: Complete Buyer's Guide

Navigating the $24+ billion IAM market with a comparison of 29 leading identity solutions

30 minRead →

Strategic Frameworks & Playbooks

AI Marketing Strategy for B2B SaaS: Expert Implementation

Strategic guide to AI-powered marketing intelligence for B2B SaaS companies

14 minRead →

Strategic Frameworks & Playbooks

The AI Revolution Toolkit: Strategic Framework for Building AI-Powered B2B SaaS Solutions

Frameworks for evaluating and integrating AI across B2B SaaS operations

14 minRead →

Strategic Frameworks & Playbooks

Essential DevOps Tools for B2B SaaS: Founder's Guide

A curated guide to the tools that power modern B2B SaaS infrastructure

9 minRead →

Strategic Frameworks & Playbooks

Building Enterprise Cybersecurity: A Strategic Guide to Security Categories for B2B SaaS

Essential security categories for competing in enterprise B2B SaaS markets

13 minRead →

Buyer's Guides & Solution Comparisons

Comprehensive CIAM Providers Directory: Top Identity Authentication Solutions

Expert analysis of 30+ CIAM solutions across six provider categories

35 minRead →

Strategic Frameworks & Playbooks

Enterprise CIAM Strategy Guide: Implementation & ROI Framework

Implementation frameworks, vendor evaluation, and ROI analysis for enterprise CIAM

13 minRead →

AI Deep Dives

The Complete Guide to Grok AI: Applications, Technical Analysis, and Implementation for Business Leaders

Everything business leaders need to evaluate and implement Grok AI

20 minRead →

AI Deep Dives

Grok AI - Core Concepts, Capabilities, Technical Foundation

Understanding Grok AI's architecture, training methodology, and distinctive capabilities

30 minRead →

AI Deep Dives

Grok 3 Architecture: How It Works Under the Hood

Deep-dive into Grok AI's transformer architecture, benchmarks, and engineering insights

28 minRead →

AI Deep Dives

Grok 3 vs ChatGPT vs Claude, Which AI Wins in 2026?

Comprehensive comparison of leading LLMs across performance, safety, and cost

19 minRead →

Authentication & Cryptography

bcrypt, scrypt, and Argon2: Choosing the Right Password Hashing Algorithm

A comparative analysis of leading password hashing algorithms for different security requirements

22 minRead →

Authentication & Cryptography

BLAKE2 & BLAKE3: Fast & Secure Hashing Options

High-performance hashing alternatives to traditional algorithms like SHA-2 and SHA-3

20 minRead →

Authentication & Cryptography

Secure Password Storage: Best Practices with Modern Hashing Algorithms

A comprehensive guide to modern password hashing techniques and implementation best practices

25 minRead →

Technical Implementation Guides

CIAM 101: A Practical Guide to Customer Identity and Access Management in 2025

From basic authentication to intelligent identity platforms

25 minRead →

Technical Implementation Guides

CIAM Implementation Guide: 5 Key Components & Best Practices 2025

Essential components and configuration for scalable identity solutions

30 minRead →

Technical Implementation Guides

CIAM Performance Optimization and Scalability Guide

Enterprise-scale authentication optimization for millions of users

26 minRead →

Technical Implementation Guides

CIAM Security Best Practices & Templates Guide 2025 | Implementation

Enterprise-grade security controls and implementation templates for CIAM systems

28 minRead →

Authentication & Cryptography

MD5: Understanding its Uses, Vulnerabilities, and Why It's Still Around

Examining MD5's cryptographic weaknesses and its persistent role in non-security applications

20 minRead →

Authentication & Cryptography

SHA-2 Family: Choosing Between SHA-256, SHA-384, and SHA-512

Analyzing the architectural differences, performance trade-offs, and use cases of SHA-2 variants

22 minRead →

Authentication & Cryptography

Passwordless Authentication Implementation Checklist

A structured approach to transitioning from passwords to passwordless authentication

18 minRead →

Buyer's Guides & Solution Comparisons

Passwordless Authentication Solution Selection Matrix

A comparative framework for evaluating passwordless authentication methods across organizational needs

15 minRead →