Skip to content
PrivateAI
← Back to Home
Privacy Rights

California's DROP Deadline Is August 1 — Here's Exactly What Happens to Your Data

9 min read min readBy PrivateAI Team

In 14 days, more than 600 companies that buy and sell your personal information become legally required to delete it — if you've asked them to. California's Delete Request and Opt-Out Platform, known as DROP, lets any California resident submit one free request that reaches every registered data broker in the state at once. Starting August 1, 2026, those brokers must act on it or face fines of $200 per day.

If you live in California and have never heard of DROP, this is the moment to submit your request. Here's what the law actually requires, what it covers, and exactly how to use it before the deadline hits.

California isn't the only state moving on this front — see our rundown of three new state privacy laws that took effect July 1 if you split time between states or have family elsewhere.

What DROP Actually Is

DROP stands for the Delete Request and Opt-Out Platform. It's a free tool built by the California Privacy Protection Agency (CPPA) as part of a 2023 law called the Delete Act. Before DROP existed, if you wanted a data broker to stop selling your information, you had to find that broker, figure out their opt-out process, and repeat that process one company at a time — sometimes across hundreds of companies you'd never even heard of.

DROP changes that. You create one profile, verify that you're a California resident, and submit a single deletion request. The CPPA then forwards that request to every data broker registered in the state — over 600 of them as of this year. Instead of chasing down 600 separate companies, you fill out one form.

The platform has been live since January 1, 2026, and more than 215,000 Californians have already registered. But the part that makes this month different is what happens on the broker side starting August 1.

Why August 1 Is a Real Deadline

Registering with DROP and submitting a request is one thing. Actually forcing a data broker to comply is another — and that's what changes on August 1, 2026.

Before this date, data brokers could register with the state and technically exist on the DROP system without a hard legal clock forcing them to process the deletion requests sitting in their queue. Starting August 1, that changes:

  • Data brokers must check DROP for new deletion requests at least once every 45 days.
  • Once a broker retrieves a request, it has 90 days to act on it and report the outcome back through the platform.
  • Brokers must maintain a "suppression list" — a record of everyone who has asked to be deleted — so they don't quietly re-collect your data later and start selling it again.
  • If a broker doesn't resolve a request in time, the law defaults that request to an opt-out, meaning the broker must at minimum stop selling or sharing your data even if full deletion is still pending.

This is why the timing matters right now. Any request submitted before August 1 is already sitting in the queue, waiting for that legal clock to start. Submitting your request now — rather than waiting until September or later — means you're first in line the moment brokers are required to act.

The Penalty That's Making Brokers Pay Attention

California isn't treating this as a suggestion. Data brokers that fail to process deletion requests through DROP face fines starting at $200 per day, per violation. The CPPA has already levied fines against at least one data broker for Delete Act violations and has stood up a dedicated enforcement team — sometimes called a "data broker strike force" — along with a Chief Privacy Auditor role specifically to check compliance.

That enforcement posture is exactly why this is a good moment to submit a request if you haven't already. Brokers that were slow-walking compliance now have a real financial reason to clear their backlog quickly, and your request is more likely to get processed promptly if it's already in the system when the deadline hits.

Who Can Use DROP, and What It Costs

Any California resident can use DROP. There's no cost to register, verify your residency, or submit a deletion request — the CPPA built and operates the platform, and by law it must remain free to consumers.

You do not need to be tech-savvy to use it. The entire process is a web form: you create a profile, confirm you live in California, and submit your request. You don't need to know which data brokers hold your information or track down each company's individual privacy policy. That's the entire point of the platform — it removes the burden of chasing hundreds of companies yourself.

What Kind of Data Gets Deleted

A single DROP request covers a broad range of information that data brokers commonly collect and resell, including:

  • Basic identifiers — your name, address, phone number, email
  • Online behavioral data — browsing habits, app usage, ad-tracking profiles
  • Financial information — income estimates, purchase history, credit-related data brokers hold
  • Health-related data — data not covered by medical privacy law but collected by brokers (fitness app data, wellness purchases, etc.)
  • Location data — where you've been, based on phone or app tracking
  • Relationship information — household members, known associates
  • Inferences — conclusions brokers have drawn about you, such as predicted income bracket, political leanings, or likely health conditions

That last category matters more than most people realize. Data brokers don't just sell what you've told them — they sell what they've guessed about you based on patterns in your data. A DROP deletion request is supposed to reach those inferences too, not just the raw facts.

Data brokers are also required to pass your deletion request along to any third parties they've shared your data with — other processors, service providers, or additional data brokers down the chain. In theory, one request triggers a ripple effect through the resale network, not just a single company's database.

How to Submit Your DROP Request

The process is straightforward:

  1. Go to the official DROP platform, run by the California Privacy Protection Agency at privacy.ca.gov. Be cautious of copycat sites — this is a government-run tool, and you should only use the official CPPA domain.
  2. Create a profile. You'll provide basic identifying information so the system can verify you're a California resident.
  3. Verify your residency. The platform will walk you through confirming your California residency status.
  4. Submit your deletion request. Once verified, you submit a single request that the CPPA distributes to all registered data brokers on your behalf.
  5. Keep a record. Take a screenshot or save a confirmation of your submission date. If a broker fails to comply after August 1, having proof of when you submitted your request matters if you ever need to file a complaint with the CPPA.

That's it — one form, one submission, and it covers every data broker registered with the state at the time you submit it.

What DROP Doesn't Cover

DROP is powerful, but it isn't a magic eraser for your entire digital footprint. A few limits are worth understanding:

  • It only covers registered data brokers. The law defines a data broker fairly specifically, and DROP only reaches companies that have registered under that definition. Companies that collect your data directly — retailers, banks, social media platforms, the apps on your phone — are not "data brokers" in this legal sense, even though they may also be collecting and using your information.
  • It doesn't stop you from generating new data. If you keep using apps and services that collect information about you, brokers who scrape or purchase that new data may pick it up again later. That's part of why the ongoing 45-day check-in requirement exists — it's meant to catch re-collection, not just handle a one-time cleanup.
  • Some data may be exempt. Information a broker needs for legal compliance, fraud prevention, or certain regulatory purposes may not be subject to deletion, even after a valid request.

Think of DROP as a powerful reset button for the data-broker resale industry specifically — not a way to disappear from the internet entirely. For the parts of your footprint DROP can't touch — like avoiding new profiles being built the next time you search something sensitive — see our guide to researching sensitive topics without leaving a profile that follows you.

If you'd rather not wait 45–90 days per request or want ongoing monitoring instead of a one-time submission, a paid removal service can run continuous sweeps on your behalf — see our comparison of the best data removal services in 2026.

The Kind of Companies DROP Actually Reaches

"Data broker" sounds abstract until you see what kind of businesses fall under that label. California's registry includes hundreds of companies you've likely never directly signed up with, including:

  • People-search sites — the services that let anyone type in your name and pull up your address, phone number, relatives, and sometimes your income bracket, often for a small fee
  • Marketing data resellers — companies that compile purchase histories and demographic profiles, then sell access to advertisers
  • Risk and identity data firms — brokers that aggregate public records into profiles used for background checks, tenant screening, or lead generation
  • Ad-tech data aggregators — firms that buy location and behavioral data from apps and resell targeting profiles to advertisers

These are the companies most people never interact with directly, which is exactly why a single-request tool like DROP matters. You can't opt out of a company whose name you've never heard, from a relationship you never knew existed. DROP sidesteps that problem by pushing your request to the entire registered list at once, rather than requiring you to first identify every broker holding your data. (If you've ever been on the other side of this — say, as a landlord pulling reports on applicants — it's worth reading how AI tenant screening tools quietly build their own broker-fed profiles.)

Why This Is Different From Past Opt-Out Laws

California and a handful of other states have had some version of "right to delete" on the books since the original CCPA took effect in 2020. In practice, those rights were hard to use. Each data broker set its own opt-out process, buried it in a privacy policy, and often required you to submit a request separately to each one — assuming you even knew the company existed.

The Delete Act changes the mechanics, not just the rights. Instead of a right that exists on paper but requires enormous manual effort to exercise, DROP centralizes the request into the state's infrastructure. You submit once. The state distributes it. And now, with the August 1 compliance deadline attached to real fines, there's a financial incentive for brokers to actually process it instead of letting requests sit in a queue indefinitely.

That combination — one request reaching hundreds of companies, backed by a per-day penalty for ignoring it — is what makes this meaningfully different from the opt-out rights that came before it.

Common Questions About DROP

Do I need to submit a new request for each data broker?

No. One DROP submission is distributed to every broker registered with the state at the time of your request. You don't need to identify or contact any of them individually.

What if a new data broker registers after I submit my request?

Newly registered brokers are added to the list brokers must check against, but your original request may not automatically reach a broker that registers after your submission date. Submitting again periodically, or checking your DROP profile status, helps catch brokers that register later.

Will this stop robocalls and spam texts immediately?

Not immediately, and not entirely. Deletion and suppression take effect over the 45-to-90-day compliance window described above, and some robocall and text campaigns run through channels DROP doesn't reach. Expect a gradual reduction, not an instant stop.

Does this replace a credit freeze or fraud alert?

No. DROP addresses data brokers reselling your information. It has no effect on credit bureaus or financial fraud protections, which are separate systems you'd still need to manage on their own.

Is my information at risk by submitting a request?

The verification step requires confirming you're a California resident, but the platform is operated by the state privacy agency specifically to reduce data exposure, not increase it. It does not require payment information.

Protecting Yourself Going Forward

Submitting your DROP request handles data that's already out there. But new accounts and sign-ups keep generating fresh data that brokers can pick up again down the road. One simple habit that reduces how much new data gets tied back to you: use a dedicated email address for privacy-related tools and account sign-ups, separate from the email you use for banking, shopping, and everyday communication.

Proton Mail is a good option for this specifically because it's encrypted end-to-end and isn't run by an ad-supported business that profits from your data the way many free email providers do — see how it stacks up against other options in our best private email providers comparison. Setting up a Proton address just for things like your DROP profile, opt-out confirmations, and other privacy tools keeps that activity cleanly separated from your main inbox — and out of the ad-targeting systems tied to it. If you want to take the email-separation habit further, our guide on signing up for AI tools without your real email address covers alias strategies you can reuse for any sign-up, not just DROP.

Affiliate Disclosure: This article may contain affiliate links. If you make a purchase through these links, we may earn a small commission at no extra cost to you. We only recommend products we genuinely believe in. This helps support our work and allows us to continue providing free content.

Your Action Checklist Before August 1

  • Visit the official DROP platform at privacy.ca.gov and confirm you're a California resident.
  • Submit your one deletion request now, rather than waiting until after the deadline.
  • Save a confirmation or screenshot with the date you submitted.
  • Mark your calendar to check back in roughly 45–90 days to confirm brokers are reporting progress.
  • Consider a dedicated email address for privacy tools going forward, so new sign-ups don't immediately feed the same resale pipeline you just asked to be cleared.

This is one of the rare moments where a single, free, five-minute action creates a legal obligation for hundreds of companies to act on your behalf. Don't let the deadline pass without submitting your request.

Last updated: 2026-07-18

Stay Ahead of the Next Deadline

New privacy laws and deletion tools like DROP roll out with almost no mainstream coverage until the deadline is already close. We track these so you don't have to find out too late.

Get the monthly privacy law tracker

We cover new state and federal privacy tools before enforcement starts — plus exactly what to do before each deadline.