California’s DROP Is Live: What It Does, What It Doesn’t, and How to Use It
Rob Shavell
Reading time: 10 minutes
Key takeaways:
- California’s Delete, Request, and Opt-Out Platform lets Californians opt out of 600+ data brokers with one request. Data brokers began processing requests on August 1st.
- The sign-up process requires minimal personal data, and DROP claims it will protect your information.
- DROP does not currently have a monitoring process to ensure your data stays deleted. It relies on data brokers self-reporting their deletion progress. It also includes exemptions for publicly available data, which makes up the bulk of most data broker profiles.
- DeleteMe provides a way to verify compliance and also to monitor for exposure on data broker sites that aren’t part of California’s registry.
- For CA residents, DeleteMe + DROP = better together.
What is DROP?
The California Delete, Request, and Opt-Out Platform allows Californians to ask the 600+ data brokers operating and registered in the state to delete their data in just one request. It works like the California Do Not Call Registry, which removes personal phone numbers from telemarketer lists.
DROP requires personal information to complete those requests. It is minimal, and the platform promises to protect personal information with robust security and privacy measures.
DROP opt-out requests are enforced by the California Privacy Protection Agency, A.K.A. CalPrivacy. Unfortunately, data brokers can find ways around the enforcement. Case in point, those spam calls keep coming long after registering on the Do Not Call list,
Still, when Californa established DROP in January of 2026, we called it a win for everyone. It gives Californians more leverage when it comes to personal information removal from data broker sites. It’s a powerful tool, especially when paired with a privacy service like DeleteMe.
The DROP timeline
- January 1st, 2026 – Requests start: Submissions to California’s Delete, Request, and Opt-Out Platform (DROP) started in January of this year.
- August 1st, 2026 – Opt-Outs take effect: As of August 1st, data brokers have started processing those requests.
- November 1st, 2026 – California gives data brokers 90 days to comply, so the initial DROP requests should be processed by November 1st.
- 45-day cycles – From then on, data brokers must check back every 45 days to make sure they are still honoring those requests.
How to Sign Up for DROP
If you are a California resident, you can submit a request through DROP in six steps.
1. Go to the DROP opt-out page and accept the terms
Navigate to https://consumer.drop.privacy.ca.gov/ and read through the Terms of Use. You will have to scroll all the way to the bottom of the list of terms before you can click “I accept.”

2. Verify that you are a California resident
The DROP process will ask you to confirm California residency. Click “Verify you’re a California resident.” You will be taken to the California Identity Gateway, a government website that allows you to verify your identity while providing minimal personal information.
Alternatively, if you already have a Login.gov account, you can sign into that account to verify your residency.

3. Provide your personal information
The California Identity Gateway will request:
- Your first and last name
- Your birth date
- Your California street address
- Your phone or email to receive a code
- Your SSN (if you don’t want to enter your email or phone)
Once you’ve entered your personal information, click “Submit.”

4. Enter the verification code
You should receive an email or a text message with a verification code. Enter the code on the California Identity Gateway and submit it. You will be brought back to the DROP website. Your identity has been verified.
5. Create your DROP profile
Enter your personal information into the DROP form. You can enter your name, as well as any previous names, your date of birth, zip code, email addresses, and phone numbers you want removed.
You can also optionally include your vehicle identification number (VIN), mobile advertising IDs (MAIDs), and connected TV IDs.
This data will be “hashed,” meaning scrambled to protect your identity. The more information you share, the easier it will be for data brokers to find you and delete your data.
6. Submit your request and receive your DROP ID
Once you submit, DROP will send you to a confirmation page that includes an 8-digit number to help track your request. Save this DROP ID and don’t share it with anyone else.
Data brokers started processing requests this month. The new law gives them 90 days to report how they processed an initial request, and every 45 days they have to circle back to make sure the data stays down.
DROP Challenges
As mentioned, DROP is an important measure for consumer privacy in California. Hopefully, many other states will follow suit.
There are still some challenges DROP can’t fully address in its current form.
1. DROP applies to a limited number of data brokers.
DROP applies only to the 600 data brokers that are part of the state’s data broker registry. There are still hundreds of data brokers that fail to register with the state. These will not receive an opt-out request through DROP. No one is monitoring for your info on these sites unless you already have a membership with a data removal service like DeleteMe.
2. California data brokers don’t always comply with requests.
Of the data brokers on the registry, many are known for failing to comply with opt-out requests. A 2026 Stanford study showed just 9% of data brokers were in full compliance with California’s Delete Act as of August 11th. The Delete Act is the foundation of DROP. The study noted that future enforcement actions and compliance audits that will begin in 2028 may help to increase that number.
This compliance gap is one reason it can be helpful for a private third party to monitor for compliance and continue to send requests until data brokers remove your information.
3. Data brokers re-upload your information.
Many data brokers re-upload profiles after a certain amount of time. DROP requires data brokers to add your data to a suppression list and check back every 45 days to ensure your info stays private. However, the expectation is that data brokers will self-monitor, and historically, they haven’t done a very good job of that.
4. Data brokers may deny having your record when they do.
Sometimes, data brokers will report “record not found” even when your record is clearly in their database and searchable on Google. In the DeleteMe platform, you can submit a custom request to ensure your information is removed. Right now, DROP doesn’t offer custom removals.
We expect to see CalPrivacy increase its enforcement activity in the coming years. Already, failure to register may result in fines, as happened in two recent cases where data brokers paid $52k and $110k respectively for failure to register. Those fines may be viewed as the cost of doing business for data brokers, but it’s a start.
5. DROP allows exemptions for publicly available data
According to DROP’s website:
“There are cases where data brokers may keep some of your data.
Exempted — These data brokers have data about you but haven’t deleted it because it’s exempt under the law. Examples include:
- Public records, like vehicle or real estate ownership or voting records
- Responding to a criminal or civil investigation”
Legally, this means a data broker can respond to a DROP request by only deleting data that is not sourced from or already included in public records.
The problem is that voting files, which are just one type of public record, already can include:
- Names
- Addresses
- Ages
- Phone numbers
- Email addresses
- Political party affiliations
And additional data in certain states.
Property records will allow data brokers to keep information on your current and previous addresses.
DROP does apply to precise geolocation data and other sensitive information that is not of public record.
Even if data brokers decide to remove your entire profile in response to DROP initially, it’s only a matter of time until these companies begin to take advantage of the loopholes and exemptions.
When DeleteMe opts out on your behalf, we ask that your entire profile be removed from data broker sites, including your name, age, phone number, voting record, etc. DeleteMe’s not perfect, and neither is DROP – but they’re better together and move privacy protection for Californians in the right direction.
6. DROP doesn’t have a business portal
DROP currently does not provide a way for businesses to protect the privacy of their employees. This is important because cybercriminals are known to reference data broker sites to research potential targets within companies.
DeleteMe’s business plans help fill this gap.
Delete, Request, and Opt-Out Platform FAQs
Here’s everything else you might want to know about DROP.
1. How much information does DROP collect?
To submit any kind of removal request, you will need to provide certain information. DROP requires your:
- Name(s)
- Date of birth
- ZIP code(s)
- Email address(es)
- Phone number(s)
You can also optionally submit your:
- Mobile advertising ID (MAID)
- Connected TV ID
- Vehicle identification number (VIN)
DROP promises to protect this information with advanced security features.
2. If you can use DROP, why use DeleteMe?
Laws alone are rarely enough to stop data privacy violations on the part of data brokers. The data economy is too well-established.
DeleteMe can:
- Monitor your exposure after opt-outs
- Identify data broker compliance failures
- Submit custom, persistent removal requests
- Continuously monitor and re-remove your data as it resurfaces
Using DeleteMe helps you enforce the rights that DROP and California’s Delete Act provide.
3. Is DROP a DeleteMe competitor?
DROP is not a DeleteMe competitor, strictly speaking. We are a data removal service that constantly monitors your exposure and deletes your information from broker sites. DROP is a government website that allows you to opt out from 600+ registered data brokers with one request. DROP’s process is based on data brokers accurately reporting their removals over a period of time and does not apply to exempt data obtained from public records.
4. Is privacy.ca.gov/drop legit?
Yes, privacy.ca.gov/drop is the legitimate website you can visit to submit a DROP privacy request and opt out of 600+ websites.
5. Will data brokers comply with DROP privacy requests?
Some will. Some will delay as long as possible. Some won’t honor opt-outs at all, and some aren’t registered through DROP which means CalPrivacy will have a harder time monitoring for compliance.
The best option is to rely on DROP for a baseline level of privacy and use a service like DeleteMe to monitor for compliance on opt-out requests and to check for your data beyond the California data broker registry.
Final thoughts
To finish up, we’ll go back to what we already said once about DROP:
DROP is progress.
DeleteMe is protection.
Use both to take back control of your data and stay safer online.
Learn More
- Read our original guide to the Delete, Request, and Opt-Out Platform and why it’s a win for everyone.
- Learn more about data brokers with our comprehensive guide.
- Add your number to the California Do Not Call Registry.
Save 10% on any individual and
family privacy plan
with code: BLOG10
Our privacy advisors:
- Continuously find and remove your sensitive data online
- Stop companies from selling your data – all year long
- Have removed 35M+ records
of personal data from the web
news?
Don’t have the time?
DeleteMe is our premium privacy service that removes you from more than 750 data brokers like Whitepages, Spokeo, BeenVerified, plus many more.
Save 10% on DeleteMe when you use the code BLOG10.



