California Just Made It Easier to Disappear From Data Broker Databases
Key Takeaways
- California's DELETE Request and Opt-out Platform (DROP) tool lets state residents send a single deletion and opt-out request to all 614 registered data brokers in one step, replacing a process that previously required filing individually with each company.
- As of August 1st, 2026, data brokers will have 45 days to act on requests — meaning filing now puts you at the front of the queue.
- A single DROP request can include identifying information, such as Social Security numbers, precise geolocation, browsing history, email addresses, and phone numbers, as well as inferred data, such as political views or health information.
- The tool has real limits: it doesn't cover companies that aren't registered data brokers (including Google), new brokers who register after you file, and doesn't prevent ongoing data collection — only its sale and use.
California has launched a tool that lets residents wipe their personal data from hundreds of companies with a single request. The DELETE Request and Opt-out Platform (DROP) is administered by the California Privacy Protection Agency and sends a simultaneous deletion and opt-out request to every data broker registered with the state.
As of writing, that's 614 companies. Previously, exercising the same rights required filing individually with each one — a process so time-consuming it was effectively inaccessible for most people, according to the Electronic Frontier Foundation, which advocated for the law that created DROP.
Filing a request before August 1st means you're on the ground floor: data brokers have until August 1 to begin complying, and once they do, they have 45 days to act on each request received. The opt-out of sale request lasts indefinitely.
The deletion request covers a wide range of personal data: social security numbers, precise geolocation, browsing history, phone numbers, email addresses, and inferred data, including guesses data brokers have made about your political views, health conditions, or personal circumstances based on your purchasing or browsing behavior.
To file, you go to the California Privacy Protection Agency's DROP website. You'll need to provide some personal information to verify your identity (name, address, phone number, email), which the EFF acknowledges carries a certain irony, but which is necessary for the system to match your request to your records in each broker's database. The agency is bound by its terms of service not to sell or share what you provide.
Why This Actually Matters — and What It Won’t Fix
Data brokers are the largely invisible infrastructure behind a significant portion of the spam, scam calls, unsolicited emails, and targeted advertising that most people experience as routine annoyance.
They collect personal information (from public records, app data, purchase histories, social media) repackage it, and sell it to anyone willing to pay: marketers, insurers, employers, law enforcement, and in some cases, stalkers or predatory lenders. Most people have no idea how many of these companies hold their data, or what they've inferred from it.
DROP doesn't eliminate this system. It creates a meaningful lever within it. For California residents, it's one of the most practical privacy tools currently available; a single action that reaches hundreds of companies at once and legally requires them to respond. That's genuinely useful.
But the limits are real and worth understanding clearly. DROP only reaches registered data brokers. Google, Meta, and other large platforms that collect and share personal data are not on the list. New brokers registering after you file won't receive your request automatically.
And the opt-out stops companies from selling your data, it doesn't stop them from continuing to collect it. You will likely need to refile periodically as new brokers enter the registry and as your data continues to be collected and re-aggregated.
The Bigger Picture
I think tools like DROP are genuinely worth celebrating, with clear eyes about what they represent. This is a state government creating infrastructure that makes an existing legal right actually exercisable by ordinary people, not just by privacy specialists with the time and knowledge to navigate hundreds of individual opt-out processes. That's meaningful progress.
It's also a reminder of how far the default sits from where it should be. The fact that 614 companies currently hold and sell personal data about California residents (legally, as a business model) and that opting out requires a dedicated government platform, individual verification steps, and ongoing maintenance, tells you something about how data collection became normalized before the legal framework caught up.
For anyone outside California: versions of the Delete Act have been introduced in other states, and regulators across the country are watching California's implementation. In the meantime, the EFF's Opt-Out October guide covers privacy steps available to residents of all states. The tools are limited, but they exist, and using them is better than not using them.
Be part of the resistance, quietly.
Get Mysterium VPN

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.
