Pull to refresh
Logo
California's one-stop data-deletion system starts enforcing against brokers

California's one-stop data-deletion system starts enforcing against brokers

Rule Changes

A single request through the state's DROP platform now orders 600-plus registered data brokers to erase a person's data every 45 days

August 1st, 2026: Deletion enforcement begins

Overview

For years, deleting yourself from the data-broker economy meant filing separate requests with hundreds of companies you had never heard of. From August 1, 2026, one form in California does it all at once.

The state's Delete Request and Opt-Out Platform, run by the California Privacy Protection Agency, routes a single verified request to every registered broker. More than 600 brokers must now check the platform at least every 45 days and delete matching data, including data they inferred about a person. Miss a request and the fine is $200 per person, per day.

More than 300,000 Californians had already queued requests before the deadline. That backlog makes August the first real-world test of whether a centralized deletion right can work at scale in the United States.

Why it matters

One form now orders 600-plus companies to erase your personal data, and California can fine each one $200 a day for ignoring it.

Questions about this story

No questions yet — be the first to ask.

Key Indicators

600+
Registered data brokers
Firms that must honor deletion requests submitted through DROP.
300,000+
Requests queued before deadline
Californians who submitted deletion requests before enforcement began.
$200
Fine per request, per day
Penalty for each consumer a broker fails to delete, accruing daily.
45 days
Deletion and re-check cycle
Brokers must check DROP and complete deletions on this recurring schedule.

Voices

Curated perspectives — historical figures and your fellow readers.

Ever wondered what historical figures would say about today's headlines?

Sign up to generate historical perspectives on this story.

Play

Exploring all sides of a story is often best achieved with Play.

Most of these play right now — no account needed. Sign up to save scores, keep a streak, and unlock Debate and Predict. Log in Sign Up
Predict 4 ways this could play out. Back the one you believe — contrarian picks score more when a scenario has a resolution date. Log in to play

People Involved

Organizations Involved

Timeline

October 2023 August 2026

6 events Latest: August 1st, 2026 · 1 week ago
Tap a bar to jump to that date
  1. DROP opens to consumers

    Milestone

    Californians can submit a single deletion request that reaches every registered broker. More than 300,000 sign up in the following months.

  2. Agency warns brokers against hiding

    Regulatory

    An enforcement advisory targets undisclosed trade names, unlisted websites, and reliance on parent-company registrations to obscure broker identities.

  3. First broker registration deadline

    Regulatory

    Data brokers must register annually with the state. The agency later fines several firms for failing to do so on time.

Historical Context

3 moments from history that rhyme with this story — and how they unfolded.

June 2003

National Do Not Call Registry opens (2003)

The Federal Trade Commission opened a single registry where people could block most telemarketing calls with one signup. By late October 2003 it held 53.7 million phone numbers. Telemarketers had to scrub their lists against it regularly or face fines of up to $11,000 per call.

Then

Tens of millions registered within months, and telemarketers challenged the registry in court before it survived and took effect.

Now

The registry became a lasting model for one-stop, government-run opt-out systems that put the burden on companies to check a central list.

Why this matters now

DROP applies the same design to data deletion: one government list, and companies must check it on a fixed schedule or pay per violation.

May 2018

Vermont's first data-broker registry (2018)

Vermont became the first US state to require data brokers to register and disclose basic information about their practices. The law made the industry visible for the first time. It did not, though, give residents a way to force brokers to delete their data.

Then

Hundreds of brokers registered, revealing an industry that had operated largely in the dark.

Now

Registration spread to California and other states, but registries alone left consumers without a deletion tool.

Why this matters now

DROP is the next step Vermont's law lacked: not just knowing who holds your data, but a working switch to make them erase it.

January 2020

California Consumer Privacy Act takes effect (2020)

California's landmark privacy law gave residents the right to see, delete, and stop the sale of their personal data. Enforcement began in July 2020. The catch: people had to exercise those rights company by company, one request at a time.

Then

Businesses added privacy request forms, but few consumers filed the many separate requests needed to cover the data-broker ecosystem.

Now

The law set the rights but exposed a gap in scale, which the Delete Act and DROP were written to close.

Why this matters now

DROP turns the CCPA's per-company deletion right into a single request that reaches every registered broker at once.

Sources

(9)