Californians' data deletion requests, DROP, become enforceable Aug. 1

Californians' data deletion requests, DROP, become enforceable Aug. 1

Starting Aug. 1, registered data brokers in California must honor deletion requests submitted through the state's Delete Request Opt-out Platform (DROP). About 350,000 residents have already signed up. The tool lets consumers avoid contacting hundreds of companies individually. Non-compliant brokers face fines of $200 per day per affected Californian. Cal Privacy has already fined 12 brokers for failing to register. The tool won't erase all online data, but offers a new way to push back.

We oftentimes are the product, our information, our data is the product that people collect, package up into digital dossiers and sell.
  1. jboggan

    I've been building the infra for data brokers to connect to DROP (easy), actually effect deletions (hard), and make sure the data stays deleted (harder): forgetmenaut.com

    DROP is pretty significant considering that it's the first compliance system meant to have an immediate effect (delete the data), backward-looking effect (forward a legally-binding deletion request to everyone that data was sold to or shared with), and a forward-looking effect (never let that record re-enter your system, in perpetuity). This is significantly more tracking and auditing infrastructure than anyone in the industry has ever normally run, not to mention that the request volume is 100-10000x what most of these brokers would process in previous years.

    We'll see how well companies actually managed to comply when audits are performed for every registered broker in 24 months. I also think the impending prosecutions (and likely bankruptcies) of several unregistered data brokers will encourage the others to take it more seriously.

  2. ryandrake

    As good intentioned as it is, I don't like the wording used around this law. "Request" and "Ask" and "please delete my information." Notice that regular users have to "ask nicely" but when it's something like the DMCA, which benefits corporations, they use "takedown notices" and "demand letters."

    I don't want to ask data brokers, pretty please with sugar on top. I want to be able to demand they do it, and require them to immediately do it and provide proof that they did, under penalty of perjury.

  3. petilon

    I hope other states adopt this. One of the biggest mistakes I have made is giving my real phone number to Dun & Bradstreet. Now the spam calls and messages (from people they sold my info to) won't stop. I don't want to change my phone number.

  4. hedora

    Does this apply to Google, car companies, etc, or did they bribe in exceptions for themselves (like California grocery stores did for the Do Not Sell My Personal Information law)?

    Also, who gets the $200/day? If I issue a drop request, wait 145 days, then buy my data from brokers, do they have to pay me $20,000 per record they return?

  5. MrZander

    Out of curiosity, does anyone know how this is enforceable for a company not based in California? Can CA fine a data broker that is based in another state but that is selling CA residents' information?

More from this day

2026-08-02