One Form Tells 654 Data Brokers to Delete You. In California It Is Free, and Since August They Have Had to Do It.
September 23, 2026
It went live on January 1 and the brokers' deadline landed on August 1. The state says it takes under ten minutes, and that the typical Californian who has signed up has already been deleted by more than forty companies.
After almost every scam call, scam text or too-personal piece of junk mail, the customer asks us the same question: how did they get my number? Or my email, or my address, or the fact that I am sixty-eight and own my house.
Sometimes the answer is a breach — something was stolen. More often nothing was stolen at all. Your details were collected, packaged and sold, entirely legally, by companies you have never heard of and never dealt with. That is a whole industry, and California is the one place in the country where you can now hand it a single piece of paper.
Since January 1, 2026 the state has run a free tool called DROP that sends one deletion request to every data broker registered in California. Since August 1, 2026 those brokers have been legally required to go and get that request and act on it. This is what it does, what it will not do, and the ten minutes it takes — written for someone who lives here, because that is the one thing that decides whether you can use it.
First, the difference between a breach and a broker
These two get mixed up constantly, and the difference decides which tool you reach for.
A breach is theft. A company that held your information lost control of it, and some months later you get a letter about it. We have written separately about how to check one of those letters is genuine and what to do in what order.
A data broker is the opposite: nothing went wrong. California law defines one as a business that "knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship" (Civil Code section 1798.99.80(c)). You never signed up, never clicked anything, and never had the chance to say no — that is the definition, not a loophole in it.
The state's own description of what they hold is worth reading slowly. CalPrivacy, the agency that runs the system, lists Social Security numbers, precise geolocation, browsing history, email addresses, phone numbers, interests, health-related information and shopping habits. It also lists what brokers work out from that data rather than collect: political views, searches about conditions like pregnancy, cancer or diabetes, family and relationship details, and financial ones — including, in the agency's words, "predictions about how much you'd be willing to pay for a given product." Those inferences count as personal information under California law, so they are deletable too.
And the buyer list is not abstract. CalPrivacy names advertisers, employers and recruiters, political campaigns, retailers, landlords and debt collectors — and then says plainly that brokers may also sell to buyers with malicious intent, including hate groups, hostile foreign governments and scammers. That last one is the sentence that brings this onto our desk.
What DROP is, and what the law now requires
The Delete Act — Senate Bill 362, passed in 2023 — told the state to build one mechanism that lets a person direct every registered data broker to delete their information with a single request. The agency adopted the regulations for it on September 26, 2025, the Office of Administrative Law approved them on November 6, 2025, and they took effect on January 1, 2026. The tool is called the Delete Request and Opt-out Platform, or DROP.
Two dates matter to you. On January 1, 2026 Californians could start submitting requests. On August 1, 2026 the other half switched on: data brokers must now access DROP at least once every 45 days and process the deletion requests waiting there, subject to limited exceptions (Civil Code section 1798.99.86(c)). Before August the requests piled up; since August they have been an obligation with a fine attached.
It is free. The agency states it flatly on its own page — "Free — we will never charge you to use DROP" — and that sentence is going to matter later in this article.
As of the state's update on August 25, 2026, 654 data brokers were in the system. One form reaches all of them, including the ones headquartered in other states, and it keeps reaching the ones that register after you sign up.
The ten minutes: what you actually do
You start at privacy.ca.gov/DROP. The state describes it as a one-time process that generally takes less than ten minutes, and in our experience that is honest as long as you have decided in advance what you are willing to type in.
Step one is residency. DROP is only for California residents, and it checks that through the California Identity Gateway, the state's own identity platform. You do not need to create an account with it, and the information you enter there is used to confirm residency and is not kept by DROP. There is an option to sign in with Login.gov instead; CalPrivacy's own advice is to use that only if you already have a Login.gov account, which is sensible — do not open a federal login account in order to fill in a state form.
Step two is your profile. The absolute minimum is your name, your date of birth and your ZIP code. Everything else is optional and you can come back later.
Step three is submitting it. You get an eight-digit DROP ID on screen, and you can have it emailed to you. Save it somewhere you will still have it in six months — a password manager, or written in the same place you keep account recovery codes — because it is how you check your status later. The state also says, and we would underline it, do not share your DROP ID with anyone.
The counterintuitive part: put more in, not less
Most people's instinct on a government form about privacy is to give as little as possible. Here that instinct works against you, and it is worth understanding why before you decide.
Brokers do not receive your details. DROP hashes what you enter — turns it into a fixed string of characters that cannot practically be turned back — and the brokers match against the hash. The agency publishes its own example: you type emailaddress@email.com, you see it displayed as e###s@e###m, and the data broker sees IokUeTFtxXZQdmjolr4Kn//apUY5a6J8sVdHyiWqqUk=. They are checking whether that string appears in their files, not reading your address.
Matching is the whole game. A broker deletes your record if any identifier you supplied matches theirs — and then, importantly, it must delete everything it holds about you, not just the piece that matched. So an old email address from 2009 that you never use is not clutter on the form; it is another key that might open another broker's file. Different brokers know you by different things.
You can enter more than one of everything except your date of birth: several names including maiden names, several email addresses, several phone numbers. If you have moved, the old phone number is worth adding. If you changed your name, the old one is often the one the broker still has.
The three identifiers nearly everyone skips: your phone, your TV and your car
DROP also accepts three technical identifiers, all optional, that most people leave blank because they do not know where to find them. They are the ones that catch the brokers who track devices rather than people.
Your phone's advertising ID. This is the Mobile Advertising ID, or MAID — a long code, 32 characters and four hyphens, that lets apps and ad networks follow activity across apps on one device. On Android, CalPrivacy's directions are Settings, then Google, then Privacy and security, then Ads. On a Samsung it is Settings, Google, Security and privacy, More Privacy Settings, Ads. On an iPhone there is nothing to copy: Apple does not show its version of the number anywhere in the interface, and the agency's own note is that if "Allow Apps to Request to Track" under Settings, Privacy and Security, Tracking is switched off, your device does not currently have one at all. If it is on, turning it off stops that tracking going forward. CalPrivacy explicitly says it does not require or advise using any third-party app to dig the number out, which is the right call — an app that offers to find your advertising ID is an odd thing to install for privacy reasons.
Your television. Smart TVs carry a connected TV ID used the same way, and the location differs by brand: with the remote, go into settings and look under Support, System Information, About or Device information for something called a connected TV ID, unique ID or device ID. It is up to 36 characters. If your TV has been signed in to streaming apps for years, this is a genuinely useful one.
Your car. A VIN is the 17-character code on the plate at the base of the windshield, on the sticker in the driver's door jamb, and on your registration, title and insurance paperwork. It is in DROP because cars are a data source now: in a separate action, CalPrivacy joined the Attorney General and four district attorneys to hold General Motors accountable over data sharing from connected vehicles, resulting in a $12.75 million civil penalty.
None of the three is required. If you cannot find one in two minutes, leave it out and submit — you can add it later.
The five words you will see when you check back
This is the part no news article covers, and it is where people decide the thing did not work. You check status with your DROP ID, and each broker reports one of five results.
Pending means that broker has not processed your request yet. Brokers have up to 90 days to report how they handled it, so pending is normal early on.
Deleted means what it says: they matched you and deleted the non-exempt personal information they held.
Exempted means they have information about you and the law lets them keep it. More on that in a moment.
Opted-out is the interesting one. It means the broker could not make an exact match from what you gave them — so they still have data, but they may no longer sell or share it. The agency's own example is a shared family email address that cannot be tied to one person. If you see a lot of these, adding another identifier is the fix.
Record not found means they did not find you, either because they have nothing or because what you gave them was not enough. Again: add more information.
One thing to hold on to — this is not a one-off. After the first pass, brokers must re-check and delete newly matching data at least every 45 days, and a request they could not match has to be kept and kept working, so you do not resubmit. You can go back into your profile and add information once every 45 days.
What DROP will not do
The honest limits, because a tool oversold is a tool people abandon.
It does not touch information you handed over yourself. If you created an account, joined a loyalty scheme or signed up for a newsletter, that is first-party data and the business is not required to delete it because of your DROP request. You can ask them directly under your ordinary California privacy rights — but that is a separate request to a separate company.
It does not override other laws. Public records stay: vehicle and real estate ownership, voting records. Data needed for a criminal or civil investigation stays. Patient health information under HIPAA, information affecting your credit score under the Fair Credit Reporting Act, and financial information governed by Gramm-Leach-Bliley all stay. That is what Exempted means when you see it.
It does not stop scam calls. It reduces the supply. CalPrivacy's own wording is careful and we will not improve on it: limiting how your data gets sold "can reduce the volume of unwanted texts, calls, or emails you receive," and "results will vary by consumer and may take time to notice." Keep blocking and reporting the texts you get; this works underneath that, not instead of it.
And it is for California residents only. That is not a small print problem for us — everyone we work with in Los Angeles, Orange, Riverside, San Diego and Ventura counties qualifies — but if you are helping a relative in another state, this particular tool is not available to them.
There is a trade-off worth knowing about too, and the state names it: with less data circulating you may see fewer targeted ads and less personalised content. Most people consider that the point.
Is it actually working? The state publishes numbers
As of August 25, 2026, more than 500,000 Californians had registered, and brokers had reported deleting tens of millions of records. Of the 654 brokers in the system, roughly a quarter had reported processing requests in the first weeks after the August 1 deadline — and 99.9% of people who had signed up had already been deleted by at least one broker, with the typical user removed by more than forty of them.
The state's own expectation is that by November 2026 every broker in DROP should have completed a first full download-and-report cycle. So if you sign up now, the useful moment to check your status is a couple of months out, not a couple of days.
Enforcement is real and is running in parallel. The fines are $200 a day for a broker that fails to register, and $200 a day per deletion request for one that fails to delete, plus the agency's investigation costs. In August the agency's board required LocateSmarter LLC, an Iowa broker, to pay $116,490 — its first action against a data broker under both the California Consumer Privacy Act and the Delete Act — partly for registering late and partly because the company demanded the last four digits of people's Social Security numbers before it would let them opt out. On September 1 a Virginia broker, SalesIntel Research, was required to pay $36,400 for failing to register on time, and ordered to get into DROP and process deletion requests through it going forward.
The scam that is going to follow this, because one always does
Every widely publicised consumer right grows a parasite industry within a year, and this one has the perfect shape for it: an unfamiliar government process, an eight-digit reference number, and a wait of several months in which nothing visible happens.
So, the rules. DROP is free and the agency says it will never charge you to use it. Nobody from the state is going to phone you about your deletion request. Your DROP ID is not something to read out to a caller, type into a form you reached from an email, or post in a review. When you want to check your status, go to privacy.ca.gov/DROP yourself, the same way you did the first time — not through a link someone sent you.
Paid removal services are a separate matter and are not illegal; some have existed for years. Just be clear about what you would be buying: for the 654 brokers registered in California, the state now does this for nothing, and does it every 45 days.
And take the LocateSmarter case as a portable rule, because it is the cleanest one we have seen in a while. A company that wants part of your Social Security number before it will stop selling your data is not being careful — in California it is doing the specific thing a regulator just fined a company for. No opt-out needs your Social Security number.
If you only do this for one person, pick the one getting the calls
The people whose phones ring six times a day with fake toll charges, fake Medicare kits and panicked grandchildren are usually not the people who will sit down and work through a state web form. DROP allows for that: you can submit a request on behalf of another California resident with their permission — the agency's examples are a parent filing for a child and a family member filing for an elderly relative. You verify that person's residency as part of the process, so have their details to hand.
It is a good half hour of a Sunday: sign up yourself, then sit with a parent and do theirs, collecting the old email addresses and the previous phone numbers as you go. CalPrivacy also publishes DROP brochures in eleven languages, which is useful if the person you are helping would rather read it in their own.
What we do with this, and what we do not
We are a computer and home-network shop, not a law firm, and none of this is legal advice — it is what we tell a customer who asks why the calls will not stop. But it has become a normal part of a security visit: we will sit with you and go through DROP alongside the things that make a faster difference, like blocking and reporting spam texts properly, tightening what your phone shares, and getting recovery details straight on the email account everything else hangs off.
The way to think about it is supply and demand. Freezing your credit, filtering your calls and knowing what a real breach letter looks like all deal with what has already reached you. DROP is the only one of these that reaches back up the chain and removes you from the inventory. It takes ten minutes, it costs nothing, and as of this month it is the rare consumer protection with a deadline the other side has to meet.
Keep reading
- A Letter Says Your Data Was Breached. Here Is How to Check It Is Real and What to Do in What Order.
- Getting Nonstop Spam Texts? How to Block and Report Them the Right Way (iPhone & Android)
- That Panicked Call From a Loved One Might Be AI: The Voice-Clone "Grandparent" Scam
- That "Microsoft Security Alert" Pop-Up With a Phone Number Is a Scam
- Someone Says They Can Get Your Money Back? That's the Second Scam
Free calculators
Service areas we cover
We don't sell hardware or warranties — call and we'll tell you what's worth buying and upgrading.
Call (626) 655-0020