Local Tech Fix (626) 655-0020
All articles

DROP Cannot Touch the Companies You Signed Up With Yourself. Here Is How You Make Them Delete You.

September 23, 2026

The state form takes ten minutes and covers 654 brokers. The airline, the pharmacy chain, the gym and the app you signed up for in 2019 are not on that list — but California gives you a separate, free, enforceable way to reach each of them.

white and black eraser
Photo by Marija Zaric on Unsplash

We wrote recently about DROP, the state tool that sends one free deletion request to every data broker registered in California. It is the best ten minutes of privacy housekeeping available to anyone who lives here, and we now walk customers through it as a normal part of a security visit.

It also has one boundary that catches people out, and the question always arrives about a week later: "I did the DROP thing — why is the gym still emailing me?" Because the gym is not a data broker. California defines a broker as a business that sells your information despite having no direct relationship with you. The moment you created an account, joined a loyalty scheme, booked an appointment or handed over an email address at a checkout, that company has a direct relationship with you, and DROP does not reach it.

Those companies are not out of reach. They are just reached one at a time, under the ordinary California Consumer Privacy Act, and the process has real deadlines attached to it. This is the operational version: where the form is legally required to be, what they can ask you for, what they are allowed to refuse, how long they have, and what to do on the day the deadline passes in silence.

One thing to settle first, because it changes everything below: these are rights of California residents. The law defines a consumer as a natural person who resides in California, even if they are temporarily out of state. Everyone we work with in Los Angeles, Orange, Riverside, San Diego and Ventura counties qualifies. A relative in Nevada does not, and should be pointed at their own state's attorney general instead.

Does this company even have to answer you?

Start here, because it saves a lot of wasted correspondence. The CCPA applies to for-profit businesses doing business in California that meet at least one of three tests, which the Attorney General states plainly: gross annual revenue over $25 million; buying, selling or sharing the personal information of 100,000 or more California residents or households; or deriving 50% or more of annual revenue from selling California residents' personal information.

That is a short list of thresholds but a long list of companies, because the first one catches essentially every national retailer, carrier, insurer, airline, bank, hotel chain, supermarket, streaming service and large app you have ever signed up for. If the company has a "Your Privacy Choices" link in its website footer, it has already answered this question for you — it would not have built one otherwise.

It does not catch the independent shop down the road, and we should say so about ourselves: we are a small computer and network repair business, we are nowhere near any of those three thresholds, and the CCPA does not apply to us. Nonprofits and government agencies are generally outside it too. If you send a formal CCPA demand to your dentist or your local plumber, you are likely to get a polite and entirely lawful shrug. Ask them to delete your details as a customer instead; most small businesses will simply do it.

There is one exemption worth knowing has ended. The carve-outs for employment-related personal information and for business-to-business contact data expired on December 31, 2022. So the company you work for, or used to work for, is covered like anyone else — a former employer holding a file on you is answerable to the same requests as a retailer.

The five things you can actually ask for

People say "delete my data" for all five of these, and the difference matters, because the company is allowed to treat your request literally.

The right to know. You can ask a business to disclose the categories and the specific pieces of personal information it has collected about you, where it got them, why it uses them, which categories of third parties it discloses them to, and what it sells or discloses. It must cover the 12-month period before your request, and it must do it free of charge. You can make this request up to twice a year.

The right to delete. You can ask a business to delete the personal information it collected from you, and to tell its service providers to do the same — subject to a list of exceptions we go through below, which is longer than most people expect.

The right to correct. You can ask a business to fix inaccurate information it holds about you. Worth knowing before you rely on it: as of the Attorney General's August 28, 2026 update, the California Privacy Protection Agency's rulemaking on the correction right and the limitation right was still in progress and those proposed regulations were not yet final or effective. The statutory right exists; the detailed rules around it are still being written.

The right to opt out of sale or sharing. You can tell a business to stop selling or sharing your information. "Sharing" here has a specific meaning — sharing for cross-context behavioral advertising, which is targeting ads to you based on your activity across other websites. Once you have opted out, the business cannot start again unless you authorize it, and it has to wait at least 12 months before it is even allowed to ask you to opt back in.

The right to limit use of sensitive personal information. This is the least used and often the most relevant one. Sensitive personal information is a defined subset: government identifiers such as Social Security numbers; an account login, financial account, debit or credit card number together with the password or security code that would open it; precise geolocation; the contents of your mail, email and text messages; genetic and biometric data; information about health, sex life or sexual orientation; and information about racial or ethnic origin, religious or philosophical beliefs or union membership. You can direct a business to use that category only for limited purposes, such as actually providing the service you asked for.

Where the request form has to be — and why the contact-us page is the wrong door

This is the part that turns a fifteen-minute job into a three-week one when you get it wrong. A business must designate at least two methods for submitting requests to know, delete or correct — for example an email address, a web form or a hard-copy form. One of them has to be a toll-free telephone number, and if the business has a website, one of them has to be through that website. A business that operates exclusively online and has a direct relationship with you only has to provide an email address.

The instructions must be in its privacy policy. That is a legal requirement, not a courtesy, so the privacy policy is where you go first — bottom of the homepage, usually, and the link is often titled "Privacy" or "California Privacy Rights". In a mobile app, look on the download page or in the app's settings menu.

Now the trap, in the Attorney General's own words: the designated method "may be different from its normal customer service contact information." Sending a deletion demand to the general support inbox, or raising it in a chat window, frequently means nothing legally happened. No clock started. Nobody is late. Use the designated channel, even when it is uglier and slower than the one you already had open.

For opt-outs specifically there is a separate, more visible route. A business that sells or shares personal information must post a clear and conspicuous link, and the permitted labels are "Do Not Sell or Share My Personal Information", "Your Privacy Choices" or "Your California Privacy Choices", in the header or footer of its site. If you cannot find it, open the privacy policy — if the business sells or shares, the link has to appear in there as well. Businesses that use or disclose sensitive personal information beyond the permitted purposes must post a comparable link for the limitation right.

One small thing worth not chasing: the Attorney General publishes an official CCPA opt-out icon, the little symbol you sometimes see beside "Your Privacy Choices". Using it is optional — the AG's own page says businesses "can use" it and that it does not substitute for the mandatory link. So the absence of the icon tells you nothing. The absence of the link tells you something.

Two things a business is not allowed to do: it cannot make you create an account just to submit a request, and it cannot make you waive these rights. Any contract term saying you waive them is unenforceable. If you already have an account with them, though, it is allowed to require you to submit the request through it.

Say which request you are making, in words

The Attorney General publishes anonymized examples of CCPA cases its office has taken up, and one of them is the best argument we know for being pedantic in the first sentence of your request.

A healthcare business that matched patients with open vaccination appointments "incorrectly treated some consumer requests to know as requests to delete and permanently deleted consumers' personal information." People had asked what the company held on them. The company erased it instead. That is unrecoverable, and it happened at scale before anyone noticed.

So do not open with "please delete my data" when what you want is a copy of it, and do not open with a vague paragraph about privacy and hope the intake team picks the right box. Name the right: "This is a request to know under the CCPA. I am not requesting deletion." If you want both, say so, and say the order — know first, then delete — because once they have deleted, there is nothing left to disclose to you.

The same care applies to an account you still want. Deletion is not a tidy-up: it can take the account, the order history, the warranty registration and the loyalty balance with it.

The clocks: ten business days, forty-five calendar days, ninety at the outside

These are the numbers to write down, because they are the whole basis of any complaint you might later make.

For a request to know, delete or correct, the California Privacy Protection Agency states that a business must confirm receipt of your request within 10 business days and must substantively respond within 45 calendar days. It can extend by another 45 days — 90 in total — but only if it notifies you. A silent extension is not an extension.

For an opt-out of sale or sharing, or a request to limit sensitive information, the clock is much shorter: as soon as feasibly possible, and no more than 15 business days from receipt.

Note what the 45 days is measured from. It runs from the date the business received the request. Verifying your identity does not pause it, which is why a company that spends three weeks emailing you back and forth about proof of address is running down its own clock, not yours.

If nothing arrives, the official advice is the unglamorous version and it is correct: re-check the privacy policy to confirm you used a designated method, then follow up with the business — both to confirm it is actually subject to the CCPA and to chase the request. Do that in writing, on the same channel, so that the follow-up is on the record too.

Why they are asking you for more information

For requests to know, delete or correct, a business must verify that you are who you say you are, so being asked for more detail is normal rather than obstructive. There is a hard limit on it, though, and it is the sentence to quote if you ever need to: if the business asks for personal information to verify your identity, it can only use that information for verification.

Opt-out requests are different and more people should know this. A business is not required to verify an opt-out. It may ask basic questions to work out which records are yours — it cannot sensibly stop selling the right person's data otherwise — but a verification wall in front of an opt-out button is not how the right is meant to work.

There is a floor under all of this. A company that demands part of your Social Security number before it will honor an opt-out is not being cautious; in California that is the specific conduct a regulator has already fined a company for, as we covered in the piece on DROP. No opt-out needs your Social Security number.

And if you are using an authorized agent rather than asking yourself, expect the opposite problem: the business may require more from both of you. For requests to know or delete it can require the agent to show your signed permission, and it can require you to verify your identity with it directly or confirm directly that you gave the agent permission.

Why they said no — and which noes are legitimate

A refusal is not automatically defiance. The exception list is real, and knowing it stops you spending a month arguing a point you cannot win.

On deletion, a business may keep information it needs to complete your transaction or provide a product or service you reasonably expect, for certain warranty and product-recall purposes, for certain security practices, for certain internal uses compatible with the context in which you gave it, and to comply with legal obligations or to exercise or defend legal claims. It may also refuse if it genuinely cannot verify you.

A category that surprises almost everyone: publicly available information is outside the CCPA entirely. That includes information from federal, state and local government records — professional licenses, and property records, which is why your address is so hard to make disappear. Certain medical information and consumer credit reporting information are also exempt. Victims of domestic violence, stalking, sexual assault, human trafficking and elder or dependent abuse, along with law enforcement officers, public officials and reproductive health workers, have a separate route through the California Safe at Home program to ask that an address not be posted publicly.

There is also a denial reason that sounds like a dodge and is not. The agency notes a business may deny deletion where "the information was not collected directly from you" — but adds a condition worth holding them to: even then, if the business sells or shares your personal information, it must inform you of your right to opt out. A refusal to delete is not a refusal to stop selling.

Two specific questions come up in our shop constantly. A debt collector is still calling after you asked it to delete you — yes, creditors, collection agencies and other debt collectors can still pursue a debt you owe regardless of your deletion request. And the credit bureaus are still reporting on you — yes, Equifax, Experian and TransUnion operate under the Fair Credit Reporting Act, which is a different law with its own dispute process, and that is the process to use.

For requests to know, a business may refuse if it cannot verify you, if the request is manifestly unfounded or excessive, or if it has already given you your personal information more than twice in a 12-month period. It also may not hand over certain things even while confirming it holds them: your Social Security number, financial account numbers and account passwords are withheld by design — though it must tell you it collects that type of information.

If you do not know why you were refused, ask. The state's advice on every single right is the same: follow up with the business and ask it for its reasons. A documented refusal with a stated reason is far more useful to you afterwards than silence, including if you later complain.

"We are only a service provider"

Sooner or later you will send a request and get a reply saying the recipient is a service provider and cannot act on it. This is usually true and is not a brush-off.

Businesses hire other businesses to do work for them — the payment processor that handles the card, the carrier that ships the order, the platform that sends the email. Under the CCPA those service providers have different obligations, and it is the business, not its supplier, that is responsible for answering your request. If you send it to the supplier, it may legitimately deny it.

What to do: reply and ask who the business is, on whose behalf they processed your information. Sometimes they will tell you and you can re-send to the right place. Sometimes they cannot, and you may have to work it out from what the service is. This is one of the genuinely unsatisfying corners of the law, and it is better to know it exists than to read the reply as stonewalling.

The one switch that does your opt-outs for you

Everything above is per-company, which is exhausting by design. For the opt-out right specifically — and only that right — there is a shortcut that is legally binding, and hardly anybody has turned it on.

It is called an opt-out preference signal, and the common implementation is the Global Privacy Control, or GPC. The Attorney General describes it as a "stop selling or sharing my data switch". You enable it once, in your browser, and from then on every covered website you visit receives your opt-out request automatically. The crucial sentence is this one, from the AG: "Under law, it must be honored by covered businesses as a valid consumer request to stop the sale or sharing of personal information." It is not a polite preference like the old Do Not Track header. It is a request with legal force behind it.

Where to find it today: the AG names Mozilla Firefox, DuckDuckGo and Brave as browsers where it is available, or you can add it as a browser extension — the EFF's Privacy Badger is the example the state itself gives. This is a settings change, not a purchase, and it takes about thirty seconds.

The honest limits, because a tool oversold is a tool abandoned. It travels with the browser, not with you, so it has to be turned on in each browser on each device — the laptop, the phone, the tablet, and the second browser you only use for one stubborn website. It covers opt-out of sale and sharing only; it does not delete anything you have already handed over, and it does not replace a deletion request. And it does nothing about email you asked for: unsubscribing from a mailing list is a separate job.

Two things change on January 1, 2027

The first is the reason the GPC advice above is about to get much less fiddly. California enacted AB 566, the California Opt Me Out Act — Chapter 465, approved by the Governor on October 8, 2025, adding section 1798.136 to the Civil Code. Beginning January 1, 2027 it prohibits a business from developing or maintaining a browser that does not include consumer-configurable functionality to send an opt-out preference signal, and it requires that the functionality "shall be easy for a reasonable person to locate and configure." The browser company must also explain publicly how the signal works and what it is intended to do. In plain terms: the switch that today exists in a handful of browsers is meant to exist in all of them, findable, within roughly fifteen months of this being written.

The second concerns decisions made about you by software. The California Privacy Protection Agency describes rights attached to automated decisionmaking technology used for significant decisions — the agency's examples are employment, housing, financial services, education and healthcare. Where they apply you can be told the technology is in use, opt out of its use, and request meaningful information about how it worked and how it affected you. The agency states that businesses must comply with the ADMT-specific requirements by January 1, 2027.

Neither of these is something to act on today. Both are worth knowing about before somebody sells you a subscription to do it for you.

They cannot punish you for asking

Businesses cannot deny you goods or services, charge you a different price, or give you a worse level or quality of service just because you exercised a CCPA right. That is the non-discrimination right and it is unconditional in that form.

Two honest qualifications sit next to it. If the information you refuse to give, or ask to have deleted or not sold, is genuinely necessary for the company to provide the thing you asked for, it may simply not be able to complete the transaction — that is not retaliation, it is the service not being possible.

And loyalty programs are explicitly allowed to continue. A business may offer promotions, discounts and deals in exchange for collecting, keeping or selling your information, provided the incentive is reasonably related to the value of that information. The practical consequence is one to think about before you send: asking a supermarket or airline to delete or stop selling your data may end your participation in the deal you were getting. The state's advice is to ask the business first if you are unsure, and that is sound. We would add one thing — a company running such a program has to post a notice of financial incentive, and the AG has pursued a grocery chain that did not. If you cannot find one, that itself is a fair question to put to them.

Keep a boring little file

This is our own advice rather than the state's, and it is the difference between a complaint that goes somewhere and one that does not. It takes two minutes per request.

When you send a request, save four things: the date, the exact URL or address of the designated method you used (take a screenshot of the form before you submit it), the wording of what you asked for, and the acknowledgment email if one arrives. Then put two dates in your calendar — ten business days for the acknowledgment, forty-five calendar days for the substantive answer.

Then, if a deletion was promised, check. Try to log in a month later. Search your own name and email on the company's site. A confirmation email that says your data has been deleted, sitting beside an account that still opens, is exactly the evidence that makes a regulator able to act.

We set this up for customers as a single folder in their email, or a note in their password manager alongside the account itself. It is dull, and it is the part that works.

If they ignore you: what a complaint actually does

First, the disappointing bit, stated up front so you do not build a plan on it. You cannot sue a business for most CCPA violations. The one exception is a data breach: if your non-encrypted, non-redacted personal information was stolen because the business failed to maintain reasonable security, you can sue for the damages you actually suffered or for statutory damages of up to $750 per incident. Even then, before suing you must give the business written notice of which CCPA sections it violated and allow 30 days for it to cure the violation in writing.

For everything else, enforcement belongs to the California Privacy Protection Agency and the Attorney General, and the way you participate is by complaining. Neither of them represents you individually — the agency says so directly, and cannot act as your attorney — but complaints are how patterns get identified, and patterns are what turn into sweeps, investigations and enforcement actions.

You can file with the agency online or on paper. It accepts both sworn and unsworn complaints. An unsworn complaint can be filed anonymously, with the trade-off that nobody can follow up with you. A sworn complaint attests to the truth of the allegations under penalty of perjury and must include the name of the business, the facts supporting each alleged violation, the documents or evidence supporting them, your name and contact details, and authorization for the agency to talk to the business about it. One deadline to note: the agency may not enforce a violation that occurred more than five years ago.

The agency publishes what separates a useful complaint from a useless one, and it maps exactly onto the boring little file. Its own example of a helpful complaint reads like this: I submitted a deletion request to this company on this date, through the portal in their privacy policy at this URL, they sent me this acknowledgment email which is pasted below, and two months later my account is still active and the content I asked them to remove is still visible. Its example of an unhelpful one is "[Company] isn't deleting my information" — with no date, no channel, no response quoted, nobody can tell whether a violation occurred, because there are lawful reasons a company may not have deleted.

After you file, agency staff read every complaint. They may contact you for more, contact the business, open an inquiry or an investigation, conduct an audit, refer it to another agency, or bring an enforcement action — or use it to monitor compliance across an industry. There is no guarantee of action on your individual matter, and investigations are generally confidential until something becomes public. You can also file a consumer complaint with the Attorney General's office, and for a privacy problem that does not involve California, the agency points you to your own state's attorney general or the FTC.

It is worth knowing that this route does work, even when it is invisible. The Attorney General's published case examples are a catalogue of exactly the obstructions people run into: a "Do Not Sell My Personal Information" link that opened nothing but a cookie menu; a link that only functioned in some browsers; a fitness chain whose opt-out toggle was backwards, so switching it "on" opted you in; an automotive company with no toll-free number and a broken request form; a social media app that simply was not answering in time. In each case the business was notified and fixed it. Somebody complained first.

What we do with this, and what we do not

We are a computer and home-network shop, not a law firm, and none of this is legal advice. It is the answer we give when a customer asks the obvious follow-up question to the DROP conversation, and it comes up often enough to be worth writing down properly.

The practical order we suggest is this. Do DROP first: it is one form, it is free, and it covers the 654 companies you never chose. Then turn on the GPC in the browsers you actually use — thirty seconds, and it handles the opt-out half of every covered site you visit from now on. Then, and only then, pick the two or three specific companies that genuinely bother you — the one that has your medical details, the one whose breach letter arrived last year, the account belonging to someone who has died — and do those properly, one at a time, through the designated method, with the dates written down.

What we will not do is sell you a subscription to press these buttons on your behalf. Paid removal services are legal and some are long-established, but be clear about what you would be buying: for registered data brokers the state now does it for nothing, every 45 days, and for the companies in this article an authorized agent is subject to more verification hurdles than you are, not fewer. The work is a folder, a calendar reminder and a willingness to be pedantic about which right you are exercising.

And the security point underneath all of it: the less of you there is in circulation, the less raw material there is for the calls, the texts and the too-convincing emails that bring most people to our door in the first place.

Keep reading

Free calculators

Service areas we cover

Want a second opinion before you buy?

We don't sell hardware or warranties — call and we'll tell you what's worth buying and upgrading.

Call (626) 655-0020

Gear we recommend

All gear →