If you have ever poked at a data broker’s opt-out page - the manual, per-broker version of the loop we walked through in our March 2026 AI privacy audit - you know the drill: enter your name and email, click a button, watch the broker claim it has processed your request, then wait six months to do it again because the broker has re-collected everything. California’s new privacy agency has built the most ambitious counter-loop to that cycle in the United States, and it does something no other state has shipped: one form, 614 brokers, one identity verification.
The Delete Request and Opt-Out Platform - branded DROP and run by the California Privacy Protection Agency, also called CalPrivacy - went live January 1, 2026. According to EFF’s explainer, 614 data brokers are now registered in the system. On August 1, 2026, the brokers cross into the binding phase: from that date, every submitted request must be honored within 45 days. That is the operational pitch. The catch lives in the residency rule.
What DROP actually does
The consumer side of DROP is reachable through the CPPA’s About DROP page. A user fills in identifiers - at minimum a name and an email address, with optional advertising IDs, VINs, and phone numbers - and the platform hashes that data before any broker sees it. The CPPA’s technical documentation describes the design: brokers receive the hashed values, match them against their own records, and either delete the data or return one of four statuses - exempted, opted-out of sale, record not found, or partial deletions.
The hash is what makes the model work. EFF notes that once a value is hashed it is essentially irreversible, so the broker can confirm a match without taking possession of the original email or phone. That moves the consumer’s identity out of the loop. The broker is the one doing the local match against its own database.
After the August 1 compliance deadline kicks in, each broker has 45 days to act on a request. The penalty for failing to delete, per the CPPA documentation, is $200 per day, per consumer request, plus enforcement costs. That number is the part of the rule that tends to make even large brokerages pay attention when request volume scales.
What it covers, and what it does not
EFF lists the categories covered: Social Security numbers, precise geolocation, browsing history, email addresses, phone numbers, and what the agency calls “inferred data.” EFF frames that last bucket as political views, health inferences such as pregnancy or chronic illness, and other sensitive classifications a broker has derived from your trail. That is the bucket most people do not know a broker has on them.
The exclusions are just as important. EFF points out that public-record data - vehicle and real-estate ownership, voter registration - is not deletable through DROP. The CPPA documentation adds HIPAA-protected health data, Fair Credit Reporting Act records, and Gramm-Leach-Bliley financial data to the exempt list. Those categories are carved out for specific federal reasons, not because the state chose to spare brokers.
Two operational limits matter most. EFF is clear that a California residency check applies; if you do not live in California, you cannot submit a request yourself, though an authorized filer can submit on your behalf with attestation. Second, new brokers can register after you file, and non-registered companies - EFF’s worked example is Google - are outside the platform entirely. The 614 is a snapshot, not a ceiling.
One more limit the CPPA documentation spells out: brokers are required to delete data they bought or collected from other sources, but not data you provided directly to that broker. For that, the consumer still has to file a separate privacy request through the broker’s own portal.
What This Means
The shape of DROP is more important than the 614 number. Until January 1, the only honest way to clean up a data-broker profile was to send each broker a separate opt-out, often with a mailed notarized form, and to do it again every quarter because the brokers re-collect. DROP collapses the loop into a single submission and moves the verification step to a neutral agency. That is a meaningful change for the population it covers, even if the residency rule caps the addressable audience at one state’s residents.
The platform is also a stress test. The 45-day clock is the part that has to actually run to know whether 614 different companies, each with its own legal team and database, can hit a uniform SLA. EFF recommends treating a DROP request as part of a recurring digital-footprint review rather than a one-time fix, and pairing the submission with the agency’s annual Opt-Out October window so the request lands during the period when brokers are most attentive to opt-out volume.
For the 49 states outside California, DROP is not a tool but a signal. It is the first U.S. deployment of a centralized broker opt-out backed by a per-day enforcement penalty, and it is the model privacy advocates are now pointing other state legislators toward. The practical answer for everyone else is the one EFF repeats throughout the explainer: file through each broker’s own portal, shrink the surface brokers can collect from in the first place, and treat the August 1 deadline as a forcing function for the next state bill.
The Bottom Line
California’s DROP tool lets a state resident delete their personal data from 614 registered brokers with one submission, with a 45-day compliance window and a $200-per-day enforcement penalty, starting August 1, 2026. It does not cover data you gave a broker directly, public records, or any company that has not registered. If you live outside California, watch the rollout, file manually, and use the tool’s launch as a forcing function for the next state bill.
Related on Intelligibberish
- EFF: AI Moderation Is Now Default, but Appeal Has Not Caught Up - the same EFF framing, applied to the platforms that decide what you see.
- More privacy coverage on Intelligibberish