DROP Is a Bus, Not a Broom
August 1 is California’s data-broker processing day. File one request against the broker class—then understand the hashed list, the 45-day loop, the exceptions, and what DROP will not touch.

August 1 is not a privacy holiday. It is the day California’s one-to-many deletion bus becomes an enforceable duty for the registered data-broker class.
The Delete Act (SB 362) already forced the California Privacy Protection Agency to build an “accessible deletion mechanism.” CPPA calls the product DROP—Delete Request and Opt-out Platform. Consumers could start filing as of January 1, 2026. Beginning August 1, 2026, a data broker must access that mechanism at least once every 45 days, process the queue, cascade deletes to associated service providers and contractors, and then keep scrubbing.
If you treat that as “everything about me is gone,” you will be disappointed on purpose. DROP is a bus. It is not a broom.
Quick verdict
Use it if you are a California resident (or an authorized agent for one). One verifiable request can hit the broker class that sells dossiers on people it does not actually serve. The statute puts a dollar figure on failure: $200 per deletion request per day for brokers that do not delete as required. That is real leverage if CPPA staffs it.
Do not confuse DROP with a CCPA delete button against every company you actually have an account with. Google, Meta, your bank, your insurer, your employer SaaS stack, and most first-party apps are a different fight. FCRA, GLBA, insurance privacy, and HIPAA-adjacent carveouts still matter “to the extent” those regimes cover the entity.
What changed on August 1
Civil Code §1798.99.86(c) is the load-bearing sentence. Beginning August 1, 2026, a data broker shall:
- Access the accessible deletion mechanism at least once every 45 days.
- Within 45 days of receiving a request, process deletions of personal information related to the consumer, consistent with the section.
- If the delete cannot be verified, process it as a sale/share opt-out under §1798.120 (as limited by §§1798.105, .145, .146).
- Direct service providers and contractors to delete (or to apply the same opt-out path).
Then subdivision (d) adds the anti-repopulation claw. After a consumer has submitted a request and the broker has deleted pursuant to the section:
- the broker shall delete that consumer’s personal information again at least once every 45 days (unless the consumer asks otherwise or an exception applies); and
- the broker shall not sell or share new personal information of that consumer unless the consumer requests otherwise or §§1798.145 / 1798.146 permit it.
CPPA’s own broker page says the quiet part in plain English: under the Delete Act, beginning August 1, 2026, brokers must access the mechanism at least every 45 days and process consumer deletion requests, subject to limited exceptions. The registry page says California residents may use DROP to submit one request to active data brokers, and brokers are required to begin processing those requests on August 1, 2026.

Kyber analysis graphic from statute and CPPA final regulations. Not an official CPPA interface.
Architecture: how the bus actually moves
CPPA’s final regulations (Title 11, Division 6, Chapter 3; OAL approval November 6, 2025; effective January 1, 2026) turn the statute into plumbing.
Access means list retrieval. Regulation §7601 defines “Access the DROP” as retrieving a consumer deletion list. Signing into an account without pulling the list does not count. §7612 requires access at least once every 45 calendar days, manually or by automation, with a manual fallback if automation fails.
The payload is hashed. A “consumer deletion list” carries consumer identifiers (email, phone, or name + DOB + ZIP, among options) in hashed form, plus a transaction identifier and the hashing algorithm. Brokers must standardize their own records (lowercase, strip junk characters, normalize DOB/ZIP/phone), hash with the same algorithm, and match.
Status is a closed vocabulary. On later access sessions, brokers report codes such as:
- Record deleted
- Record opted out of sale
- Record exempted
- Record not found
Agency data is not marketing fuel. §7616: personal information from the Agency may be used only to comply with §1798.99.86. Selling or sharing it is prohibited. Brokers shall not contact the consumer to “verify” a DROP request.
“Delete” is defined hard—and soft at the edges. Reg §7613 says delete means permanently and completely erasing from existing systems (including archives/backups), deidentifying, or aggregating—except minimum data kept to keep complying with the 45-day claw. Archives may wait until the backup is restored or accessed for sale/disclosure/commercial purposes. That is not “gone from every tape forever on day one.” It is the regulation’s own delay lane.

Source: CPPA final Text of Regulations, Accessible Deletion Mechanism (drop_ftr.pdf). State regulation text used for documentary reporting.
Who is on the bus
§1798.99.80(c): a data broker is a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship.
It does not include, to the extent covered:
- FCRA entities
- GLBA entities
- Insurance Information and Privacy Protection Act entities
- HIPAA covered entities / business associates for processing exempt under §1798.146
That is the whole plot. People-search shops, marketing databases, and dossier merchants that never had you as a customer are the target class. Your bank login and your social account are not automatically “data broker” problems under this title.

Kyber scope map. “Not prohibited by this section” is not the same as “unregulated,” “approved,” or “harmless.”
Field Manual — file the request without LARPing omnipotence
1. Confirm you are in the right population
DROP is built around California consumers and residency verification by the Agency (reg §7620). If you are not a California resident, this is not your one-click wipe. Use ordinary CCPA/CPRA rights, other state rights, and data minimization instead.
2. Start at the official rails
- Consumer entry points are published by CPPA / CalPrivacy. The agency banner states DROP is officially live.
- Consumer portal path referenced by CPPA: privacy.ca.gov/drop/
- Registry context: cppa.ca.gov/data_broker_registry
- Broker instructions (useful to understand the other side of the glass): cppa.ca.gov/data_brokers
Kyber’s research host hit Cloudflare/JS challenges on some privacy.ca.gov paths. That is a tooling limit, not proof the service is down. Use a normal browser. If the page fails, try again from CPPA’s “Use DROP” links and keep a screenshot of any error for your own records.
3. Expect identity proofing—because the bus is dangerous both ways
A universal delete feed that anyone could poison would be a weapon. The regs require California residency verification before submission. You may add identifiers (email, phone, DOB, mobile ad IDs) to improve match rates. More identifiers can improve deletion and concentrate sensitive join keys at the Agency for compliance purposes. Give what you need for matching; do not dump your life story into optional fields.
Authorized agents are explicitly supported (§1798.99.86(a)(8); reg §7621) after the consumer’s residency is verified. Agents disclose name/email/trade name; they cannot cancel a request unless the consumer directs it.
4. Prefer one request across the class—then prune if you must
Statute design: a single verifiable consumer request can demand deletion from every data broker that maintains your PI, including associated service providers/contractors. You may also selectively exclude specific brokers. Default to the full class unless you have a concrete reason to spare one.
You may alter a previous request only after at least 45 days (§1798.99.86(a)(4); reg §7620(d)).
5. Save receipts like an adult
Before you close the tab:
- confirmation / transaction identifiers the portal shows you
- date/time of submission
- which identifier categories you supplied (not the raw secrets in a public note)
- a local PDF or screenshot of the status page
You will need those when you recheck status. The statute requires the mechanism to let you verify status of the request. Use that feature. Do not trust vibes.
6. Recheck on a 45–90 day clock
Brokers poll on a ≤45-day cadence and have 45 days to process after receipt. Reality is match quality + exemptions + backlog. Calendar a recheck around day 50 and again around day 100. Look for status movement: deleted, opted out of sale, exempted, not found.
“Not found” is not victory. It can mean the broker never had you—or never matched the hash. If a major people-search brand still shows your listing after a successful DROP cycle, hit that broker’s own privacy rights flow and keep the DROP request alive for the recurring claw.
7. Still send first-party deletes where you actually have accounts
DROP does not replace:
- platform privacy dashboards
- “Do not sell/share” links
- CCPA delete/correct/know requests to businesses you use
- data-broker opt-outs outside California’s registry class
Think in layers: broker bus + first-party rights + stop generating free dossier fuel.
8. Cut the fuel line
Deletion without minimization is a hamster wheel. Practical exits that actually reduce re-collection:
- stop posting government ID images, home addresses, and kids’ full identifiers into public profiles
- use unique emails / aliases per vendor so one breach does not relink everything
- prefer cash or privacy-preserving payment where lawful and practical for low-trust merchants
- lock down people-search exposure with the same DROP request rather than twelve separate “remove listing” CAPTCHA farms when the broker is in-class
- for creators and small operators: own domain + email, export audiences, reduce dependency on rented social graphs (Platform Dependency is the longer argument)
9. Watch enforcement, do not cosplay it
§1798.99.82(d): failure to comply with §1798.99.86 → CPPA administrative action; $200 for each deletion request for each day the broker fails to delete as required, plus reasonable agency expenses. Independent audits begin January 1, 2028, every three years thereafter (§1798.99.86(e)).
That is a weapon on paper. This package does not claim same-day fine totals or a live compliance dashboard. If a broker ignores you, document status codes and dates; use CPPA complaint channels; do not invent private rights of action the statute does not give you in this write-up.
Money and incentive
Brokers pay to exist on the bus. Registration fees fund the registry and the mechanism. CPPA may charge an access fee when brokers access DROP (§1798.99.86(f)). Mid-year operators face graduated first-access fees in the regs (thousands of dollars depending on month). Compliance shops will sell matching middleware. None of that is a reason to skip filing. It is a reason to understand who gets paid either way.
The secondary market’s business model is you, packaged. DROP forces that market to subscribe to a deletion feed. That is progress. The first-party attention market and the government identity stack are still building other cages—see Kyber’s age-control stack brief and driver-data rail coverage.
Vendor and agency position
CPPA / CalPrivacy: DROP is live. Consumers may submit. Registered brokers must create accounts, select consumer deletion lists, and beginning August 1, 2026, access at least every 45 days and process requests subject to limited exceptions. Agency pages direct brokers to privacy.ca.gov materials for processing instructions.
Statute (through the Legislature and chaptered SB 362): one-to-many deletion mechanism; 45-day access/process loops; cascade; recurring delete; no sell/share of new PI after success; $200 per request per day administrative fine path; 2028 audits.
Broker bar / compliance vendors: expect “are you ready” marketing about matching, fees, and list selection. Treat that as industry self-talk unless tied to the statute or regs.
Kyber: File if you qualify. Measure status. Keep first-party deletes and data minimization. Refuse the victory-lap narrative.
Evidence boundary
Publication-ready
- §1798.99.86 duties beginning August 1, 2026 (access ≥ every 45 days; process within 45 days; cascade; opt-out fallback for unverifiable requests).
- §1798.99.86(d) recurring delete and no sell/share of new PI after successful delete (with stated exceptions).
- §1798.99.82(d) $200 per deletion request per day administrative fine authority for §1798.99.86 failures.
- §1798.99.80(c) data-broker definition and enumerated carveouts.
- CPPA final DROP regulations architecture: hashed lists, 45-day access, match/standardize rules, status codes, no consumer contact to “verify,” no selling Agency-supplied PI.
- CPPA first-party statements that DROP is live and broker processing begins August 1, 2026.
- Consumer submission framed as available from January 1, 2026 on CPPA registry page; agency establish-by date of January 1, 2026 in statute.
Not established by this package
- Exact count of currently registered brokers (public registry UI is JS-driven; do not trust empty-state strings or secondary “600+” round numbers without a verified export).
- Same-day CPPA enforcement actions or collected fine totals for August 1, 2026.
- That any specific commercial people-search profile has already been wiped for you.
- Pixel-perfect consumer portal click-path (research host blocked on some privacy.ca.gov URLs).
- That DROP removes first-party platform or regulated-carveout dossiers.
Not covered by this section alone
- ALPR networks and municipal camera contracts.
- Age-assurance / digital ID gates.
- Federal commercial data purchases.
- Your own public records exhaust.
Practical exits checklist
- If CA resident: file DROP; save transaction/status proof.
- Recheck status ~50 and ~100 days out.
- Send first-party delete / do-not-sell requests to platforms you actually use.
- Unique aliases; reduce public identifier sprawl.
- Export and own audience/email if you publish for a living.
- Watch CPPA announcements for enforcement patterns after the processing clock starts.
- Do not pay random “we’ll scrub the internet” middlemen without verifying they are lawful authorized agents and that you still control the Agency relationship.
Internal reading
- California expanded mobile ID and built an interstate driver data rail
- ICE wants a million-subject alert machine
- De-Flock is the easy part. Deprovisioning is the story
- Texas didn’t lose age gates. It lost the filter mandate
Follow-up triggers
- First CPPA administrative actions citing §1798.99.86 after August 1, 2026.
- Verified registry CSV export and methodology for broker census.
- Material amendments to DROP regs or SB 361 follow-ons affecting fees/metrics.
- Documented match-failure patterns from readers (with redacted receipts).
- January 1, 2028 audit cycle startup.
File the request. Keep the receipts. Stay skeptical of anyone selling invisibility.
Sources
- https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.99.86
- https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.99.82
- https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.99.80
- https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB362
- https://cppa.ca.gov/regulations/pdf/drop_ftr.pdf
- https://cppa.ca.gov/regulations/drop.html
- https://cppa.ca.gov/data_broker_registry
- https://cppa.ca.gov/data_brokers
- https://cppa.ca.gov/
- https://privacy.ca.gov/drop/