Skip to main content
Privacy Law & Rights
9 min read

U.S. State Privacy and Data-Broker Rights: How to Verify 2026 Rules

Primary-source guide to checking state privacy scope, California DROP, Texas Chapter 541, Colorado opt-out signals, verification, exemptions, and request evidence.

Rahul Kandoriya
Written byRahul Kandoriya·Last updated August 25, 2026
U.S. State Privacy and Data-Broker Rights: How to Verify 2026 Rules
U.S. State Privacy and Data-Broker Rights: How to Verify 2026 Rules
Coverage scope: The OfflistMe catalog currently records 1000+data-broker workflows. Paid access lets you select workflows at once; you review and send or submit the generated requests, while provider eligibility and outcomes remain outside OfflistMe's control.

The United States does not have one general consumer-privacy deletion rule that applies identically to every person, business, data source, and state. State laws differ in covered businesses, thresholds, definitions, exemptions, verification, rights, response windows, appeals, universal opt-out signals, regulator powers, and effective dates.

This is a research and request-planning guide, not a live legal database or legal advice. It uses primary regulator and statute sources for selected examples and explains how to verify a rule before citing it. A provider's public opt-out route is not proof that a statutory right applies, that the provider has a profile, or that every copy will be deleted.

Quick Answer

First identify four things: where the person resides, who controls the data, what data and processing are involved, and what request is being made. Then read the current statute, regulator guidance, and provider notice. A deletion request, sale opt-out, targeted-advertising opt-out, correction request, search-result removal, and public-record redaction are different actions.

The Scope Questions That Control a Request

QuestionWhy it matters
What is the person's residence?Consumer rights often depend on state residence and sometimes on the person's context.
Who is the recipient?A covered controller, data broker, public agency, employer, search engine, and court have different duties.
What is the data source?Publicly available information, consumer-provided data, sensitive data, credit information, health data, and professional records may be treated differently.
What is the request?Deletion, correction, opt-out of sale, targeted-advertising opt-out, access, appeal, and complaint routes are not interchangeable.
Is there an exemption?Sectoral laws, FCRA, HIPAA, employment, public records, security, legal claims, and fraud-prevention exceptions can affect the result.
What proof is required?A provider may need to match the request, confirm residency, or distinguish the person from an unauthorized requester.

Do not copy a statute citation into a request until those questions have been answered.

Request Drafting

Turn privacy-rights research into a reviewable removal plan

Choose relevant provider workflows, review the generated drafts in your browser, and send or submit each request yourself. State scope, eligibility, and provider requirements still need checking.

Start with selected brokers Free for selected workflows · No opt-out profile stored · No card needed

Selected Current Examples

California: CCPA and the Delete Act

The California Privacy Protection Agency (CalPrivacy) explains that the CCPA, as amended by the California Privacy Rights Act, gives California residents defined rights over personal information held by covered businesses. Rights, thresholds, verification, exemptions, and request limits apply. CalPrivacy: Rights under the CCPA

California's Delete Act created the Delete Request and Opt-Out Platform (DROP) for a defined class of California data brokers. CalPrivacy says California residents may submit a single deletion request through DROP to data brokers registered with the state, subject to the platform's scope and exceptions. Beginning August 1, 2026, covered brokers must access DROP at least once every 45 days to download and process consumer deletion requests. CalPrivacy: About DROP and the Delete Act and DROP processing requirements

DROP is not a universal internet deletion button. It does not automatically remove a government record, court filing, search-engine result, social post, private database, or a provider outside the covered data-broker framework. Use the live CPPA instructions and registry to confirm the current scope.

Texas: Chapter 541

Texas Chapter 541, the Texas Data Privacy and Security Act, creates rights and duties for covered controllers and consumers subject to statutory thresholds and exemptions. The current Texas statute is the controlling source for definitions, applicability, rights, verification, response, appeals, and enforcement. Texas Business and Commerce Code, Chapter 541

Do not describe Chapter 541 as a single portal that deletes every broker profile. A consumer still identifies the provider, reads its privacy notice, submits the request through the provider's current route, and uses the appeal or complaint path if the response is incomplete. A covered request may have a response period and extension rules, but the exact clock and exception depend on the request and statute.

Colorado: CPA and universal opt-out mechanisms

The Colorado Attorney General explains that the Colorado Privacy Act provides Colorado consumers rights including access, correction, deletion, and opt-outs for sale, targeted advertising, and certain profiling, subject to the act's definitions and exemptions. The Colorado guidance also describes recognized universal opt-out mechanisms, including Global Privacy Control, for covered processing. Colorado Privacy Act

Colorado's guidance notes that the act does not cover every context: for example, a person acting in an employment or job-applicant context is treated differently from a person acting in an individual or household context. Publicly available information and other exemptions also matter. Do not use a Colorado request template for every data source or employment decision without checking the current rule.

Universal Opt-Out Signals

Global Privacy Control and other universal opt-out mechanisms can communicate a preference to covered businesses in jurisdictions that recognize them. The signal's meaning depends on the state, controller, processing purpose, browser implementation, and current rule.

A universal signal generally does not:

  • erase a historical broker profile;
  • correct an inaccurate public record;
  • remove a search result;
  • establish that a particular company is covered;
  • replace an access or deletion request; or
  • prove that every downstream recipient stopped using the data.

The Colorado Attorney General's current UOOM guidance is a useful example of how recognition and scope should be checked. Colorado universal opt-out guidance

How to Verify Another State

For a state not covered in the selected examples, use this sequence:

  1. Find the current privacy page of the state attorney general, privacy agency, or legislature.
  2. Open the enacted statute, not only a bill summary or law-firm article.
  3. Confirm the effective date and whether later amendments or rules changed it.
  4. Read definitions of consumer, controller, sale, sensitive data, publicly available data, and data broker.
  5. Check thresholds, exemptions, employment and sector rules, and private-right-of-action limits.
  6. Confirm request methods, identity verification, response and appeal periods, fees, and complaint routes.
  7. Compare those requirements with the provider's current privacy notice and the exact source listing.

If a primary source cannot be verified, label the row unknown rather than filling it with an estimated deadline, fee, penalty, or registry status.

Right to Delete Versus Other Actions

ActionTypical targetEvidence to preserve
Delete personal dataCovered controller or provider, subject to exceptionsRequest, verification, response, source check
Correct inaccurate dataController, reporting company, agency, or publisherIncorrect field, correct evidence, investigation result
Opt out of sale or sharingCovered controller and defined processingSignal or request, confirmation, later preference check
Opt out of targeted advertisingCovered controller or recognized signalCurrent preference setting and confirmation
Remove a search resultSearch engineExact result URL, eligibility, decision
Correct or redact a public recordOriginal custodianRecord identifier, statute or agency route, decision
Dispute a consumer reportConsumer reporting companyReport, disputed item, investigation, notice

One action rarely completes another. A broker opt-out does not correct a court record, and a search-engine removal does not delete the source page.

A Request Template That Avoids Overclaiming

Use the provider's current channel and adapt the wording to the law that actually applies:

Subject: Request concerning personal information and matching profile

Hello,

I am requesting that you review the profile or record at:
[exact URL or record identifier]

The matching details are:
[minimum information needed to identify the record]

I request the following action under your current privacy process:
[delete / correct / opt out of sale or sharing / explain the applicable process]

Please identify any verification, exception, or permitted extension you are applying.
Please confirm the scope of the response and the date of completion or denial.

Thank you.

Add a state-law citation only after confirming residence, provider scope, data category, and request type. Do not claim that the request is “legally binding” or that the provider must comply with a statute that may not apply.

Escalation and Evidence

Keep the submission, provider acknowledgement, verification exchange, response, appeal, and later source check. If a provider does not respond or appears to misapply a right, read the statute's complaint or appeal route. A regulator complaint can inform enforcement, but it is not a promise that the agency will represent the individual or order a particular deletion.

CalPrivacy states that it does not represent individual consumers or act as their attorney; a complaint may inform its work, but the agency is not required to take action or bring a particular case. CalPrivacy complaint guidance

OfflistMe can help a user review recorded provider routes and prepare browser-local drafts for relevant commercial sources. The user chooses the source, reviews the legal and factual basis, completes provider verification, sends or submits the request, and keeps the evidence. The catalog does not determine legal coverage or guarantee an outcome.

Frequently Asked Questions

Can I use California rights if I live elsewhere?

Do not assume so. California rights and DROP have defined California scope. A provider may voluntarily offer a broader route, but that is different from a nationwide statutory entitlement.

Does a state privacy law cover every data broker?

No. Coverage depends on the law's definitions, thresholds, exemptions, business role, and the data processing at issue. A provider's presence in a directory is not proof of coverage.

Is 45 days the universal response deadline?

No. Some laws use a period around 45 days, but the request type, state, extension, notice, verification, and exemption can change the clock. Use the applicable statute and provider notice.

Does DROP remove data from search engines?

Not by itself. A DROP request addresses covered data brokers. Search-result removal and source-page changes are separate routes.

Can a provider charge for a deletion request?

The answer depends on the statute, request frequency, duplication, identity verification, and the provider's role. Some laws restrict fees for qualifying requests, but the rule is not universal. A service that helps prepare a request may charge for assistance even when a direct provider route does not. Ask the provider to identify the basis for any fee.

Verification Checklist

  • [ ] Confirm the person's residence and context.
  • [ ] Identify the provider, source record, and processing purpose.
  • [ ] Read the current enacted statute and regulator guidance.
  • [ ] Check thresholds, exemptions, verification, response, appeal, and complaint rules.
  • [ ] Use the provider's current route and minimum necessary information.
  • [ ] Keep request-level evidence and a dated source check.
  • [ ] Treat unknown legal status as unknown; do not invent a deadline or penalty.

Sources and limits

These are selected examples, not a complete 50-state legal database. A current official statute or regulator page controls over this summary; residence, provider role, data category, processing purpose, exemptions, verification, and effective dates can change the result. No legal request is submitted by this guide.

Sources and Related Guides

Reviewed August 25, 2026. Verify every legal statement against the current official source before relying on it.

Take back your privacy today

Review provider-specific routes, prepare your requests locally, and send or submit each one yourself.

Review Provider Routes

Free to review provider routes · Optional one-time unlock from $9.00 · No subscription