U.S. State Privacy and Data-Broker Rights: How to Verify 2026 Rules
Primary-source guide to checking state privacy scope, California DROP, Texas Chapter 541, Colorado opt-out signals, verification, exemptions, and request evidence.
The United States does not have one general consumer-privacy deletion rule that applies identically to every person, business, data source, and state. State laws differ in covered businesses, thresholds, definitions, exemptions, verification, rights, response windows, appeals, universal opt-out signals, regulator powers, and effective dates.
This is a research and request-planning guide, not a live legal database or legal advice. It uses primary regulator and statute sources for selected examples and explains how to verify a rule before citing it. A provider's public opt-out route is not proof that a statutory right applies, that the provider has a profile, or that every copy will be deleted.
Quick Answer
First identify four things: where the person resides, who controls the data, what data and processing are involved, and what request is being made. Then read the current statute, regulator guidance, and provider notice. A deletion request, sale opt-out, targeted-advertising opt-out, correction request, search-result removal, and public-record redaction are different actions.
The Scope Questions That Control a Request
| Question | Why it matters |
|---|---|
| What is the person's residence? | Consumer rights often depend on state residence and sometimes on the person's context. |
| Who is the recipient? | A covered controller, data broker, public agency, employer, search engine, and court have different duties. |
| What is the data source? | Publicly available information, consumer-provided data, sensitive data, credit information, health data, and professional records may be treated differently. |
| What is the request? | Deletion, correction, opt-out of sale, targeted-advertising opt-out, access, appeal, and complaint routes are not interchangeable. |
| Is there an exemption? | Sectoral laws, FCRA, HIPAA, employment, public records, security, legal claims, and fraud-prevention exceptions can affect the result. |
| What proof is required? | A provider may need to match the request, confirm residency, or distinguish the person from an unauthorized requester. |
Do not copy a statute citation into a request until those questions have been answered.
Turn privacy-rights research into a reviewable removal plan
Choose relevant provider workflows, review the generated drafts in your browser, and send or submit each request yourself. State scope, eligibility, and provider requirements still need checking.
Selected Current Examples
California: CCPA and the Delete Act
The California Privacy Protection Agency (CalPrivacy) explains that the CCPA, as amended by the California Privacy Rights Act, gives California residents defined rights over personal information held by covered businesses. Rights, thresholds, verification, exemptions, and request limits apply. CalPrivacy: Rights under the CCPA
California's Delete Act created the Delete Request and Opt-Out Platform (DROP) for a defined class of California data brokers. CalPrivacy says California residents may submit a single deletion request through DROP to data brokers registered with the state, subject to the platform's scope and exceptions. Beginning August 1, 2026, covered brokers must access DROP at least once every 45 days to download and process consumer deletion requests. CalPrivacy: About DROP and the Delete Act and DROP processing requirements
DROP is not a universal internet deletion button. It does not automatically remove a government record, court filing, search-engine result, social post, private database, or a provider outside the covered data-broker framework. Use the live CPPA instructions and registry to confirm the current scope.
Texas: Chapter 541
Texas Chapter 541, the Texas Data Privacy and Security Act, creates rights and duties for covered controllers and consumers subject to statutory thresholds and exemptions. The current Texas statute is the controlling source for definitions, applicability, rights, verification, response, appeals, and enforcement. Texas Business and Commerce Code, Chapter 541
Do not describe Chapter 541 as a single portal that deletes every broker profile. A consumer still identifies the provider, reads its privacy notice, submits the request through the provider's current route, and uses the appeal or complaint path if the response is incomplete. A covered request may have a response period and extension rules, but the exact clock and exception depend on the request and statute.
Colorado: CPA and universal opt-out mechanisms
The Colorado Attorney General explains that the Colorado Privacy Act provides Colorado consumers rights including access, correction, deletion, and opt-outs for sale, targeted advertising, and certain profiling, subject to the act's definitions and exemptions. The Colorado guidance also describes recognized universal opt-out mechanisms, including Global Privacy Control, for covered processing. Colorado Privacy Act
Colorado's guidance notes that the act does not cover every context: for example, a person acting in an employment or job-applicant context is treated differently from a person acting in an individual or household context. Publicly available information and other exemptions also matter. Do not use a Colorado request template for every data source or employment decision without checking the current rule.
Universal Opt-Out Signals
Global Privacy Control and other universal opt-out mechanisms can communicate a preference to covered businesses in jurisdictions that recognize them. The signal's meaning depends on the state, controller, processing purpose, browser implementation, and current rule.
A universal signal generally does not:
- erase a historical broker profile;
- correct an inaccurate public record;
- remove a search result;
- establish that a particular company is covered;
- replace an access or deletion request; or
- prove that every downstream recipient stopped using the data.
The Colorado Attorney General's current UOOM guidance is a useful example of how recognition and scope should be checked. Colorado universal opt-out guidance
How to Verify Another State
For a state not covered in the selected examples, use this sequence:
- Find the current privacy page of the state attorney general, privacy agency, or legislature.
- Open the enacted statute, not only a bill summary or law-firm article.
- Confirm the effective date and whether later amendments or rules changed it.
- Read definitions of consumer, controller, sale, sensitive data, publicly available data, and data broker.
- Check thresholds, exemptions, employment and sector rules, and private-right-of-action limits.
- Confirm request methods, identity verification, response and appeal periods, fees, and complaint routes.
- Compare those requirements with the provider's current privacy notice and the exact source listing.
If a primary source cannot be verified, label the row unknown rather than filling it with an estimated deadline, fee, penalty, or registry status.
Right to Delete Versus Other Actions
| Action | Typical target | Evidence to preserve |
|---|---|---|
| Delete personal data | Covered controller or provider, subject to exceptions | Request, verification, response, source check |
| Correct inaccurate data | Controller, reporting company, agency, or publisher | Incorrect field, correct evidence, investigation result |
| Opt out of sale or sharing | Covered controller and defined processing | Signal or request, confirmation, later preference check |
| Opt out of targeted advertising | Covered controller or recognized signal | Current preference setting and confirmation |
| Remove a search result | Search engine | Exact result URL, eligibility, decision |
| Correct or redact a public record | Original custodian | Record identifier, statute or agency route, decision |
| Dispute a consumer report | Consumer reporting company | Report, disputed item, investigation, notice |
One action rarely completes another. A broker opt-out does not correct a court record, and a search-engine removal does not delete the source page.
A Request Template That Avoids Overclaiming
Use the provider's current channel and adapt the wording to the law that actually applies:
Subject: Request concerning personal information and matching profile
Hello,
I am requesting that you review the profile or record at:
[exact URL or record identifier]
The matching details are:
[minimum information needed to identify the record]
I request the following action under your current privacy process:
[delete / correct / opt out of sale or sharing / explain the applicable process]
Please identify any verification, exception, or permitted extension you are applying.
Please confirm the scope of the response and the date of completion or denial.
Thank you.Add a state-law citation only after confirming residence, provider scope, data category, and request type. Do not claim that the request is “legally binding” or that the provider must comply with a statute that may not apply.
Escalation and Evidence
Keep the submission, provider acknowledgement, verification exchange, response, appeal, and later source check. If a provider does not respond or appears to misapply a right, read the statute's complaint or appeal route. A regulator complaint can inform enforcement, but it is not a promise that the agency will represent the individual or order a particular deletion.
CalPrivacy states that it does not represent individual consumers or act as their attorney; a complaint may inform its work, but the agency is not required to take action or bring a particular case. CalPrivacy complaint guidance
OfflistMe can help a user review recorded provider routes and prepare browser-local drafts for relevant commercial sources. The user chooses the source, reviews the legal and factual basis, completes provider verification, sends or submits the request, and keeps the evidence. The catalog does not determine legal coverage or guarantee an outcome.
Frequently Asked Questions
Can I use California rights if I live elsewhere?
Do not assume so. California rights and DROP have defined California scope. A provider may voluntarily offer a broader route, but that is different from a nationwide statutory entitlement.
Does a state privacy law cover every data broker?
No. Coverage depends on the law's definitions, thresholds, exemptions, business role, and the data processing at issue. A provider's presence in a directory is not proof of coverage.
Is 45 days the universal response deadline?
No. Some laws use a period around 45 days, but the request type, state, extension, notice, verification, and exemption can change the clock. Use the applicable statute and provider notice.
Does DROP remove data from search engines?
Not by itself. A DROP request addresses covered data brokers. Search-result removal and source-page changes are separate routes.
Can a provider charge for a deletion request?
The answer depends on the statute, request frequency, duplication, identity verification, and the provider's role. Some laws restrict fees for qualifying requests, but the rule is not universal. A service that helps prepare a request may charge for assistance even when a direct provider route does not. Ask the provider to identify the basis for any fee.
Verification Checklist
- [ ] Confirm the person's residence and context.
- [ ] Identify the provider, source record, and processing purpose.
- [ ] Read the current enacted statute and regulator guidance.
- [ ] Check thresholds, exemptions, verification, response, appeal, and complaint rules.
- [ ] Use the provider's current route and minimum necessary information.
- [ ] Keep request-level evidence and a dated source check.
- [ ] Treat unknown legal status as unknown; do not invent a deadline or penalty.
Sources and limits
These are selected examples, not a complete 50-state legal database. A current official statute or regulator page controls over this summary; residence, provider role, data category, processing purpose, exemptions, verification, and effective dates can change the result. No legal request is submitted by this guide.
- CalPrivacy: Rights under the California Consumer Privacy Act
- CalPrivacy: About DROP and the Delete Act
- CalPrivacy: Processing DROP requests
- CalPrivacy: Submit a complaint
- Texas Chapter 541
- Colorado Privacy Act
- Colorado universal opt-out guidance
Sources and Related Guides
Reviewed August 25, 2026. Verify every legal statement against the current official source before relying on it.
Understand your privacy rights
Where a privacy right is relevant, these plain-English explainers show what each law covers and what to verify before making a request.
Take back your privacy today
Review provider-specific routes, prepare your requests locally, and send or submit each one yourself.
Review Provider RoutesFree to review provider routes · Optional one-time unlock from $9.00 · No subscription
