Skip to main content
Privacy Law & Rights
7 min read

California Data Broker Opt-Out Guide: Your CCPA Rights Explained (2026)

California data-broker opt-out guide covering CCPA scope, the California Delete Act and DROP, verification, source boundaries, and follow-up options.

Rahul Kandoriya
Written byRahul Kandoriya·Last updated August 25, 2026
California Data Broker Opt-Out Guide: Your CCPA Rights Explained (2026)
California Data Broker Opt-Out Guide: Your CCPA Rights Explained (2026)
Coverage scope: The OfflistMe catalog currently records 1,000+data-broker workflows. Paid access lets you select workflows at once; you review and send or submit the generated requests, while provider eligibility and outcomes remain outside OfflistMe's control.

California residents have several privacy mechanisms, but they are not interchangeable. The CCPA/CPRA provides rights for covered businesses and requests. The Delete Act creates a California data-broker registry and a centralized deletion mechanism called DROP. A provider-specific request may still be needed for a source outside the relevant scope.

This guide is a dated educational summary, not legal advice. Start with the California Privacy Protection Agency (CPPA) and its current data-broker instructions before relying on a date, portal step, or legal conclusion.

Quick answer

  • A qualifying California consumer request can involve deletion, access, correction, or opt-out rights, subject to coverage, verification, exemptions, and the provider's role.
  • California residents can use the official DROP mechanism for active data brokers within its statutory scope. The CPPA's official material says data brokers must begin accessing and processing DROP requests on August 1, 2026, at least once every 45 days, subject to limited exceptions.
  • DROP does not automatically remove every website, original public record, search result, affiliate, or downstream copy.
  • A provider's voluntary nationwide route is different from California's legal scope.
  • Keep request, response, and source-check evidence; a portal status or automated acknowledgement is not proof that every copy was deleted.

Individual CCPA requests

The CCPA can provide covered California consumers with rights including know/access, delete, correct, and opt out of sale or sharing, depending on the business, data, purpose, and exception. Review the current California privacy-rights guidance and CPPA regulations for the applicable details.

For a covered request to delete, California regulations generally provide a 45-calendar-day response period, with a possible additional period when the business gives the required notice and explanation. That is a response rule, not a guarantee that deletion is available in every case or that a source, search result, or downstream copy will disappear.

Request Drafting

Exercise your statutory data deletion rights

Review source-aware privacy-rights request drafts directly in your browser. Send or submit each request yourself after checking the provider route and applicable law.

Start Free Statutory Opt-Out Free for selected workflows · No opt-out profile stored · No card needed

When submitting:

  1. identify the provider and exact record;
  2. choose the request type clearly;
  3. provide only information reasonably needed for matching and verification;
  4. save the confirmation and provider response; and
  5. use the current appeal or complaint route if necessary.

What the Delete Act and DROP add

The CPPA's official data-broker page states that the accessible deletion mechanism allows a consumer, through a single verifiable request, to direct covered data brokers that maintain related personal information to delete it, subject to limited exceptions.

The CPPA's current materials also state that:

  • California residents may use DROP to submit one request to active data brokers within the mechanism's scope;
  • data brokers that operated in 2025 or newly operate in 2026 must create an account under the agency's instructions; and
  • beginning August 1, 2026, covered data brokers must access the mechanism at least once every 45 days and process requests subject to limited exceptions.

The California Data Broker Registry publishes information submitted by registered businesses. Registry inclusion is evidence about the registry record. It is not proof that a provider has a profile about you, that every brand is included, or that a request will result in a particular source change.

How to use the current mechanism

1. Start with the official CPPA instructions

Use the CPPA consumer privacy-request information and the CPPA data-broker page. Follow the live portal's current California-residency and verification instructions.

2. Submit the minimum needed for matching

Use the identifiers the official mechanism requests. Avoid adding unrelated identity documents or sensitive values. Keep the confirmation privately.

3. Preserve the request evidence

Record the submission date, scope shown in the portal, reference information, and any broker status. Do not place the request contents in public notes, analytics, or a third-party tracker.

4. Verify important source pages separately

Check the provider pages that matter to your safety or employment after the relevant processing window. Record the exact URL and observed status. A DROP status does not itself prove that a separate search result or source outside the mechanism changed.

5. Handle out-of-scope sources

Use the provider's current first-party route for sites, brands, original records, or downstream copies outside DROP. OfflistMe can prepare a browser-local draft for user review and sending; it does not determine DROP eligibility, submit the portal request, or guarantee deletion.

What DROP does not automatically do

DROP is not a universal deletion button. It does not by itself:

  • delete the original government or court record;
  • remove a live page from a company outside the covered data-broker scope;
  • remove a search-engine result while the source page remains live;
  • prove that an affiliate, reseller, client, or downstream copy shares the same suppression list;
  • override a statutory exception or matching failure; or
  • create a nationwide right for a non-California resident.

If a provider voluntarily applies a California request to other residents or products, label that as provider policy rather than California law.

Evidence-ready California tracker

EventEvidence
Residency verificationPortal status or confirmation; avoid retaining unnecessary sensitive details
DROP submissionDate, reference, and scope shown
Broker processingStatus or response supplied through the mechanism
Source checkExact provider URL, date, and observed result
Search checkSearch result and eligible tool response, if relevant
EscalationFollow-up, appeal, complaint, and response

Use separate statuses: prepared, submitted, acknowledged, provider-reported, source-checked, returned, or unknown.

How to write an individual request

Use the provider's current route and adapt the request:

I am a California resident requesting [delete / correct / access / opt out] regarding the personal information associated with [exact URL or matching details]. Please confirm receipt, explain any verification required, and identify the response and appeal process. If you deny or limit the request, please state the reason and applicable exception.

Do not cite CCPA merely to make a message sound formal. Confirm that the business, request, and data are within the law's scope.

Follow-up and complaints

If a provider does not respond or gives an unclear denial:

  1. confirm the request and verification were completed;
  2. check the current notice and response rules;
  3. send a written follow-up through the provider's current route;
  4. use the provider's appeal process where available; and
  5. consult the CPPA complaint or enforcement instructions when the issue falls within its jurisdiction.

A complaint is an escalation option, not a guarantee of enforcement or a particular remedy.

How OfflistMe fits

OfflistMe is a user-controlled request-preparation layer. Its public catalog contains 1,034 recorded workflow profiles within a 1,052-record research catalog. These figures are catalog and research counts, not California registry counts, live profile matches, legal coverage, or outcome rates.

The app can show recorded route information and prepare a browser-local draft. You decide what to send, use the provider's current route, complete verification, and keep the result. The app does not automatically submit every request, bypass provider controls, or guarantee deletion.

Review the directory →

Frequently asked questions

Is California DROP free?

Current California consumer guidance presents DROP as a free public mechanism for California residents. Confirm the current consumer instructions and use the official CPPA route rather than an unofficial intermediary.

Can non-California residents use DROP?

The statutory mechanism is for California residents. A provider may voluntarily honor a California-style request more broadly, but that is not a nationwide legal entitlement.

Does a 45-day rule mean my data is gone in 45 days?

No. Individual CCPA response periods and the DROP broker-access cycle are different rules. Matching, processing, exceptions, source changes, search indexing, and downstream copies can produce different results.

Does DROP reach every registered broker?

It is designed for active data brokers within the mechanism's scope. Check the live CPPA instructions and registry. Do not infer that every website, related brand, or downstream copy is included.

Do I still need individual opt-outs?

Possibly. A source may be outside DROP, a provider may have a separate product or brand, or you may need a correction or other request type. Verify the source and its current route.

Can I delete a court or property record through DROP?

DROP addresses covered data-broker records. It does not automatically erase the original government or court record. Address the original source only through an applicable legal or administrative process.

Sources

Reviewed August 25, 2026. Verify the current CPPA portal, provider route, and legal scope before relying on this guide.

Related guides

Take back your privacy today

Review provider-specific routes, prepare your requests locally, and send or submit each one yourself.

Review Provider Routes

Free to review provider routes · Optional one-time unlock from $9.00 · No subscription