Skip to main content
Privacy Law & Rights
8 min read

California Delete Act (SB 362) & DROP: Source-Checked Consumer Guide (2026)

Source-checked guide to California's Delete Act and DROP: covered-broker scope, the August 1, 2026 45-day access cycle, source limits, and follow-up steps.

Rahul Kandoriya
Written byRahul Kandoriya·Last updated August 25, 2026
California Delete Act (SB 362) & DROP: Source-Checked Consumer Guide (2026)
California Delete Act (SB 362) & DROP: Source-Checked Consumer Guide (2026)
Coverage scope: The OfflistMe catalog currently records 1,000+data-broker workflows. Paid access lets you select workflows at once; you review and send or submit the generated requests, while provider eligibility and outcomes remain outside OfflistMe's control.

The California Delete Act (Senate Bill 362) created a centralized deletion mechanism for California residents. The California Privacy Protection Agency (CPPA) calls that mechanism the Delete Request and Opt-Out Platform (DROP). It is designed to let an eligible California resident submit one verifiable request to covered data brokers rather than repeat the same request at every registered broker.

This guide explains what the official CPPA material says, what the mechanism does not establish, and how to keep evidence while using it. The primary sources are the CPPA consumer DROP guidance, CPPA information for data brokers, the California Data Broker Registry, the current DROP Terms of Use, and the CPPA DROP regulations page. Laws, agency instructions, and portal behavior can change; check those sources before relying on a date or procedure.

What SB 362 and DROP do

The Delete Act applies to businesses that meet California's data-broker definition and the law's exclusions. The CPPA explains that a data broker knowingly collects and sells personal information about a consumer to third parties when the consumer does not have a direct relationship with the business. The definition and exemptions matter: a company appearing in a people-search catalog is not automatically a registered California data broker.

The CPPA's current materials state that:

Request Drafting

Exercise your statutory data deletion rights

Review source-aware privacy-rights request drafts directly in your browser. Send or submit each request yourself after checking the provider route and applicable law.

Start Free Statutory Opt-Out Free for selected workflows · No opt-out profile stored · No card needed
  1. California residents may use DROP to submit one deletion request to active data brokers covered by the mechanism.
  2. Data brokers that operated in 2025 or newly operate in 2026 must create a DROP account under the agency's instructions.
  3. Beginning August 1, 2026, data brokers must access the accessible deletion mechanism at least once every 45 days and process consumer deletion requests, subject to limited exceptions.
  4. The California Data Broker Registry publishes information submitted by registered businesses. Registry inclusion is evidence about the registry record, not proof that a provider has every possible record about a person or that a request will produce a particular outcome.

These statements describe the legal and administrative mechanism. They do not promise that every online publisher, search engine result, downstream copy, or company outside the covered definition will be affected.

Who can use it

DROP is a California mechanism for California residents. The CPPA's final regulations describe the consumer deletion request as going through DROP and require California residency verification before submission. Check the live portal and the current regulations for the exact verification and review process.

A broker may voluntarily apply a California request more broadly, but that is a provider decision. Do not describe a California request as a nationwide legal deletion order, and do not assume that a non-California resident can use the statutory mechanism.

What you submit and who receives it

Before submitting, review the current DROP Terms of Use. They state that submitting a deletion request consents to disclosure of the personal information you provide to data brokers for processing. The consumer guidance describes encryption and hashed identifiers for matching, and lets you choose which optional identifiers to provide, but you should still use accurate information and provide only what you are comfortable submitting. Residency verification and the request itself are separate steps; keep only the private evidence you need.

What DROP does not cover automatically

DROP is not a universal deletion button for the internet. It does not by itself:

  • remove a live source page from a company that is outside the covered data-broker scope;
  • remove a search-engine result when the source page is still live;
  • erase a public record at the government or original-record source;
  • establish that a separate brand, affiliate, customer, contractor, or downstream copy is within the same request;
  • decide whether a legal exemption or matching issue applies to a particular record; or
  • replace a provider-specific request for a site outside the mechanism.

When a source remains visible, save the exact URL and date, then use the source's current privacy route. If the source page changed or was deleted, review the search engine's current personal-information and outdated-content tools separately.

What the 45-day rule means

The CPPA says that, beginning August 1, 2026, covered data brokers must access DROP at least once every 45 days and process deletion requests subject to limited exceptions. That is an access and processing obligation for covered brokers. It is not a promise that every matched record disappears immediately after a consumer submits a request, and it is not a universal deadline for every privacy request made outside DROP.

Keep these events separate in your log:

EventEvidence to keep
California residency or portal verificationPortal status or confirmation, without retaining unnecessary sensitive material
DROP request submissionSubmission date, reference information, and the scope shown in the portal
Broker processingBroker status or response, if supplied through the mechanism
Source verificationExact provider URL, date checked, and whether the matching profile changed
Follow-up or complaintCopy of the request, response, and the official channel used

Do not infer deletion from an automated acknowledgement. A search result can remain after a source changes, and a source can later receive data from a different upstream record.

A careful workflow for California residents

1. Read the current CPPA instructions

Start at the California consumer DROP page, the California consumer privacy-request page, and the CPPA data-broker information page. Use the live portal and follow its current residency and verification instructions.

2. Submit only the information needed for matching

Use the identifiers the current portal requests. Avoid adding unrelated identity documents or sensitive information unless the official process requires it. Keep a private record of the submission date and confirmation; do not place personal request contents in public notes or analytics.

3. Review the official status and then check important sources

A portal status is one evidence point. For safety-critical or employment-sensitive exposure, separately check the exact source pages that matter to you. Record whether the source was removed, changed, still live, or not found.

4. Handle out-of-scope sources separately

Use each provider's current first-party privacy or opt-out route for sources outside DROP. OfflistMe can prepare a browser-local draft and route information for the user to review and send. It does not submit a DROP request, determine California residency, guarantee acceptance, or verify downstream deletion.

5. Escalate with evidence

If a covered request is not processed or a response appears inconsistent with the applicable rules, keep the request and response record and consult the CPPA's current complaint or enforcement instructions. A complaint is an escalation path, not a guarantee of a particular result.

DROP compared with an individual request

QuestionDROPIndividual provider request
Who operates the route?CPPA's state mechanismThe provider or its privacy service
Typical scopeCovered data brokers within the mechanismThe particular provider and request scope
Who decides matching and exceptions?The applicable rules and covered broker processThe provider under its notice and applicable law
Does it remove a search result?Not by itselfNot necessarily; search and source are separate
Evidence to preservePortal submission and statusExact URL, request, verification, and response

Neither route should be marketed as a permanent, universal outcome. The relevant question is whether the source, person, request, and legal scope are supported by evidence.

How OfflistMe fits

OfflistMe is a user-controlled preparation layer for source-specific requests. Its current public catalog contains 1,034 recorded workflow profiles within a 1,052-record research universe. Those are catalog and research counts, not the number of California-registered brokers, not a guarantee that every profile matches a user, and not an outcome rate.

The app can help a user review a provider route, prepare a draft locally, and retain a checklist for sending and follow-up. The user decides what to send and completes any provider verification. DROP remains the official California mechanism for the scope defined by California law.

Frequently asked questions

Is DROP the same as opting out of data sale?

No. DROP is a deletion mechanism. California's other opt-out rights and preference signals can address different processing activities. Read the current CPPA guidance for the right and request type that fits the situation.

Is DROP available to every person in the United States?

The statutory mechanism is for California residents. A provider may choose to honor a California request more broadly, but that is not a nationwide legal rule.

Does DROP delete my information from every data broker?

It is intended to reach covered, active data brokers within the mechanism. It does not establish coverage of every website, affiliate, search engine, original public record, or downstream copy. Check the current CPPA scope and handle out-of-scope sources separately.

Does the 45-day cycle mean removal takes 45 days?

No. The 45-day language describes how often covered brokers must access the mechanism beginning August 1, 2026, subject to the law and exceptions. Matching, processing, source changes, search indexing, and follow-up can create different observable timelines.

Is DROP free?

Current California consumer guidance says DROP is available to California residents for free. Confirm the live consumer instructions and never pay an unofficial intermediary claiming to be the government portal; broker access and registration fees are a separate provider-side obligation.

What should I do if a result remains in Google?

First determine whether the source page is still live. Ask the source provider to address its record. If the source changed or was removed, review Google's current eligible personal-information or outdated-content request tools. Search-result handling does not prove source deletion.

Sources and review date

Reviewed against the linked official pages on August 25, 2026. Re-check before publishing legal advice or relying on a portal step.

Related guides

Take back your privacy today

Review provider-specific routes, prepare your requests locally, and send or submit each one yourself.

Review Provider Routes

Free to review provider routes · Optional one-time unlock from $9.00 · No subscription