California Delete Act (SB 362) & DROP: Source-Checked Consumer Guide (2026)
Source-checked guide to California's Delete Act and DROP: covered-broker scope, the August 1, 2026 45-day access cycle, source limits, and follow-up steps.
The California Delete Act (Senate Bill 362) created a centralized deletion mechanism for California residents. The California Privacy Protection Agency (CPPA) calls that mechanism the Delete Request and Opt-Out Platform (DROP). It is designed to let an eligible California resident submit one verifiable request to covered data brokers rather than repeat the same request at every registered broker.
This guide explains what the official CPPA material says, what the mechanism does not establish, and how to keep evidence while using it. The primary sources are the CPPA consumer DROP guidance, CPPA information for data brokers, the California Data Broker Registry, the current DROP Terms of Use, and the CPPA DROP regulations page. Laws, agency instructions, and portal behavior can change; check those sources before relying on a date or procedure.
What SB 362 and DROP do
The Delete Act applies to businesses that meet California's data-broker definition and the law's exclusions. The CPPA explains that a data broker knowingly collects and sells personal information about a consumer to third parties when the consumer does not have a direct relationship with the business. The definition and exemptions matter: a company appearing in a people-search catalog is not automatically a registered California data broker.
The CPPA's current materials state that:
Exercise your statutory data deletion rights
Review source-aware privacy-rights request drafts directly in your browser. Send or submit each request yourself after checking the provider route and applicable law.
- California residents may use DROP to submit one deletion request to active data brokers covered by the mechanism.
- Data brokers that operated in 2025 or newly operate in 2026 must create a DROP account under the agency's instructions.
- Beginning August 1, 2026, data brokers must access the accessible deletion mechanism at least once every 45 days and process consumer deletion requests, subject to limited exceptions.
- The California Data Broker Registry publishes information submitted by registered businesses. Registry inclusion is evidence about the registry record, not proof that a provider has every possible record about a person or that a request will produce a particular outcome.
These statements describe the legal and administrative mechanism. They do not promise that every online publisher, search engine result, downstream copy, or company outside the covered definition will be affected.
Who can use it
DROP is a California mechanism for California residents. The CPPA's final regulations describe the consumer deletion request as going through DROP and require California residency verification before submission. Check the live portal and the current regulations for the exact verification and review process.
A broker may voluntarily apply a California request more broadly, but that is a provider decision. Do not describe a California request as a nationwide legal deletion order, and do not assume that a non-California resident can use the statutory mechanism.
What you submit and who receives it
Before submitting, review the current DROP Terms of Use. They state that submitting a deletion request consents to disclosure of the personal information you provide to data brokers for processing. The consumer guidance describes encryption and hashed identifiers for matching, and lets you choose which optional identifiers to provide, but you should still use accurate information and provide only what you are comfortable submitting. Residency verification and the request itself are separate steps; keep only the private evidence you need.
What DROP does not cover automatically
DROP is not a universal deletion button for the internet. It does not by itself:
- remove a live source page from a company that is outside the covered data-broker scope;
- remove a search-engine result when the source page is still live;
- erase a public record at the government or original-record source;
- establish that a separate brand, affiliate, customer, contractor, or downstream copy is within the same request;
- decide whether a legal exemption or matching issue applies to a particular record; or
- replace a provider-specific request for a site outside the mechanism.
When a source remains visible, save the exact URL and date, then use the source's current privacy route. If the source page changed or was deleted, review the search engine's current personal-information and outdated-content tools separately.
What the 45-day rule means
The CPPA says that, beginning August 1, 2026, covered data brokers must access DROP at least once every 45 days and process deletion requests subject to limited exceptions. That is an access and processing obligation for covered brokers. It is not a promise that every matched record disappears immediately after a consumer submits a request, and it is not a universal deadline for every privacy request made outside DROP.
Keep these events separate in your log:
| Event | Evidence to keep |
|---|---|
| California residency or portal verification | Portal status or confirmation, without retaining unnecessary sensitive material |
| DROP request submission | Submission date, reference information, and the scope shown in the portal |
| Broker processing | Broker status or response, if supplied through the mechanism |
| Source verification | Exact provider URL, date checked, and whether the matching profile changed |
| Follow-up or complaint | Copy of the request, response, and the official channel used |
Do not infer deletion from an automated acknowledgement. A search result can remain after a source changes, and a source can later receive data from a different upstream record.
A careful workflow for California residents
1. Read the current CPPA instructions
Start at the California consumer DROP page, the California consumer privacy-request page, and the CPPA data-broker information page. Use the live portal and follow its current residency and verification instructions.
2. Submit only the information needed for matching
Use the identifiers the current portal requests. Avoid adding unrelated identity documents or sensitive information unless the official process requires it. Keep a private record of the submission date and confirmation; do not place personal request contents in public notes or analytics.
3. Review the official status and then check important sources
A portal status is one evidence point. For safety-critical or employment-sensitive exposure, separately check the exact source pages that matter to you. Record whether the source was removed, changed, still live, or not found.
4. Handle out-of-scope sources separately
Use each provider's current first-party privacy or opt-out route for sources outside DROP. OfflistMe can prepare a browser-local draft and route information for the user to review and send. It does not submit a DROP request, determine California residency, guarantee acceptance, or verify downstream deletion.
5. Escalate with evidence
If a covered request is not processed or a response appears inconsistent with the applicable rules, keep the request and response record and consult the CPPA's current complaint or enforcement instructions. A complaint is an escalation path, not a guarantee of a particular result.
DROP compared with an individual request
| Question | DROP | Individual provider request |
|---|---|---|
| Who operates the route? | CPPA's state mechanism | The provider or its privacy service |
| Typical scope | Covered data brokers within the mechanism | The particular provider and request scope |
| Who decides matching and exceptions? | The applicable rules and covered broker process | The provider under its notice and applicable law |
| Does it remove a search result? | Not by itself | Not necessarily; search and source are separate |
| Evidence to preserve | Portal submission and status | Exact URL, request, verification, and response |
Neither route should be marketed as a permanent, universal outcome. The relevant question is whether the source, person, request, and legal scope are supported by evidence.
How OfflistMe fits
OfflistMe is a user-controlled preparation layer for source-specific requests. Its current public catalog contains 1,034 recorded workflow profiles within a 1,052-record research universe. Those are catalog and research counts, not the number of California-registered brokers, not a guarantee that every profile matches a user, and not an outcome rate.
The app can help a user review a provider route, prepare a draft locally, and retain a checklist for sending and follow-up. The user decides what to send and completes any provider verification. DROP remains the official California mechanism for the scope defined by California law.
Frequently asked questions
Is DROP the same as opting out of data sale?
No. DROP is a deletion mechanism. California's other opt-out rights and preference signals can address different processing activities. Read the current CPPA guidance for the right and request type that fits the situation.
Is DROP available to every person in the United States?
The statutory mechanism is for California residents. A provider may choose to honor a California request more broadly, but that is not a nationwide legal rule.
Does DROP delete my information from every data broker?
It is intended to reach covered, active data brokers within the mechanism. It does not establish coverage of every website, affiliate, search engine, original public record, or downstream copy. Check the current CPPA scope and handle out-of-scope sources separately.
Does the 45-day cycle mean removal takes 45 days?
No. The 45-day language describes how often covered brokers must access the mechanism beginning August 1, 2026, subject to the law and exceptions. Matching, processing, source changes, search indexing, and follow-up can create different observable timelines.
Is DROP free?
Current California consumer guidance says DROP is available to California residents for free. Confirm the live consumer instructions and never pay an unofficial intermediary claiming to be the government portal; broker access and registration fees are a separate provider-side obligation.
What should I do if a result remains in Google?
First determine whether the source page is still live. Ask the source provider to address its record. If the source changed or was removed, review Google's current eligible personal-information or outdated-content request tools. Search-result handling does not prove source deletion.
Sources and review date
- CPPA: Information for Data Brokers
- CPPA: California Data Broker Registry
- CalPrivacy: Consumer DROP guidance
- CalPrivacy: How DROP works
- Current DROP Terms of Use
- CPPA: DROP System Requirements
- CPPA: final DROP regulations
- California consumer privacy-request and DROP guidance
Reviewed against the linked official pages on August 25, 2026. Re-check before publishing legal advice or relying on a portal step.
Related guides
Understand your privacy rights
Where a privacy right is relevant, these plain-English explainers show what each law covers and what to verify before making a request.
Related Data Broker Removal Guides
Take back your privacy today
Review provider-specific routes, prepare your requests locally, and send or submit each one yourself.
Review Provider RoutesFree to review provider routes · Optional one-time unlock from $9.00 · No subscription
