Skip to main content
Category Pillar Hub

Statutory Privacy Laws & Consumer Legal Rights

Understand your statutory privacy rights under CCPA/CPRA, California Delete Act (DROP), GDPR Art 17/21, VCDPA, and state statutes.

Navigating Statutory Data Privacy Rights

Modern data privacy is enforced through a matrix of state, federal, and international statutes. Understanding the exact statutory provisions under which you issue data deletion demands significantly increases broker compliance and legal accountability.

When you send a removal request citing a legal section that actually applies to your situation, it can help the provider identify the request. Rights, exemptions, verification rules, response periods, and remedies depend on the law, requester, provider role, and facts.

Major Privacy Laws Explained

  • California CCPA / CPRA and Delete Act (SB 362): The CCPA/CPRA provides defined rights to know, delete, and opt out of sale or sharing for eligible California residents, while SB 362 created the CPPA-managed DROP mechanism for covered data-broker deletion requests.
  • GDPR and UK GDPR: Articles 17 (erasure) and 21 (objection) can provide rights for people within the law's scope, subject to exemptions and other conditions. The UK GDPR is a separate domestic regime.
  • State Privacy Frameworks: A growing number of US states have comprehensive privacy laws, but coverage, definitions, exemptions, and deadlines differ. Check the current statute or regulator guidance for the state and request at issue.
  • Judicial & Officer Protection Laws: Daniel's Law (NJ), state judicial privacy protection acts shielding law enforcement and judicial officers' home addresses.

Generate requests in under 60 seconds

Generate opt-out requests for the listings you choose

Review recorded provider workflows and use OfflistMe to prepare requests for the listings you choose. Provider acceptance and removal outcomes are outside OfflistMe's control.

Guides in Privacy Law & Rights

Showing 10 curated privacy guides

California Delete Act (SB 362) & DROP: Source-Checked Consumer Guide (2026)
Privacy Law & Rights

California Delete Act (SB 362) & DROP: Source-Checked Consumer Guide (2026)

Source-checked guide to California's Delete Act and DROP: covered-broker scope, the August 1, 2026 45-day access cycle, source limits, and follow-up steps.

Read article
Is Doxxing Illegal? How to Assess the Law and Respond (2026)
Privacy Law & Rights

Is Doxxing Illegal? How to Assess the Law and Respond (2026)

Jurisdiction-aware guide to doxxing, threats, stalking, protected-person laws, evidence preservation, platform reports, and source-specific privacy steps.

Read article
California Data Broker Opt-Out Guide: Your CCPA Rights Explained (2026)
Privacy Law & Rights

California Data Broker Opt-Out Guide: Your CCPA Rights Explained (2026)

California data-broker opt-out guide covering CCPA scope, the California Delete Act and DROP, verification, source boundaries, and follow-up options.

Read article
FTC Data Broker Reports and Enforcement: What Consumers Can Verify (2026)
Privacy Law & Rights

FTC Data Broker Reports and Enforcement: What Consumers Can Verify (2026)

A source-bounded guide to the FTC's 2014 data-broker report, later location-data enforcement, and the privacy claims consumers can verify today.

Read article
FCRA and Data Brokers Explained: What the Fair Credit Reporting Act Actually Covers (2026)
Privacy Law & Rights

FCRA and Data Brokers Explained: What the Fair Credit Reporting Act Actually Covers (2026)

Source-aware FCRA guide: distinguish consumer reports, people-search pages, permissible purpose, employment notices, disputes, credit freezes, and privacy requests.

Read article
Texas Data Privacy Rights and Data Brokers (TDPSA Guide, 2026)
Privacy Law & Rights

Texas Data Privacy Rights and Data Brokers (TDPSA Guide, 2026)

A statute-bounded Texas TDPSA guide to covered scope, consumer rights, authentication, response windows, exemptions, and broker requests.

Read article
Virginia Data Privacy Rights: VCDPA Guide for Data Broker Opt-Outs (2026)
Privacy Law & Rights

Virginia Data Privacy Rights: VCDPA Guide for Data Broker Opt-Outs (2026)

Virginia CDPA guide covering consumer rights, controller duties, deletion requests, appeal routes, and how residents can address broker-held data.

Read article
Colorado Data Privacy Rights: CPA Guide for Data Broker Opt-Outs (2026)
Privacy Law & Rights

Colorado Data Privacy Rights: CPA Guide for Data Broker Opt-Outs (2026)

Colorado Privacy Act guide covering universal opt-out signals, consumer rights, deletion requests, appeals, and data-broker obligations.

Read article
U.S. State Privacy and Data-Broker Rights: How to Verify 2026 Rules
Privacy Law & Rights

U.S. State Privacy and Data-Broker Rights: How to Verify 2026 Rules

Primary-source guide to checking state privacy scope, California DROP, Texas Chapter 541, Colorado opt-out signals, verification, exemptions, and request evidence.

Read article
How to Write a Privacy-Rights Opt-Out Request (Source-Aware Guide)
Privacy Law & Rights

How to Write a Privacy-Rights Opt-Out Request (Source-Aware Guide)

Source-aware guide to privacy requests: identify the listing, use the provider's current route, cite only applicable law, minimize verification, and preserve follow-up evidence.

Read article

Frequently Asked Questions

Common questions regarding privacy law & rights

What is the California Delete Act (SB 362)?

California created the CPPA-run DROP mechanism for eligible deletion requests involving covered data brokers within the program's statutory scope. It is not a guarantee that every broker, record, source, or downstream copy is covered or removed by one submission; check current CPPA instructions.

Do data brokers have to comply with GDPR Article 17?

Article 17 may apply when the requester, controller, processing, and request meet the GDPR or UK GDPR conditions. The usual response period is one month, subject to extensions, exemptions, identity checks, and the applicable regime; it is not a universal deletion guarantee.