Skip to main content
CCPA/CPRA · Effective 2020-01-01

California Data Removal Guide (2026)

California residents may have CCPA/CPRA rights to know, delete, correct, and opt out of sale or sharing when the business and request fall within the law. Scope, verification, exemptions, and the live CPPA process determine what happens for a specific data-broker profile.

Research status: published state guide pending fresh official-source re-verification.

This page is educational orientation, not legal advice. Scope, exemptions, deadlines, penalties, regulator powers and broker routes can change. Verify the current statute and state regulator guidance before relying on a right or deadline.

Rahul Kandoriya
Written byRahul Kandoriya·Founder, OfflistMe·Last updated August 13, 2026

At a glance

Comprehensive state privacy law
Recorded: CCPA/CPRA
Broker response deadline
45 days in this research snapshot for qualifying requests; extensions and exemptions may apply
Enforcement
California Privacy Protection Agency

California Consumer Privacy Act (as amended by CPRA) (CCPA/CPRA)

The CCPA/CPRA provides rights that can include access, deletion, correction, and opting out of sale or sharing, subject to business scope, verification, exemptions, and other limits. A covered business generally has a statutory response process for a verifiable request, including possible extensions; confirm the current rule for the request at issue. California also operates the CPPA Data Broker Registry and DROP, a separate centralized mechanism for covered active data brokers.

What rights do California residents have?

  • Right to deletion (Cal. Civ. Code § 1798.105)
  • Right to opt out of sale or sharing (§ 1798.120)
  • Right to limit use of sensitive personal info (§ 1798.121)
  • Private right of action for security breaches (§ 1798.150)
  • Statutory damages for qualifying security-breach claims: $107-$799 per consumer per incident under the current adjusted range
  • DROP single-request mechanism for California residents; CPPA says broker processing begins August 1, 2026 with recurring access requirements

Where does your data leak from in California?

The FTC explains that people-search sites may combine public records, public social profiles, and information from other brokers. The examples below are a research snapshot, not an exhaustive or person-specific source map for California:

  • California Data Broker Registry and DROP (CPPA live guidance)
  • Los Angeles County Assessor public records
  • California DMV abstracted records
  • Vital records via California Department of Public Health

Generate requests in under 60 seconds

Generate requests for 1009 US/global broker workflows for $9

OfflistMe prepares user-reviewed request drafts for the selected catalog routes. You choose the jurisdictional wording, review each draft, and send or submit it yourself; broker verification and outcomes remain outside OfflistMe's control.

What if a broker ignores your request?

If a qualifying request does not receive a response within the applicable window, review the current extension and exemption rules, then consider the California Privacy Protection Agency complaint route. The authority's jurisdiction and available remedies vary.

File a complaint with California Privacy Protection Agency

FAQ: California data removal

How long do data brokers have to respond to a CCPA deletion request?+

The CCPA provides a response process commonly described as 45 days for a verifiable request, with a possible extension when the law permits and notice is provided. Verification, exemptions, request scope, and the current CPPA guidance matter; preserve the dates and use the appropriate complaint route if the provider does not respond as required.

What is the California DELETE Act?+

SB 362 created DROP (Delete Request and Opt-out Platform), a centralized mechanism where a California resident can submit a single verifiable deletion request directed to active data brokers covered by the mechanism. The CPPA says consumers can submit requests and brokers must begin processing them from August 1, 2026, with access at least every 45 days. Check the current CPPA instructions for scope, status, and exceptions.

Can I sue a data broker for ignoring my CCPA request?+

The CCPA provides a private right of action for certain security-breach claims involving specified personal information; it does not create a general private action for an ordinary ignored deletion request. Administrative penalties and other remedies depend on the provision, facts, and enforcing authority, so check the current CPPA and statutory materials rather than applying one amount to every complaint.

Do I need to prove I am a California resident?+

A business may use a reasonable verification process appropriate to the request, and the current CPPA or provider instructions may require matching information. Do not assume that a government ID is always prohibited or always necessary; ask why it is requested, use the provider's secure route, and disclose no more than is reasonably needed. OfflistMe prepares user-reviewed request drafts but does not determine a provider's verification decision.

Related resources

Other state guides