California DROP: Delete Request and Opt-Out Platform
DROP is California’s centralized deletion mechanism under the Delete Act (SB 362). The CPPA says a single verifiable request can be directed to active data brokers covered by the mechanism; scope, non-exempt data, matching, verification, and exceptions still matter.
The key facts
- Platform
- Delete Request and Opt-Out Platform (DROP)
- Operator
- California Privacy Protection Agency (CPPA)
- Current status
- Under current CPPA guidance, broker processing duties began August 1, 2026; verify current status and exceptions
- Broker access cadence
- At least once every 45 days under current CPPA guidance
- Registration details
- Check the live CPPA filing instructions and applicable year
- Fees and disclosures
- Check the current CPPA broker guidance for the applicable obligation
- Legal basis
- Cal. Civ. Code § 1798.99.86
- DROP website
- privacy.ca.gov/drop
How DROP works for consumers
- 1
Use the current CPPA consumer process and submit a single verifiable request with only the matching information the route requires.
- 2
The CPPA operates the accessible deletion mechanism and provides request-status information through its current process.
- 3
Covered active data brokers must access DROP at least once every 45 days under the CPPA guidance.
- 4
A broker evaluates the match and processes non-exempt information within the applicable scope and timeline.
- 5
Exceptions, verification requirements, source limits, and matching outcomes still apply; a DROP request does not erase independent public records or every downstream copy.
Before you submit
DROP requires California-residency verification before a request can be submitted. The current DROP Terms of Use say that submitting a request consents to disclosure of the personal information you provide to data brokers for processing. The official consumer guidance describes encryption and hashed matching, but the fields you provide still affect which brokers can match you.
Use accurate information, provide only what you are comfortable submitting, and re-check the live terms and privacy notice before sending.
Timeline
- Oct 2023
SB 362 (Delete Act) signed by Governor Newsom.
- Jan 1, 2024
Administration, enforcement, and rulemaking authority for the data broker registry transferred to the CPPA from CA DOJ.
- 2025
SB 361 enacted, expanded disclosure requirements.
- Jan 1-31, 2026
Annual 2026 registration window; the CPPA listed a $6,000 registration fee plus a processing fee.
- Aug 1, 2026
The CPPA says data brokers must begin processing DROP requests.
- Jan 1, 2028
First independent third-party audit requirement begins.
- Jan 1, 2029
The registry must begin including the required audit-status and most-recent-submission disclosures.
SB 361: expanded 2026 disclosure requirements
SB 361 (2025) tightens what data brokers must disclose at annual registration. In addition to basic business information, brokers now must disclose:
OfflistMe’s California broker registry index already surfaces these disclosures per-broker.
Audit requirements (2028-2029)
January 1, 2028: Registered data brokers must undergo an independent third-party audit every 3 years to determine compliance with the Delete Act. The audit report and related materials must be provided to the CPPA within 5 business days of a written request.
January 1, 2029: Data brokers must also disclose in their registration whether they have undergone an audit, the most recent year of submission, and related materials. This creates an additional public-transparency signal about broker compliance.
Generate requests in under 60 seconds
Generate requests while keeping your evidence visible
FAQ
What is the California DROP platform?+
DROP stands for "Delete Request and Opt-Out Platform." It is the California Privacy Protection Agency’s (CPPA) mechanism created under the Delete Act (SB 362). A California resident can submit a single verifiable request directed to active data brokers covered by the mechanism, subject to non-exempt data, matching, verification, and other limits.
When did broker processing begin?+
The CPPA says data brokers must begin processing DROP requests on August 1, 2026, access DROP at least once every 45 days, and report request status within the required timeline. Check the live CPPA consumer and broker pages for current access, status, and exceptions.
How does a consumer use DROP?+
A California resident submits one verifiable request through the current DROP process. The request is directed to active data brokers covered by California law, and each broker must access DROP at least once every 45 days and process requests within the required timeline. A provider-specific follow-up may still be needed for scope, matching, exceptions, or other sources.
What does DROP mean for data brokers?+
The current CPPA guidance describes registration, applicable fees, DROP account and processing duties, at-least-45-day access, limited exceptions, and later audit requirements. Confirm the filing year, entity status, fee, and exact obligation in the live CPPA instructions before relying on a checklist.
What is SB 361?+
SB 361 (2025) expanded California data-broker disclosure requirements. The CPPA describes additional sensitive-data, personal-information, and sharing-practice fields; use the current filing and CPPA guidance to distinguish a required disclosure from a claim that a broker actually holds or sells a particular field.
Will DROP work for consumers outside California?+
DROP is the California mechanism, and the current CPPA process determines eligibility and verification. Residents elsewhere must use the rights and routes that apply in their own jurisdiction; do not assume a provider will extend California treatment or that a DROP request controls a non-covered source.
Does DROP replace CCPA deletion requests?+
No, it supplements them. CCPA’s right to delete against any covered business still exists. DROP specifically handles deletions from registered data brokers. Consumers may continue to submit direct CCPA deletion requests to any broker, or use DROP for batch processing. For businesses that aren’t data brokers (e.g., a retailer), direct CCPA requests remain the path.
What information do I submit to DROP?+
You must verify California residency before submitting a request, then choose the identifying information the current process accepts for matching. The current DROP Terms say that submitting a request consents to disclosure of the personal information you provide to data brokers for processing. The consumer guidance describes encrypted and hashed matching, so review the live Terms and provide only accurate information you are comfortable submitting.
What happens if a broker ignores a DROP deletion request?+
The Delete Act and CPPA guidance provide administrative enforcement and penalty provisions, but the applicable provision, amount, day count, entity status, and facts matter. Preserve the request and status evidence, then use the current CPPA complaint or enforcement information before asserting a violation.
How will DROP affect subscription data-removal services?+
DROP changes the available California route, but provider-managed services may still differ in authorization, monitoring, source scope, reporting, and follow-up. Compare current terms; do not assume the state mechanism makes every paid workflow redundant or guarantees a particular outcome.
Does OfflistMe still matter once DROP is live?+
It can remain useful for a different workflow: OfflistMe prepares user-reviewed drafts and route links for selected catalog profiles, while you send, verify, and follow up. It is separate from DROP, does not submit to the state platform, and does not guarantee coverage or an outcome.
Related
Sources: California Privacy Protection Agency, Data Brokers · CalPrivacy consumer DROP guidance · current DROP Terms · California Civil Code §1798.99.86. Reviewed August 25, 2026; confirm live instructions before acting. These sources do not establish eligibility, a match, an exemption decision, or a guaranteed result for a particular request.
