privacy 5 min read

California Just Made Data Deletion a Single Click — And Brokers Have to Keep Checking

Until now, erasing yourself from the data broker economy meant filing requests one company at a time. There are more than 500 registered brokers in California alone. Do the math on that afternoon.

California just inverted the whole arrangement. As of August 1, 2026, a resident files one request and every registered broker in the state is on the hook to delete them. It’s the first system of its kind in the US.

One caveat up front: this is week one. There’s no meaningful body of real-world experience yet, no war stories, no first enforcement action. So this piece looks at how the machine is built and what it’s likely to break, rather than pretending anyone has receipts already.

What DROP Actually Is

DROP stands for Delete Request and Opt-Out Platform. It’s a centralized deletion portal run by the California Privacy Protection Agency (CPPA), authorized by SB 362 — the Delete Act, passed in 2023.

The mechanics are refreshingly simple. A resident registers on the DROP site, verifies their identity, and lands on a master list. Every data broker registered in California must query that list every 45 days and delete the personal information of everyone on it. The consumer never contacts a single broker.

The rollout came in two stages. The consumer-facing intake opened January 1, 2026. The brokers’ obligation to actually poll the list and delete — that started August 1, 2026. This week is the real starting gun.

Why This Isn’t Just CCPA With Better Branding

The right to deletion already existed under CCPA. It was just functionally unusable.

Under the old regime, you had to find the brokers yourself — companies you had no way of knowing held your data in the first place. Every one had its own request form, its own identity verification hoops, its own timeline. Five hundred brokers meant five hundred separate processes. That’s not a right. That’s a hobby.

DROP flips the cost structure. The searching and the repeating move from the consumer to the business. You register once. The brokers carry the recurring obligation to check. No new right was created here — the friction cost of exercising an existing one just collapsed.

And the deletion isn’t a one-shot event. Because brokers must re-query every 45 days, a broker that reacquires your data from a fresh source has to delete it again on the next cycle. It behaves less like an eraser and more like a standing block.

How Much Does Getting Caught Hurt

The statute carries civil penalties: $200 per day for failing to register, and roughly $200 per violation for failing to process deletion requests. Investigation costs and attorney’s fees can stack on top.

Those numbers look small in isolation. They don’t stay small. Data brokers handle records on millions of people. If tens of thousands of Californians are on the DROP list and a broker’s system quietly skips a polling cycle, that’s a multiplication problem, and it compounds fast.

The more telling signal isn’t the dollar figure — it’s that CPPA has already been fining brokers for registration failures over the past couple of years. This is not a paper regulation. What’s genuinely unknown is how tightly the agency can enforce at scale. Regulators have finite headcount and finite budgets, and 500-plus registrants is a lot of surface area.

Does This Actually Dent Surveillance Advertising and AI Training Data

The interesting question. Short answer: it cracks the foundation. It doesn’t bring the house down.

The clear casualties are the pure reseller brokers — outfits whose entire business is scraping public records and app SDK exhaust and selling identity graphs downstream. California is roughly 12% of the US population. Losing that slice of inventory hurts, and it keeps hurting on a rolling basis rather than as a one-time write-down. Once advertisers notice California targeting accuracy degrading, pricing power goes with it.

But the escape hatches are wide. Three of them.

First-party data is out of scope. A company with a direct relationship with you — any service you signed up for — isn’t a data broker under the law. That exemption covers most of the advertising business at the large platforms. Google, Meta, and Amazon didn’t build first-party data moats by accident, and this regulation quietly rewards that architecture.

Models already trained are not reversible. The deletion obligation attaches to databases brokers hold. Surgically removing one person’s contribution from weights already trained on that data is a hard technical problem. Machine unlearning is an active research area, not a production standard. DROP constrains future collection. It leaves past training intact. Every model shipped before August 2026 keeps whatever it absorbed.

Jurisdiction stops at the state line. Data on non-Californians flows exactly as before. The same business model runs unchanged in the other 49 states and overseas.

What to Watch Next

Three numbers will tell you whether this becomes structural or stays symbolic.

DROP registration counts. If it plateaus in the tens of thousands, the industry absorbs it as a manageable compliance line item and moves on. If it reaches millions, the business model itself needs rewriting.

The size of the first enforcement action. Which company CPPA goes after, when, and for how much will set the real deterrent level — far more than anything in the statute text.

Whether other states copy it. California privacy law has been the template for other states repeatedly — CCPA seeded a wave of state privacy statutes across the country. The moment a second state ships its own DROP equivalent, brokers stop treating this as a California problem and start treating it as an architecture problem.

The deeper shift here is conceptual. For a decade, privacy law has been written around whether you have a right. DROP is the first serious attempt to legislate the cost of using it — to treat friction itself as the violation. That framing travels well, and regulators in Brussels and Washington are watching.

Try this: pick one service you use daily and count the clicks it would take to remove your data from it entirely. If you lose count, you’ve found the actual problem.

privacy data brokers CCPA regulation AI

Comments

    Loading comments...