California's DROP: Delete Your Data From Every Registered Broker, Free

California residents have a free, state-run route to broker deletion. Most privacy content never mentions it.


DROP is a free platform run by the California Privacy Protection Agency that lets a California resident submit one verified deletion request that reaches every data broker registered in the state. Since 1 August 2026, registered brokers have been legally required to check the platform at least once every 45 days and process the deletion requests they find. It costs nothing, and it's worth trying before paying for a commercial removal subscription.

What DROP is

DROP stands for Delete Request and Opt-Out Platform. It exists because of California's Delete Act, which requires data brokers operating on Californians' data to register with the state and to honour deletion requests through a single mechanism rather than each running its own opt-out maze.

The Agency describes it as "a website application called the Delete Request and Opt-Out Platform" through which consumers make "a single verifiable request." It lives at databroker.drop.privacy.ca.gov. Source: California Privacy Protection Agency. Checked: 2026-08-19.

The significant part is the direction of effort. Ordinarily you find each broker, locate its opt-out page, prove your identity, and repeat several hundred times. DROP inverts it: you make one request, and the legal obligation to go and collect it sits with the brokers.

The dates that matter

DateWhat applies
1–31 January, annuallyBroker registration window. The 2026 fee is $6,000 plus a processing fee.
1 August 2026Registered brokers must access the deletion mechanism at least every 45 days and process the requests they find.
1 January 2028First independent audit due, then every three years.
All dates from the CPPA's data broker page. Checked: 2026-08-19.

The August 2026 date is the one that changed things. Before it, the platform accepted requests but brokers had no processing obligation. Now they do.

Who can use it

California residents. The Delete Act is state law and DROP is built to serve people it covers. If you live elsewhere, this specific route isn't open to you — though Vermont, Texas and Oregon operate broker registries of their own, and the EU and UK give a right to erasure under the GDPR that applies to brokers like anyone else.

What it does and doesn't reach

Read this before assuming it solves everything
  • Registered brokers only. A broker that fails to register is breaking the law, but it still won't see your request through this channel.
  • It's a deletion mechanism, not an erasure guarantee. Brokers have processing obligations and there are compliance deadlines; that is not the same as instant disappearance.
  • It doesn't touch companies you have a direct relationship with. Your bank, your retailer and your newsletter are not data brokers. This doesn't unsubscribe you from anything.
  • It doesn't stop future collection. New records keep being generated from public records, purchases and signups. Deletion is a snapshot.
  • It's new. The processing obligation is weeks old at the time of writing. How thoroughly it works in practice is a question for evidence, not prediction — and we'd rather say that than guess.

Does this replace a paid removal service?

For some people, plausibly. For others, no. The honest position is that it depends on facts that aren't settled yet.

Arguments for trying DROP first: it's free; it reaches every registered broker in one request; and the obligation to act sits with the brokers under state law rather than resting on a company negotiating on your behalf.

Arguments for a commercial service: paid services also pursue sites beyond the registered-broker list — Incogni advertises "420+ data broker sites" on its Standard plan and "3,000+ additional sites" on Unlimited (incogni.com/pricing, checked 2026-08-19). They also work for residents of other states and countries, and they handle the repetition for you.

A reasonable sequence for a Californian: submit through DROP, wait, see what actually drops off, and only then decide whether a subscription is buying you anything extra. That ordering costs nothing and gives you evidence instead of a guess.

What it doesn't fix at all

Deletion is backward-looking. It removes records that exist; it does nothing about the address you type into a checkout form next week, and it can't tell you which company leaked you in the first place.

Those are prevention problems, and they need a different tool — a different email address for each service, so that a leak is contained and attributable. The distinction is worked through in data removal vs data prevention.

Used together they cover both halves: DROP clears what's already circulating among registered brokers, and per-service addresses stop the next signup from adding to it.

Sources

Give every service its own address

Don't SPAM Me puts unlimited aliases on a domain you own. Any address at that domain starts working the first time mail arrives, and when spam turns up you know exactly which company leaked it. The software is free; you bring the domain, or register one during setup.

Get started — free

Keep reading