Skip to content
News

California's DROP is live: delete yourself from data brokers in one request

California's DROP platform is live: one verified request tells every registered data broker to delete your data. Brokers must process it by August 1, 2026.

Email Unsubscriber Team 6 min read
Flat vector illustration of a cream DELETE request ticket with a verification stamp, beside a star-pinned state map tile, broker cards sweeping toward a bin, and an AUG 1 calendar page.

You live in California, and your inbox keeps filling with mail from companies you never contacted. Until this year, getting off their lists meant hunting down data brokers one at a time and filing on each broker’s own form. As of 2026, the state runs a single request that does it for you.

DROP, California’s Delete Request and Opt-out Platform, went live to residents on January 1, 2026. One verified request tells every data broker on the state registry, more than 600 of them, to delete your personal information and stop selling it. Registered brokers must begin processing those requests by August 1, 2026.

This is an educational overview of California’s Delete Act, not legal advice. For a specific situation, check the regulator linked in each section or consult a lawyer in your state.

What is California’s DROP?

DROP is a free, state-run website where a California resident files one deletion request that reaches every registered data broker at once. The California Privacy Protection Agency (CPPA) runs it under the Delete Act (SB 362), the law the governor signed in October 2023.

Data brokers are companies that collect and resell personal information, including your email address, about people who never dealt with them directly. Before DROP, opting out meant filing with each broker separately, on each broker’s own page. DROP replaces hundreds of those separate opt-outs with a single verified request. If you want the fuller picture of where those brokers pick up your address in the first place, we trace it in how data brokers get your email.

What just changed in 2026?

Two things went live this year, and a third deadline is bearing down. First, the platform opened to residents on January 1, 2026, so the single-request deletion tool exists and accepts submissions now. Second, on December 17, 2025, the CPPA issued its first enforcement advisory under the Delete Act, warning brokers to clean up how they register. Third, the date brokers actually have to act on is August 1, 2026, when they must start honoring the requests sitting in the system.

Before August 1, you can file, but a broker is not yet obligated to delete anything. Filing early still helps. Your request queues up, and the broker’s clock starts the moment the obligation kicks in.

Who does DROP cover, and what are its limits?

DROP covers California residents and registered data brokers, and nothing outside those two boundaries. You must verify California residency to file, and the request only reaches companies on the state’s data-broker registry.

That leaves real gaps, and it is worth being honest about them. A company you subscribed to directly is not a data broker, so DROP does not touch it. A broker that never registered is not in the system, which is exactly why the December advisory matters. And residents of other states have no equivalent platform yet. If you live outside California, your route is slower and runs broker by broker, backed by your own state’s privacy law. Our roundup of the new privacy laws taking effect in 2026 maps what your state may already give you.

How do you use DROP?

Filing takes three steps on the CPPA’s official DROP site, and you clear the identity check once rather than per broker.

  1. Verify your residency. DROP confirms you are a California resident through the state’s California Identity Gateway. This proves you are eligible before your request goes out.
  2. Create your profile. You enter the identifying details brokers need to match their records to you, including the email addresses you want scrubbed.
  3. Submit one deletion request. That single request reaches every data broker on California’s registry, more than 600 of them, and tells each to delete your data and stop selling or sharing it.

The expected outcome is one action standing in for hundreds of individual opt-outs. You do not file with each broker, and you never repeat the identity check.

When will data brokers actually delete your data?

Not immediately, and not all at once. The obligation to process DROP requests starts on August 1, 2026. Before that date, a broker can leave a queued request untouched without breaking any rule.

After August 1, the schedule tightens. A registered broker must check DROP at least every 45 days to pull new deletion requests, then delete the matching records within 90 days of retrieving them. Under the Delete Act, a broker that fails to delete faces $200 for each deletion request for each day it stays out of compliance, according to Byte Back’s analysis of the live platform. Deletion is not a one-time sweep either. Once you are in DROP, brokers keep honoring your request on that recurring cycle.

Why did California warn brokers about trade names?

Because a broker you cannot name is a broker you cannot escape. On December 17, 2025, the CPPA released Enforcement Advisory No. 2025-01, its first under the Delete Act. The agency said some brokers were making themselves hard to identify by operating under trade names or websites that never appeared on their annual registration.

The advisory told brokers to disclose every trade name and website they use, and to register independently instead of sheltering under a parent company’s filing. A broker that skips registration faces $200 per day, on top of the fees and investigation costs the agency incurs, according to the CPPA’s announcement. For you, the point is coverage. The cleaner the registry, the more brokers your one DROP request can actually reach. Every business that operated as a data broker last year had to register by January 31, 2026.

What DROP does not do, and what to do next

DROP pulls your data out of the broker resale market. It does not stop the senders already landing in your inbox. A newsletter you signed up for, a store whose account you created, a service you still use: none of those are data brokers, so DROP leaves them running. To stop those, you still unsubscribe from each one, and under CAN-SPAM the sender has 10 business days to comply.

Two habits close the rest of the gap. First, switch on Global Privacy Control, a browser signal that tells sites not to sell or share your data, which California and about a dozen other states legally require businesses to honor. Second, clear the marketing lists you are already on, because every sender you remove is one less company keeping your address priced as live inventory.

Doing that across years of senders by hand is the tedious part. Email Unsubscriber scans your Gmail or Outlook in your own browser, lists every subscription sender, and fires the real one-click opt-out where the sender supports it. The scan runs on your device, and we never read, analyze, or monetize your email content. It is a one-off payment with nothing to cancel. DROP handles the brokers; this handles the inbox.

Frequently asked questions

What is California's DROP platform?

DROP is the Delete Request and Opt-out Platform, a free state-run website run by the California Privacy Protection Agency under the Delete Act. A California resident files one verified deletion request that reaches every data broker on the state registry, more than 600 of them, telling each to delete their personal information and stop selling it.

When did California's DROP go live?

DROP opened to California residents on January 1, 2026, so you can submit a deletion request now. Data brokers are not required to begin processing those requests until August 1, 2026. Filing before that date still queues your request, so a broker's obligation to act on it starts the moment the August deadline arrives.

Who can use California's DROP?

Only California residents can file through DROP, and the platform verifies residency through the state's California Identity Gateway before a request goes out. The request reaches only companies on California's data-broker registry. Companies you subscribed to directly are not data brokers, and residents of other states have no equivalent single-request platform yet.

How do I delete my data from data brokers in California?

Go to the CPPA's DROP site, verify your California residency once through the California Identity Gateway, create a profile with the identifying details brokers use to match you, and submit a single deletion request. That one request reaches every registered data broker, more than 600 of them, and tells each to delete your data and stop selling it.

When do data brokers have to delete my data?

Registered data brokers must begin processing DROP requests on August 1, 2026. After that date they must check the platform at least every 45 days to pull new requests and delete the matching records within 90 days. Under the Delete Act, a broker that fails to delete faces $200 for each deletion request for each day it stays out of compliance.

Does DROP stop marketing emails?

Not directly. DROP removes your data from registered data brokers, which slows the flow of new marketing lists. It does not stop senders you already subscribed to, because a newsletter or store is not a data broker. To stop existing marketing email you still unsubscribe from each sender, and under CAN-SPAM the sender has 10 business days to comply.

Why did California issue an enforcement advisory to data brokers?

On December 17, 2025, the CPPA released Enforcement Advisory No. 2025-01 because some brokers were making themselves hard to identify by using trade names or websites not listed on their registration. The advisory requires brokers to disclose every trade name and website and to register independently. Failing to register carries a $200-per-day penalty.