You live in California, and your inbox keeps filling with mail from companies you never contacted. Until this year, getting off their lists meant hunting down data brokers one at a time and filing on each broker’s own form. As of 2026, the state runs a single request that does it for you.
DROP, California’s Delete Request and Opt-out Platform, went live to residents on January 1, 2026. One verified request tells every data broker on the state registry, more than 600 of them, to delete your personal information and stop selling it. Registered brokers must begin processing those requests by August 1, 2026.
This is an educational overview of California’s Delete Act, not legal advice. For a specific situation, check the regulator linked in each section or consult a lawyer in your state.
What is California’s DROP?
DROP is a free, state-run website where a California resident files one deletion request that reaches every registered data broker at once. The California Privacy Protection Agency (CPPA) runs it under the Delete Act (SB 362), the law the governor signed in October 2023.
Data brokers are companies that collect and resell personal information, including your email address, about people who never dealt with them directly. Before DROP, opting out meant filing with each broker separately, on each broker’s own page. DROP replaces hundreds of those separate opt-outs with a single verified request. If you want the fuller picture of where those brokers pick up your address in the first place, we trace it in how data brokers get your email.
What just changed in 2026?
Two things went live this year, and a third deadline is bearing down. First, the platform opened to residents on January 1, 2026, so the single-request deletion tool exists and accepts submissions now. Second, on December 17, 2025, the CPPA issued its first enforcement advisory under the Delete Act, warning brokers to clean up how they register. Third, the date brokers actually have to act on is August 1, 2026, when they must start honoring the requests sitting in the system.
Before August 1, you can file, but a broker is not yet obligated to delete anything. Filing early still helps. Your request queues up, and the broker’s clock starts the moment the obligation kicks in.
Who does DROP cover, and what are its limits?
DROP covers California residents and registered data brokers, and nothing outside those two boundaries. You must verify California residency to file, and the request only reaches companies on the state’s data-broker registry.
That leaves real gaps, and it is worth being honest about them. A company you subscribed to directly is not a data broker, so DROP does not touch it. A broker that never registered is not in the system, which is exactly why the December advisory matters. And residents of other states have no equivalent platform yet. If you live outside California, your route is slower and runs broker by broker, backed by your own state’s privacy law. Our roundup of the new privacy laws taking effect in 2026 maps what your state may already give you.
How do you use DROP?
Filing takes three steps on the CPPA’s official DROP site, and you clear the identity check once rather than per broker.
- Verify your residency. DROP confirms you are a California resident through the state’s California Identity Gateway. This proves you are eligible before your request goes out.
- Create your profile. You enter the identifying details brokers need to match their records to you, including the email addresses you want scrubbed.
- Submit one deletion request. That single request reaches every data broker on California’s registry, more than 600 of them, and tells each to delete your data and stop selling or sharing it.
The expected outcome is one action standing in for hundreds of individual opt-outs. You do not file with each broker, and you never repeat the identity check.
When will data brokers actually delete your data?
Not immediately, and not all at once. The obligation to process DROP requests starts on August 1, 2026. Before that date, a broker can leave a queued request untouched without breaking any rule.
After August 1, the schedule tightens. A registered broker must check DROP at least every 45 days to pull new deletion requests, then delete the matching records within 90 days of retrieving them. Under the Delete Act, a broker that fails to delete faces $200 for each deletion request for each day it stays out of compliance, according to Byte Back’s analysis of the live platform. Deletion is not a one-time sweep either. Once you are in DROP, brokers keep honoring your request on that recurring cycle.
Why did California warn brokers about trade names?
Because a broker you cannot name is a broker you cannot escape. On December 17, 2025, the CPPA released Enforcement Advisory No. 2025-01, its first under the Delete Act. The agency said some brokers were making themselves hard to identify by operating under trade names or websites that never appeared on their annual registration.
The advisory told brokers to disclose every trade name and website they use, and to register independently instead of sheltering under a parent company’s filing. A broker that skips registration faces $200 per day, on top of the fees and investigation costs the agency incurs, according to the CPPA’s announcement. For you, the point is coverage. The cleaner the registry, the more brokers your one DROP request can actually reach. Every business that operated as a data broker last year had to register by January 31, 2026.
What DROP does not do, and what to do next
DROP pulls your data out of the broker resale market. It does not stop the senders already landing in your inbox. A newsletter you signed up for, a store whose account you created, a service you still use: none of those are data brokers, so DROP leaves them running. To stop those, you still unsubscribe from each one, and under CAN-SPAM the sender has 10 business days to comply.
Two habits close the rest of the gap. First, switch on Global Privacy Control, a browser signal that tells sites not to sell or share your data, which California and about a dozen other states legally require businesses to honor. Second, clear the marketing lists you are already on, because every sender you remove is one less company keeping your address priced as live inventory.
Doing that across years of senders by hand is the tedious part. Email Unsubscriber scans your Gmail or Outlook in your own browser, lists every subscription sender, and fires the real one-click opt-out where the sender supports it. The scan runs on your device, and we never read, analyze, or monetize your email content. It is a one-off payment with nothing to cancel. DROP handles the brokers; this handles the inbox.
