California’s DROP Tool Puts 614 Data Brokers on a 45-Day Clock

California's Delete Request and Opt-out Platform lets residents send one deletion and opt-out-of-sale request to every data broker registered in the state, and brokers must start complying by August 1,…

California’s Delete Request and Opt-out Platform (DROP), created under the state’s Delete Act, went live January 1 but its real teeth arrive August 1, when the 614 data brokers currently on California’s registry must begin honoring consolidated deletion and opt-out-of-sale requests within 45 days, according to EFF Deeplinks. For an industry built on aggregating and reselling consumer profiles, that is a meaningful operational shift: instead of fielding scattered individual requests across dozens of intake channels, brokers now face a single state-run pipeline capable of routing bulk requests to their entire registered universe at once.

The compliance burden is real but bounded. EFF notes the deletion mandate reaches identifying data — Social Security numbers, geolocation, browsing history, contact details — plus inferences drawn from that data, such as health or political-view guesses, but explicitly carves out public-record information like vehicle or real-estate ownership. Brokers can also be selectively excluded from a given request if a consumer wants to preserve a relationship with a specific company. That granularity matters for data companies weighing how much engineering investment to put into DROP-specific deletion pipelines versus treating it as another CCPA-adjacent compliance line item.

Why this is bigger than California

The more consequential number for the industry may not be 614 or 45, but the fact that similar Delete Act-style bills are circulating in other statehouses, with regulators watching California’s rollout as a template, per EFF. If DROP functions smoothly, expect multistate compliance vendors to pitch unified deletion-request handling as a product category, and expect brokers to lobby hard over registry definitions — since, as EFF points out, non-registered aggregators like large ad-tech platforms fall outside DROP’s reach entirely. Watch the August 1 enforcement start date closely: how the California Privacy Protection Agency handles early non-compliance will shape whether other states move from proposal to statute.

As of time of writing, a single DROP request reaches 614 brokers. After August 1, once data brokers receive a request, they will have 45 days to address the request.

EFF Deeplinks

Read the full story at EFF Deeplinks →

The Data Commenter, in your inbox

Data markets, alt data, and the AI training-data economy. No spam, unsubscribe anytime.

Discussion lives in the inline notes attached to article passages.