On August 1, California moved a remarkable privacy promise from theory to its first real test. More than 325,000 residents had already used the state's Delete Request and Opt-Out Platform, or DROP, by July 10, sending a single request intended to reach more than 600 active data brokers. Those companies must now begin matching the requests to their records and deleting non-exempt personal information.
The short answer is that DROP could become the most important consumer privacy tool in the country, but clicking one button cannot prove that a hidden database changed. California has solved the exhaustion problem: people no longer have to find and negotiate with hundreds of companies individually. It has not yet solved the proof problem. A deletion right is credible only when regulators can verify what disappeared, explain what was exempted and punish companies that treat silence as compliance.
The old privacy bargain was designed to wear people down
Before DROP, California residents already had legal rights to ask many companies to delete or stop selling their information. The practical burden remained on the consumer. Each broker could present a different form, verification demand, vocabulary and response process. People first had to discover companies they might never have heard of, then persuade those companies to locate information collected without a direct relationship.
Two recent research projects show why centralization matters. In a May 2026 empirical study of California's broker registry, researchers reported that only 9% of 522 registered brokers fully complied with transparency requirements. Their audit of 250 request processes found that 43% made at least one privacy right impossible to exercise and 64% introduced substantial friction. A separate July study used synthetic consumer identities to send opt-out and deletion requests across the registered broker ecosystem. The researchers said most brokers appeared compliant, but a significant share did not reply or acknowledge requests, while some demanded intrusive identity verification.
Those findings do not prove brokers will defy DROP. The centralized system changes the mechanics substantially. They do establish the right question for the first months of operation: not whether the portal accepts a request, but whether the industry produces trustworthy, reviewable results.
DROP shifts the work to the companies that hold the data
California's system converts the information a consumer submits into protected, hashed values. Brokers standardize and hash their own records, then compare the two sets rather than receiving a consumer's raw entries through DROP. A match should trigger deletion of non-exempt data held by the broker and its service providers or contractors.
The law creates an ongoing obligation, not a one-time cleanup. Brokers must access DROP at least once every 45 days. After a successful deletion, they must keep deleting newly collected information on a rolling basis and may not resume selling or sharing it unless an exception applies or the consumer changes the request. If a broker cannot verify a deletion request, it generally must treat the request as an opt-out from sale or sharing instead of doing nothing.
Consumers will see statuses such as deleted, exempted, opted out, not found or pending. The California Privacy Protection Agency, known as CalPrivacy, warns that updates may take as long as 90 days to appear. That delay is not automatically evidence of misconduct: a broker can take up to 45 days to retrieve a batch and then has a processing window. It does mean the first meaningful public assessment should focus on the quality and distribution of those statuses after the initial cycles, not on opening-day screenshots.
A status label is the beginning of accountability, not the end

A consumer cannot inspect a broker's production databases, contractor systems or future data purchases. The words record deleted therefore represent a claim by the regulated company. To make that claim trustworthy, CalPrivacy should publish aggregate results that reveal how often brokers report deletion, exemption, failed matching and prolonged pending status without exposing individual users.
Regulators should also look for outliers. A broker that reports almost no matches may genuinely hold little information about the people who applied. It may also have poor matching practices. A company invoking exemptions far more often than its peers may have a defensible business reason, or it may be stretching an exception. Aggregate comparisons will not prove a violation, but they can tell investigators where to ask harder questions.
The need for scrutiny is not hypothetical. A February 2026 minority staff report from Congress's Joint Economic Committee examined five registered brokers after reporting showed that opt-out pages had been hidden from search engines with “no index” code. Four companies made their privacy controls more accessible after scrutiny; one did not respond to the committee's requests, according to the report. Of the five, only 6sense told the committee that it used audits covering both the visibility of its controls and the success rates of requests.
The same report estimated that identity theft linked to four major data-broker breaches produced $20.9 billion in consumer losses. That number is a committee staff estimate built from reported breach populations, assumed identity-theft rates and median losses—not a direct accounting of every dollar. Even with that caveat, it illustrates why deletion is more than a preference about advertising. Data that no longer needs to exist cannot be stolen in the next breach.
The strongest counterpoint deserves an answer
Matching and deletion are technically difficult. People change phone numbers, use multiple email addresses and share household identifiers. A false match could erase another person's information, while aggressive deletion could conflict with fraud prevention, legal retention requirements or other recognized exceptions. Brokers deserve clear technical rules and a fair chance to complete the first processing cycle before being accused of failure.
But complexity is an argument for measurable standards, not for private self-certification. California has already given brokers a common exchange, formal status categories and recurring deadlines. Independent audits required by the law do not begin until 2028 and then occur every three years. During the gap, enforcement should rely on system logs, anomaly analysis, targeted testing and complaints rather than waiting for the audit calendar.
What consumers can do now
- Use the official portal. California residents can submit a free request at privacy.ca.gov/drop. Avoid look-alike services that ask for payment.
- Keep the DROP ID. It is needed to check results. Expect some requests to remain pending during the first processing cycles.
- Balance matching against disclosure. Optional identifiers can improve the chance of finding records, but consumers should read the state's explanation and provide only information they are comfortable using for that purpose.
- Document persistent problems. Save dates and status details without publishing sensitive identifiers. Californians who believe their privacy rights were violated can use CalPrivacy's complaint form.
Bottom line
DROP deserves to succeed because it reverses an unfair bargain: the people who profit from assembling personal information should carry the labor of finding and deleting it. The portal is an impressive beginning. The real achievement will come when a consumer can click delete, receive an intelligible result and trust that a regulator—not merely the broker—can prove what happened next.