essay / 2026 / california + privacy Deletion-request forms, hashed identifier worksheets, broker registry binders, status stamps, and sealed records fill a California privacy compliance archive table.

editorial object

California Turned Privacy Deletion Into Public Infrastructure

DROP replaces hundreds of broker-by-broker opt-outs with a state-run request ledger, hashed identifier lists, status reporting, and a duty to keep deleted people out of future data sales.

California has activated a machine for deleting people from the data-broker economy. One request through the state’s Delete Request and Opt-out Platform, called DROP, can reach more than 600 registered brokers. Since August 1, those brokers have been legally required to retrieve requests, match them against their records, erase the associated personal information and inferences, suppress future sales, and report what happened.

The useful development is the shape of the system. Privacy law usually hands a person a right and leaves them to discover which companies hold their data, locate hundreds of hostile forms, prove their identity repeatedly, and chase every silent inbox. DROP centralises the request while keeping execution distributed across the companies that built the dossiers.

one request becomes a recurring obligation

The public DROP site verifies California residency through the California Identity Gateway or Login.gov. A resident then creates a profile containing the identifiers brokers can use for matching: name, birth date, ZIP code, phone numbers, email addresses and optional device, connected-TV or vehicle identifiers. The person chooses how much to provide. More identifiers increase the chance of a match.

DROP turns that profile into broker-facing deletion lists. The final regulations define those lists as hashed identifiers paired with a transaction ID and the hashing algorithm. Brokers select every list corresponding to identifiers they hold, retrieve new or amended requests at least once every 45 days, and run the hashes against their own records.

A match reaches beyond the original email address or phone number. The broker has to delete personal information associated with that identifier, including inferences built from it, unless an exemption applies. That can cover location histories, purchase segments, health assumptions, household links, predicted interests and the scores produced from those records. The request also acts as an opt-out from future sale or sharing. A broker cannot solve the problem by deleting today’s row and rebuilding the same person from tomorrow’s feed.

the state built a control plane for absence

Deletion sounds like a database operation. Broker systems make it a routing problem. One company may keep identity records in a warehouse, advertising segments in a customer platform, event trails in object storage, audience exports in partner systems and inferred attributes in a model pipeline. Vendors and downstream recipients may hold further copies.

The regulation forces each broker to build an inventory and execution path across that mess. It must retrieve the relevant request lists, normalise its identifiers, locate matching records, propagate deletion to service providers and contractors, apply suppression, preserve an audit trail, and send a status back to CalPrivacy. Possible outcomes include deletion, opt-out, exemption or record not found.

This is public infrastructure in a precise sense. California supplies identity eligibility, a registry, a request ledger, a delivery mechanism, status semantics and enforcement. Private firms remain responsible for mapping the request into their own data systems. The state does not need a copy of every dossier. It needs enough protocol to make every registered broker answer the same command.

The regulations address that paradox directly. Brokers must maintain a list of deletion requests so the covered information stays deleted. Information supplied through DROP can only be used to comply with the deletion law. Selling or sharing it is prohibited. Brokers cannot contact a consumer to demand another verification ritual. They must protect the request data and report account or platform-related breaches.

That boundary matters because a central deletion service necessarily creates a sensitive directory of people who want out. DROP reduces exposure by sending hashed identifiers in broker-specific lists rather than publishing a readable master file. The architecture still concentrates authority. Account security, matching quality, broker registration and audit work decide whether the system deletes dossiers or merely produces immaculate status codes.

enforcement replaces privacy-page theatre

CalPrivacy’s implementation announcement says brokers must access DROP every 45 days and report the status of each request after retrieval. The consumer service gives brokers up to 90 days to complete deletion. The law attaches a $200-per-request, per-day penalty to failures, according to the Associated Press.

Those numbers change the economics. A buried opt-out page can absorb individual complaints as customer-support debris. A state ledger can produce a visible backlog, standard outcomes and fines that compound across requests. The broker now needs a functioning deletion pipeline before the queue arrives.

the blind spots remain expensive

DROP only reaches brokers registered in California. A company that avoids registration, misclassifies itself or sits inside a legal exemption can escape the main pipeline until enforcement catches up. Public records, credit-reporting data and other exempt categories remain outside parts of the deletion duty. The system also governs deletion and sale more aggressively than initial collection. Data can continue entering the market before the request suppresses it.

Matching creates another hard edge. People with stable email addresses and phone numbers are easier to find. People whose data was misspelled, pseudonymised, attached to old addresses or fused into household graphs may receive “record not found” while the broker still holds a shadow of them. Providing more identifiers improves deletion and increases the sensitivity of the request itself. That trade belongs in audits, error reviews and enforcement metrics, rather than being dumped back on the resident.

California has still crossed an important line. It has treated privacy execution as a shared service instead of a scavenger hunt. The strongest part of DROP is ordinary machinery: one intake, a verified scope, standard request objects, scheduled retrieval, durable suppression, named outcomes and penalties for silence. Rights survive contact with industry when somebody builds the control plane.