California data privacy and data broker removal

By Updated Corrections

California gives residents a broad set of privacy rights, including a free state platform that sends one deletion request to data brokers registered with the state.

At a glance

  • Comprehensive privacy law? Yes. California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (CCPA/CPRA)
  • In effect since Jan 1, 2020
  • Your core rights Access & Know, Delete, Correct, Opt Out of Sale +3 more
  • Honors Global Privacy Control? Yes
  • Data-broker registry? Yes
  • Can you sue? (private right of action) Limited (data breaches only)
  • Enforced by California Privacy Protection Agency + Attorney General

Last verified July 2026 · Reviewed quarterly

What Delist can do for you in California

California recognizes an authorized agent under the California Consumer Privacy Act (CCPA), as amended by the CPRA. When you authorize Delist, we file opt-out requests as your agent, and a data broker covered by the law is required to act on them once it verifies the request.

California also lets your agent file deletion requests. We file them two ways for you: through the state's DROP platform for registered data brokers, and directly with each business under the California Consumer Privacy Act (CCPA), as amended by the CPRA.

Basis: Cal. Civ. Code § 1798.135 (CCPA); § 1798.99.86 (Delete Act / DROP). Reviewed September 1, 2026. How the three groups work: our authorized-agent framework.

Your rights in California

California residents are protected by the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020.

Sensitive data gets extra protection. You can tell companies to limit how they use your most sensitive personal information, including biometric data, precise location, health information, race or ethnicity, and sexual orientation. That's a higher bar than the standard opt-out that applies to other data.

Does this cover the company that has my data?

Only larger companies are covered. A business must follow the law if it does business in California and meets any one of these thresholds:

What's changing.
  • DROP went live for consumers on January 1, 2026. Since August 1, 2026, brokers must access DROP at least every 45 days and process applicable requests. First independent audits begin January 1, 2028.
  • SB 361 (2025) expanded what brokers must disclose.
  • AB 45 reproductive-health-data protections took effect January 1, 2026.
  • New CCPA rules on risk assessments, cybersecurity audits, and automated decision-making phase in from January 1, 2026; the automated-decision opt-out starts January 1, 2027.
  • AB 566, the Opt Me Out Act, requires browsers to offer opt-out signals by January 1, 2027.

How to remove yourself from data brokers in California

California gives you more tools than most states. Here's how to use them, strongest first.

1. Use DROP: one request reaches registered brokers

California's DROP (the Delete Request and Opt-out Platform) lets an eligible California resident submit one verified request for data brokers registered with the state. It's free, state-run, and went live January 1, 2026. Brokers must process applicable requests subject to the Delete Act, its regulations, and permitted exceptions.

Submit your DROP request at privacy.ca.gov. Since August 1, 2026, registered brokers must access DROP at least every 45 days, process applicable requests, and report status under the Delete Act and implementing regulations.

DROP is for eligible California residents and applies to data brokers required to register with California. It does not remove information from every website, search engine, public record, or organization outside that scope.

2. Turn on Global Privacy Control

Global Privacy Control is a free browser signal that communicates a request not to sell or share your data. California requires covered businesses to treat a valid signal as a request to opt out of sale or sharing, subject to the law and regulations.

3. File direct opt-out requests

For brokers the registry and GPC don't reach, you can file directly. Look for the "Do not sell my personal information" link in a company's website footer, or send a formal access, deletion, or correction request through its privacy policy page.

Covered companies must respond within the legal deadline. If they don't, you can file a complaint with the California Privacy Protection Agency or the Attorney General.

4. Automate ongoing removal

A broker may later ingest a new record from public records, data-sharing networks, or commercial databases. Re-listing timing varies by broker and source, so periodic checks matter.

Delist finds where your information is exposed and files the removals for you, then runs a full scan every month so it stays down. Start with a free scan to see where you show up.

Run a free scan

California's data broker law: what it means for you

California's Delete Act (SB 362, 2023) created DROP, a free one-request deletion tool for eligible California residents that applies to data brokers required to register with the state. Statutory exemptions and broker compliance still matter.

Here's what the law actually requires:

What the registry is, and what it isn't. The registry makes covered brokers identify themselves publicly. DROP goes further by distributing a verified request to registered brokers for processing. It does not guarantee deletion of data that falls outside the law or a permitted exception.

Other privacy protections in California

Beyond the comprehensive privacy law, California has additional protections that may apply to you:

How to file a privacy complaint in California

File with the California Privacy Protection Agency at cppa.ca.gov (consumer complaint portal), or the California Attorney General at oag.ca.gov/privacy/ccpa.

Most state agencies enforce privacy law in the aggregate, investigating patterns of violations rather than settling individual disputes. Filing still matters: your complaint creates a record that can trigger enforcement.

Frequently asked questions

Does California have a data privacy law?

Yes. California residents are protected by the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (CCPA/CPRA), which gives you rights to access, delete, and control your personal data.

Can I sue a company for violating my privacy in California?

Only for data breaches. California allows lawsuits for data breaches but general privacy violations are enforced by the state agency, not individual litigation.

How do I opt out of data brokers in California?

Check the state's data-broker registry, turn on Global Privacy Control in your browser, and file direct opt-out requests. Services like Delist can file these for you and keep watching as your information reappears.

Does California require websites to honor Global Privacy Control?

Yes. California law requires covered businesses to treat Global Privacy Control as a valid opt-out request. Enable it in your browser for automatic protection.

Is there a data broker registry in California?

Yes. California requires data brokers to register with the state. The public registry lets you see which brokers are collecting and selling personal information.

What is DROP and how do I use it?

DROP is California's free Delete Request and Opt-out Platform. An eligible California resident can submit one verified request for registered data brokers to process under the Delete Act and its regulations. It launched January 1, 2026 at privacy.ca.gov; brokers began processing applicable requests on August 1, 2026.

This page is privacy-rights information, not legal advice. Privacy law changes often; confirm current rules with your state privacy agency or a licensed attorney before acting. Last verified July 13, 2026. We re-check state privacy laws quarterly.

Take back your privacy in California

Delist finds where your information is exposed and files the removals for you, then runs a full scan every month so it stays down.

Run a free scan