California data privacy and data broker removal
California gives residents more control over their personal data than any other state, including a free state tool that deletes your information from every registered data broker in a single request.
Your rights in California
California residents are protected by the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020.
- Right to access and know. Request a copy of the personal information a company holds about you.
- Right to delete. Ask a company to delete your personal information.
- Right to correct. Request fixes to inaccurate personal information.
- Right to opt out of sale. Tell a company to stop selling your personal information.
- Right to opt out of sharing. Stop companies from sharing your data for targeted advertising.
- Right to limit sensitive data use. Restrict how companies use your most sensitive data.
- Right to data portability. Get your data in a portable format you can take elsewhere.
- Right to appeal automated decisions. Opt out of significant decisions made about you by algorithm, and ask for human review.
- Non-discrimination. Companies can't penalize you for using these rights.
Does this cover the company that has my data?
Only larger companies are covered. A business must follow the law if it does business in California and meets any one of these thresholds:
- At least $25 million in annual gross revenue (adjusted yearly for inflation).
- Buys, sells, or shares the personal information of 100,000 or more California residents or households a year.
- Earns 50% or more of its annual revenue from selling or sharing personal information.
- DROP went live for consumers on January 1, 2026. Brokers must process deletions every 45 days starting August 1, 2026. First independent audits begin January 1, 2028.
- SB 361 (2025) expanded what brokers must disclose.
- AB 45 reproductive-health-data protections took effect January 1, 2026.
- New CCPA rules on risk assessments, cybersecurity audits, and automated decision-making phase in from January 1, 2026; the automated-decision opt-out starts January 1, 2027.
- AB 566, the Opt Me Out Act, requires browsers to offer opt-out signals by January 1, 2027.
How to remove yourself from data brokers in California
California gives you more tools than most states. Here's how to use them, strongest first.
1. Use DROP: one request covers every registered broker
This is the strongest removal tool available to any US consumer. California's DROP (the Delete Request and Opt-out Platform) lets you submit one verified request that directs every registered data broker to delete your personal information. It's free, state-run, and went live January 1, 2026.
DROP only covers brokers registered in California, and only California residents can use it. Many brokers operate nationally without registering. That gap is where the remaining steps, and services like Delist, come in.
2. Turn on Global Privacy Control
Global Privacy Control is a free browser setting that tells every site you visit not to sell or share your data. It takes about two minutes to turn on and works quietly on every site. California law requires covered businesses to honor it, so it carries legal weight, not just a polite request.
3. File direct opt-out requests
For brokers the registry and GPC don't reach, you can file directly. Look for the "Do not sell my personal information" link in a company's website footer, or send a formal access, deletion, or correction request through its privacy policy page.
Covered companies must respond within the legal deadline. If they don't, you can file a complaint with the California Privacy Protection Agency or the Attorney General.
4. Automate ongoing removal
Here's the part most guides skip: even after you finish every step above, brokers pull your information back in from public records, data-sharing networks, and commercial databases. Within a few months, your profiles reappear. Staying removed isn't a one-time task. It's ongoing work that's hard to keep up with by hand.
Delist finds where your information is exposed and files the removals for you, then runs a full scan every month so it stays down. Start with a free scan to see where you show up.
Run a free scan →California's data broker law: what it means for you
California has the strongest data-broker law in the country. The Delete Act (SB 362, 2023) requires every data broker to register with the state, and gives you a free, one-request deletion tool (DROP) that reaches all of them.
Here's what the law actually requires:
- Brokers must register with the state every year by January 31. The 2026 registration fee is $6,000 plus a payment-processing fee.
- The state keeps a public registry of every broker at cppa.ca.gov, so anyone can see who's collecting and selling personal information.
- Missing the January 31 deadline costs $200 per day, plus the state's investigation costs.
- The state now runs a dedicated data-broker enforcement effort. It reached a $55,400 settlement with one broker, and has sought a penalty of up to $46,000 against another (National Public Data) for registering late.
Other privacy protections in California
Beyond the comprehensive privacy law, California has additional protections that may apply to you:
- Safe at Home, an address-confidentiality program for survivors of domestic violence, stalking, sexual assault, and related threats, run by the California Secretary of State.
- AB 45 (2025, effective January 1, 2026) limits collecting and using personal data near reproductive-health facilities and bans certain location tracking.
- Strong protections for minors. Companies need opt-in consent to sell or share the personal information of anyone under 16, and parental consent for anyone under 13.
- The Confidentiality of Medical Information Act protects your medical information.
- California has no standalone judge-protection law, though the federal Daniel Anderl Act protects federal judges nationwide.
- Biometric data. California has no standalone biometric-privacy law with a private right of action. Biometric information is treated as sensitive personal information under the CCPA and enforced by the state, unlike Illinois, where residents can sue directly.
How to file a privacy complaint in California
File with the California Privacy Protection Agency at cppa.ca.gov (consumer complaint portal), or the California Attorney General at oag.ca.gov/privacy/ccpa.
Most state agencies enforce privacy law in the aggregate, investigating patterns of violations rather than settling individual disputes. Filing still matters: your complaint creates a record that can trigger enforcement.
Frequently asked questions
Does California have a data privacy law?
Can I sue a company for violating my privacy in California?
How do I opt out of data brokers in California?
Does California require websites to honor Global Privacy Control?
Is there a data broker registry in California?
What is DROP and how do I use it?
Sources
This page is privacy-rights information, not legal advice. Privacy law changes often; confirm current rules with your state privacy agency or a licensed attorney before acting. Last verified July 13, 2026. We re-check state privacy laws quarterly.