California data privacy and data broker removal
California gives residents a broad set of privacy rights, including a free state platform that sends one deletion request to data brokers registered with the state.
At a glance
- Comprehensive privacy law? Yes. California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (CCPA/CPRA)
- In effect since Jan 1, 2020
- Your core rights Access & Know, Delete, Correct, Opt Out of Sale +3 more
- Honors Global Privacy Control? Yes
- Data-broker registry? Yes
- Can you sue? (private right of action) Limited (data breaches only)
- Enforced by California Privacy Protection Agency + Attorney General
What Delist can do for you in California
California recognizes an authorized agent under the California Consumer Privacy Act (CCPA), as amended by the CPRA. When you authorize Delist, we file opt-out requests as your agent, and a data broker covered by the law is required to act on them once it verifies the request.
California also lets your agent file deletion requests. We file them two ways for you: through the state's DROP platform for registered data brokers, and directly with each business under the California Consumer Privacy Act (CCPA), as amended by the CPRA.
Basis: Cal. Civ. Code § 1798.135 (CCPA); § 1798.99.86 (Delete Act / DROP). Reviewed September 1, 2026. How the three groups work: our authorized-agent framework.
Your rights in California
California residents are protected by the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020.
- Right to access and know. Request a copy of the personal information a company holds about you.
- Right to delete. Ask a company to delete your personal information.
- Right to correct. Request fixes to inaccurate personal information.
- Right to opt out of sale. Tell a company to stop selling your personal information.
- Right to opt out of sharing. Stop companies from sharing your data for targeted advertising.
- Right to limit sensitive data use. Restrict how companies use your most sensitive data.
- Right to data portability. Get your data in a portable format you can take elsewhere.
- Right to appeal automated decisions. Opt out of significant decisions made about you by algorithm, and ask for human review.
- Non-discrimination. Companies can't penalize you for using these rights.
Does this cover the company that has my data?
Only larger companies are covered. A business must follow the law if it does business in California and meets any one of these thresholds:
- At least $25 million in annual gross revenue (adjusted yearly for inflation).
- Buys, sells, or shares the personal information of 100,000 or more California residents or households a year.
- Earns 50% or more of its annual revenue from selling or sharing personal information.
- DROP went live for consumers on January 1, 2026. Since August 1, 2026, brokers must access DROP at least every 45 days and process applicable requests. First independent audits begin January 1, 2028.
- SB 361 (2025) expanded what brokers must disclose.
- AB 45 reproductive-health-data protections took effect January 1, 2026.
- New CCPA rules on risk assessments, cybersecurity audits, and automated decision-making phase in from January 1, 2026; the automated-decision opt-out starts January 1, 2027.
- AB 566, the Opt Me Out Act, requires browsers to offer opt-out signals by January 1, 2027.
How to remove yourself from data brokers in California
California gives you more tools than most states. Here's how to use them, strongest first.
1. Use DROP: one request reaches registered brokers
California's DROP (the Delete Request and Opt-out Platform) lets an eligible California resident submit one verified request for data brokers registered with the state. It's free, state-run, and went live January 1, 2026. Brokers must process applicable requests subject to the Delete Act, its regulations, and permitted exceptions.
DROP is for eligible California residents and applies to data brokers required to register with California. It does not remove information from every website, search engine, public record, or organization outside that scope.
2. Turn on Global Privacy Control
Global Privacy Control is a free browser signal that communicates a request not to sell or share your data. California requires covered businesses to treat a valid signal as a request to opt out of sale or sharing, subject to the law and regulations.
3. File direct opt-out requests
For brokers the registry and GPC don't reach, you can file directly. Look for the "Do not sell my personal information" link in a company's website footer, or send a formal access, deletion, or correction request through its privacy policy page.
Covered companies must respond within the legal deadline. If they don't, you can file a complaint with the California Privacy Protection Agency or the Attorney General.
4. Automate ongoing removal
A broker may later ingest a new record from public records, data-sharing networks, or commercial databases. Re-listing timing varies by broker and source, so periodic checks matter.
Delist finds where your information is exposed and files the removals for you, then runs a full scan every month so it stays down. Start with a free scan to see where you show up.
Run a free scan →California's data broker law: what it means for you
California's Delete Act (SB 362, 2023) created DROP, a free one-request deletion tool for eligible California residents that applies to data brokers required to register with the state. Statutory exemptions and broker compliance still matter.
Here's what the law actually requires:
- Covered brokers must register with the state annually and provide required disclosures.
- The state keeps a public registry of every broker at cppa.ca.gov, so anyone can see who's collecting and selling personal information.
- Missing the January 31 deadline costs $200 per day, plus the state's investigation costs.
- The California Privacy Protection Agency can enforce registration and Delete Act obligations.
Other privacy protections in California
Beyond the comprehensive privacy law, California has additional protections that may apply to you:
- Safe at Home, an address-confidentiality program for survivors of domestic violence, stalking, sexual assault, and related threats, run by the California Secretary of State.
- AB 45 (2025, effective January 1, 2026) limits collecting and using personal data near reproductive-health facilities and bans certain location tracking.
- Strong protections for minors. Companies need opt-in consent to sell or share the personal information of anyone under 16, and parental consent for anyone under 13.
- The Confidentiality of Medical Information Act protects your medical information.
- California has no standalone judge-protection law, though the federal Daniel Anderl Act protects federal judges nationwide.
- Biometric data. California has no standalone biometric-privacy law with a private right of action. Biometric information is treated as sensitive personal information under the CCPA and enforced by the state, unlike Illinois, where residents can sue directly.
How to file a privacy complaint in California
File with the California Privacy Protection Agency at cppa.ca.gov (consumer complaint portal), or the California Attorney General at oag.ca.gov/privacy/ccpa.
Most state agencies enforce privacy law in the aggregate, investigating patterns of violations rather than settling individual disputes. Filing still matters: your complaint creates a record that can trigger enforcement.
Frequently asked questions
Does California have a data privacy law?
Yes. California residents are protected by the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (CCPA/CPRA), which gives you rights to access, delete, and control your personal data.
Can I sue a company for violating my privacy in California?
Only for data breaches. California allows lawsuits for data breaches but general privacy violations are enforced by the state agency, not individual litigation.
How do I opt out of data brokers in California?
Check the state's data-broker registry, turn on Global Privacy Control in your browser, and file direct opt-out requests. Services like Delist can file these for you and keep watching as your information reappears.
Does California require websites to honor Global Privacy Control?
Yes. California law requires covered businesses to treat Global Privacy Control as a valid opt-out request. Enable it in your browser for automatic protection.
Is there a data broker registry in California?
Yes. California requires data brokers to register with the state. The public registry lets you see which brokers are collecting and selling personal information.
What is DROP and how do I use it?
DROP is California's free Delete Request and Opt-out Platform. An eligible California resident can submit one verified request for registered data brokers to process under the Delete Act and its regulations. It launched January 1, 2026 at privacy.ca.gov; brokers began processing applicable requests on August 1, 2026.
Sources
This page is privacy-rights information, not legal advice. Privacy law changes often; confirm current rules with your state privacy agency or a licensed attorney before acting. Last verified July 13, 2026. We re-check state privacy laws quarterly.