California privacy rights: deletion, opt-outs and DROP

Use California privacy rights and DROP accurately: choose a request, verify with minimal data, track deadlines, and understand exemptions.

Lena OrtizUpdated 9 min read

Quick answer

Quick answer to California privacy rights: deletion, opt-outs and DROP

A California resident can ask a covered business to know, delete, or correct covered personal information, opt out of covered sale or sharing, and limit certain sensitive-data use. Submit the specific request through the business's official privacy route, provide only information needed for verification, and track the response. Use the free DROP system separately to send one deletion and sale opt-out request to active data brokers registered with CalPrivacy, then inspect each broker's status and exceptions.

  • California's know, delete, correct, opt-out, limit, and equal-treatment rights are distinct remedies—not one universal deletion command.
  • CalPrivacy says covered businesses should respond within 45 days, while DROP brokers may take up to 90 days to report processing.
  • DROP can return deleted, exempted, opted-out, record-not-found, or pending; none should be interpreted beyond its defined scope.

Topics: California privacy rights · CCPA · California DROP · Data-broker deletion

California residents have several distinct privacy rights under the California Consumer Privacy Act, plus a statewide deletion mechanism for registered data brokers. The practical route is to choose the right request—know, delete, correct, opt out, or limit—send it through the business's official privacy channel, save the response, and use DROP for the registered-broker layer.

This guide reflects official CalPrivacy guidance checked on 14 August 2026. It is general information, not legal advice, and it does not claim that every business, record, or person is covered.

The California rights are not one delete button

CalPrivacy summarizes the core CCPA rights as LOCKED:

| Right | What it addresses | | --- | --- | | Limit | Limit covered use and disclosure of sensitive personal information | | Opt out | Stop covered sale or sharing for cross-context behavioural advertising | | Correct | Correct inaccurate personal information a covered business holds | | Know | Learn what personal information is collected, used, and shared | | Equal treatment | Exercise rights without unlawful discrimination | | Delete | Ask a covered business to delete covered personal information, subject to exceptions |

Choose the remedy that matches the problem. If a company has the wrong address, a correction request may preserve a necessary account while fixing the risk. If you want it to stop selling covered data, an opt-out is not the same as closing the account. If you need to understand what exists first, begin with a know request.

Check the business and data in scope

The CCPA applies to covered businesses, not every person, nonprofit, government office, or record. Other state and federal laws can govern financial, health, credit, employment, education, communications, and public-sector information. Public records and other categories can also be exempt from a particular deletion mechanism.

Use the business's current privacy notice and CalPrivacy's guidance to determine which route it offers. For a difficult case, contested exception, or safety issue, consult a qualified California lawyer or an appropriate advocate.

Submit a request to a covered business

CalPrivacy's current consumer workflow is:

  1. Find the official privacy channel. Look for Privacy Policy, Do Not Sell or Share My Personal Information, Your California Privacy Choices, or similar language on the business's site.
  2. Select the right. State whether you want to know, delete, correct, opt out, or limit covered processing. A single message can be ambiguous; name each requested action.
  3. Provide only necessary matching information. A business may need to verify identity. CalPrivacy says you need provide only what it needs to complete the request and offers a complaint route if it demands excessive information.
  4. Save the evidence. Record the request URL, date, confirmation, case number, scope, and information you supplied.
  5. Track the response. CalPrivacy says businesses should respond within 45 days and may contact you if they need additional time.

Each business is normally a separate request. A deletion request to a retailer, for example, does not automatically reach an unrelated broker that obtained the same identifier elsewhere.

If the business ignores the request or you believe it did not follow the law, use the California Privacy Protection Agency's official complaint route. A complaint is stronger when it includes the exact request, confirmation, dates, response, and unresolved issue.

Use DROP for registered data brokers

The Delete Request and Opt-out Platform is a separate, free mechanism for California residents. It sends one request to active data brokers registered with CalPrivacy rather than requiring a manual form for every broker.

The current sequence is:

  1. verify California residency through the California Identity Gateway, with a direct information option or Login.gov
  2. create a profile with the identifiers you choose to provide
  3. submit the request and save the DROP ID
  4. return to check broker-level outcomes

Name, date of birth, and ZIP code are enough to submit. Email addresses, phone numbers, former names, mobile advertising IDs, connected-TV IDs, and VINs are optional matching signals. Adding data can improve matching, but disclose only what you are comfortable using for this official process.

DROP opened for consumer requests on 1 January 2026. Registered brokers began processing them on 1 August 2026. CalPrivacy says brokers process requests at least every 45 days and may take up to 90 days to report their result.

Interpret each DROP status accurately

| Status | What the official guidance says it can mean | | --- | --- | | Deleted | Matched covered data was deleted and will no longer be sold, while legally exempt information may remain | | Exempted | The broker says all matched data it kept is exempt, such as certain public or health-related information | | Opted-out | The broker could not make an exact match; it must stop selling information associated with the provided identifier as described by DROP | | Record not found | The broker had no responsive record or could not locate one from the submitted data | | Pending | The broker has not completed processing; it can have up to 90 days to report |

“Record not found” is not proof that the broker has never held data. “Deleted” does not mean every public record on the internet disappeared. “Exempted” is an outcome to inspect, not silently translate into compliance or non-compliance without understanding the cited basis.

You can update a DROP profile when a name, phone, email, device identifier, or vehicle changes. CalPrivacy says current and future brokers registered with the agency are included unless the consumer narrows the list, and brokers must address future matching data within the mechanism's rules.

Know what DROP does not remove

CalPrivacy identifies several boundaries. DROP does not necessarily delete:

  • information you gave directly to a business in a first-party relationship
  • publicly available information
  • information exempt under another rule or needed for a permitted purpose
  • a page from Google, Bing, a social platform, an archive, or the original public-record source

Some data may instead fall under health, financial, consumer-reporting, or other privacy laws. The CCPA also does not govern law-enforcement searches, and CalPrivacy explains that state-agency information is addressed through other protections. Use the regulator or record-holder route that fits the data.

Separate broker deletion from search-result removal

After a business or broker changes the source, search engines may still show an old result. Verify the live page first, then use Google's or Bing's outdated content route for stale snippets and vanished pages. If the personal information is still live and meets a search engine's removal policy, use that policy route instead.

Likewise, a search-engine approval does not complete a CCPA or DROP request. It reduces discovery of a URL; it does not direct the source business to delete its covered records.

Keep a California request ledger

For each request, record:

  • business or broker and its official privacy URL
  • right exercised
  • request and verification dates
  • minimum matching information provided
  • confirmation or DROP ID
  • response deadline and any extension notice
  • response and stated exception
  • complaint or appeal reference, if any
  • source, search, and broker verification dates

That ledger makes a regulator complaint, resubmission, or reappearance check specific and reproducible. Protect it carefully because it can connect several sensitive identifiers.

For the broker-by-broker layer, use the opt-out directory. For a result that remains in Google or Bing, use the search-result removal workflow.

Continue reading