Drop45 › DROP guides

What is the California DROP program?

DROP stands for Delete Request and Opt-Out Platform. It is the state-run system through which every registered California data broker receives and processes consumer deletion requests. This guide covers DROP for data brokers — the processing side. If you are a California resident who wants your own data deleted, privacy.ca.gov/drop is the consumer platform you want.

What DROP is

DROP is the Delete Request and Opt-Out Platform, built and run by the California Privacy Protection Agency (CalPrivacy, also written CPPA). It exists so a California resident can make one deletion request instead of chasing hundreds of companies individually.

Consumers submit through the California DROP website; brokers collect those requests from the data broker portal in the same system. CalPrivacy calls that second half DROP for data brokers, and it is the only half this guide is about. The platform was required by SB 362, the Delete Act, and CalPrivacy had to have it running by January 1, 2026 (Civ. Code § 1798.99.86(a)).

The dates that matter

WhenWhat happens
January 2026Consumers can submit DROP requests. Brokers create DROP accounts and register where applicable.
March 2026DROP Sandbox opens — a test environment for validating your hashing and integration against fake data.
August 1, 2026Brokers must begin processing requests, and consumers start seeing status updates.

The 45-day cycle

From August 1, 2026 a data broker must access DROP at least once every 45 calendar days. The clock starts when you download a list, and you then have up to 45 days to finish the cycle. Four steps repeat forever:

  1. Download your selected consumer deletion list or lists, by API or manually in DROP. After the first download you only receive new or amended requests.
  2. Standardize and hash your own records — lowercase text, strip special characters, apply the date, phone and ZIP formatting rules, and follow the concatenation protocol for the multi-identifier lists.
  3. Match and process. Delete all non-exempt personal information for every match, and direct your service providers and contractors to do the same. Where several consumers share one matched identifier, opt them all out of sale and sharing instead.
  4. Report a status for every request, within 45 days of downloading it.

If your automated connection to DROP fails, you must tell CalPrivacy in writing through your DROP account within 45 days (Cal. Code Regs., tit. 11 § 7612(b)(1)).

The six consumer deletion lists

DROP publishes hashed identifiers across six lists:

You must select every list whose identifiers could match consumers in your records. You may select fewer only where the extra lists would match the exact same set of consumers — for example, if you hold both an email address and a phone number for every consumer, one of the two is enough (Cal. Code Regs., tit. 11 § 7610(a)(3)).

The four statuses you report back

The ongoing duty people miss

A "Not found" is not the end of it. You must keep a list of everyone who has submitted a DROP request and screen newly collected records against it before selling or sharing them. A deletion request is a standing instruction, not a one-time event.

A 45-day cycle checklist

  1. Download the current list(s) — note the download date, it starts your clock.
  2. Export your consumer records with the identifiers your selected lists use.
  3. Standardize and hash, then match against the DROP hashes.
  4. Delete or opt out every match, and instruct service providers and contractors.
  5. Build the Id,Status response file and upload it inside 45 days.
  6. Add every requesting consumer to your ongoing suppression list.
  7. Keep evidence of what you ran, when, and against how many records.

Drop45 does the matching half of this. Upload a DROP consumer deletion list and your own records; standardization, SHA-256 hashing and matching all run in your browser, so consumer data never leaves your machine. Free for up to 500 records per run.

Run a match now — free