How to log in to DROP and get your API key
Where the DROP portal lives, how to get into it, and how to generate the API key you need to automate downloads.
- The data broker portal is databroker.drop.privacy.ca.gov. It's separate from the consumer DROP site.
- Pick your consumer deletion lists first. API keys only cover the lists you've selected.
- API keys live under the API Key tab. Sandbox keys are in the same portal.
Where is the DROP data broker login?
Brokers sign in at databroker.drop.privacy.ca.gov. Most search results point to the consumer DROP pages, where Californians submit deletion requests. Brokers use a separate portal.
If you don't have an account yet, create one from the same portal. CalPrivacy reviews new accounts and usually approves them within two business days, by email.
Who can have an account?
Only businesses operating as data brokers. Each broker gets one account, and the account is tied to the broker itself. Under the regulations, you also have to:
- keep your credentials confidential and limit them to people authorized to act for your business;
- restrict access to DROP, and to anything derived from it, to those same people;
- tell CalPrivacy right away about any unauthorized use or security breach;
- take responsibility for everything done through your account.
That's § 7610(a)(1) of the DROP regulations. It matters when you bring in engineers, contractors or vendors: they should be acting on your behalf, under your account.
Step 1: choose your consumer deletion lists
DROP splits requests into lists by identifier type: email, phone, name with date of birth and ZIP code, and so on. You select the lists that match the identifiers you actually hold.
- Sign in and go to Home → Consumer Deletion Lists.
- Select every list that matches data in your records, then click Save.
Two rules to know. You can only drop a list if another list you've selected would match exactly the same consumers. And you can only change your selection once every 45 days (§ 7611), so get it right the first time.
Step 2: generate a production API key
- Open the API Key tab.
- Click Get a new API key.
- Store it somewhere safe, like a secrets manager. Don't paste it into scripts or shared docs.
Every request sends the key in a header:
X-API-KEY: your-api-key-here
The production base URL is https://api.drop.privacy.ca.gov. Keys are scoped to the lists you selected in step 1. If you change your list selection, or think a key leaked, generate a new one.
Step 3: get a sandbox key for testing
In the same portal, go to SANDBOX ENVIRONMENT → ISSUE SANDBOX API KEY. There's no separate signup. The sandbox base URL is https://api.drop.privacy.ca.gov/sandbox. Build and test there before you touch production.
CalPrivacy also publishes the full API definition as an OpenAPI file, covering the download, upload and amend endpoints.
What the key lets you do
- Download your deletion lists as a ZIP of CSV files. After the first full download, each download only includes new or amended requests.
- Upload the status of each request (record deleted, opted out of sale, exempted, or not found).
- Amend a status you've already reported.
You have to download at least once every 45 days. If your automated connection fails and it isn't your fault, you still have to download manually through the portal, and tell CalPrivacy about the failure within 45 days of your last access (§ 7612).
Common snags
- "I can't find the login." Use the broker portal above, not the consumer site.
- "My key doesn't return a list." Check that the list is selected and saved under Consumer Deletion Lists. Keys only see selected lists.
- "Can more than one person log in?" The account doesn't support multiple users. Share access only with people authorized to act for your business.
Check every record against DROP with one API call
Purgepath keeps your DROP list current daily and tells you exactly what to delete. Unlimited scrubs by API or CSV upload, $500/month.
Sources
This article is general information as of October 5, 2026, not legal advice. Rules and fees can change; check the sources above and talk to counsel about your situation.