Blog · California DROP

How to log in to DROP and get your API key

Where the DROP portal lives, how to get into it, and how to generate the API key you need to automate downloads.

Updated October 5, 2026 · Purgepath

Short version

Where is the DROP data broker login?

Brokers sign in at databroker.drop.privacy.ca.gov. Most search results point to the consumer DROP pages, where Californians submit deletion requests. Brokers use a separate portal.

If you don't have an account yet, create one from the same portal. CalPrivacy reviews new accounts and usually approves them within two business days, by email.

Who can have an account?

Only businesses operating as data brokers. Each broker gets one account, and the account is tied to the broker itself. Under the regulations, you also have to:

That's § 7610(a)(1) of the DROP regulations. It matters when you bring in engineers, contractors or vendors: they should be acting on your behalf, under your account.

Step 1: choose your consumer deletion lists

DROP splits requests into lists by identifier type: email, phone, name with date of birth and ZIP code, and so on. You select the lists that match the identifiers you actually hold.

  1. Sign in and go to Home → Consumer Deletion Lists.
  2. Select every list that matches data in your records, then click Save.

Two rules to know. You can only drop a list if another list you've selected would match exactly the same consumers. And you can only change your selection once every 45 days (§ 7611), so get it right the first time.

Step 2: generate a production API key

  1. Open the API Key tab.
  2. Click Get a new API key.
  3. Store it somewhere safe, like a secrets manager. Don't paste it into scripts or shared docs.

Every request sends the key in a header:

X-API-KEY: your-api-key-here

The production base URL is https://api.drop.privacy.ca.gov. Keys are scoped to the lists you selected in step 1. If you change your list selection, or think a key leaked, generate a new one.

Step 3: get a sandbox key for testing

In the same portal, go to SANDBOX ENVIRONMENT → ISSUE SANDBOX API KEY. There's no separate signup. The sandbox base URL is https://api.drop.privacy.ca.gov/sandbox. Build and test there before you touch production.

CalPrivacy also publishes the full API definition as an OpenAPI file, covering the download, upload and amend endpoints.

What the key lets you do

You have to download at least once every 45 days. If your automated connection fails and it isn't your fault, you still have to download manually through the portal, and tell CalPrivacy about the failure within 45 days of your last access (§ 7612).

Common snags

Check every record against DROP with one API call

Purgepath keeps your DROP list current daily and tells you exactly what to delete. Unlimited scrubs by API or CSV upload, $500/month.

Sources

This article is general information as of October 5, 2026, not legal advice. Rules and fees can change; check the sources above and talk to counsel about your situation.