FAQ

California DROP FAQ for data brokers

Short answers to the questions data brokers ask most about DROP and the Delete Act.

Updated October 8, 2026 · Purgepath

DROP basics

What is DROP?

DROP is California's Delete Request and Opt-out Platform, run by CalPrivacy. A consumer submits one deletion request, and every registered data broker has to download it and act on it.

When did data brokers have to start processing DROP requests?

August 1, 2026.

How often do data brokers have to access DROP?

At least once every 45 days. See the 45-day checklist.

How long do data brokers have to delete data after a DROP request?

Within 45 days of receiving it. After that, they have to keep deleting that consumer's data at least every 45 days and can't sell or share new data about them.

What identifiers are on a DROP deletion list?

Lists are split by identifier type, such as email, phone, and name with date of birth and ZIP code. Every value is hashed with SHA-256.

Do data brokers see raw consumer data in DROP?

No. Every identifier is hashed. Brokers hash their own records the same way and compare the hashes.

Where do data brokers log in to DROP?

At databroker.drop.privacy.ca.gov. See how to log in and get your API key.

Processing requests

What happens if a DROP request doesn't match any records?

The broker reports record not found, keeps the request, and screens newly collected data against it before selling or sharing that data.

What if one identifier matches more than one person?

The broker opts every matched consumer out of sale and sharing and reports the request as record opted out of sale.

What status codes do data brokers report to DROP?

Record deleted, record opted out of sale, record exempted, or record not found. Statuses are reported at the next access session.

Do data brokers have to tell their vendors about DROP deletions?

Yes. Brokers have to direct every service provider and contractor holding the consumer's data to delete it.

How should records be standardized before hashing?

Lowercase everything, remove special characters except in email addresses, convert accented letters, format dates as YYYYMMDD, ZIP codes as five digits and phone numbers as the last ten digits. See how DROP hashing works.

Fines, fees and audits

What is the fine for not processing a DROP request?

$200 per deletion request, per day, plus investigation costs. Try the fine calculator.

What is the fine for not registering as a data broker?

$200 per day, plus the registration fees that were due and CalPrivacy's investigation costs.

How much is the California data broker registration fee?

$6,000 for 2026 and $9,500 from 2027.

When do data broker audits start?

January 1, 2028. Brokers have to be audited by an independent third party every three years and keep each report for at least six years.

About Purgepath

What is Purgepath?

An API for California data brokers. Send a record, a batch or a CSV file and Purgepath tells you which ones match a DROP deletion request. See the API docs.

How current is the DROP list Purgepath checks against?

Purgepath pulls new DROP requests every day and keeps your list current. Every response shows when your list last synced.

Can I send hashes instead of raw records?

Yes. Hashed-only mode accepts SHA-256 hashes you compute yourself. See hashed-only mode.

How much does Purgepath cost?

$500 a month for unlimited scrubs by API or CSV upload. No setup fees.

How do I get access to Purgepath?

Join the waitlist. We are at capacity and onboard new brokers from the waitlist.

Is Purgepath affiliated with CalPrivacy?

No. Purgepath is an independent company.

Check every record against DROP with one API call

Purgepath keeps your DROP list current daily and tells you exactly what to delete. Unlimited scrubs by API or CSV upload, $500/month.

General information as of October 8, 2026, not legal advice. Sources: Cal. Civ. Code sections 1798.99.80 to 1798.99.89, the DROP regulations (Cal. Code Regs. tit. 11, sections 7600 to 7616), and CalPrivacy's published guidance. See each guide for links.