If you've seen headlines this month about California's new data deletion law, you're not imagining the buzz. On August 1, 2026 the first real enforcement deadline went into effect for California's Delete Act - the law that created DROP, the state's one-stop tool for asking data brokers to erase your personal information.
More than 300,000 Californians had already signed up for DROP in the months leading up to the deadline, and registered data brokers are now legally required to act on those requests. It's the most ambitious data-deletion effort any state has tried. But it's also worth understanding exactly what it does, and just as importantly, what it doesn't, before you assume your information is handled.
What the Delete Act and DROP actually do
California's Delete Act (Senate Bill 362) was signed into law back in 2023, but it took until early 2026 for its centerpiece to go live: the Delete Request and Opt-out Platform, or DROP. The idea is simple in theory. Instead of contacting every data broker individually, a California resident can submit one deletion request through DROP, and every broker registered with the state has to honor it.
As of August 1, that requirement has real teeth. Registered brokers must check DROP every 45 days, download the current list of deletion requests, and match it against their own records using standardized identifiers like email addresses, phone numbers, and mobile ad IDs. If they find a match, they're required to delete not just the basic information they collected, but any inferences built from it, and to keep that person's data off their books going forward. Brokers that miss the window face fines of $200 per unprocessed request, per day, which is why compliance teams across the data broker industry have been scrambling all summer.
Who's actually protected here
DROP is a meaningful tool, but it was built with specific boundaries:
It only protects California residents. If you don't live in California, DROP doesn't apply to you at all, regardless of how much of your data is floating around online.
It only reaches brokers registered with the state. California requires data brokers to register annually, and only those on that registry are bound by DROP's deletion rules. Brokers that haven't registered, whether out of noncompliance or because they don't consider themselves a "data broker" under the law's definition, aren't part of the system.
It doesn't cover every category of data. Information governed by other federal laws, like credit reporting data under FCRA or financial data under GLBA, falls outside DROP's scope. Public records that a broker can legally re-collect after deletion are also fair game again.
What DROP leaves out
Even for the Californians it's designed to help, DROP has a real structural gap: it only reaches "personal information" as California's privacy law defines it, and that definition excludes publicly available information, meaning data lawfully pulled from government records like property filings, court records, and voter rolls, as long as the broker's use of it is compatible with why the government made it public in the first place. A lot of what people-search sites display is built from exactly that kind of public-record data. So a profile can legally persist or resurface after a deletion request, not because a broker is defying DROP, but because that category of data may never have been within DROP's reach to begin with.
And then there's everyone outside California entirely. Residents of the other 49 states have no equivalent one-stop government platform. Depending on where you live, your only option is what's always been available: locating each data broker individually, often across dozens or hundreds of sites, and submitting opt-out requests one at a time, each with its own process and its own wait time.
How Papaya Privacy fills the gap
This is exactly the problem Papaya Privacy was built to solve, for California residents and everyone else. Where DROP gives Californians a single request that reaches registered brokers, we go further: we monitor and submit removal requests across more than 350 data broker and people-search sites nationwide, regardless of where you live or whether a broker happens to be registered with any state.
Just as importantly, we don't treat removal as a one-time event. Because so much of what people-search and data broker sites display is sourced from public records, a listing can resurface even when a broker is fully complying with the law, simply because that data was never within a deletion mandate's reach to begin with. Papaya Privacy continuously rescans those sites and files fresh removal requests whenever your information resurfaces, so a single moment of "removed" doesn't quietly reverse itself six months later.
California's deadline is a genuine milestone, and if you're a resident who's filed a DROP request, that's a meaningful step. But it's a floor, not a ceiling. If you want broader, ongoing protection that doesn't depend on your zip code or a broker's registration status, that's where we come in.
Ready to see what's out there under your name? Sign up today to check how many of the 350+ sites we monitor already have your information listed.
