California Privacy Law
California's DROP Act is Live. Here's What It Actually Covers
On August 1, 2026, registered data brokers became required to check California's new deletion platform every 45 days. It is a real step forward, and a narrow one. Here is what DROP does, what it doesn't, and why ongoing monitoring still matters.
What Is DROP
A Free, State-Run Deletion Request Platform
The Delete Request and Opt-Out Platform, known as DROP, is the deletion mechanism created by California's Delete Act (SB 362), signed into law in October 2023 and run by the California Privacy Protection Agency. Instead of contacting every data broker individually, California residents can submit a single request through DROP that is routed to every broker registered with the state.
Consumers have been able to submit requests through DROP since January 1, 2026. As of August 1, 2026, registered brokers are required to check the platform at least once every 45 days and report the status of each request they retrieve within that same window.
For a specific, narrow category of companies, that is a genuine improvement over the broker-by-broker opt-out process it replaces.
The Fine Print
What DROP Doesn't Cover
Only Registered Brokers Are In Scope
DROP only reaches companies that have registered as data brokers with California. People-search sites, background-check aggregators, and marketing databases that fail to register or operate offshore fall outside the system entirely.
Public Records Aren't Covered
Court filings, property records, voter files, and business registrations sit outside the Delete Act. These public sources are frequently how people-search sites repopulate a profile after it's been deleted.
It's a Request, Not a Monitor
DROP processes a one-time request. It doesn't scan the web for new profiles, impersonation, or information that reappears after a broker reacquires data from another source.
Coverage Ends at the State Line
DROP has no authority over brokers operating outside California's registration requirements, and it does nothing for exposure that isn't routed through a registered data broker in the first place.
It's Opt-In and Self-Service
Nothing proactively notifies you when your information surfaces on a new broker's site next month, or next year. You have to know DROP exists and resubmit as new exposure appears.
Deletion, Not Prevention
DROP clears data a broker already holds. It does not stop that broker, or any other source, from collecting new information about you the day after your request is processed.
Beyond One Request
Why Ongoing Protection Still Matters
A platform that requires a broker to check in every 45 days is not the same as a service watching for new exposure every day, verifying removals took effect, and re-engaging when information reappears. For executives, founders, family offices, and other high-profile individuals, that difference is the whole risk.
Continuous Monitoring
Ongoing scanning across data brokers, people-search sites, and the public web, including sources that never register with any state platform.
Verified Removal
Hush confirms an exposure is actually gone rather than assuming a submitted request was processed and closed.
Coverage Beyond One State
Exposure doesn't stop at a state line. Most personal data lives with brokers who answer to no single regulator.
Family and Household Protection
The same monitoring and removal extends to the people around you, often the easiest path back to your own exposure.
Response to Relisting
Data brokers routinely repopulate profiles from new sources. Hush identifies relisted exposure and re-initiates removal.
Get Started
A State Deletion Request Is a Starting Point, Not an Endpoint
Talk to a privacy advisor about continuous monitoring and verified removal for you, your family, or your organization.