California DROP After the August 1 Deadline: What Happened
August 1, 2026 has come and gone. Our May review of DROP was written when the deadline was still ahead of us, so this is the follow-up: what California's regulator has actually published since, what it has not, and what that means if you submitted a request. Every number below comes from a page we read, linked where it appears. Where nothing has been published yet, we say so.
What the August 1 Deadline Required
Under the Delete Act, California residents have been able to file one deletion request through DROP (the Delete Request and Opt-Out Platform) since January 1, 2026. August 1, 2026 is the date registered data brokers had to start acting on those requests. According to a Privacy Rights Clearinghouse summary, brokers must now:
- Access DROP at least once every 45 days to retrieve deletion requests.
- Delete the personal information within 45 days of receiving a request, and tell their service providers and contractors to do the same.
- Delete again, on the next 45-day cycle, any information they re-acquire.
- Report any denial to CalPrivacy and name the legal exemption they relied on.
On penalties, a law-firm analysis dated August 5, 2026 puts the fine for failing to process a request at $200 per deletion request for each day the broker fails to process it. The same piece noted that the processing requirement was only days old and that the agency had not yet published enforcement outcomes specific to deletion processing.
What Has Happened Since
Signups and enrolled brokers
On the day-by-day count, Freshfields reported more than 345,000 deletion requests as of August 7, 2026. By August 25, CalPrivacy announced that more than 500,000 Californians had registered and that 654 data brokers were enrolled. That is well above the roughly 530 we used in May, so treat any older broker count as out of date. Other sources we read cite 500+ and 580+, so counts differ by source and date.
Reported deletion results
In the same August 25 announcement, CalPrivacy said that about 25% of enrolled brokers had already reported processing deletions, that 99.9% of consumers had a profile deleted by at least one broker, that the typical user had information removed by 40 or more brokers, and that tens of millions of records had been deleted overall.
Read those carefully. "At least one broker" is a low bar, and it is not a per-broker deletion rate. The 25% figure leaves open how many of the other brokers had processed deletions but not yet reported them. These are the agency's own figures, and we found no independent audit of them. We also found no published breakdown of deletions by broker, and no figure for how many requests were denied under an exemption.
Enforcement: real fines, but for registration
CalPrivacy has announced three data broker penalties since the deadline. None of the ones we found is for failing to process a DROP deletion request.
- LocateSmarter, August 11: a $116,490 penalty for failing to register as a data broker and for violating CCPA opt-out requirements. A law-firm write-up describes the amount as $110,490 plus a $6,000 DROP registration fee, and says its opt-out process asked for the last four digits of a Social Security number.
- Cybba, August 13: $52,400 for failing to register by the 2025 deadline. CalPrivacy also ordered it to use DROP and process future deletion requests through it.
- SalesIntel Research, September 1: $36,400 for not registering on time, with the same DROP orders.
That pattern matters. Registration is easy for a regulator to verify from the outside. Whether a specific broker deleted a specific person's record is much harder to see. We went through that gap in more detail, with our own filing data, in California Started Fining Data Brokers, But Not for Ignoring You.
Not yet published
- Any fine for failing to process DROP deletion requests after August 1.
- A per-broker compliance or deletion rate.
- How many requests brokers denied, and under which exemptions.
- Anything that lets a consumer see which brokers acted on their own request.
If a later CalPrivacy release changes any of these, this page will be updated.
What DROP Does Not Cover
- Anyone outside California. DROP is available only to verified California residents. If you live in another state, there is no equivalent single request.
- Brokers outside the registry. DROP reaches enrolled brokers, which CalPrivacy counts at 654. Companies that sell personal data without registering are outside DROP's reach, which is what the registration fines above are aimed at. We did not find an official count of how many brokers operate in total, so we will not give one.
- A paper trail you can use. The reporting duties in the sources above run from the broker to CalPrivacy. We did not find anything that sends each broker's answer back to you. A deletion you cannot verify is a deletion you are taking on faith.
- Re-listing you can see. The rules say brokers must delete again if they re-acquire your data, on the following 45-day cycle. That is a real improvement over a one-time request. But the consumer still has no view of whether it happened, so checking for a re-listed profile is still on you.
What to Do Now
- If you live in California, file in DROP. It is free, takes under ten minutes according to CalPrivacy, and your request stays active until you withdraw it.
- Spot-check a few people-search sites after the 45-day window from when your request was submitted or retrieved. Search your name and city on the sites that matter most to you. Screenshot what you find.
- If a broker still lists you, ask it directly in writing. A deletion demand under the CCPA, sent to the broker's privacy contact, gives you something DROP does not: the broker's own reply on the record.
- Complain to CalPrivacy when a registered broker ignores you. The agency is the one that can fine a broker for not processing requests.
- If you are outside California, DROP is not available to you. You would need to send deletion requests to brokers one at a time, or use a service that does it.
Where GhostVault fits
GhostVault files deletion demands with 500+ registered data brokers, works in all 50 states, and shows you each broker's reply. Only a written confirmation from the broker counts as removed, and a sent or delivered request does not. It is $99/year for the Individual plan, and the free footprint scan shows what is exposed with your details masked. It does not guarantee any broker will delete anything, and it is not a substitute for filing in DROP if you live in California. Do both.
Frequently Asked Questions
Does California DROP work?
Partly, by CalPrivacy's own numbers. As of August 25, 2026 the agency said 99.9% of consumers had a profile deleted by at least one broker, with a typical user seeing removals at 40 or more. That figure says some brokers are acting. It does not say all of them are. For what we saw in our own testing before the deadline, see the six-month review and the original review.
Did data brokers comply with the deadline?
Not all of them, and the full picture is not published. CalPrivacy said about 25% of enrolled brokers had reported processing deletions by August 25. The fines announced so far are for registration failures, not for ignoring deletion requests. A per-broker compliance report has not been released.
What if a broker ignores my DROP request?
The law allows fines of $200 per request per day for failing to process, but we found no announced fine of that kind yet. Your practical options are to send the broker a written CCPA deletion demand, keep its reply, and file a complaint with CalPrivacy. Do not read a silent broker as a deleted record.
Is DROP enough, or do I need a removal service?
If you live in California, DROP is worth doing first because it is free and has legal force. Its limits are scope (California residents and enrolled brokers) and visibility (you do not see broker-by-broker results). A removal service can extend coverage to other states and show you replies, but none can promise a deletion. We compare the two in California DROP vs Data Removal Services.

This is one possible source in a much larger personal-data ecosystem.
Scan supported sources for free, then use Ghost to organize requests, follow-ups, and verified outcomes.