- What: New platform helps Californians reduce digital footprint
- Impact: Aims to improve personal data privacy and security
Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands An Informa TechTarget Publication Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise Newsletter Sign-Up Newsletter Sign-Up Cybersecurity Topics Related Topics Application Security Cybersecurity Careers Cloud Security Cyber Risk Cyberattacks & Data Breaches Cybersecurity Analytics Cybersecurity Operations Data Privacy Endpoint Security ICS/OT Security Identity & Access Mgmt Security Insider Threats IoT Mobile Security Perimeter Physical Security Remote Workforce Threat Intelligence Vulnerabilities & Threats Recent in Cybersecurity Topics Application Security AI Harnesses Burst With Potential Exploit Opps AI Harnesses Burst With Potential Exploit Opps by Robert Lemos Jul 30, 2026 4 Min Read Application Security OpenAI's Rogue Model Claims More Victims Beyond Hugging Face OpenAI's Rogue Model Claims More Victims Beyond Hugging Face by Alexander Culafi Jul 29, 2026 3 Min Read World Related Topics DR Global Asia Pacific Europe Latin America Middle East & Africa See All The Edge DR Technology Events Related Topics Upcoming Events Podcasts Webinars SEE ALL Resources Related Topics Resource Library White Papers Reports Webinars Newsletters Podcasts Heard It From a CISO Reporters' Notebook Dark Reading's 20th Videos Dark Reading Polls Partner Perspectives Meet the Editors Advertise With Us About Us Dark Reading Resource Library Data Privacy Cybersecurity In-Depth: Feature articles on security strategy, latest trends, and people to know. DROP Platform Lets Californians Reduce Digital Footprint The Delete Request and Opt-out Platform (DROP) launches Aug. 1 and hundreds of thousands of California residents already registered. Other states could follow if the process goes smoothly. Arielle Waldman , Features Writer , Dark Reading July 31, 2026 5 Min Read Source: baona via Getty Images California residents can now request to have their data deleted with a single click. But companies that haven't prepared for the state's new regulation may be scrambling to keep up with compliance. In 2023, California legislators passed The Delete Act , intended to help state residents gain control over their personal information and their privacy. Creating a free, centralized platform for consumers to request the deletion of their data from more than 600 registered data brokers simultaneously was one requirement under the new law. The single platform became aptly known as the Delete Request and Opt-out Platform (DROP), which is managed by the California Privacy Protection Agency (CPPA) and officially launches on Aug. 1. By then, data brokers – any business that knowingly collects and sells personal information to third parties without consumer knowledge – must begin processing deletion requests made through DROP. Third parties could include advertisers, retail companies, political campaigns, landlords, and debt collectors. Social Security numbers, geolocations, browsing histories, email addresses, health information, and shopping habits are just some examples of the data at stake. Related: Inconsistent Privacy Labels Don't Tell Users What They Are Getting Registration for DROP initially opened on Jan. 1 and as of June, more than 300,000 Californians signed up, according to the CPPA. Beginning next month, brokers will be required to check the platform every 45 days to identify deletion requests, securely match them against their databases, and take action. More than 20 U.S. states have passed or enacted data privacy laws that require parties to delete personal data at the consumer’s request, similar to the “right to be forgotten” in the European Union’s General Data Privacy Regulation (GDPR). But California’s new law could serve as a blueprint for more stringent compliance. Like vehicle emission standards and CCPA itself, the size of California’s economy makes its regulations resonate nationwide. A Smooth Rollout “Is Probably Unrealistic” While it seemed Californians signed up with ease, companies may find Delete Act compliance challenging, depending on their level of preparedness. Compliance steps for brokers include paying an annual, nonrefundable fee, setting up a DROP account, conducting retrieval testing, meeting reporting requirements, and maintaining adequate security to prevent unauthorized account access. Companies will have their work cut out for them if they're beginning Delete Act compliance this month, warns John Pavolotsky, partner at Stoel Rives and co-chair of the firm's artificial intelligence (AI), privacy, and cybersecurity group. Theoretically, they should have started months ago, he adds. Related: EU Financial Institutions Leak Data Through Cookie Trackers Pavolotsky cites resources the state rolled out to help brokers, including a sandbox where they could test out their systems on synthetic data deletion requests. "Hopefully things will run relatively smoothly," Pavolotsky tells Dark Reading. “But as a practical matter, given that there are 581 data brokers and 325,000 [consumers] in the queue, to imagine that things will run completely smoothly is probably unrealistic." The massive deluge of opt-out requests could present challenges for organizations, and automation may be the answer. There is an automated opt-out from sale and sharing of personal data through the Global Privacy Control, a browser setting that allows users to tell websites that don't want their personal information shared or stored, but that doesn't apply to deletion, says Pavolotsky. California is the first state to test out this type of delete mechanism, serving as a blueprint for broader applications. Once Aug. 1 hits, companies will see whether the state views the trial period as an opportunity to work out the kinks — tolerating imperfect technical compliance as long as companies are making good-faith efforts — or whether enforcement will be more stringent from Day One. Related: AI Rising: Do We Know Enough About the Data Populating It? Progress will become clearer by the end of August, says Pavolotsky, reiterating that companies who haven't put in the time to comply will likely have a hard time. But if DROP execution goes smoothly, it will inspire other states to follow suit. "I think it's going to be challenging, not because the requirements are unfair or vague. It's just that it's a new mechanism and a new system," he adds. "And yes, California is a big state, but this is one of many compliance requirements a data broker company has." Users Need An Easier Delete Button The Delete Act and DROP platform are a natural contingence of California's more stringent privacy laws, following the establishment of the California Consumer Privacy Act in 2018. Since then, ensuring data privacy has only grown more critical, because tracking where user data is or who's got their hands on it becomes increasingly murky. The Electronic Frontier Foundation (EFF), a nonprofit defending users' digital rights, highlighted several risks driving the passage of these laws. Data brokers often supply spammers with personal contact information; removal could reduce pesky, unwanted messages and improve personal cybersecurity by limiting exposure. Secondly, fewer companies holding individual data means less risk when breaches occur, as evidenced by the ongoing influx of data breach notifications. "Third and finally, it gives you an opportunity to exert more control over how your personal information is collected and used, an important element of privacy," Hayley Tsukayama, EFF's director of state affairs wrote in the blog post . While consumers have a right to request data deletion, actually making those requests "is an incredibly time-consuming and tedious process", added Tsukayama. DROP cuts down the process considerably by linking a request to California's broker registry, she said. The one-stop data deletion shop is sensible for data protection in California, agrees Pavolotsky. "Privacy is a top priority of the California legislature, and implicitly, a priority of constituents," he says. About the Author Arielle Waldman Features Writer, Dark Reading Arielle spent the last decade working as a reporter, transitioning from human interest stories to covering all things cybersecurity related in 2020. Now, as a features writer for Dark Reading, she delves into the security problems enterprises face daily, providing context and actionable steps. She looks for stories that go past the initial news to understand where the industry is going. Her coverage areas include identity and access management, cyber risk and operations, industrial control systems, operational technology, and ransomware trends. She previously lived in Florida where she wrote for the Tampa Bay Times before returning to Boston where her cybersecurity career took off at TechTarget SearchSecurity. When she's not writing about cybersecurity, she pursues personal projects that include a mystery novel and poetry collection. See more from Arielle Waldman Want more Dark Reading stories in your Google search results? Add Us Now More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars Experts Explain How to Develop a Framework for Cyber-Fraud Fusion Prevention at Machine Speed: Hunting Beyond Known Detections 0-Day to 10x Discovery: Security at the Speed of Mythos When AI Becomes an Insider: Rethinking Risk in Critical Infrastructure Governing the Agent; Identity Security in the Age of Autonomous AI More Webinars Edge Picks Application Security AI Agents in Browsers Light on Cybersecurity, Bypass Controls AI Agents in Browsers Light on Cybersecurity, Bypass Controls Cyber Risk Browser Extensions Pose Heightened,