delete-actdropccpadata-brokersprivacy

You Asked California to Delete You. Here Is What the Statute Means by "Delete."

Ben TobinUpdated 10 min read

A California resident files a DROP request and pictures something specific: their name, address and phone number gone from the companies that buy and sell them, and the search results going quiet.

The statute means something narrower. Not deceptively narrower — the text is public, short, and mostly clear — but narrower in ways nobody encounters until they go looking for the gap between what they expected and what happened.

The narrowing is done almost entirely by four definitions. Here they are.

1. "Data broker" excludes anyone you have dealt with directly

Civil Code § 1798.99.80(c):

"'Data broker' means a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship."

The operative clause is the last one. A company that got your data from you — the retailer, the airline, the app, the gym, the utility, the site you signed up for in 2014 — is not a data broker as to you, no matter how freely it sells what it holds. It is not on the registry, it does not read DROP, and your DROP request does not reach it.

This is the largest single gap between expectation and statute, and it is the one people find last. DROP was built for the companies you have never heard of. The companies you have heard of are a different rail: a direct CCPA deletion request, sent to each one.

2. Four industries are carved out — and the carve-out is partial, not total

The same section excludes from "data broker":

"An entity to the extent that it is covered by the federal Fair Credit Reporting Act"

"An entity to the extent that it is covered by the Gramm-Leach-Bliley Act"

"An entity to the extent that it is covered by the Insurance Information and Privacy Protection Act"

"An entity, or a business associate of a covered entity, to the extent their processing of personal information is exempt under Section 1798.146"

In plain terms: consumer reporting, banking and financial services, insurance, and health information. The credit bureaus are the ones that surprise people most — they hold more about the average person than any people-search site, and to the extent they operate as consumer reporting agencies under the FCRA, DROP is not the instrument that reaches them. The FCRA has its own dispute and disclosure machinery, which is older and in some respects stronger.

Now read three words again: "to the extent that." The exclusion attaches to the processing, not to the company. A business can be a data broker for one line of business and exempt for another. That is why "is this company on the registry?" is the wrong question. The right one is which of its activities are inside the definition — and that is not something a consumer can determine from outside.

3. "Personal information" excludes what is publicly available

Under § 1798.140, personal information is defined expansively — information that "identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household."

And then:

"'Personal information' does not include publicly available information or lawfully obtained, truthful information that is a matter of public concern."

"Publicly available" is itself defined broadly: information lawfully made available from federal, state or local government records; information a business reasonably believes was lawfully made available to the general public by the consumer or through widely distributed media; and information the consumer disclosed to someone without restricting the audience.

Sit with what that means for a people-search site. The property record, the voter file, the court docket, the professional licence, the business filing, the marriage record — the load-bearing material of the entire people-search industry is government records. A site built on that foundation has a real argument that much of what it publishes about you is not "personal information" as the CCPA defines it, and therefore not what the deletion right operates on.

Whether that argument wins in any given case is not settled, and I am not the person to tell you how it comes out. But it is not a fringe position, and it explains more "I filed and nothing changed" experiences than bad faith does.

4. "Sale" requires consideration

The definition of sale in § 1798.140 turns on transferring personal information to a third party "for monetary or other valuable consideration." "Other valuable consideration" is doing a lot of work and was drafted deliberately wide — but the trigger for the broker definition is a business that "collects and sells." Data moved under structures that are not sales sits differently.

5. What "delete" permits a company to keep

Here is the one that feels most like a contradiction and is not.

Section 1798.105(c) requires a business receiving a verifiable deletion request to delete the information from its records, notify its service providers and contractors to do the same, and notify third parties it sold or shared the information to — and then adds: "unless this proves impossible or involves disproportionate effort." That qualifier is attached to the downstream notice, which is precisely the part a consumer most wants to happen.

Section 1798.105 also lets a business retain a confidential record of the deletion request itself, specifically so it does not re-sell what it just deleted.

And § 1798.99.86 requires a broker, having deleted you once, to keep deleting: to delete your personal information on a continuing basis and not to sell or share new personal information about you.

Put those together and a structural fact falls out. A company cannot suppress a person it has no record of. Ongoing suppression — the strongest and most useful thing the Delete Act does, the thing that finally engages the industry's habit of re-listing people — requires the company to retain enough about you to recognise you when you turn up again in a new data feed. "Deleted" under this statute means your data removed, and a marker for you retained. That is not a loophole. It is the price of the part that actually works.

6. The exceptions travel with the request

Section 1798.105 lists exceptions where a business need not delete, where retention is reasonably necessary — among them completing a transaction the information was collected for, security and integrity, debugging, compliance with the California Electronic Communications Privacy Act, certain research, internal uses aligned with the consumer's expectations, and legal obligations. One of them is the exercise of free speech, or enabling another party to exercise theirs.

A publisher of public-record information is exactly the kind of party that raises a free-speech objection to a deletion demand, and courts have historically been receptive to that framing in the abstract. That exception, and the publicly-available carve-out above, are the two doors through which most of what frustrates people passes.

7. An unverified request quietly becomes something lesser

Under § 1798.99.86, when a broker cannot verify a deletion request, it must "process the request as an opt-out of the sale or sharing of the consumer's personal information."

That is a real protection and it is not nothing. It is also not deletion, it happens without anyone telling you it happened, and verification turns on whether the identifiers you supplied match what the broker holds. Which brings us back to the practical advice that matters more than any of the above: the identifiers you put into DROP are the entire surface area of your request. Former surnames, old addresses, the email you stopped using, the phone number you gave up. Every one you add is another chance to be recognised.

So is the Delete Act weak?

No — and I would rather be accurate than rhetorical here, because being unfair to this statute serves nobody.

The Delete Act is the strongest instrument of its kind in the United States. Forward-looking suppression is a genuine structural fix that no opt-out form anywhere else provides. One request reaching every registered broker is an enormous improvement over filing hundreds of them by hand. Getting it built at all was hard.

What it is not is a universal erase button, and the distance between those two things is made of ordinary statutory definitions rather than anybody's bad faith. If you file expecting the erase button, you will conclude the system failed. If you file understanding what it reaches, you will use it well, and you will know what still needs doing separately.

What still needs doing separately

  • Companies you dealt with directly — outside the broker definition; each needs its own CCPA deletion request.
  • Credit reporting, banking, insurance and health entities — to the extent they are covered by FCRA, GLBA, the Insurance Information and Privacy Protection Act or § 1798.146, they sit under their own regimes, which have their own procedures.
  • Sites built on public records — many run their own opt-out processes that are broader than what the statute compels. Those are open to everyone, including non-Californians, and are often the fastest route.
  • Data already in breach corpora — no deletion right reaches a stolen copy.
  • Government records themselves — a records question, not a deletion one.

Frequently asked questions

Why is my information still online after I filed a DROP request?

Several possibilities, none distinguishable from the outside: the site is not a registered data broker; the company has a direct relationship with you and is therefore outside the broker definition; the material is drawn from public records and the company treats it as outside "personal information"; the identifiers you filed did not match what the company holds, so the request was processed as an opt-out rather than a deletion; or the record was deleted while a cached or syndicated copy persists elsewhere.

Does DROP reach the credit bureaus?

To the extent an entity is covered by the federal Fair Credit Reporting Act, it is excluded from the "data broker" definition in § 1798.99.80. The FCRA provides its own disclosure and dispute rights, which are separate from and older than the Delete Act.

Does DROP reach companies I have accounts with?

No. The definition covers a business that sells the personal information of a consumer "with whom the business does not have a direct relationship." A company you transact with directly is outside it, and needs a direct CCPA deletion request instead.

If my data came from public records, can a company refuse to delete it?

The CCPA's definition of personal information excludes publicly available information, which includes information lawfully made available from government records. A company relying on that position may take the view that the deletion right does not operate on the material. Whether that position holds in a given case is a legal question, and one to put to counsel rather than to a vendor.

Does deletion mean the company keeps nothing about me?

No, and it cannot. Ongoing suppression under § 1798.99.86 requires a broker to keep deleting your information going forward and not to sell or share new information about you — which is only possible if it retains enough to recognise you. Section 1798.105 also permits a confidential record of the request itself, so the deleted information is not re-sold.

Is any of this a reason not to file?

No. Filing is free, it reaches every registered broker at once, and the forward-looking suppression obligation is the strongest consumer protection in this area in the country. Understanding the limits is a reason to file and to do the other things, not a reason to skip it.

Disclosure

I run Sirveil, a small California company whose service determines whether a named individual's information is publicly indexed at a named website at a given moment, and reports that observation as INDEXED, NOT INDEXED, or INDETERMINATE. We do not verify that anyone complied with anything, and we do not audit or certify anyone. Index presence is not proof that a deletion request was ignored, and index absence is not proof that data was deleted. I have a commercial interest in how deletion and verification get regulated, and I disclose it wherever I write. Read this accordingly — and note that an article explaining why deletion is harder than it looks is an article that happens to suit a company selling observation. I have tried to be fair to the statute for exactly that reason.


Sources: Cal. Civ. Code §§ 1798.99.80, 1798.99.86, 1798.105 and 1798.140. Read 6 September 2026 via Justia's publication of the California Codes; the Legislature's own site at leginfo.legislature.ca.gov disallows automated retrieval, so quotations here should be confirmed against the official text before being relied on.

NONE OF THIS CONSTITUTES LEGAL ADVICE. The author writes as a commercial party with a disclosed interest, not as counsel, and this article creates no attorney-client relationship. Statutory definitions are summarised and, where quoted, quoted in part. How any exception applies to a particular company or a particular record is a legal question. Confirm the current text with the Legislature and your own position with your own counsel.

Share this article

PostShare

Get privacy insights delivered

No spam. Unsubscribe anytime. We send one email per week with new guides and data broker news.

Start protecting your personal data

Scan, verify, remove: Sirveil finds where brokers list you, you confirm which entries are yours, and your takedown requests are prepared, transmitted, and chased on your behalf — tracked end to end.

Get Sirveil

Available now on the App Store and Google Play.