EPISODE · Jul 29, 2026 · 43 MIN
One Request, 600 Companies and one Deep Dive: Inside California's New Data Deletion Machine
from The AI, Privacy, and Security Weekly Update · host R. Prescott Stearns Jr.
California’s Delete Act (SB 362) introduced DROP (Delete Request and Opt-out Platform), which launched on January 1, 2026. It lets residents submit one deletion request that automatically propagates to all registered data brokers in the state—currently around 500 companies. The Core Problem It SolvesData brokers collect and resell personal information from people they’ve never directly interacted with. Before DROP, individuals had to manually find each broker, submit separate requests, and hope for compliance with no centralized tracking.How DROP WorksResidency Verification: Users prove they’re Californian via the California Identity Gateway or Login.gov (no permanent state account needed). This avoids redundant collection of sensitive data by brokers.Provide Identifiers: Users submit details like name (and former names), date of birth, ZIP code, email, phone, mobile advertising IDs (MAID), connected TV IDs, and VINs. More identifiers improve matching accuracy across brokers.Centralized Submission: One request is sent to all registered brokers.Privacy-Preserving Matching: California does not share raw personal data. Instead, it normalizes and hashes identifiers, creating deletion lists. Brokers hash their own records and compare hashes. Matches trigger deletion without exposing underlying data—similar in concept to lightweight privacy-preserving techniques.Recurring Compliance Cycle: Starting August 1, 2026, brokers must check DROP at least every 45 days (via API or download), process new requests, and honor prior deletions through ongoing suppression.Multi-Identifier Lists: Separate hashed lists exist for different data types; brokers use those relevant to their holdings.Full Deletion: A match requires deleting all associated records for that individual, not just the matching identifier, and preventing future sales.Reporting and Transparency: Brokers report completion status back through DROP, allowing users to track progress from pending to completed.Ongoing Obligation: Deletion is not one-time; brokers must maintain suppression lists indefinitely.Global Reach: Any data broker processing significant volumes of Californians’ data (threshold ~100,000 records) must register and comply, regardless of headquarters location.Broker Burden: Requires new infrastructure for hashing pipelines, scheduled polling, cross-identifier matching, suppression, and reporting. The state provides documentation, webinars, and test environments.Enforcement: Third-party audits begin in 2028 and recur every three years. Fines reach $200 per consumer per day for noncompliance.Scope and RequirementsWhy It MattersDROP targets brokers handling highly sensitive data (geolocation, biometrics, SSNs). Beyond faster deletions, it compels the industry to adopt stronger technical privacy and security practices. The architecture is innovative: the state coordinates mass privacy actions across hundreds of companies without ever holding or seeing raw personal data. If successful under real-world load from August 2026 onward, it could become a model for other states and countries—enabling deletion at scale without relying on trust.Closing Insight: The real breakthrough isn’t just the deletion feature but the underlying privacy infrastructure that makes coordinated, verifiable, and secure data removal possible.
Embed this episode
NOW PLAYING
One Request, 600 Companies and one Deep Dive: Inside California's New Data Deletion Machine
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.