Published on The Shield | Cat Karow | May 2026
On August 1, 2026, California's Delete Act stops being a feel-good headline and becomes a law that actually requires data brokers to do something.
That something is: delete your data.
I know. Bold ask.
But after decades of watching an industry that built a multi-billion-dollar business on selling your life story to anyone with a credit card, I'll take "legally required to delete it when asked." It's not everything. It's not even close to everything. But it's the first time the bar has been set above the floor, and I want you to know exactly what it means, what it doesn't mean, and who's going to try to limbo under it anyway.
Grab a coffee. Let's get into it.

The Setup: What Is DROP and Why Should You Care
California's Delete Request and Opt-Out Platform (DROP) launched January 1, 2026. It is, in the most literal sense, the government finally building the thing privacy advocates have been screaming for since 2005.
Before DROP, opting out of data brokers meant visiting each one individually, filling out their incredibly special, uniquely terrible, definitely-not-designed-to-confuse-you opt-out form, waiting 30 days, discovering they re-collected your data from a different source, and then doing it all again forever until you died, at which point they'd probably still have your data.
There are over 500 registered data brokers in California alone. The math on doing that manually is not math. It's a hostage situation.
DROP collapses the whole nightmare into one form. You verify your California residency, submit your request, and it fires to every registered broker simultaneously. The state runs the platform. Brokers are required to plug into it. One and done. Sort of.
Here's the part where I remind you that DROP launched in January and mandatory compliance doesn't begin until August 1. So for the last seven months, your deletion requests have been sitting in a queue while data brokers did exactly what they always do: whatever they wanted.
That ends in 87 days. We'll see.
The Good: This Is Actually a Big Deal
Let's be real for a second before I get into the rest of it.
The DELETE Act is the most consumer-empowering data law currently operating in the United States. Full stop. And the permanent suppression requirement is the piece that nobody's talking about enough.
Deletion without suppression is basically a sandcastle at low tide. You can scrub your data today and a broker will just re-buy it from another broker next Tuesday. The Delete Act requires brokers to maintain your record on a suppression list, so any time new data on you flows into their systems, it gets automatically scrubbed every 45 days going forward. That's actually meaningful. That's the thing that turns a one-time opt-out into something that resembles real protection.
And CalPrivacy is already enforcing. In January 2026, they handed S&P Global a $62,600 fine for failing to register. S&P Global. Not some fly-by-night people-search site. One of the most recognizable financial data brands in the world. The excuse was "administrative error." The fine was real. Point being: they're not playing games.
The penalty structure also has teeth if they use them. $200 per day per unprocessed deletion request. If a broker sits on 1,000 requests for 30 days, that's $6 million in exposure. For a scrappy little people-search site running on a VPS and vibes, that's not a fine. That's a funeral.
So yes. This is progress. Real, meaningful, overdue progress.
Now let me tell you about the bad and the ugly.
The Bad: What "Bare Minimum" Actually Looks Like
I want you to understand what complying with the Delete Act looks like at the legal floor, because industry will meet the floor and call it a palace.

Checking DROP once every 45 days is legal compliance. Forty-five days. That's six weeks. If you submitted a deletion request on August 2nd, a broker technically has until mid-September to even open the inbox. And then another 45 days to process and report back. We are potentially talking about three months between "I asked them to delete my data" and "they have to have done anything about it."
"Not found" is a valid response. If a broker claims they don't have your data, they can close the request as not found. This is totally fine when true. It is absolutely going to be abused. If you have ever appeared on a people-search site, had your address aggregated anywhere, or breathed near a zip code, some of these brokers have your data. "Not found" from a people-search company that has your childhood home listed on their free preview page is not a data hygiene issue. It's a compliance strategy.
"Opted out" is not the same as "deleted." Opted out means they stop selling your data. They may still keep it. The law allows brokers to report this status in certain circumstances. Watch for this. Know the difference. "Opted out" is not what you asked for.
The first independent audit isn't until January 2028. So for the next 19 months, we're running on the honor system. CalPrivacy can investigate. They can sweep. They can fine. But they're one agency trying to watchdog 500+ brokers and an industry that has had 20 years to perfect the art of looking compliant while doing whatever it wants. The math, again, is not math.
The Ugly: Who's Not Covered (And They Know It)
Here's where the Delete Act stops being a delete act and starts being a "delete some of it, kinda" act.
Your credit bureau record is completely untouched. Experian, Equifax, TransUnion. The Fair Credit Reporting Act governs them. They are explicitly carved out. The people most responsible for the data that actually determines whether you can rent an apartment, get a car loan, or be approved for a job? DROP cannot touch them.
Your bank doesn't care about this law. Gramm-Leach-Bliley Act governs financial institutions. Also carved out.
Your hospital isn't moving. HIPAA entities and their business associates are exempt for protected health information. Your medical data isn't going anywhere.
Every company you've ever given your email address to is off the hook. If you have a direct relationship with a business, they are not a data broker under this law. That means every app, every retailer, every newsletter you signed up for in a moment of weakness. All of them. The Delete Act applies to the invisible middlemen who buy and sell your data without you ever knowing they exist. It does not apply to the companies who collected it from you directly and then quietly sold it to the invisible middlemen. That pipeline is still wide open.
What's left? Still enormous. People-search sites. Location data marketplaces. Ad-tech aggregators. Lead generators. Political data firms selling inferences about your "likely" religion, your estimated income, whether you own a gun, whether you're going through a divorce. All of that is in scope.
But the data that actually runs your life? The credit score data, the insurance data, the healthcare data? That's sitting in a room DROP isn't allowed to enter. And the industry knows it.
The Red Flags: What to Watch For
You can't audit this yourself. Nobody can. But here's what bad-faith compliance looks like so you know what you're seeing when it happens.
Mass "not found" responses from brokers who obviously have your data. If your full name, address history, and relatives are listed on a preview page of a people-search site, and they respond to your deletion request with "not found," that is not a data hygiene problem. That is a lie with a compliance status attached.
"Opted out" across the board instead of "deleted." Legitimate brokers will have legitimate reasons to report opted-out in some cases. But if every response comes back as opted-out instead of deleted, they're holding your data and calling it compliance.
No response at all past 45 days. That's potentially a $200/day violation. Start a log. Document the date you submitted. If you hit 90 days with no status update, that's worth escalating to CalPrivacy.
Brokers who registered in January and quietly go dark. The suppression requirement means this is supposed to be a living, ongoing process. Not a one-time exercise. If a broker processes your first deletion and then stops running the suppression pipeline, re-collected data just accumulates again. You would never know without an audit. Hence: the 2028 audit problem.
The Bottom Line
The California Delete Act is the best consumer data law in the country right now. DROP is real, the penalties are real, and CalPrivacy has already shown it will enforce.
But "best in the country" is doing a lot of heavy lifting in a country that doesn't have a federal privacy law and where your data can legally be sold, repackaged, and re-sold before you finish reading this sentence.
August 1 is the line. On August 1, the industry runs out of the excuse that compliance isn't required yet. What happens on August 2 is what we're actually here to find out.
My prediction? The big players will have built compliant pipelines because the fine math is too scary for them. The mid-tier people-search sites will do the bare minimum and call it done. And a meaningful chunk of the long tail will gamble that CalPrivacy can't find them before the 2028 audit. Some of them will be wrong about that. Most of them will be right.
The Delete Act is a start. It is not a finish line. It is not a clean slate. Your data did not disappear. What happened is that for the first time, a government told this industry "no" and backed it up with something resembling consequences.
That is progress. Messy, incomplete, full-of-carve-outs progress. But progress.
I'm watching. You should be too.
If you're a California resident:
Go to privacy.ca.gov/drop and submit your request now. It takes five minutes and you want your request already in the queue when August 1 hits. Do it today.
If you're not in California:
Illinois is building a similar system targeting January 1, 2027. Vermont has a registry. Oregon and Texas have registry-only setups. Nebraska went a different direction with a comprehensive consumer rights statute. The patchwork is real, and where you live determines how much of this applies to you. Lobby your state legislature. Seriously.
If federal action ever comes:
I will believe it when I see it. Don't hold your breath. Definitely don't delete your DROP bookmark.
Cat Karow is the CEO and co-founder of ZoraSafe, an AI-powered scam and fraud protection app for seniors, families, and caregivers. She writes The Shield at theshield.blog and is the author of the forthcoming book SOLD: How America Built a Legal Market for Human Beings. She has been yelling about data brokers since before it was a personality trait. 🦊
