July 13, 2026

California’s Delete Act and Data Privacy Challenges

Millions of Social Security numbers are for sale on the dark web, a result of recent data breaches in the United States. This poses significant risks, allowing criminals to engage in identity theft by opening credit cards or filing fraudulent tax returns. Many Californians are trying to address these issues by leveraging their rights under the state’s Delete Act.

Understanding California’s Delete Act

The Delete Act, also known as SB 362, enhances privacy rights, granting Californians the ability to remove their personal data from hundreds of registered data brokers. This is possible through DROP, the Delete Request and Opt-out Platform. According to CalPrivacy, the personal and sensitive information that can be deleted includes:

  • Social Security number
  • Precise geolocation
  • Browsing history
  • Email addresses
  • Phone numbers
  • Interests
  • Health-related information
  • Shopping habits

However, data given directly to a business, exempted data, and publicly available data will not be deleted. Data brokers registered with the California Privacy Protection Agency (CPPA) must delete and abstain from selling personal information. Post August 1, brokers must begin processing deletion requests, with 45 days to confirm deletions to CalPrivacy and the requesters.

Failure to comply could result in fines of $200 daily for each unprocessed request. As of July 1, 332,292 Californians signed up for data deletion.

The Reality of Data Brokers

CalPrivacy’s registry contains nearly 600 data brokers, with various brokers selling personal data such as precise locations, identity details, gender identity, reproductive health data, and union membership information. Approximately 18 brokers deal with information about minors, accessible for deletion requests via DROP. Some brokers sell personal data to government agencies, police, foreign entities, and AI developers.

Challenges in Data Deletion

Despite the risks of unauthorized access to sensitive information, less than 1 percent of Californians have requested data deletion. Tom Kemp, CalPrivacy Executive Director, noted the prevalence of data brokers selling data without control. Kemp encourages Californians to reduce their data exposure, anticipating increased participation once data deletion commences.

Interested individuals can check eligibility and apply for data deletion via DROP by August 1.

Laws and Efforts Beyond California

Nationwide, no federal law directly regulates data brokers or bans personal data sales. Current U.S. privacy regulations are fragmented, with some states offering opt-out or opt-in options.

As of April, 20 states, including California, Colorado, and New Jersey, had enacted privacy laws. Some are striving to create a centralized system similar to DROP. For example, Connecticut plans to implement a centralized deletion mechanism by July 2028.

Other states like Oregon, Texas, and Vermont require data broker registration, though they lack a one-stop deletion system. Efforts are underway to strengthen privacy laws nationwide, inspired by California’s example.

TAGS: