Originally published at https://monstadomains.com/blog/data-broker-deletion/
On August 1, 2026, a compliance deadline passed that almost nobody outside privacy law noticed, and it quietly changed the economics of an entire industry built on reselling your personal information. Every data broker registered in California is now legally required to log into a state operated platform, pull a list of the people who want their records erased, and act on it. The data broker deletion mandate is the first system of its kind anywhere in the United States. It is also a useful stress test of how much control a person can realistically claw back once their information is already in circulation.
The Data Broker Deletion Deadline That Landed On August 1
California’s Delete Request and Opt Out Platform, known as DROP, went live on January 1, 2026. For seven months it accepted requests from residents while brokers watched from the sidelines with no obligation to respond. That grace period is over. Since August 1, every broker registered with the state privacy regulator has been obligated to access the platform and process what it finds there. The regulator’s published data broker requirements are specific: brokers must access the accessible deletion mechanism at least once every 45 days, and they had 45 days from August 1 to clear their first batch of requests.
The design of the data broker deletion system is deliberately blunt. A California resident submits one request through one form. Every registered broker must honour it. There is no per company opt out maze, no confirmation email chain, no unsubscribe link buried three clicks into a footer. For an industry that spent two decades making deletion as tedious as the law would allow, a single button is close to an existential problem.
How The DROP System Actually Processes A Request
Understanding the mechanics matters, because the gaps in the machinery are where the interesting parts live. Brokers had to register with the state by January 31 and create an account in the system. Failure to register at all carries administrative fines and costs. The data broker deletion workflow then runs on a fixed cadence rather than on demand, which is the first thing worth noticing about it.
The 45 Day Check In
A broker is not required to respond the moment you file. It is required to check the platform at least once every 45 days. That means a data broker deletion request filed the day after a company’s last check can sit untouched for six weeks before anyone there is even aware it exists. The obligation is real, but it is a batch process, not a switch, and the difference matters if you are trying to get a record removed quickly.
The Penalty That Gives It Teeth
The Delete Act sets the statutory penalty at 200 dollars per deletion request per day of noncompliance. That per request, per day structure is what separates this from the decorative privacy laws that came before it. A broker sitting on ten thousand ignored data broker deletion requests is not facing a rounding error on a legal budget. It is facing a number that grows every morning until the records are actually gone.
Why Data Broker Deletion Stops Short Of Your WHOIS Record
Here is where domain owners should pay close attention. The mandate applies to entities meeting the legal definition of a data broker, meaning businesses that knowingly collect and sell personal information about consumers with whom they have no direct relationship. Your domain registrar does have a direct relationship with you. It sold you a service. That relationship is precisely what places it outside the data broker deletion regime, no matter how much personal information it holds about you.
So the record you filed at registration, the name and street address and phone number attached to your domain, sits in a category this system was never built to reach. Worse, that record has already been scraped. WHOIS data has fed commercial datasets for years, and once a downstream aggregator ingests it, a data broker deletion request may remove that copy while the authoritative registrar record stays exactly where it is, ready to be scraped again next quarter.
What The Data Broker Deletion Fight Reveals About Consent
The deeper lesson of the August deadline is not that deletion is finally possible. It is that deletion had to be legislated at all. A functioning consent model would not require a state agency to build software, register an entire industry, and attach a daily fine before companies would honour a request to stop holding data they were never given permission to sell in the first place.
Evidence that the underlying collection continues arrived within days of the deadline. On August 4, 2026, the Electronic Frontier Foundation reported that advertising software development kits handed to app developers were automatically feeding user location data into the systems location brokers use to track people. The EFF’s ongoing privacy research keeps landing on the same conclusion: the collection layer is upstream, automated, and largely invisible to the person being collected. A data broker deletion request is a mop, and the tap is still running.
That asymmetry is the whole story. Data broker deletion is retroactive, slow, jurisdictionally bounded, and requires you to know the mechanism exists at all. Collection is instant, global, and requires you to do nothing whatsoever. Any privacy strategy resting entirely on the first half of that equation is fighting the wrong battle.
The Federal Bill Circling The Same Problem
California is not operating in a vacuum. The Online Privacy Act of 2026, introduced in the House in March as HR 8014 and referred to the Energy and Commerce Committee, would push the United States away from its patchwork of sector specific rules toward a comprehensive rights based regime with harder mandates on data minimisation and retention. Whether it survives committee is another question entirely, and most comprehensive federal privacy bills historically have not.
What the bill signals is a shift in regulatory instinct: from asking companies to disclose what they collect toward asking why they collected it at all. That is a meaningfully different question, and it is the one the data broker deletion system only partially answers. Minimisation prevents the record from ever existing. Data broker deletion negotiates for its removal after the fact, on the holder’s schedule rather than yours.
The Enforcement Reality Behind The Data Broker Deletion Rules
Enforcement depends on registration, and registration depends on brokers correctly identifying themselves as brokers. Companies that never register are not in the system, are not checking the platform, and will never see your request. The data broker deletion mandate therefore covers the compliant portion of a market whose least compliant participants have the strongest possible incentive to stay invisible.
There is also a geographic limit worth stating plainly. This is a California statute protecting California residents. If you live anywhere else, the platform was not built for you, and the broker holding your file has no obligation to you under it. The precedent matters and other states will copy it, but precedent is not protection you can rely on today.
What Domain Owners Should Do In Response
If you are a California resident, file through DROP. It costs nothing and it removes real records from real databases. Treat it as cleanup rather than as a solution, because a data broker deletion request cannot reach data you have not yet created, and it cannot reach the registrar record sitting underneath your domains.
The more durable response is upstream. Audit what your existing domains expose by running your own name through a WHOIS lookup tool and reading the result as an adversary would. Then close the gap, because keeping registration details out of public queries is what stops the next scrape from becoming next year’s broker record and next year’s data broker deletion request. Our breakdown of why WHOIS privacy falls short alone covers what that layer does and does not protect.
For anything genuinely sensitive, the strongest position is never handing over the identifying data at all. Registering a domain without ID checks means there is no verified identity record for a broker to buy, a court to subpoena, or a breach to leak. Data that was never collected cannot be sold, lost, or argued over in a deletion queue.
The Takeaway
Three things are worth carrying out of the August 1 deadline. The data broker deletion mandate is genuine progress with genuine teeth, and if you qualify for it you should absolutely use it. It runs on a 45 day batch cadence inside one state’s borders, so it is a slower and far narrower instrument than the headlines suggest. And it does not touch your registrar record, which means domain owners leaning on data broker deletion are protected in exactly the place they need it least.
The pattern underneath is consistent: every deletion regime is a negotiation to remove information you already surrendered. At MonstaDomains we would rather you never surrendered it. If your registration details are sitting in public WHOIS today waiting to be harvested, locking down your WHOIS records is the single most useful thing you can do this week.

Top comments (0)