Skip to content
DropDue

Glossary/GLOSSARY

DROP

DROP is the Delete Request and Opt-out Platform, the California Privacy Protection Agency system that takes deletion requests from consumers and publishes them to registered data brokers as lists of hashed identifiers.

In plain terms

A consumer verifies their identity with the state once and submits one request. DROP turns the identifiers in that request into hashes and adds them to the deletion lists brokers download. There are six list types: email, phone, mobile advertising ID, connected TV ID, name with date of birth and zip, and name with vehicle identification number. A broker downloads the lists it selected using an API key scoped to those lists, matches them against its own records, and uploads a status for every identifier it was given.

What it means for a registered broker

DROP is the only channel. There is no side agreement with a consumer and no alternative file format. One account on the data broker portal covers registration, fees, and the API key, and the key is what your tooling uses to download and upload. Downloads are stateful batches, so you run one open cycle at a time. Uploads are accepted for validation first and confirmed afterwards, which is why a submitted cycle and a filed cycle are not the same thing.

Where it comes from
Delete Act, SB 362 (2023)