The European “right to be forgotten” is set out in an 88-page regulation. Its Californian equivalent can now be summed up in three words: “Drop. Delete. Done.”
Since 1 January 2026, residents of California have been able to register on Drop, the delete request and opt-out platform. This public service enables them to submit a single request to all data brokers registered with the California Privacy Protection Authority. Since 1 August, these companies have been required to check the platform and process requests at least once every 45 days. They have a maximum of 90 days to respond to each request.
The process begins with verification of California residency. The user then provides at least their name, date of birth and postcode. They can add their email addresses, telephone numbers, former names or less obvious identifiers: their telephone’s advertising number, smart TV ID or car chassis number.
This data is not necessarily the information that the individual is seeking to delete. It serves as a key. Each broker compares it with its own records to identify matching profiles. Drop uses hashing so that companies can carry out this matching process without receiving the original information in plain text.
When a profile is identified, the deletion is not limited to the name or address used to trace it. It covers other information linked to the individual: precise geolocation, browsing history, purchasing habits, financial situation or health-related information. Inferences drawn from this data are also affected. A data broker may, for example, have attributed political views, a pregnancy, a chronic illness, a level of debt or family composition to someone without that person ever having disclosed any such information.
Impossible to reconstruct
This is what sets this industry apart. A data broker does not merely collect information from its own clients. It gathers, cross-references, enriches and resells data obtained from other sources, sometimes from advertisers, recruiters, property owners, political campaigns or debt collection agencies. Consumers are often unaware that such companies exist. Before Drop, they therefore had to first find out who held their data before they could request its deletion.
The platform does not make everything disappear. Information received directly by a company as part of its relationship with a customer is not covered by this mechanism. Public registers, such as certain information relating to property or vehicle ownership, may be retained. Other categories remain governed by US sector-specific legislation on healthcare, credit or financial services.
Even where the broker cannot identify the correct profile with certainty, they must cease selling or sharing the associated data. This requirement also applies to brokers who join the register at a later date, unless the user explicitly decides to exclude certain brokers. It is therefore not merely a one-off data-cleansing exercise: it is also intended to prevent the gradual rebuilding of the same commercial profile.
A fine of $200 per day
The requirement is subject to a penalty. A broker who fails to delete the relevant data is liable to an administrative fine of $200 per day per request, to which may be added the costs incurred in enforcing the law. A company that fails to register also risks a fine of $200 per day.
Europe did not wait for California to recognise the right to be forgotten. Article 17 of the GDPR allows an individual to have their data erased when it is no longer necessary, when their consent has been withdrawn, or when its processing is unlawful. It also allows individuals to object to the use of their data for marketing purposes. Its scope is broader than that of Drop, as it is not limited to data brokers.
However, the comparison reveals a practical shortcoming. In Luxembourg, the procedure set out by the CNPD begins with the following instruction: “Identify the organisation responsible and the means of contacting it.” You must then write to the organisation, using its form or finding the address given in its privacy policy. The organisation normally has one month to respond, with a possible extension of two months for complex requests. In the event of a refusal or failure to respond, the individual may refer the matter to the CNPD, providing evidence of their prior attempts. The right therefore exists, but exercising it involves as many procedures as there are data controllers. The difficulty becomes considerable when dealing specifically with companies whose business involves collecting information with no direct link to the data subject.
The figures from Luxembourg show that this is not a minor issue. In its 2025 annual report, the CNPD states that 22 per cent of the complaints received relate to the right to erasure. This is the second most common reason, behind the right of access, which accounts for 25 per cent of cases.
Drop therefore does not necessarily grant Californians more rights than Europeans. It provides them with a common point of access, a register of the companies concerned, verified identity, tracking of requests and a periodic obligation to process them. It shifts some of the burden from the individual to the companies that make a living from their data.
Eight years after the GDPR came into force, Europe is still mainly busy explaining to citizens how to write to each data controller themselves. California is now raising a question that is more troubling than legal: can a right be considered fully effective when, in order to exercise it, one must already know who is infringing it?


