Skip to content

Demo site. Fictional data; nothing is sent to anyone. Open the guided demo

California, United States

California privacy rights: CCPA, the Delete Act and DROP

Short answer

California residents can ask covered businesses what personal information they hold, have it deleted or corrected, and stop its sale or sharing under the California Consumer Privacy Act (CCPA). Businesses have 45 calendar days to respond. Under the Delete Act, one free request through the state's DROP platform reaches every registered data broker. How these rights apply to an already-trained AI model is not settled.

Published
Last reviewed

General information, not legal advice. This page has not yet been reviewed by a lawyer; check the linked primary sources before relying on it.

Key takeaways

  • The CCPA protects California residents and binds for-profit businesses above set revenue or data thresholds.
  • A business has 45 calendar days to respond and may extend once by another 45 days.
  • Since 1 August 2026, registered data brokers must collect DROP deletion requests at least every 45 days.
  • Enforcement is by the California Privacy Protection Agency and the Attorney General. Private CCPA lawsuits are limited to certain data breaches.

Who is protected?

The CCPA protects California residents: natural persons who reside in California, even if temporarily outside the state. It applies to for-profit businesses that do business in California and have gross annual revenue of over $25 million, or buy, sell or share the personal information of 100,000 or more California residents or households, or earn 50% or more of annual revenue from selling residents' personal information. It generally does not apply to nonprofits or government agencies.

The Delete Act covers data brokers: businesses that knowingly collect and sell to third parties the personal information of consumers they have no direct relationship with. Brokers must register each year with the California Privacy Protection Agency (CPPA).

What rights do you have?

  • Know what personal information a business collects, why, and who receives it.
  • Delete personal information the business collected from you, with exceptions such as completing a transaction, security or a legal obligation.
  • Correct inaccurate personal information.
  • Opt out of the sale or sharing of your information, and limit the use of sensitive personal information.
  • Non-discrimination for using these rights.

Data brokers usually hold information they did not collect from you directly. Through the Delete Act, a DROP request reaches every registered broker. A broker that has deleted your data must delete again at least every 45 days and must not sell or share new personal information about you unless you ask otherwise.

How do you use them?

  1. For one business, use a request method listed in its privacy policy. It must offer at least two, such as a web form, email address or toll-free number, and may ask you to verify your identity.
  2. For data brokers, file one request at DROP. You confirm California residency, enter identifiers such as name, date of birth, email and phone number, and receive a DROP ID.

You may authorise an agent to submit CCPA requests for you. A business may require proof of your signed permission. The Delete Act requires the deletion mechanism to support authorised agents.

Deadlines and enforcement

A business must respond to a verifiable request within 45 calendar days. It may take a further 45 days when reasonably necessary if it tells you within the first 45.

DROP opened on 1 January 2026. Since 1 August 2026, brokers must access it at least once every 45 days and process the deletion requests they find. The state says a status update can take up to 90 days. A broker that cannot verify a request must treat it as an opt-out of sale or sharing. First-party data, data exempt by statute and publicly available information are not covered.

The CPPA can fine a business up to $2,500 per violation, or up to $7,500 for intentional violations and those involving consumers it knows are under 16. A broker that fails to delete faces $200 per deletion request per day. You can complain to the CPPA or the Attorney General, though neither acts as your lawyer. Private lawsuits under the CCPA are limited to certain data breaches.

How this applies to AI and face data

Biometric information used to establish identity is personal information, and processing it to uniquely identify someone makes it sensitive personal information. The exclusion for publicly available information does not cover biometric information a business collected about you without your knowledge.

The statute says personal information can exist in 'artificial intelligence systems that are capable of outputting personal information'. We have not found a regulation or court decision that settles what a deletion request requires for such a system.

A deletion request can reach stored data such as source images, dataset entries and profiles. It is not a way to remove a person from an already-trained model.

What you can do yourself

These steps are free and do not need UltoPulto.

  1. Send a request using the methods in the business's privacy policy and keep a dated copy.
  2. File a free deletion request with all registered data brokers at privacy.ca.gov/drop.
  3. Check the data broker registry to see whether a company is registered.
  4. If a business misses the 45-day deadline, complain to the CPPA or the Attorney General.

What UltoPulto can do

  • Send deletion and opt-out requests to people-search sites and data brokers, citing the CCPA.Built
  • Send access, deletion and objection requests to AI model providers.Built
  • Keep an evidence trail of each request, reply and deadline.Built
  • Follow up after the 45-day deadline, then draft a regulator complaint for you to review and sign.Built
  • Deliver requests only to contacts our team has verified. Until then a request stays a draft.In rollout
  • Guided DROP filing and tracking of broker compliance.Planned

What UltoPulto cannot do

  • We are not a law firm and do not give legal advice.
  • No service can remove a person from an AI model that has already been trained.
  • Outcomes depend on the organisation and the regulator. A business can refuse where a legal exception applies.
  • We do not file in DROP for you today. It is free to use directly.

Sources

  1. 1California Consumer Privacy Act (CCPA)State of California Department of Justice, Office of the Attorney GeneralGovernmentOpened 2026-10-04
  2. 2California Civil Code section 1798.140 (CCPA definitions)California Legislative InformationLawOpened 2026-10-04
  3. 3California Civil Code section 1798.155 (administrative fines)California Legislative InformationLawOpened 2026-10-04
  4. 4California Civil Code section 1798.99.86 (Delete Act: accessible deletion mechanism)California Legislative InformationLawOpened 2026-10-04
  5. 5California Civil Code section 1798.99.82 (Delete Act: registration and fines)California Legislative InformationLawOpened 2026-10-04
  6. 6Information for Data Brokers: Delete Request and Opt-Out Platform (DROP)California Privacy Protection AgencyGovernmentOpened 2026-10-04
  7. 7Delete Request and Opt-out Platform (DROP)State of CaliforniaGovernmentOpened 2026-10-04
  8. 8How DROP worksState of CaliforniaGovernmentOpened 2026-10-04

Questions

Is DROP free, and who can use it?

Yes. DROP is run by the State of California, is free, and is open to California residents.

Can I sue a company that ignores my deletion request?

Not under the CCPA, which allows private lawsuits only for certain data breaches. The route for an ignored request is a complaint to the California Privacy Protection Agency or the Attorney General.

Does DROP remove my data from every company?

No. It reaches registered data brokers only, and some data is exempt. A business you deal with directly needs a separate CCPA request.

Can a CCPA request remove me from a trained AI model?

The law does not clearly say what deletion means for a trained model, and no service can remove a person from one. A request can target stored personal information such as source images and dataset entries.