Getting your
Trinity Audioplayer ready... California’s new, first-of-its-kind “DROP” program enabling residents to have personal information deleted by data brokers depends on companies that have frequently failed to follow privacy law already on the books, new research from Stanford University suggests.
More than 600 companies have registered with the state as data brokers under California’s first-of-its-kind 2023 Delete Act. Under that law, California’s privacy regulator CalPrivacy created the DROP platform, a one-stop shop for Californians to have much of their personal data purged by companies that collect and sell everything from real-time locations to information related to reproductive health and gender identity. As of last week, about 520,000 California residents had signed up.
However, Stanford researchers reported in a new paper that fewer than 1 in 10 of the data brokers who have registered for the DROP program had complied fully with transparency requirements of the California Consumer Privacy Act of 2018, that requires them to respond to data-deletion requests by individual consumers and remove information. Large numbers of data brokers threw up friction and “dark patterns” that made it harder for consumers to get their information removed, the researchers said.
On transparency, the researchers analyzed the websites and privacy policies of the 522 data brokers registered at the time, to determine their compliance between June and September 2025 with the requirement to report the number of data-deletion requests they had received, and to post a privacy policy. Separately, the researchers analyzed a random sample of 250 of the brokers’ online-request processes, identifying friction and dark-pattern design features, including 21% of brokers making consumers solve CAPTCHA puzzles, and 43% forcing people to resubmit the same form multiple times or submit multiple forms collecting the same information.
“Clearly there have been companies not taking this seriously,” said report co-author Jennifer King, privacy and data policy fellow at the Stanford University Institute for Human-Centered Artificial Intelligence. King said she thinks many companies she and her colleagues found noncompliant with the privacy law believe state privacy regulators are too overwhelmed by the amount of data collection they’re charged with policing, or that the regulators don’t understand the industry well enough to enforce privacy laws effectively.
“The Stanford report was excellent,” said CalPrivacy Executive Director Tom Kemp, in revealing many data brokers’ failure to follow the privacy act.
Kemp emphasized the actions his agency had taken under that law against noncompliant companies and said Cal Privacy will continue with enforcement and auditing. He also pointed to the work CalPrivacy is doing to make sure data brokers register for the DROP program.
So far, the agency has fined more than a dozen data brokers for failing to register under the Delete Act, with penalties of $200 per day mostly totaling $30,000 to $60,000, Kemp said. He believes those sanctions have rippled through the data broker industry, driving up registrations.
But the Stanford finding of widespread noncompliance with privacy law “is really concerning,” and shows the need for stronger enforcement, said Lena Cohen, a staff technologist and privacy expert at the Electronic Frontier Foundation, a San Francisco-based civil liberties nonprofit.
“If there are weak enforcement mechanisms, companies can sort of factor the low risk of enforcement into the cost of doing business, and keep violating our privacy,” Cohen said. “Unless companies face serious consequences for violating our rights, they’re unlikely to put privacy ahead of profits.”
Walnut Creek auto-industry marketing and consumer-data company AutoWeb was one of a handful of Bay Area data brokers named in the Stanford report as having transparency issues. The company’s parent firm One Planet Group, also of Walnut Creek, told this news organization that at the time of the research, AutoWeb had “an established privacy-request process” using a third-party compliance-management platform.
One Planet said it confirmed that AutoWeb’s privacy policy directed consumers to annual deletion-request numbers, but that it had not been able to determine whether the link to its metrics was working during the research period.
“AutoWeb treats privacy compliance as an ongoing operational responsibility,” One Planet said in a statement. “We regularly review our processes, monitor regulatory developments, participate in industry and regulatory discussions, and update our practices as requirements evolve.”
Of the more than 600 data brokers currently in CalPrivacy’s registry, 115 sell people’s precise locations. More than 40 sell identity data that can include Social Security numbers. Almost 70 sell information on people’s gender identity. Eight sell data related to reproductive health, and six sell information on union membership.
Data can be harvested from consumers when they use online apps — many of which track locations — use loyalty cards, browse the internet, marry, or engage in a multitude of other activities that leave a public record or digital trail.
Data brokers build dossiers — increasingly supercharged by artificial intelligence — to draw inferences about a person’s interests, family, politics, lifestyle, finances, sexual orientation and health. They sell those dossiers to advertisers and marketers, governments, landlords, employers, and in some cases, Kemp has said, anyone willing to pay, including scammers, spammers, fraudsters and identity thieves.
Kemp has cited reports of federal immigration-enforcement agencies buying data including location information from brokers, and women being tracked going to reproductive health clinics. People have been rejected for rental units based on data from brokers, Kemp said.
Before the DROP platform was released, Californians seeking to limit the sale of their personal information faced the laborious task of making hundreds of individual requests to data brokers. Now, using DROP should compress that process into the few minutes it takes to sign up for the platform, Stanford’s King said.
And with California’s privacy agency having spun up an enforcement “strike force” and taken aim at data broker malfeasance, there will be more scrutiny — and heavy penalties — for companies defying the law, Kemp said.
The DROP platform launched Jan. 1. Data brokers are required to start processing deletion requests by mid-September, and have until November to report to CalPrivacy and individual DROP participants what data they have purged.
Even before the deadlines, about a quarter of the registered brokers have reported back, Kemp said, adding that the average DROP participant has had data deleted by 50 brokers. People who signed onto DROP before Aug. 1 should be seeing deletion results, Kemp said.
In November, CalPrivacy announced the creation of the Data Broker Enforcement Strike Force, intended to police the data broker industry’s compliance with the Delete Act and state consumer privacy act. The latest state budget provided funding the agency is using to add several members to the strike force, Kemp said.
The $200-per-day fine for noncompliance with DROP could lead to penalties of millions of dollars per day, Kemp said, providing as a hypothetical example a company failing to delete 200,000 DROP users’ data getting hit with a penalty of $40 million per day. “Exposure to potential enforcement action is increasing now that data brokers have started processing requests through DROP,” Kemp said.
Cohen described CalPrivacy as “one of the strongest privacy-enforcement agencies in the country” that does “excellent enforcement work.” But, she argued, “no government agency can match the scale of privacy violations that are happening online today.”
Neither the privacy act nor the Delete Act allow for a key solution to the enforcement problem: the right for individuals and groups to sue companies on their own over data illegally collected or sold, Cohen said.
“As good as any enforcement agency is, we need to empower people to hold companies accountable when they violate your rights,” she said.
Stanford’s King said she’ll be watching closely as DROP’s effects come into focus.
“I hope that we really see change,” she said.