Data removal. Updated 2026-09-13. About 6 minutes to read.
If you live in California, submit one DROP request. Elsewhere, use your state or GDPR deletion rights where they exist and opt out site by site where they do not.
Data brokers collect, combine and sell information about people they have no direct relationship with: names, addresses, phone numbers, relatives, purchase history, location data and inferred interests. Whether you can make them delete it depends almost entirely on where you live.
California residents now have the strongest tool anywhere: one request through the state's DROP platform that registered brokers must process. People in the EU and UK have a general right to erasure against any company. Most Americans outside the privacy law states, and Australians, have far fewer rights than they assume.
This overview is current to September 2026. Laws in this area change quickly, so it notes what is in force and what is only proposed.
Brokers fall between existing rules. They are not your bank, doctor or employer, so sector laws rarely cover them. In the US, most of what they sell is lawful to collect, including public records and marketing data, and there is no general federal privacy law. Where people do have rights, they usually come from general privacy laws that happen to apply to brokers, plus a small number of laws aimed at brokers specifically.
California's Delete Act requires data brokers to register every year with the state privacy agency, which uses the public name CalPrivacy, and created the Delete Request and Opt-out Platform, known as DROP. California residents have been able to submit requests through DROP since 1 January 2026. From 1 August 2026, registered brokers must check DROP at least every 45 days, act on matching requests within 90 days by deleting the consumer's personal information, and treat requests they cannot resolve as opt outs of sale or sharing. Brokers that fail to process requests face penalties of 200 dollars per request per day.
DROP only reaches brokers registered in California. Unregistered brokers, people search sites operating overseas and information from public government records are not covered.
Under the GDPR and UK GDPR, a broker that did not collect data from you must still tell you it holds your data, and you can object to direct marketing at any time, which the company must honour without exception. Under Article 17, you can ask for erasure when the data is no longer necessary, when you withdraw consent, when you object and there are no overriding grounds, or when the processing is unlawful. Companies must respond within one month.
GDPR also applies to companies outside Europe that monitor or target people in the EU or UK. In practice, enforcement against US people search sites with no European presence is weak. In the UK, organisations have had to run their own data protection complaints process since 19 June 2026, so complain to the company first and then to the ICO.
The Privacy Act gives Australians the right to access their information and to have inaccurate information corrected under Australian Privacy Principle 13. It requires organisations to destroy or de-identify information they no longer need, but there is no general right to demand erasure. Many small businesses are exempt, although businesses that trade in personal information for a benefit generally are not.
A statutory tort for serious invasions of privacy commenced on 10 June 2025, allowing people to sue in serious cases. On 31 August 2026 the government released an exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, with submissions closing on 18 September 2026. It proposes requiring consent before trading personal information and a right to erasure against large digital platforms. None of that is law yet.
No comprehensive one. Federal protection is limited to specific uses such as credit and employment decisions under the FCRA, sales to foreign adversaries, and FTC enforcement against unfair practices. Deletion rights come from state laws.
No. Both apply to California residents. Some brokers honour deletion requests from everyone as a policy, so it is still worth asking, and residents of other privacy law states have their own rights.
On paper, often yes, if they target or monitor people in the EU or UK. In practice, regulators struggle to enforce against companies with no European presence, so opt out directly as well.
Not much directly. You can request access and correction, and organisations must destroy information they no longer need. A right to erasure has been proposed in the 2026 reform exposure draft, but only against large digital platforms, and it is not yet law.
In California, registered brokers that fail to process DROP requests face penalties of 200 dollars per request per day, plus enforcement by CalPrivacy. Under GDPR, regulators can fine up to 4 percent of global annual turnover, although most fines against brokers are far smaller.