Data broker laws overview: what you can force brokers to delete, and where

Data removal. Updated 2026-09-13. About 6 minutes to read.

If you live in California, submit one DROP request. Elsewhere, use your state or GDPR deletion rights where they exist and opt out site by site where they do not.

Data brokers collect, combine and sell information about people they have no direct relationship with: names, addresses, phone numbers, relatives, purchase history, location data and inferred interests. Whether you can make them delete it depends almost entirely on where you live.

California residents now have the strongest tool anywhere: one request through the state's DROP platform that registered brokers must process. People in the EU and UK have a general right to erasure against any company. Most Americans outside the privacy law states, and Australians, have far fewer rights than they assume.

This overview is current to September 2026. Laws in this area change quickly, so it notes what is in force and what is only proposed.

Why there is no single data broker law

Brokers fall between existing rules. They are not your bank, doctor or employer, so sector laws rarely cover them. In the US, most of what they sell is lawful to collect, including public records and marketing data, and there is no general federal privacy law. Where people do have rights, they usually come from general privacy laws that happen to apply to brokers, plus a small number of laws aimed at brokers specifically.

California: the Delete Act and DROP

California's Delete Act requires data brokers to register every year with the state privacy agency, which uses the public name CalPrivacy, and created the Delete Request and Opt-out Platform, known as DROP. California residents have been able to submit requests through DROP since 1 January 2026. From 1 August 2026, registered brokers must check DROP at least every 45 days, act on matching requests within 90 days by deleting the consumer's personal information, and treat requests they cannot resolve as opt outs of sale or sharing. Brokers that fail to process requests face penalties of 200 dollars per request per day.

  1. Go to privacy.ca.gov/drop and choose Get Started.
  2. Verify that you are a California resident, either by signing in with Login.gov or by entering basic details that the state checks against its own records.
  3. Add the identifiers brokers use to find you: name, email addresses, phone numbers and ZIP code, plus optional identifiers such as a mobile advertising ID or vehicle identification number, which improve matching.
  4. Submit once. You receive a DROP ID, the request goes to every registered broker, and you can return to check status and update your details.

DROP only reaches brokers registered in California. Unregistered brokers, people search sites operating overseas and information from public government records are not covered.

Other US states: registries and privacy rights

  • Vermont created the first data broker registry in 2018. It requires brokers to register and disclose their practices, but it does not give consumers a right to deletion.
  • Texas and Oregon also require data brokers to register with the state.
  • About 20 states now have comprehensive consumer privacy laws, including Virginia, Colorado, Connecticut, Texas and Oregon. Most give residents the right to access, delete and opt out of the sale of their personal data, subject to exemptions.
  • Several of these states require businesses to honour Global Privacy Control, a browser signal that opts you out of sale and sharing automatically.

Federal rules: narrow, but real

  • The Fair Credit Reporting Act applies when information is used for credit, employment, insurance or housing decisions. Background check companies covered by it must follow accuracy and dispute rules.
  • The Protecting Americans' Data from Foreign Adversaries Act of 2024 bars data brokers from selling Americans' sensitive data to foreign adversary countries or entities they control.
  • The FTC has used its unfair practices powers against location data brokers, including orders against X-Mode Social in January 2024 and against Gravy Analytics and Mobilewalla in December 2024 restricting the sale of sensitive location data.
  • The CFPB proposed a rule in 2024 to treat more data brokers as consumer reporting agencies, then withdrew it in May 2025.

EU and UK: GDPR reaches brokers directly

Under the GDPR and UK GDPR, a broker that did not collect data from you must still tell you it holds your data, and you can object to direct marketing at any time, which the company must honour without exception. Under Article 17, you can ask for erasure when the data is no longer necessary, when you withdraw consent, when you object and there are no overriding grounds, or when the processing is unlawful. Companies must respond within one month.

GDPR also applies to companies outside Europe that monitor or target people in the EU or UK. In practice, enforcement against US people search sites with no European presence is weak. In the UK, organisations have had to run their own data protection complaints process since 19 June 2026, so complain to the company first and then to the ICO.

Australia: correction, not deletion, for now

The Privacy Act gives Australians the right to access their information and to have inaccurate information corrected under Australian Privacy Principle 13. It requires organisations to destroy or de-identify information they no longer need, but there is no general right to demand erasure. Many small businesses are exempt, although businesses that trade in personal information for a benefit generally are not.

A statutory tort for serious invasions of privacy commenced on 10 June 2025, allowing people to sue in serious cases. On 31 August 2026 the government released an exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, with submissions closing on 18 September 2026. It proposes requiring consent before trading personal information and a right to erasure against large digital platforms. None of that is law yet.

What these laws still cannot do

  • Remove information from public records, such as property and court records, which brokers copy freely.
  • Stop a broker relisting you from a new data source after deletion.
  • Reach brokers with no presence in your jurisdiction.
  • Clean copies already sold to other companies, unless the law requires the broker to pass on your request.

Frequently asked questions

Is there a federal data broker law in the US?

No comprehensive one. Federal protection is limited to specific uses such as credit and employment decisions under the FCRA, sales to foreign adversaries, and FTC enforcement against unfair practices. Deletion rights come from state laws.

Can I use CCPA or DROP if I do not live in California?

No. Both apply to California residents. Some brokers honour deletion requests from everyone as a policy, so it is still worth asking, and residents of other privacy law states have their own rights.

Does GDPR apply to US people search sites?

On paper, often yes, if they target or monitor people in the EU or UK. In practice, regulators struggle to enforce against companies with no European presence, so opt out directly as well.

What does Australia's Privacy Act let me delete?

Not much directly. You can request access and correction, and organisations must destroy information they no longer need. A right to erasure has been proposed in the 2026 reform exposure draft, but only against large digital platforms, and it is not yet law.

What happens to brokers that ignore deletion requests?

In California, registered brokers that fail to process DROP requests face penalties of 200 dollars per request per day, plus enforcement by CalPrivacy. Under GDPR, regulators can fine up to 4 percent of global annual turnover, although most fines against brokers are far smaller.

Tools that help

Related guides

Sources