r/PrivacyToolbox • u/EnthusiasmRoutine • 11d ago
Discussion California's DROP tool has a 25% broker compliance rate. How does enforcement actually work here?
California just passed half a million users on their DROP platform. The premise is incredibly efficient. You submit a single request, and the state forces all 654 registered data brokers to wipe your files. The privacy agency reported that nearly every user had data deleted by at least one broker.
Then you look at the raw numbers. Only a quarter of the registered brokers have even started processing these deletion requests. The legal mandate went into effect back in August.
If I configure a network and 75% of the endpoints drop the packets, the system is broken. An average user gets removals from roughly 40 brokers out of 654. Data brokers have a revenue model built on keeping your information. They have zero financial incentive to comply with a batch request out of goodwill.
A 25% compliance rate means the law is basically treated as an option right now. Does anyone know if California is issuing actual fines yet? I am genuinely curious if there is a hard penalty mechanism built into this or if the state is just sending warning letters to the non-compliant brokers.
Source: SFGATE