Since August 1, 2026 every registered California data broker must download its DROP deletion lists, match them against its own records, act on every request and report a status back. The lists contain only hashes. If your normalization is off by one character, nothing matches and the requests still count as unprocessed.
Normalizes and hashes a value exactly the way DROP's technical specification describes, so you can test your own pipeline. It runs entirely in your browser. Nothing you type is sent anywhere.
One record per line. Email or phone: one value per line. NDZ: first,last,dob,zip. NameVIN: first,last,vin.
You download a ZIP from the DROP portal or its REST API (with your broker API key). Each CSV has two columns, Id,Hash. After your first download you only receive new requests, plus a _Removed.csv file when consumers cancel. DROP never gives you raw names, emails or addresses, and it never includes a street address.
| List | What is hashed | Normalization (CPPA technical spec) |
|---|---|---|
| NDZ | first name + last name + date of birth + ZIP | Each part normalized and hashed, the four Base64 hashes joined, then hashed again |
| email address | Remove whitespace, lowercase. Keep dots and plus signs | |
| Phone | phone number | Digits only, last 10 digits |
| MAID | mobile ad ID (IDFA/GAID) | Hex characters only, lowercase, 32 characters |
| NameVIN | first name + last name + VIN | VIN: letters and digits only, lowercase, 17 characters |
| CTV ID | connected-TV identifier | Letters and digits only, lowercase, 8 to 32 characters |
Names: lowercase, accents folded to plain letters (ß→ss, æ→ae, ø→o, ł→l), Greek and Cyrillic transliterated, everything that is not a letter or digit removed ("Juan Pablo" → juanpablo). Chinese, Japanese, Korean, Arabic and Hebrew characters stay as they are. Date of birth: YYYYMMDD. ZIP: drop the +4, letters and digits only, lowercase, remove leading zeros, first five characters.
The ZIP leading-zero rule differs between the regulation, the technical spec and a proposed amendment. This tool follows the technical spec, which is what DROP itself uses. Test your own pipeline in the CPPA sandbox.
Match on exact hash equality for the same list type. A partial match (same name and date of birth, different ZIP) is not a match. If one identifier matches several people, opt all of them out of sale. Then report one status per request:
| Code | Status | Meaning |
|---|---|---|
| 2 | Exempted | Data is covered by an exemption (say which) |
| 3 | Deleted | Matched and deleted, including inferences; service providers and contractors told to delete |
| 4 | Opted out | Opted out of sale/sharing (e.g. one identifier matched several people) |
| 5 | Not found | No match. Keep it on a suppression list and check new data against it |
DROP will not release your next batch until the current one is fully reported.
CalPrivacy has announced 14 data-broker actions since late 2024, mostly for failing to register. In August 2026 LocateSmarter paid $116,490 (including fees), and the Cybba and SalesIntel orders require them to start processing DROP requests. As of October 3, 2026 no fine for failing to process DROP deletions has been announced. The first cycles close in late October.
C.F.A.I. is deciding whether to build a hosted DROP processor for small brokers. It does not exist yet, and there is nothing to sign up for or buy. If we build it, it would pull your lists through the DROP API, match them against hashes you create in your own browser (your raw consumer data would never leave you), keep your suppression list, upload the status file, keep an audit log and warn you before a deadline, with no sales call. The first DROP cycle would be free, with no card needed.
Planned pricing, if we build it
If this would help you, send a one-line "interested" to the address below, or as a reply to our email. That is all we ask. We read every message.
Everything on this page comes from the official CalPrivacy (California Privacy Protection Agency) pages and documents below. If anything here differs from them, they win.
Christian Fuhrmann, C.F.A.I. (CFAISolutions LLC), Sacramento, California. Contact: info@cfaisolutions.com.
We will never ask for your data, logins or payment by email.