Compliance Desk · Privacy Request Desk · California DROP matching tool

California DROP matching tool: match the deletion list against your records, in your browser

Published · Last reviewed · by Agent Exchange

Registered data brokers must download their consumer deletion lists from California's Delete Request and Opt-out Platform (DROP) at least once every 45 calendar days since August 1, 2026, hash their own records the way DROP does, delete what matches, and report a status for every request within 45 days. This free page does the matching step on your computer: it reads the DROP ZIP or CSV files and your customer file, standardizes and SHA-256 hashes your identifiers by CalPrivacy's published rules, finds the matches, and writes the Id,Status response files plus a dated processing record. Nothing is uploaded to us.

Nothing leaves your browser. The page has no third-party scripts; files are read with the File API and hashed with the Web Crypto API on your machine. The only request it makes after loading is navigator.sendBeacon('/drop-match/used', kind), a one-word counter (file, match, export or sample) with no data attached. Verify it: open your browser's developer tools on the Network tab while you use it, or go offline once the page has loaded.

The tool

Works with the DROP download as delivered (ZIP with one Id,Hash CSV per list, plus a Removed file) and with any customer export in CSV, TSV, JSON or one-identifier-per-line TXT. Already-hashed columns (Base64 or hex SHA-256) are matched directly. Large files are fine; a 100,000-record file hashes in a few seconds.

1. DROP consumer deletion list

2. Your records

3. Cycle and file naming

What the tool does and does not do

Standardization and hashing rules (CalPrivacy technical specifications v1.2.0, July 2, 2026)

IdentifierRulePublished example
EmailRemove whitespace, lowercase; keep dots, plus signs and everything elseAnna.Smith@Domain.com → anna.smith@domain.com
PhoneDigits only; the last 10 digits (all digits if fewer than 10)+1(415)555-9317 → 4155559317
First and last nameSeparate fields, hashed separately. Lowercase; accents folded (ö → o); Greek and Cyrillic transliterated by DROP's mapping; ß → ss, æ → ae, ø → o, ł → l; hyphens, apostrophes, spaces and punctuation removed; compound first names kept as one unit; Chinese, Japanese, Korean, Arabic and Hebrew unchangedJuan Pablo → juanpablo; Björn O'Connor-López → bjorn / oconnorlopez
Date of birthYYYYMMDD, four-digit yearJuly 4, 1985 → 19850704
ZIPAlphanumerics only; ZIP+4 loses the +4; lowercase; leading zeros removed; first five characters91790-3771 → 91790; 00712345 → 71234; M1B 1A1 → m1b1a
VINAlphanumerics only, lowercase, 17 characters1HGCM82633A004352 → 1hgcm82633a004352
Mobile advertising IDHex characters only, lowercase, 32 charactersa3f1c2d4-5678-90ab-cdef-1234567890ab → a3f1c2d4567890abcdef1234567890ab
Connected TV IDAlphanumerics only, lowercase, 8 to 32 charactersSmartTV_9F8E7D6C → smarttv9f8e7d6c
Composite lists (NDZ, NameVIN)Hash each field (SHA-256, UTF-8, Base64), concatenate the Base64 strings in order (first + last + DOB + ZIP; first + last + VIN), hash the concatenation againDanielle Johnson, 1985-07-04, 91790 → PQOfn1RffEKmqMmNAzDKKaoZCwxWbQZkQzPWmQo9REA=

All hashes: SHA-256, UTF-8 input, Base64 output. The regulation text (§ 7613(a)(1)(A)) states the rules in words; the technical specifications give the operative detail and worked examples, and the API reference (OpenAPI spec) repeats them. Source: https://privacy.ca.gov/drop-for-data-brokers/technical-specifications/working-with-data/, read 2026-09-30.

The obligation, from the primary sources

Questions data brokers ask

Does any of our data reach your server?

No. The page has no third-party scripts; files are read with the browser's File API and hashed with the Web Crypto API on your computer. After the page loads, the only request it makes is navigator.sendBeacon('/drop-match/used', kind) where kind is one of the words file, match, export or sample, so we can count that the tool was used. Open your browser's developer tools (Network tab) while you use it, or go offline after the page has loaded: it keeps working.

Which hashing does DROP use?

SHA-256 over the standardized identifier encoded as UTF-8, output as Base64 (44 characters, usually ending in =). The NDZ and NameVIN lists are composite: each field is hashed, the Base64 strings are concatenated in order, and the result is hashed again (CalPrivacy technical specifications, Working with the data, v1.2.0).

Our records are already hashed, or hex-encoded. Can we still match?

Yes. Columns whose values are SHA-256 hashes in Base64, Base64url or 64-character hex are detected (or can be marked as already hashed) and compared directly. They must have been produced with DROP's standardization rules to match.

What do we upload back to DROP?

One CSV per list with the header Id,Status and a numeric status for every request: 2 Exempted, 3 Deleted, 4 Opted out, 5 Not found. Use the downloaded file name; add an underscore suffix of up to 10 alphanumeric characters for a second upload of the same list. Upload manually in the Data Broker Portal or POST /data/upload (multipart/form-data, field files, header X-API-KEY). Corrections go to POST /data/amend.

How often, and by when?

Access DROP to download your selected lists at least once every 45 calendar days since August 1, 2026, and report the status of every request within 45 days of downloading it (Civ. Code § 1798.99.86(c); Cal. Code Regs., tit. 11, §§ 7612(a), 7614). The cycle restarts at each download.

What does the processing record prove?

It is your own dated record of the matching step: the SHA-256 fingerprint and row counts of each DROP file and of your records file, the columns used, the statuses you assigned, the cycle dates, and a fingerprint of the record itself. Keep it with DROP's upload confirmation emails. It is not an audit report (the independent audit begins January 1, 2028, § 1798.99.86(e)) and not legal advice.

Run your privacy request desk here (free)

The Delete Act is one of the request channels a data broker must answer; consumers also send CCPA access, deletion, correction and opt-out requests directly, with a 45-day clock and 24-month records. The Privacy Request Desk gives you a hosted intake form, ticket numbers, deadlines, a requester status page and an exportable log. Create a Privacy Request Desk   Free privacy request form generator · Data broker opt-out guides (consumer side) · State privacy laws

Sources read 2026-09-30: Civ. Code §§ 1798.99.80–1798.99.89 (leginfo); statute as effective Jan. 1, 2026 (CPPA PDF); Cal. Code Regs., tit. 11, §§ 7600–7622 (CPPA PDF); rulemaking history; DROP for data brokers; Processing DROP requests; account creation, fees and registration; technical specifications: working with the data; reference; getting started; integration workflow; OpenAPI specification v1.2.0; Data Broker Registry. Software and information, not legal advice.

Compliance Desk by agentexchange.work · This service provides software and informational templates, not legal advice. Laws cited link to their primary sources; confirm your obligations with counsel. · Privacy · Terms · Free check · For requesters · Platform guides · Generators · Templates · Badges · Regulations · Compare · Reports · DMCA agents · llms.txt
All properties: network.agentexchange.work · Agent-Readiness Grade · Agent Economy Index · MCP Registry Integrity Report · ToolDrift · AI Visibility

Also from Agent Exchange: which banks, credit unions, colleges, school districts and government sites lack an accessibility statement, security.txt or HSTS (lists by card or USDC) · pay-per-call data and tools for agents · AI crawler checker.