Compliance Desk · Privacy Request Desk · California DROP matching tool
California DROP matching tool: match the deletion list against your records, in your browser
Published · Last reviewed · by Agent Exchange
Registered data brokers must download their consumer deletion lists from California's Delete Request and Opt-out Platform (DROP) at least once every 45 calendar days since August 1, 2026, hash their own records the way DROP does, delete what matches, and report a status for every request within 45 days. This free page does the matching step on your computer: it reads the DROP ZIP or CSV files and your customer file, standardizes and SHA-256 hashes your identifiers by CalPrivacy's published rules, finds the matches, and writes the Id,Status response files plus a dated processing record. Nothing is uploaded to us.
navigator.sendBeacon('/drop-match/used', kind), a one-word counter (file, match, export or sample) with no data attached. Verify it: open your browser's developer tools on the Network tab while you use it, or go offline once the page has loaded.The tool
Works with the DROP download as delivered (ZIP with one Id,Hash CSV per list, plus a Removed file) and with any customer export in CSV, TSV, JSON or one-identifier-per-line TXT. Already-hashed columns (Base64 or hex SHA-256) are matched directly. Large files are fine; a 100,000-record file hashes in a few seconds.
1. DROP consumer deletion list
2. Your records
3. Cycle and file naming
What the tool does and does not do
- It does not connect to DROP. You download the lists and upload the responses yourself in the Data Broker Portal or through the API (
GET /data/download,POST /data/upload,POST /data/amend, headerX-API-KEY; getting started). - It does not delete anything or decide what is exempt. It tells you which DROP requests match which of your records and writes the files; deletion, service-provider instructions and exemption decisions (Civ. Code §§ 1798.105(d), 1798.145, 1798.146) are yours.
- Matching is exact-hash. A record matches only if your standardized identifier is byte-for-byte what the consumer typed into DROP after the same standardization. A different email address or an unparseable date of birth is a miss. The regulations also ask you to apply any other standardization you know will increase matches (Cal. Code Regs., tit. 11, § 7613(a)(1)(A)(vi)).
- Names must be first name and last name as DROP hashes them separately. A single full-name column is split at the last space (compound first names stay together), or at a comma for "Last, First".
- Test your own pipeline against the standardization and hashing tool in the DROP Sandbox; this page's rules were checked against every example CalPrivacy publishes (Working with the data).
Standardization and hashing rules (CalPrivacy technical specifications v1.2.0, July 2, 2026)
| Identifier | Rule | Published example |
|---|---|---|
| Remove whitespace, lowercase; keep dots, plus signs and everything else | Anna.Smith@Domain.com → anna.smith@domain.com | |
| Phone | Digits only; the last 10 digits (all digits if fewer than 10) | +1(415)555-9317 → 4155559317 |
| First and last name | Separate fields, hashed separately. Lowercase; accents folded (ö → o); Greek and Cyrillic transliterated by DROP's mapping; ß → ss, æ → ae, ø → o, ł → l; hyphens, apostrophes, spaces and punctuation removed; compound first names kept as one unit; Chinese, Japanese, Korean, Arabic and Hebrew unchanged | Juan Pablo → juanpablo; Björn O'Connor-López → bjorn / oconnorlopez |
| Date of birth | YYYYMMDD, four-digit year | July 4, 1985 → 19850704 |
| ZIP | Alphanumerics only; ZIP+4 loses the +4; lowercase; leading zeros removed; first five characters | 91790-3771 → 91790; 00712345 → 71234; M1B 1A1 → m1b1a |
| VIN | Alphanumerics only, lowercase, 17 characters | 1HGCM82633A004352 → 1hgcm82633a004352 |
| Mobile advertising ID | Hex characters only, lowercase, 32 characters | a3f1c2d4-5678-90ab-cdef-1234567890ab → a3f1c2d4567890abcdef1234567890ab |
| Connected TV ID | Alphanumerics only, lowercase, 8 to 32 characters | SmartTV_9F8E7D6C → smarttv9f8e7d6c |
| Composite lists (NDZ, NameVIN) | Hash each field (SHA-256, UTF-8, Base64), concatenate the Base64 strings in order (first + last + DOB + ZIP; first + last + VIN), hash the concatenation again | Danielle Johnson, 1985-07-04, 91790 → PQOfn1RffEKmqMmNAzDKKaoZCwxWbQZkQzPWmQo9REA= |
All hashes: SHA-256, UTF-8 input, Base64 output. The regulation text (§ 7613(a)(1)(A)) states the rules in words; the technical specifications give the operative detail and worked examples, and the API reference (OpenAPI spec) repeats them. Source: https://privacy.ca.gov/drop-for-data-brokers/technical-specifications/working-with-data/, read 2026-09-30.
The obligation, from the primary sources
- Who. A "data broker" is a business that knowingly collects and sells to third parties the personal information of a consumer with whom it does not have a direct relationship; entities are excluded to the extent the FCRA, GLBA, California's Insurance Information and Privacy Protection Act or the HIPAA-related exemption in § 1798.146 cover them (Civ. Code § 1798.99.80(c); leginfo.legislature.ca.gov). DROP lets consumers send one request to "over 600 registered data brokers" (privacy.ca.gov/drop, read 2026-09-30).
- Dates. The Agency had to establish the mechanism by January 1, 2026; consumers have been able to submit requests since January 2026. Beginning August 1, 2026, a data broker shall access DROP at least once every 45 days and, within 45 days after receiving a request, process it and delete all personal information related to the consumer; requests it cannot verify are processed as opt-outs of sale or sharing; service providers and contractors must be directed to do the same (§ 1798.99.86(a), (c)). After deleting, the broker must keep deleting the consumer's new personal information at least every 45 days and must not sell or share it (§ 1798.99.86(d)). An independent third-party audit is due beginning January 1, 2028 and every three years; the report is kept six years and produced within five business days of the Agency's request (§ 1798.99.86(e)).
- Penalties. $200 per deletion request for each day the broker fails to delete as required, plus the Agency's investigation and administration costs (§ 1798.99.82(d)); $200 for each day of failing to register plus the fees due (§ 1798.99.82(c)); administrative actions may be brought within five years (§ 1798.99.89). Registration runs January 1–31 each year; the 2026 fee is $6,000 plus a card-processing fee of up to 2.99% (Cal. Code Regs., tit. 11, § 7600; fees page). Brokers that started in 2026 pay a first-access fee that steps down monthly from $6,000 (January) to $500 (December) (§ 7611).
- Regulations. Cal. Code Regs., tit. 11, §§ 7600–7622 (Data Broker Registration and Accessible Deletion Mechanism) were adopted September 26, 2025, approved by the Office of Administrative Law on November 6, 2025, and took effect January 1, 2026 (cppa.ca.gov/regulations/drop.html; text). § 7610: create a DROP account and select every list whose identifiers appear in your records (fewer if they would match exactly the same consumers); § 7612: download the selected lists at least every 45 calendar days, manually or by automation; after the first download each list contains only new or amended requests; a failed automated connection must be reported in writing through the account within 45 days; § 7613: standardize (lowercase; remove special characters, folding non-English letters; date of birth YYYYMMDD; ZIP first five; phone last ten digits) and hash with the algorithm the list provides; for multi-identifier lists hash each field, combine the hashes without separators and hash again; on a match delete all associated personal information including inferences ("delete" means permanently and completely erasing, deidentifying or aggregating, with backups deleted when restored or accessed); when several consumers share a matched identifier, opt them all out of sale and sharing; keep the minimum personal information needed to keep honoring the request; keep unmatched lists to screen newly collected records before sale or sharing; § 7614: report a response code per transaction identifier (record deleted, record opted out of sale, record exempted, record not found), before the next download when uploading manually, as a CSV in the format of the downloaded list; § 7616: DROP data may be used only for compliance, never sold or shared, and consumers may not be contacted to verify their requests.
- Format. Downloads are a ZIP with one UTF-8 CSV per selected list, columns
Id,Hash: the Id is a 12-character case-sensitive Base62 work item identifier, the Hash is SHA-256 Base64. Six lists:NDZ(first name + last name + date of birth + ZIP),Email,Phone,MAID,NameVIN,CTVID. Cancelled requests arrive in aRemovedfile with aListTypecolumn and need no status. Responses use the headerId,Statuswith codes 2 Exempted, 3 Deleted, 4 Opted out, 5 Not found, named<YYYYMMDD>_<DataBrokerId>_<DataType>[_<Suffix>].csv; DROP rejects a repeated file name and a wrong header. Production APIhttps://api.drop.privacy.ca.gov, sandbox/sandbox; 429 means wait 30 seconds (working with the data, reference, integration workflow, all read 2026-09-30).
Questions data brokers ask
Does any of our data reach your server?
No. The page has no third-party scripts; files are read with the browser's File API and hashed with the Web Crypto API on your computer. After the page loads, the only request it makes is navigator.sendBeacon('/drop-match/used', kind) where kind is one of the words file, match, export or sample, so we can count that the tool was used. Open your browser's developer tools (Network tab) while you use it, or go offline after the page has loaded: it keeps working.
Which hashing does DROP use?
SHA-256 over the standardized identifier encoded as UTF-8, output as Base64 (44 characters, usually ending in =). The NDZ and NameVIN lists are composite: each field is hashed, the Base64 strings are concatenated in order, and the result is hashed again (CalPrivacy technical specifications, Working with the data, v1.2.0).
Our records are already hashed, or hex-encoded. Can we still match?
Yes. Columns whose values are SHA-256 hashes in Base64, Base64url or 64-character hex are detected (or can be marked as already hashed) and compared directly. They must have been produced with DROP's standardization rules to match.
What do we upload back to DROP?
One CSV per list with the header Id,Status and a numeric status for every request: 2 Exempted, 3 Deleted, 4 Opted out, 5 Not found. Use the downloaded file name; add an underscore suffix of up to 10 alphanumeric characters for a second upload of the same list. Upload manually in the Data Broker Portal or POST /data/upload (multipart/form-data, field files, header X-API-KEY). Corrections go to POST /data/amend.
How often, and by when?
Access DROP to download your selected lists at least once every 45 calendar days since August 1, 2026, and report the status of every request within 45 days of downloading it (Civ. Code § 1798.99.86(c); Cal. Code Regs., tit. 11, §§ 7612(a), 7614). The cycle restarts at each download.
What does the processing record prove?
It is your own dated record of the matching step: the SHA-256 fingerprint and row counts of each DROP file and of your records file, the columns used, the statuses you assigned, the cycle dates, and a fingerprint of the record itself. Keep it with DROP's upload confirmation emails. It is not an audit report (the independent audit begins January 1, 2028, § 1798.99.86(e)) and not legal advice.
Run your privacy request desk here (free)
The Delete Act is one of the request channels a data broker must answer; consumers also send CCPA access, deletion, correction and opt-out requests directly, with a 45-day clock and 24-month records. The Privacy Request Desk gives you a hosted intake form, ticket numbers, deadlines, a requester status page and an exportable log. Create a Privacy Request Desk Free privacy request form generator · Data broker opt-out guides (consumer side) · State privacy laws
Sources read 2026-09-30: Civ. Code §§ 1798.99.80–1798.99.89 (leginfo); statute as effective Jan. 1, 2026 (CPPA PDF); Cal. Code Regs., tit. 11, §§ 7600–7622 (CPPA PDF); rulemaking history; DROP for data brokers; Processing DROP requests; account creation, fees and registration; technical specifications: working with the data; reference; getting started; integration workflow; OpenAPI specification v1.2.0; Data Broker Registry. Software and information, not legal advice.
Compliance Desk by agentexchange.work · This service provides software and informational templates, not legal advice. Laws cited link to their primary sources; confirm your obligations with counsel. · Privacy · Terms · Free check · For requesters · Platform guides · Generators · Templates · Badges · Regulations · Compare · Reports · DMCA agents · llms.txt
All properties: network.agentexchange.work · Agent-Readiness Grade · Agent Economy Index · MCP Registry Integrity Report · ToolDrift · AI Visibility
Also from Agent Exchange: which banks, credit unions, colleges, school districts and government sites lack an accessibility statement, security.txt or HSTS (lists by card or USDC) · pay-per-call data and tools for agents · AI crawler checker.