Thu 23 Jul 2026 / 10:46 ET
Kernel
Long Reads 3 min read

California’s broker deletion tool draws criticism for identity hurdles

Cory Doctorow says California’s DROP privacy system asks residents to prove too much before data brokers must delete their files.

Theo Lindgren

By Theo Lindgren / Columnist

California’s broker deletion tool draws criticism for identity hurdles
img: Pluralistic

California’s new Delete Request and Opt-out Platform, or DROP, is set to begin next month with a promise that sounds useful: residents can ask the state to make every data broker operating in California erase their personal data and the inferences built from it. Cory Doctorow, writing at Pluralistic, says the machinery around that promise turns privacy into an obstacle course.

Doctorow describes DROP as the next stage of California’s state-level privacy regime, arriving in the absence of a broad federal consumer privacy law. He notes that Congress has not passed a new federal consumer privacy statute since 1988, when it restricted disclosure of video rental records. In his account, state governments are left trying to restrain data brokers without banning the business outright.

The program is not a ban. According to Doctorow, it assumes brokers may collect, process and retain data unless a person completes a formal opt-out and deletion request. That design choice is the fight. Privacy advocates tend to treat consent as something a company should obtain before surveillance. DROP treats non-consent as paperwork.

How the process works

Doctorow says a California resident starting a DROP request must first create or use a Login.gov account. Login.gov requires identity checks that can include photographing identification documents and taking selfies through apps or web pages that control the device camera. Doctorow says that level of verification has a plausible purpose for Login.gov itself because the same credential can be used across sensitive government services, including tax and Social Security systems.

His complaint is that DROP then repeats parts of the process. After logging in with Login.gov, he says the user receives a text message at the phone number already tied to the account. The link opens a site that again uses the phone camera, this time to photograph the front and back of either a California driver’s license or a U.S. passport.

Doctorow says the user is then sent back to a computer to enter biographical information and additional identifiers, including a vehicle identification number. He argues that the California DMV already has that VIN for many residents and could supply it after the state has verified the person’s identity.

The system also asks for a mobile advertising identifier, according to Doctorow. That is the long device-level ID used by apps and ad systems to recognize a phone. Doctorow says users may need to dig through phone settings or install a separate app to retrieve it, even though apps and web flows are built to request that identifier directly.

He says DROP then asks for more biographical details, followed by phone and email verification codes. Doctorow’s objection is not that verification is useless in general. It is that Login.gov has already established control of the email address and phone number earlier in the same workflow.

The larger privacy argument

The Electronic Frontier Foundation has published an explainer on California’s DROP tool, and Doctorow urges Californians to use the system despite calling it inadequate. His reason is blunt: data broker files can feed scams, identity theft, discrimination and law-enforcement targeting, he argues.

Doctorow’s preferred policy is more direct: ban data brokers, or at least require explicit opt-in consent before commercial surveillance begins. He contrasts the work required to opt out with the lack of work required for a broker to start collecting data in the first place.

That is the policy defect DROP exposes. California is offering residents a deletion lever, but according to Doctorow’s walk-through, the state has wrapped that lever in repeated identity checks and manual data entry. For people trying to get out of broker databases, the burden remains on the watched, not the watchers.

This story draws on original reporting from Pluralistic.

More Long Reads/

view all ↗