Stop Celebrating California’s DROP Law. Your Data Is Still Being Harvested.

You just got a shiny new ‘right’ to delete your data. It’s worthless.

California’s DROP (Data Deletion on Request and Proof) law goes into effect August 1. It sounds like a win: finally, you can demand that companies scrub your digital footprint. But here’s the brutal truth the headlines won’t tell you: the law gives you a key to a door that doesn’t exist.

You’ve probably already received those ‘we’ve updated our privacy policy’ emails. You’ve clicked ‘agree’ because the alternative is unthinkable. But even if you now send a deletion request, the system is designed to exhaust you. The real problem isn’t the law—it’s the invisible architecture of data harvesting.

Let’s be specific. Your phone, your TV, your car—they all generate an Advertising ID. That ID is a unique fingerprint that ad brokers use to track you across apps, websites, and devices. DROP has a field for you to request deletion of that ID. But can you actually find your Advertising ID on your Samsung TV? On your Apple devices? On the apps you use? No. You can delete data you can’t even see.

And then there are the unregistered data brokers. The law only applies to companies that are registered. But thousands of shadowy brokers operate without disclosure, buying and selling your location, your browsing habits, your health data. When you send a deletion request, it goes to the known players—the Googles and Facebooks. The unregistered ones? They never even get the memo.

This is the tension the law’s cheerleaders ignore: you have the legal right to delete data you cannot actually track, identify, or even name. The result isn’t privacy—it’s a bureaucratic maze designed to make you give up. The reader should feel violated, because you are.

Now, here’s the twist that nobody’s talking about. Some entrepreneurs see a golden opportunity: build a service that automatically sends deletion requests to every known broker every month. Sounds great, right? But think about it. To send a deletion request, you have to identify yourself. You have to provide your name, address, email, and often your phone number. Suddenly, you’re handing over even more data to a third party—and that third party now knows exactly which brokers you’re trying to escape. The burden of privacy remains entirely on the consumer, and the cure might be worse than the disease.

Let’s be clear: I’m not saying DROP is bad. It’s a step. But it’s a step on a treadmill. The real market opportunity isn’t compliance—it’s a meta-service that weaponizes automated deletion requests against unregistered brokers. But that service, if it ever arrives, will paradoxically expose more data than it deletes. Welcome to the paradox of digital privacy.

So what do you do? Stop relying on laws alone. Stop hoping that a form will save you. The only real defense is systemic, automated enforcement that doesn’t require you to know every broker’s name. Until we have that, your ‘right to delete’ is a permission slip to a locked room. You can ask to leave, but the door is invisible.

FAQ

Q: Isn't DROP better than nothing? Doesn't it at least force big companies to comply?

A: Yes, it's better than nothing. But 'better than nothing' is a low bar. The law only applies to registered companies. Unregistered brokers—which are the majority—remain untouched. And even for big companies, proving deletion is nearly impossible. You're relying on their honesty, not their compliance.

Q: What can I actually do to protect my data today?

A: Stop relying on laws. Use ad blockers, privacy-focused browsers, and VPNs. Opt out of data sharing at every device level. And demand that your state require automated, auditable deletion systems—not just a form you have to fill out. The burden should be on the data collector, not on you.

Q: Isn't the auto-deletion service idea a good solution?

A: It sounds good, but it creates a new vulnerability: you have to reveal your identity to send deletion requests. That service becomes a honeypot of exactly who you are and which brokers you're trying to escape. The paradox is that to delete your data, you have to expose more of it. The real fix is structural—make the system transparent, not more services.

📎 Source: View Source