Start with a deletion or opt-out request to the data broker. File a complaint when the broker ignores, rejects, or appears to violate that request. California residents have an additional option: the state’s Delete Request and Opt-out Platform, known as DROP, can send one verified request to registered data brokers.
The correct route depends on your goal, where you live, and what the broker did. A request asks a company to take action on your data. A complaint tells a regulator about noncompliance, deception, a security problem, or another possible violation.
Decide whether you need a request or a complaint
| Your goal | First step | Possible escalation |
|---|---|---|
| Delete your profile | Send a deletion request to the broker, or use DROP if you qualify | State privacy regulator or attorney general |
| Stop sale or sharing | Send a specific opt-out request | State regulator if the broker continues the activity |
| Correct inaccurate information | Identify the exact incorrect field and request correction | Regulator or a separate dispute process if the data is used for eligibility decisions |
| Report a deceptive privacy promise | Save the advertisement, terms, and response | FTC’s ReportFraud service |
| Report a breach or weak security practices | Preserve the breach notice and explain what was exposed | FTC and the appropriate state regulator |
A regulator complaint usually does not function as an instant deletion order. Make the direct request first unless there is a good reason not to, then use the request record as evidence.
Gather evidence before contacting anyone
Create a small evidence file before you submit anything. Include:
- The broker’s exact name and website. People-search websites, marketing databases, consumer reporting agencies, and identity-monitoring services may have different rules and complaint routes.
- The identifiers that may match your record. List current and former names, email addresses, phone numbers, and addresses only when they are relevant to the broker’s records.
- A copy of the privacy or opt-out page. Save a screenshot or PDF showing what the company promised and how you submitted the request.
- The date and time of each action. Record when you submitted the request, received an email, completed verification, or noticed that data remained available.
- Confirmation numbers and messages. Keep automated receipts, case numbers, denial notices, and requests for more verification.
- The specific problem. Write down the data that is wrong, the sale or disclosure you believe occurred, or the promise the company failed to honor.
- Evidence of impact. If the information contributed to fraud, harassment, an unwanted solicitation, or another concrete problem, describe what happened and when.
- The minimum necessary identity proof. Don’t send a full Social Security number or an unredacted identity document by ordinary email. Use the broker’s official verification channel and redact unrelated details when the channel permits it.
A clear timeline is more useful than a long accusation. Use a simple log:
| Date | Action | Result |
|---|---|---|
| March 4 | Submitted deletion request | Confirmation number received |
| March 8 | Completed identity verification | Broker said review was pending |
| April 20 | Checked the profile again | Information still appeared |
California DROP: one request for registered data brokers
California residents can use the California DROP platform to submit a verified deletion request to data brokers included in the state system. The request is designed to cover deletion and an opt-out from the sale or sharing of personal information.
DROP is not available simply because a person has a California mailing address. Before submitting a request, the platform requires verification that you are a California resident under the definition used by California regulations. Residency verification is handled through California’s identity-verification system. If the available verification providers can’t confirm your residency, the platform says you may request a review of that classification under the applicable California regulation.
How to use DROP
- Open the official DROP platform and review its terms.
- Complete the identity and California residency verification.
- Enter the personal information you know may help brokers match your records, such as email addresses, phone numbers, names, and addresses.
- Submit the deletion and opt-out request.
- Save the confirmation page and your eight-digit DROP ID.
- Check the request status later and add information if the platform allows you to improve the match.
- Save each status update or broker response.
The official explanation of how DROP works says data brokers will begin processing requests in August 2026. Starting August 1, 2026, data brokers must access the accessible deletion mechanism at least once every 45 days and process deletion requests, subject to limited exceptions.
That 45-day rule is an access cycle, not necessarily a promise that every consumer will see a completed deletion within 45 days. The same California guidance says status updates can take up to 90 days to appear. If a status is missing or appears incorrect, keep the DROP ID and use the current instructions from the California Privacy Protection Agency’s data broker page.
DROP has limits:
- It covers registered data brokers included in the platform, not every business that has ever received your information.
- The number of participating brokers can change, so check the platform rather than relying on an old coverage figure.
- Statutory exceptions can limit what a broker must delete.
- Removing a broker’s copy doesn’t necessarily remove the original public record or information held by a separate, nonregistered company.
- The access-fee language on the CPPA page concerns data brokers downloading deletion lists. Don’t treat that broker-side requirement as a consumer fee or as a reason to buy a third-party service.
Send a direct deletion or opt-out request
If you aren’t eligible for DROP, or if a company is outside its coverage, use the broker’s privacy request page or privacy email address. An ordinary marketing unsubscribe link may stop emails without deleting a profile, so use the company’s privacy-rights process when one is available.
State exactly what you want:
- Deletion: Remove personal information associated with the identifiers you provide.
- Opt-out: Stop selling or sharing your information where the applicable law or company policy provides that option.
- Correction: Fix a specific inaccurate data field.
- Disclosure: Tell you what categories of information the company maintains and how it uses or shares them, if that right applies.
You can request more than one outcome. Ask the company to confirm each one separately.
Data deletion and opt-out template
Subject: Request to delete personal information and stop sale or sharing
Hello [Broker privacy team],
I am [full name]. Please use the following information to locate records about me:
Name: [name and former names, if relevant]
Email address: [email address or addresses]
Phone number: [phone number or numbers]
Current or former address: [address, if relevant]
I request deletion of personal information associated with these identifiers. I also request that you stop selling or sharing my personal information where that right applies. If applicable, please treat this as a request under the privacy law that covers my request.
Please confirm:
1. What verification you need from me;
2. Whether the deletion request was completed;
3. Whether the opt-out was completed;
4. Any information you retained and the exception or reason for retaining it; and
5. The date and method of your final response.
Please send verification instructions through your secure privacy-request process. I will provide only information reasonably needed to identify and verify my record.
Name: [name]
Email for response: [email]
Date: [date]
Follow the broker’s verification instructions, but be cautious. If the company asks for an identity document, use its official portal rather than an unfamiliar link. Don’t provide extra information merely because it might help the company create a more detailed profile.
Accuracy correction template
Subject: Request to correct inaccurate personal information
Hello [Broker privacy team],
Your record about me appears to contain this inaccurate information:
Information shown: [quote or describe the exact field]
Correct information: [provide the correct detail]
Where I saw it: [URL, screenshot, report, or date]
Please correct the record or explain why you cannot do so. Please also tell me the source of this information and whether it was shared with another business, if that information is available under the law that applies to my request.
Please confirm receipt and provide a written response.
Name: [name]
Matching identifiers: [email, phone, or address]
Date: [date]
If the company uses the information in a consumer report for credit, employment, housing, or insurance decisions, a privacy request may not replace the formal dispute process that applies to that report.
Escalate a nonresponse or suspected violation
FTC complaints
The Federal Trade Commission is a useful route for suspected deception, unfair practices, and certain privacy or security concerns. For example, an older FTC enforcement action involving an online data broker concerned claims that consumers could pay to “lock” their records. The example is not a current deadline, but it shows why you should save the broker’s exact promises rather than paraphrasing them.
Submit the complaint through ReportFraud.gov. Include:
- The broker’s legal and trading names;
- The date you created an account or submitted a request;
- The exact deletion, opt-out, or privacy promise;
- Your request and the broker’s response;
- Screenshots, receipts, and confirmation numbers;
- What information remained visible or was allegedly sold;
- Any specific harm or risk you experienced.
The FTC may use complaints for enforcement and law-enforcement intelligence, but it doesn’t promise to resolve an individual deletion request or provide a set response time. Keep pursuing the direct request and any state remedy that applies.
State attorney general and privacy regulator complaints
A state attorney general or privacy regulator may be appropriate when a broker ignores a privacy request, fails to follow a state requirement, operates without required registration, or exposes personal information. The correct agency depends on your residence, the broker’s conduct, and the law involved.
Before submitting the complaint:
- Check the agency’s current eligibility rules.
- Attach the direct request and the company’s response.
- Give the agency a short timeline.
- Explain which promise, right, or requirement you believe was not followed.
- Ask for the result you want, such as review of the company’s conduct or correction of the record.
- Remove unnecessary Social Security numbers, account passwords, and financial information from attachments.
A complaint may lead to an inquiry or enforcement action, but agencies decide which matters they pursue. It isn’t a substitute for a private request to the company.
Vermont complaints
Vermont’s Attorney General data broker page describes the state’s Data Broker Regulation legislation, Act 171, which took full effect on January 1, 2019. That framework should not be presented as a universal Vermont deletion portal.
If you’re reporting a Vermont data broker, use the Attorney General’s current complaint instructions and explain whether the issue concerns registration, disclosure, security, or a failure to honor a request. The linked page is background information, so verify the current form and contact method before sending personal documents.
If GDPR or UK GDPR applies
California DROP and U.S. regulator complaints don’t create rights under the GDPR or UK GDPR. If you live in the European Union, European Economic Area, or United Kingdom and the relevant privacy law applies, contact the business that controls the data first. You may request erasure under Article 17 or object to certain processing under Article 21.
If the response is missing or inadequate, complain to the data protection authority for the relevant country or territory. The law has exceptions, and the applicable response period and regulator depend on the facts. Don’t assume that a broker’s international website automatically makes every U.S. complaint a GDPR matter.
Complaint templates
Follow-up after a missed response
Subject: Follow-up on privacy request submitted [date]
Hello [Broker privacy team],
On [date], I submitted a request to [delete my personal information, stop sale or sharing, or correct inaccurate information]. The confirmation or case number is [number].
I have not received a complete response. Please confirm the status, identify any verification still required, and explain any exception or reason for refusing the request.
I have attached the original confirmation and relevant screenshots. Please respond through your normal privacy-request channel.
Name: [name]
Matching identifiers: [email, phone, or address]
Date: [date]
FTC complaint summary
Company: [broker name and website]
Issue: [deceptive promise, ignored opt-out, security concern, or other issue]
Timeline:
- [date]: [what the company promised or what happened]
- [date]: [request submitted]
- [date]: [response or lack of response]
Evidence attached:
- [privacy policy or advertisement]
- [request confirmation]
- [response]
- [screenshots or breach notice]
Requested action:
Please review the company’s conduct. I understand that submitting this complaint does not guarantee an individual deletion or refund.
Contact information:
[name and safe contact details]
GDPR erasure request
Subject: Request for erasure under Article 17 GDPR
Hello [data controller or privacy team],
I request erasure of personal data associated with these identifiers:
[name]
[email address]
[other matching identifier]
Please confirm the scope of the data you hold, whether the erasure request is complete, and whether any legal exception prevents deletion. If you refuse all or part of the request, please state the reason and explain how I can contact the relevant supervisory authority.
Date: [date]
Name: [name]
Timelines and follow-up
Don’t use one deadline for every request.
- DROP: Beginning August 1, 2026, brokers must access the mechanism at least every 45 days. California’s guidance says status updates can take up to 90 days.
- Direct broker requests: The deadline depends on the law that applies, the request type, and the company’s verification process. Use the date of receipt and the deadline stated in the company’s response.
- FTC and attorney general complaints: Review times vary, and neither route guarantees a personal resolution.
If the company misses its stated deadline, send one concise follow-up with the original confirmation attached. If there’s still no meaningful response, submit the evidence packet to the appropriate regulator. Avoid sending multiple vague requests that make the timeline harder to follow.
Manual requests versus paid opt-out services
Manual requests cost nothing and give you control over what information you disclose. They can become difficult when several brokers hold similar records.
A paid service may submit requests to multiple sites and monitor results, but it doesn’t create a new legal right or guarantee that every broker will comply. Before paying, check:
- Which broker categories and websites are covered;
- Whether the service handles deletion, opt-out, or both;
- What identifying information it collects from you;
- How it stores and deletes your information;
- How often it checks for a reappearing profile;
- The subscription price and cancellation process; and
- What evidence it provides if a broker refuses or cannot find a record.
For a small number of brokers, a spreadsheet and saved confirmations are usually enough. For broader monitoring, compare the service’s coverage and privacy practices rather than relying on a claimed success percentage.
Common mistakes to avoid
- Treating a marketing unsubscribe as a full privacy request;
- Assuming DROP covers every data broker or every downstream copy;
- Confusing the 45-day DROP access cycle with a guaranteed 45-day deletion;
- Filing with the FTC without first preserving the direct request;
- Describing inaccurate data generally instead of identifying the exact field;
- Sending a complete identity document or Social Security number through an unverified email address;
- Paying a service without checking its recurring billing and cancellation terms;
- Assuming a regulator complaint will produce compensation or immediate deletion; and
- Failing to check again after the broker confirms deletion.
Frequently asked questions
Can I use California DROP if I live in another state?
No. DROP requires verification that you are a California resident under the platform’s applicable definition. If you live elsewhere, use the broker’s own privacy process and check the law and regulator route for your state.
Does a complaint to the FTC delete my information?
No. The FTC can use complaints to identify patterns and investigate businesses, but its complaint system is not an individual deletion queue. Send the deletion or opt-out request to the broker as well.
Does an opt-out delete data already held by a broker?
Not necessarily. Deletion and opting out of sale or sharing are separate outcomes, and legal exceptions may apply. Ask the broker to confirm each outcome separately.
What should I do if DROP shows no result after 90 days?
Check the status using your eight-digit DROP ID, confirm that your identifying information is accurate, and save the status page. If the result still appears missing or incorrect, follow the current CPPA instructions and attach your confirmation and timeline.
Start by identifying the broker, saving its privacy policy, and sending a precise request. Put the confirmation date on your calendar; if the response is incomplete, escalate with the same organized evidence instead of starting over.