AnuSutraVedic Wisdom & Tech
Tech Explainers6 min readSeptember 6, 2026

What "Your Data Is Being Sold" Actually Means, and How to Actually Check

California just turned on a real, working tool that lets you send one request to over 600 registered data brokers at once. Here's what a data broker actually is, and the specific, concrete steps to find out what they have on you.

R
Ravindra ValandAuthor & Researcher at AnuSutra

A padlock icon representing digital privacy and security

"Your data is being sold" gets said constantly, usually as a vague, anxiety-inducing gesture rather than a specific, actionable claim. It's also, for a genuine category of company, literally and precisely true — not a metaphor for targeted advertising, but the actual, legal business model. Those companies are called data brokers, they're registered by name in public databases in several states, and as of 2026, there's a real, working tool that lets you tell all of them at once to delete what they have.

What a Data Broker Actually Is, Specifically

A data broker is a company whose core business is collecting personal information — from public records, purchase histories, app usage, loyalty programs, and dozens of other sources — and then compiling, packaging, and selling or licensing access to that compiled profile to whoever pays for it: advertisers, insurers, background-check services, and sometimes each other. Critically, a data broker generally has no direct relationship with you at all — you didn't sign up for their service or agree to their terms, which is exactly what makes this category different from a company like a retailer or a social network that at least has a reason to be holding your information in the first place. California alone currently has more than 600 companies registered by name in its official data broker registry, a hard, checkable number rather than a vague industry estimate, and that's just the companies that have registered in one specific state under one specific state's disclosure law — the real total operating without that specific registration requirement is considerably higher.

The New, Concrete Tool: California's DROP System

Here's the part of this that's genuinely new and worth knowing about specifically, rather than generic advice to "review your privacy settings." California's Delete Act created a centralized system called DROP — the Data Broker Requests and Opt-Out Platform — that lets a consumer submit a single deletion request that applies across every registered data broker in the state's registry at once, instead of the previous requirement to track down and separately petition hundreds of individual companies. Consumers were able to start submitting requests through DROP starting January 1, 2026. Data brokers themselves weren't required to actually start acting on submitted requests until August 1, 2026, and going forward, every registered broker has to check the system at least once every 45 days, retrieve any pending requests, and either delete the matched personal information (including inferences drawn from it) or report a specific legal exemption for why they haven't. This is a real, structural change in how this kind of request works — previously, a genuinely thorough opt-out effort meant contacting each broker individually, a process specialized (and often paid) removal services exist specifically because it was so tedious to do yourself.

It's worth being precise about what DROP does and doesn't cover: it applies to companies registered under California's specific data broker law, and its practical reach is strongest for California residents, though the delete requirement applies to your information regardless of what state you live in once a broker has it, since the law regulates the broker's conduct rather than requiring the requester to be a California resident specifically in every version of the rule. It's also not a complete solution to the underlying problem — it addresses registered data brokers specifically, not every company that might hold and monetize your data through some other business relationship you do have a direct connection to, like a retailer's own internal marketing data or an app you've actually installed and granted permissions to.

The Older, Broader Tools: CCPA and GDPR Requests

Outside the specific data-broker category, two existing legal frameworks give you a direct, enforceable way to ask any company holding your data what they actually have. Under the California Consumer Privacy Act, California residents have a Right to Know — the ability to request a specific accounting of what personal data a business has collected, shared, or sold about them — and a separate Right to Delete, requiring the business to delete that data on request, subject to a list of specific legal exemptions. Businesses subject to the CCPA are required to respond to a verified request within 45 days, and the law specifically requires them to offer at least two methods for submitting one, including a toll-free phone number.

For anyone in the EU, or dealing with a company that processes EU residents' data regardless of where the company itself is based, GDPR's Article 15 provides a similar but distinct mechanism, usually called a Data Subject Access Request (DSAR) — a formal request that obligates the company (with certain exceptions) to tell you what personal data they hold and why. A DSAR doesn't have to be complicated or formally lawyer-drafted to be valid; a plain, direct request citing the specific right you're invoking — something as simple as stating you're requesting deletion of your personal data under GDPR Article 17, or under CCPA/CPRA Cal. Civ. Code § 1798.105(a) for a California request — is generally sufficient to start the legal clock on a company's obligation to respond.

What Actually Checking This Looks Like in Practice

Put together, there's now a genuinely concrete, three-part path to actually finding out what's held about you, rather than a vague sense that "it's out there somewhere." First, use California's DROP system directly if it's available to you, since it's the single most efficient path for the specific data-broker category — one request, hundreds of companies, a legal 45-day compliance cycle behind it rather than a best-effort courtesy. Second, for any specific company you have an actual account or relationship with — a retailer, a social platform, an app — send a direct CCPA or GDPR request by name, since those rights apply company-by-company rather than through a centralized system the way the data-broker-specific DROP tool does. Third, understand the real limitation of both approaches honestly: they address current holdings and future collection going forward, they don't retroactively undo profiles that have already been sold, resold, and incorporated into other companies' own derived data products before your request was made — which is less a flaw in either specific tool than an honest description of how compounding a fully decentralized data economy actually was before any of this regulatory machinery existed to interrupt it.

Topics:PrivacyData BrokersCCPAGDPR
Ravindra Valand

Written by Ravindra Valand

Founder and researcher at AnuSutra. Tracing ancient Sanskrit scriptures (Vedas, Upanishads, Bhagavad Gita) directly from canonical Sanskrit manuscripts, exploring the nexus between contemplative spiritual practices and modern cognitive science.

What "Your Data Is Being Sold" Actually Means, and How to Actually Check | AnuSutra | AnuSutra