When a data broker can deny a DROP deletion request

Written by Steven Machuca, Founder. Reviewed August 2026.

Every DROP deletion request gets one of four outcomes: deleted, exempted, opted out, or not found. Exempted is a real, lawful outcome. It isn’t a shortcut, and it isn’t optional paperwork either. It needs a ground that actually applies, a written policy behind it, and a record the 2028 audits can read.

Denials are common. Undocumented ones are the risk.

California brokers filed nearly 900,000 deletion denials in 2024, on the registry’s own numbers. That’s not an outlier. Of the 425 brokers that received at least one deletion request that year, only 59, about 14%, denied more requests than they granted. Most brokers grant far more than they deny. A high denial rate stands out against that pattern, and an auditor reading the file in 2028 is going to ask the same question a regulator would ask today: what ground supports each one.

What actually qualifies

DROP’s exemption grounds come from the CCPA itself: Civil Code §1798.105(d) and §§1798.145-1798.146. In practice, brokers apply them for reasons like security and fraud prevention, legal compliance, and conformity with federal law, the same short list already built into the 45-day DROP cycle’s exemption step. None of that list is a broker’s own call to interpret from scratch. A written, counsel-approved exemption policy has to exist before a cycle applies it, not get reconstructed afterward to explain a denial an auditor is already asking about.

What the file needs to hold

Status code 2, exempted, is what gets uploaded to the state for each of these records, but the state’s own File 2 upload is a status code, not a legal argument. The argument itself, which ground applied, who approved the policy, and when, lives in the broker’s own records, not in the file sent to California. That’s the same six-year retention duty the 2028 audit applies to every other part of the cycle: the download timestamp, the match, the deletion, and, just as much, the exemption.

The multi-consumer case isn’t an exemption

One identifier matching more than one person doesn’t get an exemption code. Status code 4, opted out, applies instead: when a single hash resolves to more than one consumer and the match can’t be narrowed to one person, the record gets treated as opted out for all of them. Exemption and multi-match are two different outcomes with two different codes, and the file should reflect which one actually happened.

Unsure whether an exemption a broker is already relying on would hold up on paper? Book a 20-minute call and bring an actual cycle’s records to look at.

Common questions

What are valid reasons to deny a DROP deletion request?

Grounds drawn from Civil Code §1798.105(d) and §§1798.145-1798.146, the same exceptions built into CCPA deletion rights generally: things like security and fraud prevention, legal compliance, and conformity with federal law. A broker applies these under a written, counsel-approved policy, not case-by-case improvisation.

How common are deletion denials?

Common enough that they're not automatically a red flag: California brokers filed nearly 900,000 in 2024. What stands out is volume without documentation. Only about 14% of brokers with at least one 2024 deletion request denied more than they granted; most grant far more than they deny.

Does an exemption need to be recorded anywhere beyond the status code?

The status code, 2, exempted, is what goes to the state in File 2. The exemption ground, the policy behind it, and counsel's approval stay in the broker's own six-year record, the same retention duty that covers every other part of the cycle. The 2028 audits read that file, not the code alone.