More than 300,000 Californians signed up for the state's Delete Request and Opt-Out Platform in its first five months of operation, according to the California Privacy Protection Agency's June 2026 update. That single figure is the closest thing to an official, state-published consumer rights request volume count anywhere in the country. Every other state with a comprehensive privacy law either publishes no aggregate request data at all or describes its enforcement activity in vague terms rather than a specific number.
How many consumer rights requests has California processed through DROP?
California's Delete Request and Opt-Out Platform, known as DROP, is a free tool built by the California Privacy Protection Agency (branded CalPrivacy) that lets a resident submit one deletion and opt-out request that reaches every registered data broker at once. It went live on January 1, 2026, and by June 2, 2026, more than 300,000 Californians had signed up, according to the agency's own announcement marking the milestone.
That is a genuinely new kind of data point for privacy researchers. Unlike DSAR volume estimates from privacy-technology vendors, which measure requests processed for their own customer base and extrapolate outward, DROP's 300,000-plus figure is a direct count from the government platform residents actually use.
| Metric | Figure | Time period | Source |
|---|---|---|---|
| DROP signups | 300,000+ | First 5 months (Jan to Jun 2026) | CalPrivacy, June 2026 update |
| Complaint portal submissions | 10,000+ | Since portal launch in 2023 | CalPrivacy, 2025 Annual Report |
| Registered data brokers | 581 | As of June 2026 | CalPrivacy, June 2026 update |
Source: California Privacy Protection Agency (CalPrivacy), June 2026 platform update and 2025 Annual Report.
Every one of the 581 registered brokers is required to begin processing requests submitted through DROP by August 1, 2026. A business that has not reviewed how its own site handles a direct deletion or opt-out request, separate from the DROP channel that only covers registered data brokers, can generate a privacy policy that documents its own consumer rights process rather than leaving that disclosure outdated while regulators keep publishing numbers like these.
Which states actually publish consumer-request volume data?
California is the outlier, not the norm. CalPrivacy discloses signup counts, complaint totals, and registered-broker counts in a public annual report and periodic platform updates. Most other states with a comprehensive privacy law publish general enforcement guidance, a rulemaking calendar, or an FAQ page, but not a running count of how many consumer rights requests residents have actually filed.
Connecticut is a useful contrast. The state's 2025 CTDPA Enforcement Report, required annually under the law, describes the Attorney General's office issuing "dozens of notices of violation and warning letters" during the year, a qualitative range rather than a specific count. Colorado's Attorney General publishes guidance on the Colorado Privacy Act and its universal opt-out mandate, but as of this post's research had not released a public aggregate total of consumer requests or complaints the way California has.
| State | Publishes an aggregate request count? | What is public | Source |
|---|---|---|---|
| California | Yes | 300,000+ DROP signups, 10,000+ complaints, 581 registered brokers | CalPrivacy, 2026 |
| Connecticut | No | Qualitative language only ("dozens" of notices and warning letters) | CT Attorney General 2025 CTDPA Enforcement Report |
| Colorado | No | General guidance and rulemaking updates, no aggregate total found | Colorado Attorney General, CPA resource pages |
| Texas | No | No public consumer-request count identified for the TDPSA | Texas Attorney General |
Source: State Attorney General and privacy-agency websites, checked against each state's own published guidance as of August 2026.
Population size does not predict which states disclose this kind of data. Texas and Florida rank second and third by population among the 20 states with a privacy law in effect, yet neither publishes anything close to California's request-level detail. A federal law could eventually force a common reporting standard, but see our tracker of federal privacy bills in Congress: 20 bills were moving through the 119th Congress as of late 2025, and only 2 narrow ones had become law, so a nationwide reporting requirement is not close.
Figure 1: California sits alone in the transparent-and-populous quadrant; every other large covered state clusters on the low-transparency side. Population share is proportional to each state's 2025 Census share among covered states; transparency position is PrivacyTerms.io's own qualitative read based on this post's research, not a published metric. Source: US Census Bureau Vintage 2025 estimates, state Attorney General and privacy-agency websites.
The takeaway: a business operating nationally cannot benchmark its own request volume against a public state number in 49 states. California is currently the only place that reporting exists at all.
What is the timeline behind California's consumer-rights infrastructure?
California's request-volume data did not appear overnight. It is the product of a specific sequence of laws and platform launches stretching back to the original CCPA, each one adding a new mechanism residents could actually use to exercise a right.
Figure 2: Eight years separate California's first privacy law from its first centralized, government-run request platform. Source: California Privacy Protection Agency, 2025 Annual Report and June 2026 platform update.
Complaint volume grew alongside that infrastructure rather than in a straight line. CalPrivacy's complaint portal, open since 2023, had logged more than 10,000 submissions by the time the agency's 2025 Annual Report was published, a roughly 120% year-over-year increase the agency attributed directly to growing consumer awareness of their rights. The takeaway: each new mechanism California adds appears to increase, not dilute, the volume of the ones that came before it.
How many requests could California's registered data brokers be handling combined?
DROP's 300,000-plus signups measure people, not individual broker-level transactions, since one signup fans out to every registered broker at once. A separate DataGrail data point offers a way to estimate what that fan-out actually looks like in practice: the company's 2026 Privacy and AI Trends Report found that the average registered California data broker fields more than 2,000 deletion requests and more than 900 opt-out requests every month, a scale that already dwarfs a typical mid-sized company's annual total.
Warning
Multiplying DataGrail's per-broker monthly average (2,000-plus deletion and 900-plus opt-out requests) by CalPrivacy's June 2026 count of 581 registered brokers works out to roughly 1.7 million requests a month, or about 20 million a year, in aggregate. That is PrivacyTerms.io's own multiplication of two separately published figures. Neither DataGrail nor CalPrivacy publishes this combined total directly, and the true figure will move as DROP's first full year of broker-side processing data becomes available after the August 1, 2026 compliance deadline.
That estimate, even treated as a rough order of magnitude, dwarfs the national DSR benchmark for an individual company. DataGrail separately found that a company with about 5 million monthly website visitors receives roughly 984 access and deletion requests a year, a figure covered in more detail in our breakdown of average DSAR volume. California's registered data-broker segment alone appears to operate one to two orders of magnitude above that per-company baseline, which is consistent with brokers being aggregators that hold data on far more individuals than a typical consumer-facing business ever collects directly.
What happens when a business ignores a consumer rights request?
Ignoring a request is not a theoretical risk in California. CalPrivacy's Enforcement Division disclosed several named settlements in its 2025 Annual Report tied directly to consumer-rights failures, including a business that failed to provide an effective opt-out mechanism and another that made it difficult for residents to use an authorized agent to submit a request on their behalf.
Figure 3: Three of CalPrivacy's disclosed 2025 enforcement actions, not an exhaustive total of the year's settlements. Source: California Privacy Protection Agency, 2025 Annual Report; CalPrivacy joint investigative sweep announcement, September 9, 2025.
Tractor Supply Company's $1.2 million settlement, the largest of the three, cited a failure to maintain an adequate privacy policy, failing to notify job applicants of their privacy rights, and failing to provide an effective opt-out mechanism, according to CalPrivacy's own case summary. American Honda Motor Co. and clothing retailer Todd Snyder were fined $632,500 and $345,178 respectively in a September 2025 joint sweep with the Colorado and Connecticut Attorneys General, both specifically for failing to honor Global Privacy Control opt-out signals; see our breakdown of how many CCPA opt-out requests are filed each year for the national growth trend behind that enforcement push. The takeaway: every named 2025 case traces back to a business failing to process a consumer rights request correctly, not to a data breach or an unrelated disclosure failure.
Does a business have to register and process these requests at all?
Not every business that collects personal data is a data broker under California's Delete Act, and only registered brokers are required to plug into DROP specifically. A business can still owe direct opt-out and deletion rights to California residents under the general CCPA even if it never registers as a broker at all.
Figure 4: Data broker registration and DROP obligations are a narrower, separate test from general CCPA applicability. Source: California Privacy Protection Agency, Data Broker Registry guidance; California Civil Code Section 1798.99.80 et seq.
Most consumer-facing businesses, retailers, SaaS companies, and content sites among them, fall into the second branch: they owe CCPA rights directly to the consumers whose data they collect, but they are not data brokers and will never appear in the 581-broker registry. That distinction matters for anyone drafting a privacy policy, since a business's own disclosures need to describe the direct request channel it actually operates, not DROP, which only covers the narrower broker category. Our full state-by-state privacy law tracker covers how the general applicability test works across all 20 states with a law in effect, not just California's broker-specific rules.
The Bottom Line
California is the only state currently publishing a real, government-sourced count of how many consumer rights requests its residents actually file, and the number it has published so far, more than 300,000 DROP signups in five months on top of 10,000-plus complaints since 2023, is large and still climbing. Every other state with a comprehensive privacy law leaves the question unanswered at the state level, which means the national vendor-side estimates covered elsewhere on this site remain the best available proxy for business planning outside California. For any business collecting data from residents of more than one state, the practical lesson is not that other states see less activity, it is that other states simply are not counting and publishing it the way California now does. A privacy policy written to the letter of the law still has to describe a working request process in every state that applies, whether or not that state ever tells the public how many requests came in.
Frequently Asked Questions
How many consumer rights requests has California processed through DROP? More than 300,000 Californians signed up for the state's Delete Request and Opt-Out Platform in its first five months of operation, according to the California Privacy Protection Agency's June 2, 2026 update, which also reported a record 581 registered data brokers.
Do other states publish consumer rights request volume data? No other state currently publishes a comparable public aggregate. Connecticut's 2025 CTDPA enforcement report describes only "dozens of notices of violation and warning letters" rather than a specific count, and Colorado's Attorney General has not released a public total of consumer requests or complaints as of this post's research.
How many complaints does California's privacy portal receive? More than 10,000 complaints since the portal launched in 2023, up roughly 120 percent year over year, according to the California Privacy Protection Agency's 2025 Annual Report.
How many data brokers are registered in California? 581 data brokers were registered with the California Privacy Protection Agency as of June 2026, the highest count since the registry was established in 2020, up from more than 500 registered brokers reported in the agency's 2025 Annual Report.
Where the Numbers Come From
- California Privacy Protection Agency (CalPrivacy). (2026, June 2). "Privacy Momentum Builds: 300,000 Californians Sign Up for DROP as Registered Data Brokers Hit a Record High." 300,000-plus DROP signups in five months, 581 registered data brokers, processing deadline of August 1, 2026.
- California Privacy Protection Agency (CalPrivacy). (2026). "2025 Annual Report." More than 10,000 complaints since 2023 portal launch, up about 120% year over year; more than 500 registered data brokers in 2025; named 2025 enforcement settlements including Tractor Supply Company ($1.2 million); Data Broker Enforcement Strike Force established late 2025; Consortium of Privacy Regulators formed April 2025.
- California Privacy Protection Agency. (2025, September 9). "Joint Investigative Privacy Sweep: CA, CO, and CT Investigate Businesses Refusing to Honor Consumers' Right to Opt-Out." American Honda Motor Co. ($632,500) and Todd Snyder ($345,178) settlements for failing to honor Global Privacy Control.
- DataGrail. (2026, May 27). "Privacy and AI Trends Report 2026." Deletion requests up 567% since 2021; average registered California data broker fields more than 2,000 deletion and 900 opt-out requests monthly, based on anonymized privacy operations data from hundreds of enterprise customers.
- Reporting on the Connecticut Attorney General's 2025 CTDPA Enforcement Report. (2026, February). Report describes "dozens of notices of violations and warning letters" without a specific total.
- Colorado Attorney General. "Colorado Privacy Act." General CPA guidance and rulemaking resources; no public aggregate consumer-request or complaint count identified as of this post's research.
Note: All figures verified as of August 2026. DROP signup and registered-broker counts are current only as of CalPrivacy's June 2, 2026 update and will climb further once brokers begin mandatory processing on August 1, 2026; this post is refreshed at least twice a year to track new CalPrivacy annual reports and platform updates.