Information checked as of 6 October 2026. Confirm on the official pages in Sources.
The short version
- People-search sites and data brokers hold information you did not give them directly. You can ask for removal, but routes differ by country and company.
- California residents can send one free request to all active data brokers through the state’s DROP platform. In the UK you can use the UK GDPR rights of erasure and objection against organisations covered by UK GDPR, plus a separate opt-out from the open electoral register.
- Removal is rarely a single action. Keep records, expect to wait, and re-check on a schedule.
Who this is for
Anyone in the UK or US who has found their personal details on a site they never signed up to. No technical skills are needed.
Background: data brokers, right to be forgotten, digital footprint.
The 12-point setup for a private, secure, high-output digital life — in one afternoon. No spam, unsubscribe anytime.
What you need
- Time (our estimate): 60 to 90 minutes for the first pass, about 15 for each re-check. Per-step times are estimates too.
- Tools: a web browser, a notes file, and a dedicated email address. Protect it with two-factor authentication.
- Details you will type: your name, and usually a ZIP code or postcode. Give only what each form asks for. See data minimisation.
The background in brief
What data brokers are
The California Privacy Protection Agency (CalPrivacy) describes a data broker as “a business that gathers and sells consumer information that the consumer didn’t give them directly.” Buyers can include advertisers, employers, landlords and debt collectors. Many people-search sites fit this description, though we have not checked any individual site against a legal definition.
What is live in California, as of 6 October 2026
California’s Delete Request and Opt-out Platform (DROP) launched on 1 January 2026. Brokers were required to begin processing requests on 1 August 2026. DROP is free, and you must be a California resident to use it. Under the Delete Act, brokers must access the system at least once every 45 days, and the statute sets an administrative fine of $200 per deletion request per day for a broker that fails to delete as required.
Important limits: DROP does not require deletion of data you gave directly to a business (although the agency says it is subject to deletion if a data broker later purchased it), exempted data, or publicly available data. The agency gives public records, such as vehicle or real estate ownership or voting records, as examples of exempt data, so a DROP request may leave some listings in place.
Step-by-step plan
-
Find out what is out there (10 to 15 minutes)
Search your name with your city, then your phone number and email address, in a private window. Copy each result’s address and the details shown into your log. Expected result: a dated list of pages showing your information.
-
If you live in California, submit a DROP request (10 minutes)
Go directly to privacy.ca.gov/drop and type the address yourself rather than following an ad, search result or email link, because lookalike sites exist. DROP is free: never pay to use it. You only need your name, date of birth and ZIP code, but the agency says the more information you enter, the more likely your data will be deleted. Residency is confirmed through the California Identity Gateway. Save your 8-digit DROP ID; do not share it. Expected result: a confirmation page and a DROP ID. Statuses will show as Pending at first. Brokers have up to 90 days to report back, and the timeline says that, as of 6 October 2026, by November 2026 all participating brokers should have completed their initial cycle.
-
Use each site’s own opt-out for the rest of the US (20 to 30 minutes)
For the pages you logged, look for a link named something like “opt out”, “do not sell or share my personal information”, or “privacy request” in the footer or the privacy policy. California residents have a legal right to ask covered businesses to delete personal information and to opt out of its sale or sharing, and covered businesses must respond to an opt-out request within 15 business days at most. If the opt-out link does not work, the California Attorney General accepts reports. We could not verify equivalent rights in other states, so ask and record the answer. Expected result: a submitted request or confirmation screenshot per page.
-
If you are in the UK, send an erasure and objection request (15 minutes)
The ICO explains that you can ask an organisation to delete your data, and that it must do so in some circumstances, including when it no longer needs the data for the original purpose, when it collected or used the data unlawfully, or when you have objected to direct marketing use. You can contact any part of the organisation, verbally or in writing, with no special words required. The ICO recommends following up verbal requests in writing. Use the template below and send it to the contact address in the site’s own privacy policy, not one from a search ad. Expected result: a reply within one calendar month, or notice of an extension.
How the two rights differ: under Article 21 you can object, on grounds relating to your particular situation, to processing based on certain lawful bases. The organisation must then stop unless it demonstrates compelling legitimate grounds or needs the data for legal claims. Objecting to direct marketing is absolute, but the ICO says this does not automatically mean erasure; the organisation may keep a suppression record, retaining just enough information to respect your preference. Article 17(1)(c) links the two: erasure applies where you object under Article 21(1) and there are no overriding legitimate grounds, or you object under Article 21(2).
-
Opt out of the open electoral register (5 minutes)
GOV.UK explains there are two versions of the electoral register: the full version and the open register (the “edited register” in Northern Ireland). The open register is the version available to anyone who wants to buy a copy. You can opt out using the register to vote service, or by contacting your electoral registration office (or the Electoral Office for Northern Ireland). Opting out does not affect your right to vote. Your details still appear on the full register, which can only be used for specified purposes such as electoral administration, campaigning, crime prevention, credit checks and, in England, Wales and Northern Ireland, jury summoning. If you register anonymously your details appear on neither version; we did not verify who qualifies, so ask your electoral registration office. Expected result: your open-register preference is updated.
-
Log everything and set diary reminders (5 to 10 minutes)
For each request, record the site, date sent, method, any reference number, and the date the one-month UK deadline falls. Expected result: one log you can use if you later complain.
Template: UK GDPR erasure and objection request
Replace everything in square brackets and keep a copy. If the page you found already shows your address, you can leave out your postal address and give only an email address.
Subject: Request for erasure and objection to processing under UK GDPR – [your full name]
[Your full name]
[Your postal address]
[Your email address]
[Date]To: [Name of organisation / Data Protection contact]
[Organisation address or privacy email]Dear Sir or Madam,
Right to erasure (Article 17) and right to object (Article 21)
I believe you hold personal data about me, including: [list what you found, for example: name, address, phone number, age, relatives, and the web addresses where it appears: URL 1, URL 2].
1. I ask you to erase this personal data under Article 17 of the UK GDPR because [choose what applies: it is no longer necessary for the purposes for which it was collected; I object under Article 21(1) and there are no overriding legitimate grounds, or I object under Article 21(2); it has been processed unlawfully].
2. I object under Article 21 to any processing of my personal data for direct marketing, including profiling related to it, and I ask you to stop this processing.
3. I also object under Article 21(1), on grounds relating to my particular situation, to any other processing based on legitimate interests or a task carried out in the public interest. My reasons are: [briefly explain, for example the effect on your privacy or safety].
Please also tell me which organisations you have shared my data with, and confirm that you have notified them of this erasure request. Please confirm in writing when the data has been erased, or, if you refuse any part, explain why and how I can complain to the Information Commissioner’s Office.
Please send a full response within one calendar month. If you cannot respond within that period, please tell me within the month why you need more time. If you need to verify my identity, please ask only for what is necessary.
Yours faithfully,
[Signature]
[Your full name]
What happens next in the UK
The organisation has one calendar month to respond, or in certain circumstances up to two extra months if it tells you within the first month why. If it asks you to prove your identity, the clock starts when it receives the additional information. It usually cannot charge a fee. It can refuse where an exemption applies, for example a legal obligation to keep the data or legal claims, or where the request is “manifestly unfounded or excessive”. If it refuses, it must still respond, and should explain why and tell you about your right to complain to the ICO or through the courts. If you are unhappy with the outcome, complain to the organisation first, then to the ICO; its helpline is 0303 123 1113 (as of 6 October 2026). As of 6 October 2026, the ICO says this guidance is under review following the Data (Use and Access) Act, so check its pages for updates.
Mistakes to avoid
- Sending ID or money unprompted. Do not send passports, driving licences or payment details unprompted, and be wary of replies or “removal” sites that ask for them. If an organisation asks for ID, the ICO says it should ask only for just enough information to be sure you are the right person.
- Treating DROP as a complete fix. It does not cover public records, or data you gave a business directly unless a data broker later bought it.
- Handing over more than needed. Where a form allows it, give the minimum.
- Paying without checking. Paid removal services exist. We have not tested how well any work and cite no success figures. If you consider one, check what it covers and what personal details you must give it. DROP is free, and organisations usually cannot charge a fee for erasure requests.
How to check it worked
- DROP: use your DROP ID to check status. “Deleted” means the broker matched you and deleted non-exempt data. “Exempted” means it may keep it by law. “Opted-out” means no exact match was found; for now the broker keeps the data but can no longer sell or share it. “Record not found” means it could not locate you; adding more details to your profile may help.
- Individual sites: repeat your original searches and compare with your log.
- UK replies: check each written reply against what you asked for: erased, partly refused with reasons, or no reply by the deadline.
Re-check cadence
DROP is ongoing rather than one-off: the agency says brokers must re-check and delete newly matching data at least every 45 days. For everything else, our suggestion (not a legal requirement) is to re-run your searches a month after sending requests, then every three months for a year. Related: self-audit tool, metadata hygiene, our digital pillar and how we test.
What we could not verify
- Which businesses qualify as covered under California’s CCPA (the sources we read do not state the thresholds).
- Who qualifies for anonymous electoral registration, and how to apply.
- Procedures and success rates for individual US people-search sites; we publish no efficacy figures.
- US privacy laws outside California, and any federal opt-out right. We make no claim about them.
- The EU GDPR text and individual EU data protection authority routes. Our legal references are to the UK version of the regulation and ICO guidance. We could not retrieve the EU text from the official EUR-Lex site in this session.
- Whether UK law applies to a given overseas site.
- The effectiveness, pricing or terms of any paid removal service.
- The ICO’s online complaint form, which loads dynamically; we confirmed only its “Check if you can complain” page and helpline.
Sources
- Delete Request and Opt-out Platform (DROP) – privacy.ca.gov – https://privacy.ca.gov/drop/ – fetched 2026-10-06
- How DROP works – privacy.ca.gov – https://privacy.ca.gov/drop/how-drop-works/ – fetched 2026-10-06
- Personal information and data brokers – privacy.ca.gov – https://privacy.ca.gov/drop/personal-information-and-data-brokers/ – fetched 2026-10-06
- Data Broker Registry – California Privacy Protection Agency – https://cppa.ca.gov/data_broker_registry/ – fetched 2026-10-06
- Accessible Deletion Mechanism – DROP System Requirements – CPPA – https://cppa.ca.gov/regulations/drop.html – fetched 2026-10-06
- California Consumer Privacy Act (CCPA) – California Attorney General – https://oag.ca.gov/privacy/ccpa – fetched 2026-10-06
- Delete Act statute text (effective 1 Jan 2026) – CPPA (PDF) – https://cppa.ca.gov/regulations/pdf/data_broker_reg_delete_act_statute_eff_20260101.pdf – fetched 2026-10-06
- Your right to get your data deleted – ICO – https://ico.org.uk/for-the-public/your-right-to-get-your-data-deleted/ – fetched 2026-10-06
- Right to erasure – ICO guidance for organisations – https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/right-to-erasure/ – fetched 2026-10-06
- Right to object – ICO guidance for organisations – https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/right-to-object/ – fetched 2026-10-06
- Check if you can complain – ICO – https://ico.org.uk/make-a-complaint/data-protection-complaints/data-protection-complaints/ – fetched 2026-10-06
- Opt out of the 'open register' – GOV.UK – https://www.gov.uk/electoral-register/opt-out-of-the-open-register – fetched 2026-10-06
- UK GDPR Article 17 – legislation.gov.uk – https://www.legislation.gov.uk/eur/2016/679/article/17 – fetched 2026-10-06
- UK GDPR Article 21 – legislation.gov.uk – https://www.legislation.gov.uk/eur/2016/679/article/21 – fetched 2026-10-06
This guide is general information, not legal, medical or financial advice.
The Signal - free dispatch
One practical email that makes your digital life calmer. Checklists, tool cautions, plain-English decisions. No noise.
Free. No spam. Unsubscribe any time.