California's Deletion List Is Reversible by Design

Dispatch #0003

By Nolan Rourke

September 4, 2026

THE COLD OPEN

On August 10, 2026, the California Privacy Protection Agency issued a stipulated order in matter ENF26-05-D-LO against LocateSmarter, LLC, a skip-tracing data supplier based in Cedar Falls, Iowa. Documented in the order: the company required consumers to submit a full name, a mailing address, and the last four digits of a Social Security number before processing an opt-out. The agency assessed $110,490 in penalties and collected a $6,000 unpaid annual registration fee. Out of nearly 40 million California residents, only a handful of consumers successfully processed an opt-out. The state mandated a remedy for this friction that became mandatory this month. It works by handing every registered broker a list.

THE MECHANISM

The Delete Request and Opt-Out Platform (DROP) opened for consumer submissions on January 1, 2026. As of August 1, 2026, every company on the California Data Broker Registry must use it. Delete Act regulation section 7612(a) dictates that brokers must access the platform and download consumer deletion lists at least once every 45 days. A Californian verifies residency through manual entry or Login.gov and supplies identifiers. CalPrivacy sorts these into six lists: NDZ, Email, Phone, MAID, NameVIN, and CTVID. The architecture normalizes every field to a published rule before hashing it. The algorithm hashes the normalized value using SHA-256 with UTF-8 input encoding and outputs it as Base64. The broker authenticates to the API, downloads a ZIP archive of UTF-8 CSV files, and runs identical hashing rules against its own internal records. The broker deletes matching records and returns a CSV status file. The audit surface consists entirely of the API logs. Everything between the download and the upload happens on the broker's isolated hardware.

THE STRUCTURAL PARALLEL

The New York City Taxi and Limousine Commission released historical trip and fare logs in 2014. Documented from Vijay Pandurangan's analysis: the agency applied an MD5 hash to roughly 19 million medallion numbers and 3 million hack licenses before release. The identifier spaces were small and format-constrained. Pandurangan generated a full lookup table in two minutes and reversed the entire dataset within an hour. The California government applied an unsalted cryptographic hash to a bounded identifier space and distributed the output to external parties. The DROP lists go exclusively to credentialed API key holders, which narrows the field of attackers. The restricted access doesn't change the structural vulnerability of the file.

THE HUMAN MECHANIC

This vulnerability operates independently of malicious intent. Every 45 days, a compliance engineer at a registered broker pulls a ZIP archive, runs a hashing job across the company's records, and executes the deletions. Independent third-party audits examining these methodologies don't begin until January 1, 2028. A state-supplied file of hashed identifiers sits on the engineer's disk. Beside it sits a functional hashing pipeline built to the state's exact specifications. Matching that file against the company's full identity graph requires running the identical query against a different table. The design fails to prevent it, and the audit surface lacks the visibility to record it.

THE STRUCTURAL FLAW

The confidentiality of the DROP deletion list relies entirely on a legal use restriction and an unsalted hash over enumerable identifier spaces. The valid North American numbering plan holds roughly 6.3 billion numbers. Computing MD5 hashes for all valid phone numbers takes just over four hours on a standard laptop. Any party holding the Phone list possesses the capability to recover the plaintext number behind every entry. A reversed Phone list functions as a continuously updated roster of verified California residents.

THE COUNTERMEASURE & ITS LIMITATIONS

Filing a DROP request takes under ten minutes and establishes a standing deletion obligation across every registered broker on a 45-day cycle. The protection has limits. It fails to reach unregistered brokers, first-party collectors, or information claimed under an enumerated exemption. Supplying a phone number places the user on the most highly enumerable list. Supplying only an email address sacrifices coverage, as the phone number serves as the primary join key across the location and telecom broker market. For privacy engineers operating inside a registered broker, the only effective control is strict isolation. Keep the downloaded lists and the API key in a logged enclave held apart from the production identity graph.

THE CLOSE

CalPrivacy fined LocateSmarter for violating data minimization principles. Under DROP, more than 600 companies receive a hashed list of every resident who opted out. A legal rule and a vulnerable algorithm protect those identifiers. File the request. Understand the operational reality of the system you are joining. Stay paranoid.

SOURCE LIST

All sources located and read on 2026-08-31.

Primary documents

  1. Documented. California Privacy Protection Agency, Order of Decision and Stipulated Order, In the Matter of LocateSmarter, LLC, matter ENF26-05-D-LO, order dated August 10, 2026. https://privacy.ca.gov/wp-content/uploads/sites/357/2026/08/Order-of-Decision-and-Stipulated-Order_LocateSmarter-LLC-.pdf Accessed 2026-08-31.

  2. Documented. CalPrivacy, DROP Technical and API Reference Documentation, version 1.0.0, March 2026. https://cppa.ca.gov/orph/drop_tech_api_ref.pdf Accessed 2026-08-31.

  3. Documented. CPPA, Delete Act regulations, final text, 11 CCR sections 7601 through 7622. https://www.cppa.ca.gov/regulations/pdf/drop_ftr.pdf Accessed 2026-08-31.

  4. Documented. CalPrivacy, DROP for Data Brokers, Technical Specifications, Working with the data. https://privacy.ca.gov/drop-for-data-brokers/technical-specifications/working-with-data/ Accessed 2026-08-31.

  5. Documented. CalPrivacy, CalPrivacy Announces Second Data Broker Enforcement Action in Less than a Week (Cybba, Inc., order dated August 13, 2026, $52,400). https://privacy.ca.gov/2026/08/calprivacy-announces-second-data-broker-enforcement-action-in-less-than-a-week/ Accessed 2026-08-31.

  6. Documented. CalPrivacy, Privacy Momentum Builds: 300,000+ Californians Sign Up for DROP as Registered Data Brokers Hit a Record High, June 2, 2026 (581 registered brokers). https://privacy.ca.gov/2026/06/privacy-momentum-builds-300000-californians-sign-up-for-drop-as-registered-data-brokers-hit-a-record-high/ Accessed 2026-08-31.

  7. Documented. CPPA, Information for Data Brokers, including the August 1, 2026 access obligation and the 45-day cycle, citing Civil Code sections 1798.99.80 through 1798.99.86. https://cppa.ca.gov/data_brokers/ Accessed 2026-08-31.

  8. Documented. Vijay Pandurangan, On Taxis and Rainbows, June 2014, the author's own account of his analysis of the NYC Taxi and Limousine Commission trip and fare log release. https://medium.com/vijay-pandurangan/of-taxis-and-rainbows-f6bc289679a1 Accessed 2026-08-31.

  9. Documented. Matt Hodges, The Privacy Theater of Hashed PII, October 19, 2025, the author's own measured benchmark on a 2020 M1 MacBook Air. https://matthodges.com/posts/2025-10-19-privacy-theater-pii-phone-numbers/ Accessed 2026-08-31.

Reporting and professional analysis

  1. Reported. Alston and Bird, California Privacy Regulators Signal Increased Scrutiny of Opt-Out Preference Signals, Data Broker Obligations, and Audit Readiness, August 14, 2026 (600-plus brokers on the platform, third-party audits from January 1, 2028, registration fee rising to $9,500). https://www.alston.com/en/insights/publications/2026/08/california-privacy-opt-out-signals-data-brokers Accessed 2026-08-31.

  2. Reported. WilmerHale, California Data Broker Updates, August 19, 2026. https://www.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20260819-california-data-broker-updates Accessed 2026-08-31.

  3. Reported. National Law Review, A Handful of Opt-Outs and a Six-Figure Fine: CalPrivacy's Message to Data Brokers, August 18, 2026. https://natlawreview.com/article/handful-opt-outs-and-six-figure-fine-calprivacys-message-data-brokers Accessed 2026-08-31.

  4. Reported. Privacy Rights Clearinghouse, Deletion obligations under DROP are here, July 31, 2026 (re-acquired data must be deleted on the following cycle, exemption reporting). https://privacyrights.org/resources-tools/advocacy/deletion-obligations-under-drop-are-here-data-brokers-must-now-delete Accessed 2026-08-31.

  5. Reported. Malwarebytes Labs, Californians can tell data brokers to DROP their information, August 3, 2026 (consumer submission flow, Login.gov residency verification, DROP ID). https://www.malwarebytes.com/blog/news/2026/08/californians-can-tell-data-brokers-to-drop-their-information Accessed 2026-08-31.

Inferred, marked as such in the body

  1. Inferred. The reversibility of the DROP Phone list to plaintext by any credentialed holder, and the tractability of the NDZ list against commercial identity graphs and voter files. This is my analytical conclusion drawn from sources 2, 4, and 9. No agency has made this finding, and no broker is alleged to have done it.

ELSEWHERE

Applied Paranoia on Facebook
Applied Paranoia on Instagram
Applied Paranoia on Youtube
Applied Paranoia on X

Two dispatches a week. No summaries of other people's reporting.