I don't say this lightly: Cory Doctorow has shaped how I think about surveillance capitalism more than almost anyone else writing today. His books have directly influenced my relationship with privacy, digital rights, and the future of the open internet, and I know they have for lots of our audience members too! So when I tell you I disagree on his recent piece on California's DROP tool where he calls it an 'obstacle course' with the slug of the article being 'privacy theater', it's because I wanted to share my difference in views in the most respectful possible way. But I'm still bowing down to the legend 🙇

My name is Henry Fisher and I run Techlore. We produce resources to make privacy & security easy for just about anyone. And if you haven't heard, DROP is a data broker removal tool for California residents, a first-of-its-kind government-run tool. And while I think skepticism is warranted, I think DROP's reality isn't at all what Doctorow implies.
The Data Broker Industry & DROP
I've been skeptical of DROP for months, and actively put off doing it myself. I'm not the kind of person to upload my personal information to a brand new tool. Additionally, the premise that you have to opt out of a system that never should've existed has rubbed me the wrong way from the start.
Doctorow's underlying diagnosis is one I hold too: data brokers are a real harm—a direct pipeline to stalking, doxxing, killing, deepfake material, and more.

And because of my skepticism, a couple weeks before Doctorow's blog, I interviewed the executive director of the California Privacy Protection Agency, Tom Kemp, the agency that built and runs DROP. I was able to ask about its privacy and security, the 'why' behind DROP, why they can't just ban data brokers outright, and a lot more that changed my views towards the service. You can watch the full hour-long interview here.
Getting the Details Right
Many of my subscribers asked for my opinion on Doctorow's piece, so while this certainly serves them, I also think it serves as an educational piece for anyone. My assumption is Doctorow's reservations are shared among many, so I hope I can add some clarity around DROP. Okay, let's dive in.
Doctorow Claim 1:
Banning data brokers would make great sense, which is why Biden's CFPB banned data brokers (only to have Trump un-ban them)
Why it's not accurate: In December 2024, the CFPB proposed a rule that would have expanded the Fair Credit Reporting Act to treat data brokers as consumer reporting agencies. That proposal was never finalized and never took effect. Data brokers operated, legally, the entire time it was pending. In May 2025, the CFPB withdrew the proposal. This is an important detail to drill down since it tells readers a functioning ban existed and got reversed, when data brokers never stopped operating. Trust me, if we banned data brokers, I'd personally hold a party to celebrate it 🥳
Doctorow Claim 2:
To start the DROP process, you are recommended to create a Login.gov ID. This is an incredibly invasive process that involves photographing multiple pieces of ID and taking several selfies using special apps and webpages that hijack your device's camera and processor in a bid to prevent bad actors from spoofing the process. [....] After you log in to DROP via Login.gov, you are sent a text message – to the phone number in your Login.gov profile – with a link to access a "secure" website that takes over your camera to let you take a "secure" photo of the front and back of your California driver's license or your US passport.
But as Tom Kemp shared, this isn't the reality for many people:
Tom Kemp, CalPrivacy Executive Director: It either uses your personal information to do quick lookups with state records...or it uses your login.gov federal account. Most people use the first option for residency verification, which is put some basic personal information... boom, you're a resident.

DROP offers both options, and it even suggests the less invasive check first. Sadly, I wasn't able to use the less invasive check, which is a common issue I stumble on when verifying my private mailing addresses. But I would expect many family & friends to successfully use the simpler system. This flow away from login.gov only requests: Name, Date of Birth, Address, and an email for a code (which accepted an alias email in my testing) With that said, if you do have to use login.gov—it sucks!
Doctorow Claim 3:
You also have to provide your mobile advertising identifier, a long, unique number that you may or may not be able to extract from your phone, depending on the model and the OS version. If you can't get it that way, you can install an app like AAID, which comes with a long list of – you guessed it – permissions to extract, store and process your private information.
This is completely optional and is not mandatory:
Tom Kemp, CalPrivacy Executive Director: You put your name or variations of your name, you put your date of birth, and you put your zip code. Now, you can stop there...Or we ask for three bits of additional information. Mobile advertising ID... a connected TV ID, or your VIN... you can control how much information you want.
The base DROP submission is quite minimal. The mobile ad ID, connected TV ID, and VIN are a further optional tier on top of that. And why are mobile IDs and TV IDs hard to get? Because the mobile & TV ecosystems make it that way! I don't see how this is a fault of the tool trying to actively remove that invasive data.
Doctorow Claim 4:
Here's the thing: the whole point of a mobile ad identifier is that apps can access it (this is how they identify and track you). That step, where the system made you switch to your phone and use your camera to photograph your driver's license? That step could have automatically pulled this data off your device. That's the whole fucking point of this exercise: that web-pages and apps can request your mobile ad identifier.
So Login.gov, a government website that isn't required to use DROP, wasn't collecting advertising IDs and passing it to DROP? I want to be very clear: That's a good thing. But more importantly, Doctorow's claim isn't feasible. Mobile ad identifiers (IDFA on iOS, GAID/AAID on Android) are native-app-level identifiers, not web-accessible ones. And DROP's login.gov flow sends a link to your phone that opens in your browser. Put simply: these can't be called from a webpage loaded in a browser.
Doctorow Claim 5:
This is either a system with no coherent threat model, or (far more probably), its threat model is that people will use it. This is California's answer to "a locked filing cabinet stuck in a disused lavatory with a sign on the door saying 'Beware of the Leopard'
I fully agree the system can be more streamlined. But on the other side of the coin:
Tom Kemp, CalPrivacy Executive Director: We've had 375,000 people sign up, which is pretty incredible in that deletions haven't begun... The satisfaction ratings that we get are very high. They're in the 4.X range on a scale of 5, which is really good for consumer-facing products... we have people that are in their 80s and 90s using this system.
And regarding threat modeling & safety:
Tom Kemp, CalPrivacy Executive Director: That data is stored in kind of five separate areas and it's hashed... Only if there is a match, then they know who that individual is, and they're required to then delete all the information... I don't even know if you signed up because the data has been hashed and the data brokers can't supplement their databases.
Everything you choose to submit gets immediately hashed into separate identifier buckets. A broker can only get a match if they already independently possess your matching hashed data on their end. For non-technical folks: this means neither party is communicating using your raw data. It's a nice privacy advantage over the traditional system.
Tom Kemp, CalPrivacy Executive Director: brokers are required to then delete all the information, even if it just matches against an email address.
This is my favorite hidden detail about DROP: Even if you never submit a VIN or mobile ad ID, if a broker happens to have your name and that VIN linked together in their own file, the match on your name alone is enough to force them to delete the whole record.
Why not just ban them outright?
This is the question underneath Doctorow's whole piece. Like Doctorow, I am in full support of a federal ban of this invasive industry. And it's why I asked Kemp about this directly in our interview to understand the challenges:
Tom Kemp, CalPrivacy Executive Director: There's been two big issues [preventing federal bans]. Issue number one is a private right of action... The second big hang-up, but probably the biggest hang-up, is preemption. Because what is happening is that oftentimes federal proposals have a very low ceiling. And so, yes, privacy would be in all 50 states, but existing states like California would actually lose privacy rights.
As for banning within California, there's reason for optimism:
Tom Kemp, CalPrivacy Executive Director: There is a bill to ban the sale of geolocation [in California]...I think there's 110 different data brokers that sell geolocation...There's another proposed law that would ban the sale of all sensitive personal information.
So California isn't rejecting the "just ban it" framework Doctorow wants. It's executing it one category at a time through a very slow, democratic process against companies that still have First Amendment rights. It's starting with geolocation, and hopes to expand beyond that.
Tom Kemp, CalPrivacy Executive Director: By default, privacy laws in the US, to not run the risk of constitutional challenges, have defaulted to an opt-out model.
While I find this process slow and painful, I am optimistic that they are the initial steps towards something much larger.
Compared to what? Better or worse than current removal options?

I always like to ask 'in comparison to what' in situations like this. Right now, paid private companies are the best option to achieve what DROP does, and our tools showcase what some of those best services currently are. A core difference is there's real enforcement behind DROP:
Tom Kemp, CalPrivacy Executive Director: Brokers who don't comply face fines of $200 per day, per incident.
He walked me through a scenario where a broker sitting on 200,000 matched records who refuses to delete could face $40 million per day. The agency already has 12 enforcement actions and real fines on the board against data brokers.
Additionally, third-party services need to continually perform opt-outs as data resurfaces on the same sites you opted out of already. DROP has a better system for this:
Tom Kemp, CalPrivacy Executive Director: The drop system is you do it once, it deletes all the information irrespective of how it's collected, and it's a perma-delete in that data brokers have to maintain a suppression list and not import any information from people that submitted requests through the drop system.
The third-party services have no statutory enforcement, no permanent suppression list so your data doesn't repopulate in six months, no public regulator you can file a complaint against if they underperform, and no required hashing system for better privacy. So DROP is an outright win by all of these measurements, and it's 100% free. However, one area where the private services can still win is in scope:
Tom Kemp, CalPrivacy Executive Director: There is a lot of value for third party privacy tools because sometimes their ecosystem of businesses that they do deletions are not technically data brokers and are not registered under our definition in the law.
Most importantly: Not even Kemp, the director of the CPPA claims that DROP is an all-in-one privacy solution. He himself in our interview was a proponent of defense-in-depth, that DROP is one layer in that stack, and it is designed to raise the floor, not the ceiling.
My New Data Removal Strategy
After gathering my findings, I did what I'd been putting off for months: I started my DROP signup. I'll be combining DROP with EasyOptOuts, which is a $20/yr service that was independently verified by Consumer Reports to be one of the most effective providers. This lets me hook into the DROP system and get potentially broader coverage. If you want something more trustless, you can always do manual opt-outs or use an on-device tool like DuckDuckGo's removal service.
I think if you're based in California: Sign up for DROP, and keep pushing for the bans. Both things can be true.
If you're not in California: Bother your politicians about DROP and ask why your state/country doesn't have a similar system. And an outright ban while you're at it!
Cory Doctorow taught a generation of us, myself included, to distrust systems that ask for our compliance. That instinct is correct, and I'm not asking you to abandon it. I'm asking you to point it in the right direction. DROP is one of the first cracks anyone's managed to put in this invasive industry. It's imperfect, it's slower than it should be, and it deserves every bit of pressure we can put on it to get better. But it's not theater. Sign up. Then let's work to make the next crack bigger.
And don't forget to watch my full interview with Tom Kemp which has a lot more information:
Surveillance Report: what matters in privacy, security, and digital rights. Weekly, free.