California Privacy Protection Agency
The California Privacy Protection Agency (CPPA, branded CalPrivacy) is the state regulator that administers and enforces the California Consumer Privacy Act and the Delete Act. Under the Delete Act it operates DROP, the Delete Request and Opt-out Platform, through which California residents file a single deletion request that every registered data broker must process at least once every 45 days beginning August 1, 2026. Data brokers integrate with DROP through the DROP Data Broker API, a three-operation REST surface on api.drop.privacy.ca.gov (download hashed consumer deletion lists as a ZIP of CSVs, upload Id,Status response files, amend prior responses) authenticated with an X-API-KEY issued in the Data Broker Portal, with a sandbox environment, HMAC-SHA256 signed webhook notifications, and an OpenAPI 3.1.0 contract published alongside the technical specifications on privacy.ca.gov. The agency also publishes the California Data Broker Registry as downloadable CSV files.
California Privacy Protection Agency publishes 1 API on the APIs.io network: DROP Data Broker API. Tagged areas include Government, Privacy, Data Brokers, Regulatory Compliance, and Data Deletion.
The California Privacy Protection Agency catalog on APIs.io includes 1 event-driven AsyncAPI specification.
California Privacy Protection Agency’s developer surface includes documentation, API reference, getting-started guide, support, pricing, engineering blog, changelog, and 29 more developer resources.
Kin Score
APIs 2
Individual APIs this provider publishes, each with its own machine-readable definition.
DROP Data Broker API
Delete Act data broker integration API for the Delete Request and Opt-out Platform (DROP). Data brokers pull a ZIP archive of hashed consumer identifiers (GET /data/download, on...
DROP Webhook Notifications
Optional outbound HTTPS webhook notifications from DROP to a data broker's endpoint, enabled in the Data Broker Portal notification settings. Five event types (download.ready, u...
MCP Servers 1
Model Context Protocol servers that expose these APIs to AI agents.
Pricing Plans 1
Published pricing tiers and plan structures.
Rate Limits 1
Documented rate limits and quota policies.
Event Specifications 1
AsyncAPI definitions for this provider's event-driven and streaming APIs.
Security Posture 3
Authentication, domain security, vulnerability disclosure, and trust-center signals.
California Privacy Protection Agency Vulnerability Disclosure
security.txt · contact published
SECURITYResources
Get Started 4
Portal, sign-up, and the first successful call
Documentation 3
Reference material describing how the API behaves
Agent Surfaces 3
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 7
Pagination, idempotency, versioning, errors, and events
Scroll for all 7
Build 1
SDKs, sample code, and the tooling you integrate with
Access & Security 3
Authentication, authorization, and security posture
Operate 5
Status, limits, changes, and where to get help
Commercial 4
Pricing, plans, and the legal terms of use
Company 4
The organization behind the API
Other 2
Properties that don't map to a standard resource type
Source (apis.yml)
Work with this as data
Every provider here is available over the APIs.io API and to AI agents over MCP.