NearSeal

2026-09-29

California just launched a tool to opt out of 600+ data brokers at once. What about the ID photo most of them still want?

California's Delete Requests and Opt-Out Platform (DROP) went live Jan. 1, 2026, built under the 2023 Delete Act and run by the California Privacy Protection Agency. It lets any verified California resident send a single deletion request to more than 600 registered data brokers at once, instead of hunting down each one's own opt-out page. Identity verification runs through the state's own California Identity Gateway or through Login.gov, and the agency's own page is specific about what that verification asks for: "basic information" to confirm state residency — not a photo of your driver's license — and "your information is not retained by DROP" afterward. Starting Aug. 1, 2026, registered brokers have to check DROP at least every 45 days and act on a request within 90, under the Delete Act's rollout.

DROP is a narrow door. Most opt-outs still go through the old one

DROP only reaches brokers registered with California — and plenty of data brokers and people-search sites either aren't covered yet or process removals the way they always have: a one-by-one request straight to that company. Consumer Reports is blunt about what that path usually demands: "Some data broker sites require a copy of your driver's license or other official ID before allowing you to opt out," and its advice is to cross out your license number before you send it — advice that only makes sense because plenty of people are, in fact, sending it. The World Privacy Forum names two specific examples: Intelius asks for "proof of identity, consisting of either: a copy of a government-issued ID," and US Search says "you will also need to have a state-issued ID or driver's license to prove your identity." Consumer Reports also makes the underlying leverage explicit: no federal law actually requires any of these sites to remove your listing at all, which is exactly why some of them can make ID submission the price of doing it.

Two ways to leave a data broker's database California resident, one request via DROP (live since Jan. 1, 2026) 600+ registered CA data brokers Verified via CA Identity Gateway or Login.gov — "basic information" → no ID photo required (privacy.ca.gov) Anyone, opting out of a broker DROP doesn't fully reach Individual opt-out form or email Government-issued photo ID required e.g. Intelius, US Search (World Privacy Forum) → yours to encrypt before you send it Data brokers are a documented breach target LexisNexis Risk Solutions, May 2025: names, SSNs, and driver's license numbers of 364,000+ people exposed via a compromised employee GitHub account Once the broker's staff has opened it, the copy is in their systems — the same systems above.
DROP's own verification asks for basic information, not an ID photo. Opt out of a broker it doesn't fully reach, though, and the ID photo is often the price of admission — sent to an industry with its own breach history.

Why the company asking matters as much as the ask itself

A government ID copy is a compact identity-theft kit on its own: full name, date of birth, photo, address, and a document number, all in one image. What makes handing it to a data broker a different risk than handing it to, say, a bank isn't the document — it's who's asking. TechCrunch reported May 28, 2025 that LexisNexis Risk Solutions — a data broker whose own business is identity verification and background data — disclosed a breach in which an attacker used a compromised employee's GitHub account to copy data on more than 364,000 people, including names, dates of birth, phone numbers, emails, Social Security numbers, and driver's license numbers. The intrusion happened Dec. 25, 2024; the company says it didn't learn of it until April 1, 2025. Nothing here says every people-search site handles submitted IDs as carelessly as that incident describes — but the ID copy you send to get off one of these sites lands inside the same industry, and industry membership is exactly what that breach is evidence about.

What encrypting your own copy actually fixes

NearSeal runs entirely in your browser, so the ID photo you're preparing to send never uploads anywhere to get encrypted — it's sealed on your own device with AES-256-GCM and a passphrase-derived key (PBKDF2-SHA256 at 220 iterations) before it goes anywhere. That removes the plaintext copy from the part of this you actually control: the scan or photo sitting in your camera roll or Downloads folder, and, if the broker accepts opt-out requests by email — as Intelius and others do — the attachment itself in transit and in your Sent folder afterward. For it to do any good on the receiving end, the passphrase has to travel a separate way from the file: a phone call to the number on the broker's own opt-out page, not a reply in the same email thread.

What it honestly can't do

If the opt-out process is a web form that expects to display your ID image on the spot — not receive a file it will decrypt later — encryption has nowhere to fit: the site's own server has to read the image the moment it arrives, so a ciphertext blob simply fails to upload or verify. That's not a NearSeal limitation to work around; it's what identity verification by photo requires structurally. Encryption also doesn't reach what happens after a human at the broker actually opens your ID, whether through that web form or a decrypted email attachment — their retention, their internal security, and everything the LexisNexis breach illustrates about that industry's track record sit entirely outside anything NearSeal touches. It doesn't force the removal either: Consumer Reports' point that no federal law requires these sites to honor an opt-out at all still stands whether your copy arrives encrypted or not. And because this is usually a one-time send, the fact that NearSeal has no passphrase recovery of any kind matters less for retention than in most cases — mainly, don't lose the passphrase before the broker's staff has had a chance to open the file. One more limit worth naming: NearSeal's default container keeps the original filename in a plaintext header field, so rename the file to something unremarkable — not "jane_doe_drivers_license.jpg" — before you encrypt it, or use the opt-in age-encryption.org format, which has no filename field at all.

Where NearSeal fits

DROP is a genuine improvement for the narrow case it covers: one request, one verification, no ID photo, reaching 600-plus registered brokers at once. It just doesn't cover every broker, and it doesn't reach the individual opt-outs — the ones that still ask you to attach a copy of your license or passport — that remain the normal path for most people, most of the time. NearSeal doesn't get you off any list, and it can't do anything once a web form has already rendered your ID on someone else's screen. What it removes is narrower and still worth doing: your own copy of that ID doesn't have to sit as plaintext on your device, or travel as a plaintext attachment, on its way to an industry that has already shown what it does with SSNs and driver's license numbers when its own security fails.

Sponsored
← NearSeal

This page shows ads only if you consent.