How we assess broker coverage, difficulty and timing
Our published rules for counting brokers, reviewing request steps and measuring removal outcomes. No invented scores or deadlines.

What the directory includes
This snapshot contains 603 business registrations from California’s official data broker registry, downloaded on September 24, 2026. The registry page was updated July 29, 2026. We count one filing per business, not every website or brand in a filing. This is a bounded public directory, not every broker worldwide. Registration does not establish that a business holds your data or has broken a law.
What a plan’s coverage number would mean
Active coverage will count distinct businesses with a reviewed request route, a supported jurisdiction, a permitted delivery method and a working follow-up process. A directory entry alone does not qualify. Current managed-request coverage is zero because sending is not available. Paid plan request limits and launch coverage are still to be confirmed. Eligibility will depend on the member and request, even at a supported broker.
How difficulty will be reviewed
An analyst will record the request route, number of required interactions, verification method, mandatory documents, account requirements and follow-up barriers. “Straightforward” requires an accessible route with no account or identity-document requirement and at most three interactions. “More steps” adds an account, several forms or manual follow-up. “Complex” requires identity documents, postal steps or a documented unresolved barrier. Identity verification can be legitimate; friction is not a judgment of wrongdoing. We publish the evidence, scope and review date. Unknown cases stay unrated.
What the historical numbers mean
Profiles reproduce the business’s reported median response and deletion-request count where a usable median and positive count exist. The CSV timing columns explicitly label 2024, while the registry page describes 2025 activity. We flag that unresolved period mismatch. These are self-reported response figures, not Avenvale measurements, current typical times or proof that information disappeared. Zero requests never becomes a zero-day removal claim.
How we will measure actual outcomes
Measure from confirmed delivery, then record first substantive response and separately verified disappearance. Keep pending, denied, partial and unverifiable cases visible. Never mark a request as removed simply because it was sent, downloaded or acknowledged. A public timing summary will require at least 20 comparable requests over a stated 90-day window, with jurisdiction, route, sample count, median response and completion counts. Show pending cases beside completed-case timing to avoid making slow unresolved cases disappear from the statistics. Small samples remain insufficient data.
Keep deadlines separate from observations
California’s DROP page says brokers must access requests at least every 45 days from August 1, 2026, and a status update can take up to 90 days. That is a specific program timeline, not a universal removal guarantee. We link official routes and scope each published deadline to its jurisdiction and request type. Do not use an old registry median as a legal deadline.
Keep each person’s status private
Public profiles describe companies. They do not reveal customer names, matches, addresses or request history. Avenvale’s current workspace records draft, approved-for-download and downloaded states; none means sent. Future delivery and follow-up statuses need evidence and individual authorization. Opening a broker page or request link does not create a deletion request.
Updates and corrections
The directory is a dated snapshot. Routes can move and filings can contain mistakes. Re-import the official registry, review differences and preserve stable profile URLs. Human-reviewed difficulty assessments will expire after 90 days or a reported route change. Until that review has happened, profiles remain unrated. The company’s own request page is the place to verify its current process.
