Skip to Main Content
Main Menu
Blog

SB 923 California: What the Expanded CCPA Deletion Right Means for Your Privacy Program

October 7, 2026

Governor Gavin Newsom signed California SB 923, known as the Expanding Privacy Rights Act, on September 27, 2026. The bill amends Civil Code sections 1798.105 and 1798.130, and it changes two things that most privacy programs currently treat as settled: how broad a deletion request has to reach, and how consumers are allowed to submit one.

Neither change is cosmetic. Both take effect January 1, 2027, and both require operational work well before that date.

What SB 923 actually changes

Today, the CCPA‘s right to delete generally reaches personal information a business collected directly from the consumer. SB 923 expands the deletion right to personal information a covered business collects “from or about” a consumer, subject to the CCPA’s existing exemptions and deletion exceptions. In practice, that means the deletion right now extends to data a business obtained about someone from other sources, such as data purchased from brokers, received from vendors or partners, appended for enrichment, or derived through identity resolution and inference. Businesses that have treated third-party or purchased data as outside the scope of a deletion request will need to revisit that position once the law is operative.

The bill does include an operational safeguard. For information obtained from sources other than the consumer, SB 923 permits a business to retain a record of the deletion request and the minimum data necessary to ensure the information remains deleted and is not used for any other purpose. This supports a suppression-list approach. Businesses using that approach should define limited retention and matching controls to prevent deleted information from re-entering active use. 

SB 923 also changes how businesses have to accept privacy requests. Under current law, a business that operates exclusively online and has a direct relationship with consumers can satisfy its intake obligations with an email address alone. Starting January 1, 2027, that same business must offer an email address and make an online method, such as a web form or an online portal, available for requests to know, delete, and correct personal information. An email inbox alone will no longer be enough for that category of business.

  • The right to delete expands from “collected from” to “collected from or about” the consumer, subject to the CCPA’s existing exemptions and deletion exceptions, reaching third party, purchased, appended, and inferred data.
  • Businesses may keep a minimal suppression record to prevent deleted third party data from being reacquired and repopulated.
  • Online-only businesses with a direct consumer relationship must add a web form or portal for requests to know, delete, and correct, in addition to an email address.
  • All of the above is operative January 1, 2027.

Why this matters for privacy programs

The practical burden here sits upstream of the consumer-facing request itself. Honoring an expanded deletion right depends on knowing where “about the consumer” data lives in the first place, across advertising, identity resolution, enrichment, and analytics vendors that many data maps don’t currently cover in detail. Teams that have scoped their data inventory around first-party collection will need to extend that mapping to third-party and inferred data sources before they can reliably fulfill a deletion request under the new standard.

The webform requirement is narrower in scope but has a hard compliance deadline: any CCPA-covered, exclusively online business with a direct consumer relationship that relies solely on email for these requests needs an online submission method in place by January 1, 2027, or it will be out of compliance from day one of the law’s operation.

SB 923 is also a useful reminder that California’s privacy legislation is not moving in one direction at a time. The same legislative session also produced SB 690, which limits private pen-register and trap-and-trace claims arising from website and app activity under CIPA. It does not eliminate other CIPA litigation risks. The two laws should therefore be tracked separately rather than treated as a single “California changed its privacy law” event.

How TrustArc can help you prepare

Preparing for SB 923 means connecting your consumer-facing intake process with the systems, data sources, and teams responsible for fulfilling deletion requests. TrustArc can help you strengthen both sides of that process.

Make privacy requests easier to submit and manage. TrustArc’s Individual Rights Manager supports configurable online intake forms for requests to know, delete, and correct personal information. Automated task assignments, jurisdiction-based deadline tracking, and secure communications help your team coordinate requests from intake through fulfillment, with an activity history to document how each request was handled.

Build visibility beyond first-party data collection. TrustArc’s Data Mapping & Risk Manager helps you maintain an inventory of personal data, systems, and processing relationships. Use that foundation to document broker, partner, enrichment, and other third-party data sources, so your deletion procedures can account for information collected about consumers, not just information collected directly from them. Connecting data mapping with rights-request workflows helps teams identify relevant systems and route fulfillment tasks to the appropriate owners.

Connect fulfillment with your broader operational controls. Individual Rights Manager’s integrations can help coordinate downstream actions in connected systems and reduce manual handoffs. As you design suppression and re-ingestion controls, those workflows can support coordination with the teams responsible for vendor feeds and data refreshes. Your organization still needs to define the suppression logic, minimum necessary retention, and applicable exceptions; request-management software alone does not prevent deleted data from returning.

Ready to prepare for SB 923? Talk to TrustArc about connecting your request intake, data inventory, and deletion workflows before January 1, 2027.

Book a Demo

Get the latest resources sent to your inbox

Subscribe
Back to Top