If your business buys, licenses, or appends consumer data from anyone else, a California deletion request is about to cover it. And if your site only offers an email address for privacy requests, you have until January 1 to add a form.
What Happened
On September 27, 2026, Governor Newsom signed SB 923, the Expanding Privacy Rights Act, according to the California Privacy Protection Agency (CalPrivacy), which sponsored the bill. Senator Josh Becker (D-Menlo Park) wrote it. It cleared the Assembly 49 to 14 on August 26, and the Senate concurred 36 to 0 the next day. The changes take effect January 1, 2027.
The bill fixes a gap that has sat in the CCPA since it was written. Section 1798.105 gave consumers the right to delete personal information a business collected from them, so data a company bought from a broker or pulled in through an enrichment vendor fell outside the request. SB 923 rewrites the right to cover information collected "from or about the consumer," regardless of source. For third-party data, a business complies by keeping a record of the request plus the minimum data needed to make sure the information stays deleted and isn't used for anything else. In practice, that means a suppression list, so the same record doesn't come back in next quarter's data refresh.
"Now the right to delete will finally do what people expect it to do: deletion, no matter how the business got that information in the first place," said CalPrivacy Executive Director Tom Kemp.
The second change amends section 1798.130. Today a business that operates exclusively online and has a direct relationship with its consumers can get by with just an email address for requests to know, delete, or correct. Starting in 2027 it has to offer an email address and an online method, such as a web form or portal.
The same day, the Governor vetoed AB 1542, which would have barred businesses from selling or sharing sensitive personal information outright. The existing right to limit the use of sensitive data stays as it is.
What Website Owners Should Do
Start with where your customer records come from. If you enrich CRM profiles, buy lead lists, or match audiences through a data partner, those sources now fall under a deletion request, and your deletion workflow has to reach every system they feed. The exemptions for fraud prevention, research, and legal obligations still apply, so nothing forces you to delete what the law lets you keep.
Then build the suppression step. Deleting a record once isn't enough if a vendor sends it back a month later, and the new statute plainly expects you to keep the minimum needed to stop that.
Finally, look at your request intake. An online-only business with a mailbox as its sole request channel will be out of step on January 1. Your privacy policy should also describe the broader deletion right accurately once the new text is in force.
Where Privisy Fits
Privisy's policy analysis stage already reads your privacy policy for the right-to-delete disclosure and follows its links looking for an interactive request form that covers at least two of the four CCPA rights. When it finds only a designated email address, the report says so. Under the current statute that finding is advisory for an online-only business; from 2027 that same gap is what SB 923 closes. Running an audit now gives you the list before the deadline instead of after it.
Check Your Request Intake Before January
Privisy audits your privacy policy, request mechanisms, and tracker behavior against the CCPA rules in force today and the ones coming next.