Insights: Alerts California Is Changing How Businesses Handle Privacy Requests: What to Do Before 2027

On September 27, 2026, Governor Gavin Newsom signed SB 923, the Expanding Privacy Rights Act, which makes two important changes to the California Consumer Privacy Act (“CCPA”). Beginning January 1, 2027, the law expands the information covered by a consumer’s deletion request and imposes a new request-submission requirement on certain online-only businesses. See Cal. S.B. 923, §§ 2–3 (2025–2026 Reg. Sess.) (amending Cal. Civ. Code §§ 1798.105, 1798.130).

Deletion Requests Will No Longer Be Limited to Information Collected “From” the Consumer

The most significant change is only a few words. Currently, the CCPA gives consumers the right to request deletion of personal information that a business collected “from” the consumer. SB 923 expands that right to personal information collected “from or about” the consumer.

That means a business cannot necessarily satisfy a deletion request by searching only for information the consumer directly provided.

Beginning January 1, 2027, the deletion right will also reach covered personal information obtained about the consumer from other sources, subject to the CCPA’s existing exceptions. Depending on a business’s practices, that could include information purchased from data brokers, received from marketing or business partners, or appended to an existing consumer profile through enrichment or identity-resolution services.

The practical question for businesses is therefore: When a consumer asks us to delete their information, do we know everywhere that information came from?

Companies should review whether their existing deletion searches extend beyond traditional first-party systems and reach third-party-sourced information maintained in customer relationship management systems, marketing platforms, and vendor-managed environments.

Deleted Data Should Not Simply Come Back

Expanding the deletion right to third-party data creates another practical problem. A business may delete information in response to a request and later receive the same information again from another source. SB 923 expressly addresses that scenario.

For information obtained from a source other than the consumer, a business may retain a record of the deletion request and the minimum data necessary to ensure the consumer’s information remains deleted and is not used for another purpose. The business may also maintain a confidential record of deletion requests for purposes permitted by the CCPA. See Cal. Civ. Code § 1798.105(c)(2)–(3) (as amended by S.B. 923).

In practice, businesses should consider whether they need a suppression mechanism that can recognize later-arriving information associated with a consumer who previously requested deletion.

But that suppression record should be limited. SB 923 does not provide a basis to retain a deleted consumer profile for convenience. The statute permits retention of the “minimum data necessary” to ensure the consumer’s information remains deleted and is not used for another purpose. Id. § 1798.105(c)(2). Businesses should therefore consider both what identifiers are actually necessary to recognize the consumer later and how those identifiers are technically restricted from being reused for marketing, analytics, profile reconstruction, or other unrelated purposes.

Online-Only Businesses Have a New Requirement Too

SB 923 also changes how certain businesses must accept consumer privacy requests. Under the existing CCPA, a business that operates exclusively online and has a direct relationship with the consumer from whom it collects personal information may satisfy the applicable request-method requirement by providing an email address.

Beginning January 1, 2027, email alone will no longer be enough. Those businesses must also provide an online method, such as a web form or online portal, through which consumers can submit requests for access, deletion, or correction. See Cal. Civ. Code § 1798.130(a)(1)(A) (as amended by S.B. 923).

Online-only businesses should therefore review their privacy-rights interfaces now. A company that currently directs California consumers only to an email address will need an additional online submission mechanism before the new requirement takes effect.

Businesses should also consider the downstream operational impact. Adding a web form is only the front end of the requirement. The submission method should connect to a process capable of authenticating requests where appropriate, routing them to the correct systems, tracking statutory response deadlines, and carrying the expanded deletion request through systems containing both first-party and third-party-sourced information. The CCPA generally requires businesses to respond to verifiable consumer requests within 45 days, subject to a possible 45-day extension when reasonably necessary. See id. § 1798.130(a)(2)(A).

What Should Businesses Do Before January 1, 2027?

Companies subject to the CCPA should consider using the remainder of 2026 to:

  • Map third-party-sourced personal information. Identify information purchased, received, appended, or otherwise obtained about consumers rather than directly from them.

  • Test deletion workflows. Determine whether existing deletion searches actually locate that information across internal systems and vendor-managed environments.

  • Build or review suppression controls. Determine the minimum information necessary to prevent previously deleted third-party data from being reintroduced and ensure that information cannot be repurposed for unrelated uses.

  • Review vendor processes. Confirm that service providers and contractors can support the expanded scope of deletion requests when relevant information resides in their systems.

  • Update online request methods. Online-only businesses with a direct consumer relationship should add a web form, portal, or other qualifying online submission mechanism if they currently rely on email alone.

  • Update privacy notices and internal procedures. Make sure descriptions of deletion rights, request methods, internal playbooks, and employee training reflect the expanded right.

The Bottom Line

SB 923 makes a small textual change with potentially significant operational consequences. Starting January 1, 2027, a CCPA deletion request will no longer be limited to personal information collected directly from the consumer. Businesses will need to account for information collected about the consumer as well.

For companies that acquire or enrich consumer information from third parties, now is the time to determine whether existing deletion workflows can find that data, delete it, and keep it from coming back.

And for online-only businesses, there is an even more concrete deadline: if email is currently your only method for accepting CCPA requests, you will need an online submission method by January 1, 2027.

close
Loading...
If you would like to receive related insights and information from Kilpatrick Townsend, please provide your contact details by filling out the form and clicking “Agree.” If you would like to access the PDF only, please click “Download Only.”