Insights: AlertsCalifornia Is Changing How Businesses Handle Privacy Requests: What to Do Before 2027September 30, 2026 On September 27, 2026, Governor Gavin Newsom signed SB 923, the Expanding Privacy Rights Act, which makes two important changes to the California Consumer Privacy Act (“CCPA”). Beginning January 1, 2027, the law expands the information covered by a consumer's deletion request and imposes a new request-submission requirement on certain online-only businesses. See Cal. S.B. 923, §§ 2–3 (2025–2026 Reg. Sess.) (amending Cal. Civ. Code §§ 1798.105, 1798.130). Deletion Requests Will No Longer Be Limited to Information Collected “From” the ConsumerThe most significant change is only a few words. Currently, the CCPA gives consumers the right to request deletion of personal information that a business collected “from” the consumer. SB 923 expands that right to personal information collected “from or about” the consumer. That means a business cannot necessarily satisfy a deletion request by searching only for information the consumer directly provided. Beginning January 1, 2027, the deletion right will also reach covered personal information obtained about the consumer from other sources, subject to the CCPA's existing exceptions. Depending on a business's practices, that could include information purchased from data brokers, received from marketing or business partners, or appended to an existing consumer profile through enrichment or identity-resolution services. The practical question for businesses is therefore: When a consumer asks us to delete their information, do we know everywhere that information came from? Companies should review whether their existing deletion searches extend beyond traditional first-party systems and reach third-party-sourced information maintained in customer relationship management systems, marketing platforms, and vendor-managed environments. Deleted Data Should Not Simply Come BackExpanding the deletion right to third-party data creates another practical problem. A business may delete information in response to a request and later receive the same information again from another source. SB 923 expressly addresses that scenario. For information obtained from a source other than the consumer, a business may retain a record of the deletion request and the minimum data necessary to ensure the consumer's information remains deleted and is not used for another purpose. The business may also maintain a confidential record of deletion requests for purposes permitted by the CCPA. See Cal. Civ. Code § 1798.105(c)(2)–(3) (as amended by S.B. 923). In practice, businesses should consider whether they need a suppression mechanism that can recognize later-arriving information associated with a consumer who previously requested deletion. But that suppression record should be limited. SB 923 does not provide a basis to retain a deleted consumer profile for convenience. The statute permits retention of the “minimum data necessary” to ensure the consumer's information remains deleted and is not used for another purpose. Id. § 1798.105(c)(2). Businesses should therefore consider both what identifiers are actually necessary to recognize the consumer later and how those identifiers are technically restricted from being reused for marketing, analytics, profile reconstruction, or other unrelated purposes. Online-Only Businesses Have a New Requirement TooSB 923 also changes how certain businesses must accept consumer privacy requests. Under the existing CCPA, a business that operates exclusively online and has a direct relationship with the consumer from whom it collects personal information may satisfy the applicable request-method requirement by providing an email address. Beginning January 1, 2027, email alone will no longer be enough. Those businesses must also provide an online method, such as a web form or online portal, through which consumers can submit requests for access, deletion, or correction. See Cal. Civ. Code § 1798.130(a)(1)(A) (as amended by S.B. 923). Online-only businesses should therefore review their privacy-rights interfaces now. A company that currently directs California consumers only to an email address will need an additional online submission mechanism before the new requirement takes effect. Businesses should also consider the downstream operational impact. Adding a web form is only the front end of the requirement. The submission method should connect to a process capable of authenticating requests where appropriate, routing them to the correct systems, tracking statutory response deadlines, and carrying the expanded deletion request through systems containing both first-party and third-party-sourced information. The CCPA generally requires businesses to respond to verifiable consumer requests within 45 days, subject to a possible 45-day extension when reasonably necessary. See id. § 1798.130(a)(2)(A). What Should Businesses Do Before January 1, 2027?Companies subject to the CCPA should consider using the remainder of 2026 to:
The Bottom LineSB 923 makes a small textual change with potentially significant operational consequences. Starting January 1, 2027, a CCPA deletion request will no longer be limited to personal information collected directly from the consumer. Businesses will need to account for information collected about the consumer as well. For companies that acquire or enrich consumer information from third parties, now is the time to determine whether existing deletion workflows can find that data, delete it, and keep it from coming back. And for online-only businesses, there is an even more concrete deadline: if email is currently your only method for accepting CCPA requests, you will need an online submission method by January 1, 2027. Related People![]() Meghan K. Farmer
mfarmer@ktslaw.com ![]() Tatum Andres
tandres@ktslaw.com |


