SB 923 Is Law: CCPA Deletion Now Covers Third-Party Data, and Email Alone Is Not Enough

Table of Contents

California just closed the biggest hole in the CCPA right to delete. On September 27, 2026, Governor Gavin Newsom signed SB 923, the Expanding Privacy Rights Act, authored by Senator Josh Becker and sponsored by the California Privacy Protection Agency. Starting January 1, 2027, a deletion request covers personal information a business holds about a consumer no matter how it got there, including data bought from brokers, appended by enrichment vendors, or handed over by a partner. Online-only businesses also lose the email-only shortcut for privacy requests. They must offer an online method, such as a webform or portal, in addition to an email address.

CalPrivacy New Laws for CCPA

Chaptered as Chapter 482 of the Statutes of 2026. Effective January 1, 2027.

The loophole

Civil Code section 1798.105 gave consumers the right to delete personal information a business had collected from them. Data the business never collected from the person sat outside the request. A CRM record typed in from a web form had to go. The same person’s record bought from a list vendor, matched by a data broker, or appended with a household income estimate did not.

That was not a corner case. Most consumer files are a mix of first-party and third-party data. A shopper deletes the account they created. The enrichment record, the lookalike segment, and the broker append stay. CalPrivacy’s announcement put it plainly: a meaningful share of a consumer’s personal information could be retained and exposed to breach or misuse after the person had already submitted a deletion request.

Tom Kemp, CalPrivacy’s executive director, said the right to delete will now “do what people expect it to do: deletion, no matter how the business got that information in the first place.”

What the statute actually requires

SB 923 expands the right to delete to personal information the business has collected from or about the consumer. Source no longer matters. Bought, licensed, scraped, appended, or received from a partner, it is in scope unless an existing CCPA exception applies. Those exceptions are unchanged. Legal holds, security, transaction completion, and the other statutory carve-outs still exist.

For information the business did not obtain from the consumer, compliance can be met by retaining a record of the deletion request and the minimum data necessary to keep that information deleted and to stop it from being used for any other purpose. That is the suppression-list rule. CalPrivacy described it as the mechanism that keeps a person deleted even as new third-party data comes in.

The standard now lines up with Delaware, Indiana, Maryland, and New Jersey, which already require deletion of non-exempt personal information about an individual regardless of source. A program built only for those states is closer to ready. A program that treated broker data as out of scope is not.

The intake change: a webform, not just an email

This is the operational piece most teams will feel first.

Today, a business that operates exclusively online and has a direct relationship with the consumer can meet the CCPA request-method rule with an email address. Section 1798.130 is what created that carve-out. SB 923 narrows it. Those businesses must still provide an email address, and they must also make an online method available, such as a webform or online portal, for requests to know, delete, and correct.

Maureen Mahoney, CalPrivacy’s deputy director of policy and legislation, said the webform will make requests simpler and push more Californians to use rights they already have. That is also why an inbox is a weak control. Email does not collect the identifiers you need to find a person across systems. It does not timestamp intake. It does not route to the team that can actually delete. It does not produce an audit log when a regulator asks how the 45-day clock was met. A support-ticket form bolted onto the marketing site has the same problem: it captures a message, not a rights request.

A DSAR system is the difference between publishing a form and being able to honor what the form collects.

  • Identity and scope up front. The form should collect the minimum needed to find the person, the request type, and the California residency signal, without asking for a copy of a driver’s license on every submission.
  • A clock that starts itself. CCPA still runs on 45 days, with one 45-day extension. Intake date, acknowledgment, and extension notice have to be automatic.
  • A workflow, not a mailbox. Deletion now has to hit the CRM, the warehouse, the enrichment vendor, the ad platform, and the broker file. Email cannot orchestrate that.
  • A suppression list that survives the next data buy. SB 923 expressly allows retention of the minimum data needed to keep a person deleted. That list has to be checked before new third-party records are loaded, or the deletion is undone on the next append.
  • An appeal path and a record. Denied or partially denied requests need a reason, a log, and a way for the consumer to appeal. CalPrivacy can test the form. An empty inbox will not pass that test.

What to fix before January 1

  • Map every source of personal information about a consumer, not just what the person typed in. Broker feeds, co-op lists, enrichment, partner shares, and offline uploads are now in the deletion set.
  • Build or buy a suppression list and wire it to ingestion. A delete that does not block the next file drop is not a delete under this statute.
  • Replace email-only intake if you are online-only. The webform or portal has to sit next to the existing email address, and it has to feed a system that can track, fulfill, and prove the request.
  • Update the privacy policy and the request instructions so they match the new scope. A policy that still says deletion applies only to information collected from the consumer will be wrong on day one.
  • Retrain whoever handles requests. The old answer, “we didn’t collect that from you,” is no longer a complete response.

SB 923 does two things

SB 923 does two things, and they land on the same day. Deletion reaches data a business bought or appended, with a suppression list as the way to keep it deleted. And the online-only email carve-out is over: a webform or portal is required, not optional. An inbox can receive a request. It cannot find third-party records, block the next data load, or show a regulator the clock was met. That is the work between now and January 1, 2027.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.