Under the CCPA as written, a business did not have to delete personal information it obtained from a third party rather than from the consumer. Enrichment files, data-broker appends, and partner feeds could stay on the record after the person asked for deletion. CalPrivacy Executive Director Tom Kemp said the bill makes the right “do what people expect it to do: deletion, no matter how the business got that information in the first place.”
The agency’s point is operational. A consumer who files a delete request and then remains in a breach notice six months later was often still in the file because the matched record came from a vendor, not from a form on the site. SB 923 treats that record as in scope.
What changes on January 1, 2027
California’s deletion standard moves toward the one already in Delaware, Indiana, Maryland, and New Jersey. Those states require deletion of personal information concerning the individual, not only information the business collected directly. CalPrivacy says businesses that already delete all non-exempt personal information on request in those states do not pick up a new workflow.
The bill also lets a business keep a suppression list so the same person is not re-added when the next third-party file arrives. That is the practical half of the fix. Without a suppression record, a monthly append from a broker puts the deleted profile back in the warehouse. The list is the exception that makes the deletion stick. It is still personal data, held for a narrow purpose, and it should not be used to rebuild the profile the consumer asked to erase.
Existing CCPA exemptions do not disappear. A business can still retain information it must keep for a legal obligation, a security incident, or another statutory exception. SB 923 does not turn every retention schedule into a violation. It removes the “we didn’t collect it from you” answer.
Requests have to be submittable online
Online-only businesses must offer an online method, such as a web form, and may not rely on an email address alone. Deputy Director of Policy and Legislation Maureen Mahoney said the form should make requests easier and pull more people into rights they already have.
Email-only intake is where deletion requests die: spam filters, shared inboxes, no ticket number, no clock start. A form creates a record. For a company already running CCPA request tooling, this is a configuration change. For a site that published a privacy@ address and called it a program, it is a build.
What to fix before the effective date
Map every store that holds personal information the business did not collect itself. Appends, identity graphs, lookalike seeds, and “enriched” CRM fields are the records this bill was written for. Confirm the deletion job reaches those stores, not only the first-party profile.
Stand up the suppression list and write down what it may be used for. Re-ingestion from a broker feed should check that list before the record lands. If a vendor cannot accept a suppression file, the contract is the gap.
If the business is online-only, put a web form next to the email address before January 1, 2027. Log the request, the systems searched, and the exemption if anything is kept. CalPrivacy sponsored the bill. It will be the agency reading those logs.