Skip to content
TrustList
News

California widens the right to delete: from 1 January, businesses must also delete data they bought and offer a webform

Editorial

By TrustList Editorial

California’s SB 923, signed on 27 September 2026, extends the CCPA right to delete to personal information a business obtained from third parties and requires online-only businesses to accept requests online. It takes effect on 1 January 2027.

About California widens the right to delete: from 1 January, businesses must also delete data they bought and offer a webform

California widens the right to delete: from 1 January, businesses must also delete data they bought and offer a webform

27 September 2026 — Governor Gavin Newsom signed SB 923, the Expanding Privacy Rights Act, on 27 September 2026, the California Privacy Protection Agency (CalPrivacy), which sponsored the bill, announced the same day. It amends the California Consumer Privacy Act (CCPA) and takes effect on 1 January 2027.

What changes

  • Deletion covers third-party data. Until now, the CCPA right to delete applied to personal information a business collected from the consumer. From 1 January it also covers personal information the business obtained from third parties, such as data brokers, enrichment services and partners.
  • Suppression lists are allowed. A business may keep a record of deleted consumers so that the same data is not re-imported the next time a third-party file arrives.
  • Online-only businesses must accept requests online, for example through a webform, rather than only by email.

CalPrivacy says the change brings California in line with the deletion standard in Delaware, Indiana, Maryland and New Jersey.

Who is affected

Businesses covered by the CCPA, and especially those that buy or enrich customer data: marketing and sales teams using lead lists, data-enrichment tools and customer data platforms; data brokers and their clients; and online-only businesses whose privacy requests currently run through an inbox.

What to do before 1 January

  • Map where third-party personal data enters your systems: purchased lists, enrichment APIs, partner feeds, advertising platforms.
  • Check that your CRM, customer data platform and data warehouse can find and delete those records when a Californian asks, not only the records you collected directly.
  • Set up a suppression list and make sure imports check it.
  • If you do business only online, add a request webform to your privacy page.
  • Ask the vendors of your consent-management and privacy-request tools whether they cover third-party-sourced data and suppression, and when.

Not yet independently verified. This rests on CalPrivacy’s own announcement; the bill text and the Governor’s signing list were not read separately, and no independent report was found. We will update this when it can be confirmed, and remove this note.

Sources

Categories & features