California widens the right to delete: from 1 January, businesses must also delete data they bought and offer a webform
EditorialBy TrustList Editorial
California’s SB 923, signed on 27 September 2026, extends the CCPA right to delete to personal information a business obtained from third parties and requires online-only businesses to accept requests online. It takes effect on 1 January 2027.
- United States of America
- California
- Sacramento, Ca
- Data Privacy Law
- +3 more
About California widens the right to delete: from 1 January, businesses must also delete data they bought and offer a webform
California widens the right to delete: from 1 January, businesses must also delete data they bought and offer a webform
27 September 2026 — Governor Gavin Newsom signed SB 923, the Expanding Privacy Rights Act, on 27 September 2026, the California Privacy Protection Agency (CalPrivacy), which sponsored the bill, announced the same day. It amends the California Consumer Privacy Act (CCPA) and takes effect on 1 January 2027.
What changes
- Deletion covers third-party data. Until now, the CCPA right to delete applied to personal information a business collected from the consumer. From 1 January it also covers personal information the business obtained from third parties, such as data brokers, enrichment services and partners.
- Suppression lists are allowed. A business may keep a record of deleted consumers so that the same data is not re-imported the next time a third-party file arrives.
- Online-only businesses must accept requests online, for example through a webform, rather than only by email.
CalPrivacy says the change brings California in line with the deletion standard in Delaware, Indiana, Maryland and New Jersey.
Who is affected
Businesses covered by the CCPA, and especially those that buy or enrich customer data: marketing and sales teams using lead lists, data-enrichment tools and customer data platforms; data brokers and their clients; and online-only businesses whose privacy requests currently run through an inbox.
What to do before 1 January
- Map where third-party personal data enters your systems: purchased lists, enrichment APIs, partner feeds, advertising platforms.
- Check that your CRM, customer data platform and data warehouse can find and delete those records when a Californian asks, not only the records you collected directly.
- Set up a suppression list and make sure imports check it.
- If you do business only online, add a request webform to your privacy page.
- Ask the vendors of your consent-management and privacy-request tools whether they cover third-party-sourced data and suppression, and when.
Not yet independently verified. This rests on CalPrivacy’s own announcement; the bill text and the Governor’s signing list were not read separately, and no independent report was found. We will update this when it can be confirmed, and remove this note.
Sources
Categories & features
- United States of America
- California
- Sacramento, Ca
- Data Privacy Law
- Privacy Law
- GDPR Compliance
- Customer Service Software
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More United States of AmericaThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.