
SB 923: California expands the CCPA right to delete - what to do before 2027
Table of contents
California's SB 923 extends the CCPA right to delete to personal information a business holds about a consumer from any source, and requires online-only businesses to offer a web form or portal for privacy requests. It takes effect on 1 January 2027. Here is what changes and how to prepare.
California has changed the rules for one of the CCPA's most important consumer rights.
On 27 September 2026, Governor Gavin Newsom signed Senate Bill 923, the Expanding Privacy Rights Act. It expands the CCPA right to delete so that consumers can ask a business to delete personal information it holds about them, whether the business collected it from the consumer or obtained it from a third party. It also requires certain online-only businesses to offer an online way to submit privacy requests. The law takes effect on 1 January 2027.
That leaves a few months to review how privacy requests are submitted, verified, tracked, fulfilled and documented. This guide explains what SB 923 changes, who needs to pay attention, and what to do before the deadline - including putting a compliant privacy request webform in place.
Key dates
Date | What happens |
|---|---|
27 September 2026 | SB 923 signed by the Governor and filed with the Secretary of State (Chapter 482, Statutes of 2026) |
Now to 31 December 2026 | Review and update your privacy-request processes |
1 January 2027 | SB 923 takes effect |
The California Privacy Protection Agency (CalPrivacy) confirms both dates. SB 923 is not a banner or privacy-policy change: it changes the operational process you use to handle consumer requests. The checklist below covers what to do before January.
What SB 923 changes
SB 923 amends Sections 1798.105 and 1798.130 of the California Civil Code. Two changes matter most for businesses.
1. The right to delete covers information collected from or about the consumer
Until now, the CCPA's deletion right covered personal information the business had collected from the consumer. The amended Section 1798.105 gives consumers the right to request deletion of any personal information the business has collected "from or about" them.
Take a typical customer profile: details submitted through a website form, purchase history, customer-service records, and enrichment data bought from a data provider. Under the expanded right, the fact that some of that information came from a third party no longer takes it outside the deletion request. CalPrivacy describes the change as closing a loophole that let businesses keep personal information obtained from third parties.
This matters most for businesses that enrich customer or prospect records from outside sources - for CRM, marketing, personalization, analytics, lead enrichment or fraud prevention. The question a deletion request asks is no longer "what did this consumer give us?" but "what do we hold about this consumer, and which of it is subject to deletion?"
2. Online-only businesses need an online request method
Businesses that operate exclusively online and have a direct relationship with their consumers currently only have to provide an email address for privacy requests. From 1 January 2027 they must also offer an online method, such as a web form or portal. The webform requirement section covers who it applies to.
What happens when a consumer submits a deletion request?
Treat a deletion request as a complete lifecycle, not an email arriving in an inbox. Be ready to:
- Receive the request.
- Verify the consumer's identity.
- Work out what personal information the request covers, and which exemptions apply.
- Locate that information across your systems, and delete or otherwise process it as required.
- Coordinate with service providers, contractors and relevant third parties.
- Keep the records the law permits, so the information does not reappear.
- Document the outcome and your response.
SB 923 requires service providers and contractors to cooperate with the business in responding, and sets specific rules for information obtained from sources other than the consumer.
The response deadline has not changed. Under Section 1798.130, a business must respond to a verifiable consumer request within 45 days of receiving it, extendable once by another 45 days when reasonably necessary, provided the consumer is told within the first 45 days. A request that lands in an unstructured email inbox is hard to verify, assign, track and complete inside that window.
The new CCPA webform requirement
The most immediately actionable part of SB 923 is the online submission requirement. It applies to businesses that:
operate exclusively online, and
have a direct relationship with the consumers they collect personal information from.
From 1 January 2027 these businesses must provide an email address and an online method, such as a web form or online portal, for requests to know, delete and correct. If your business falls into this category, a privacy email address alone will no longer be enough.
A privacy request webform gives consumers a structured way to submit those requests. Instead of leaving them to work out what to put in an email, it guides them through the submission - and it standardizes what you collect at intake.
What the webform should include
A generic "Contact us" form does not do the job. A useful privacy request webform is designed around the request workflow:
Consumer details. Only what you reasonably need for the request and for verification - typically name, email address and an account identifier.
Request type. Let the consumer choose deletion, access, correction or another applicable request.
Verification. Section 1798.130 lets a business require authentication that is reasonable in light of the personal information requested, but it cannot require the consumer to create an account to make the request.
Confirmation. Tell the consumer the request was received and what happens next.
Internal tracking. Record the request date and type, verification status, who is assigned, which systems were checked, what was done, and when you responded.
The expanded right to delete is a data-mapping challenge
For many businesses the hardest part will not be the webform. It will be finding all of the relevant personal information. If information can enter your organization through several sources, your deletion process has to account for each of them.
Data source | Example | SB 923 consideration |
|---|---|---|
Website | Registration information | Review for deletion |
CRM | Contact and customer records | Review for deletion |
Ecommerce | Purchase history | Review for applicable exemptions |
Marketing platform | Lead information | Review and coordinate |
Data provider | Enriched customer profile | Third-party source no longer excludes it |
Customer support | Tickets and correspondence | Review for applicable exemptions |
Analytics | Identifiers and associated data | Review against the data held and the law |
SB 923 does not require indiscriminate deletion of every piece of data. The statute keeps its exceptions where retention is reasonably necessary - including certain contractual, security, debugging, legal and research purposes - so have legal and privacy professionals review your specific obligations.
Third-party data: deletion that persists
If a business obtained personal information about a consumer from a source other than the consumer, it complies with a deletion request by keeping a record of the request and the minimum data necessary to make sure the information stays deleted and is not used for any other purpose. It may also keep a confidential record of deletion requests, solely to prevent the consumer's information from being sold, to comply with laws, or for other purposes the CCPA permits.
In practice, deletion is not the same as forgetting the request happened. Without a limited suppression record, deleted information simply comes back the next time a data provider sends it.
How SB 923 changes a typical privacy workflow
Stage | Workflow |
|---|---|
Before SB 923 | Request → verify → locate information collected from the consumer → delete |
From 1 January 2027 | Webform or email → verify → identify all information about the consumer → apply exemptions → delete → coordinate with providers and third parties → keep the permitted suppression record → document the response |
The process has to find information regardless of how it entered the business.
SB 923 compliance checklist
Use this checklist to prepare for 1 January 2027.
Deletion and data
Confirm your deletion process covers personal information collected from or about consumers.
Identify information received from third parties, and map the systems that hold personal information.
Review the statutory exemptions that apply to you.
Keep permitted suppression records where necessary.
Request intake
Decide whether you are an exclusively online business with a direct consumer relationship.
If you are, add a dedicated privacy request form or portal, and keep the email method too.
Let consumers choose the request type, collect only what the process needs, build in verification, and confirm each submission.
Request handling
Assign ownership of incoming requests.
Track the 45-day response period, with an extension process.
Coordinate with service providers and contractors, and document completed actions.
Website and privacy notice
Review your CCPA disclosures and explain consumer rights clearly.
Make privacy-request instructions easy to find, and test the process as a consumer would.
For the rest of your CCPA obligations, see our CCPA compliance checklist.
Privacy request webform vs. email-only process
Capability | Email-only process | Dedicated privacy webform |
|---|---|---|
Structured intake | Limited | Yes |
Standardized request type | Limited | Yes |
Confirmation to the consumer | Usually manual | Automatic |
Identity verification | Manual | Built into the workflow |
Request and deadline tracking | Manual | Built in |
Audit trail | Scattered across email | Centralized |
Consumer experience | Variable | Consistent |
For a business that gets the occasional request, email may seem manageable. As volume grows - or as the scope of each request grows, which is exactly what SB 923 does - the difference becomes significant.
How SB 923 fits into California's wider privacy landscape
California's Delete Request and Opt-out Platform (DROP) gives consumers a single place to send deletion requests to registered data brokers, who have their own obligations under the California Delete Act: since 1 August 2026, registered data brokers must access DROP at least once every 45 days to download and process deletion requests.
SB 923 covers a different relationship - the requests consumers submit directly to businesses covered by the CCPA - but the direction is the same. Consumer privacy requests are becoming more structured, more accessible and more operationally significant. For an overview of the other rights involved, see what rights the CCPA gives consumers.
What small and midsize businesses should prioritize
You do not need a large privacy department to prepare for SB 923, but you do need a repeatable process. Start with five questions:
- Where can consumers submit a request? If the online-submission requirement applies to you, have a compliant online method in place before 1 January.
- Who receives the request? Do not let requests disappear into a generic inbox.
- How do you verify the consumer? Document a reasonable verification process suited to the information involved.
- Where does the consumer's data live? Map your CRM, ecommerce platform, marketing systems, support tools, databases and relevant third parties.
- How do you prove what happened? Keep records of when each request arrived, how it was handled, what was done, and when you responded.
How CookieHub helps
The CookieHub DSAR Management Platform gives qualifying online businesses the privacy request webform SB 923 asks for, and handles what comes after the submission:
Verified intake. Requests stay inactive until the consumer confirms by email, and are validated with CSRF protection, origin checks, API key validation and rate limiting.
Structured workflows. Support for multiple request types, with deadlines visible in the workflow. Attach internal systems - such as billing, infrastructure or HR tools - to each request and track completion system by system.
Audit logging. Every action is recorded with timestamps, user attribution and request history.
Secure delivery. Disclosure files are encrypted, stored in a secure vault and delivered through time-limited download links.
It is a practical way to add an online privacy request channel without building a DSAR system in-house.
Frequently asked questions
SB 923 expands the right to delete to personal information a business has collected from or about the consumer, rather than only information collected from the consumer. It also lets a business that obtained the information from another source comply by keeping a record of the deletion request and the minimum data needed to keep the information deleted. It takes effect on 1 January 2027.
For businesses that operate exclusively online and have a direct relationship with the consumers they collect personal information from, yes: SB 923 requires an online submission method, such as a web form or online portal, in addition to an email address. The requirement takes effect on 1 January 2027.
A CCPA deletion request is a consumer's request that a covered business delete their personal information. Under SB 923 the right covers personal information the business has collected from or about the consumer, subject to the statute's exceptions.
45 days from receiving the request. The period can be extended once by another 45 days when reasonably necessary, provided the consumer is told about the extension within the first 45 days. Build deadline tracking into your privacy-request workflow.
SB 923 extends the deletion right to information collected about the consumer, including information obtained from third parties. The statute's exceptions still apply, and a business that obtained the information from another source may keep a record of the request and the minimum data necessary to make sure the information stays deleted and is not used for any other purpose.
On 1 January 2027. Use the time before then to review your deletion procedures, request channels, verification process, data mapping and request tracking.
Conclusion
SB 923 materially expands the CCPA right to delete and gives businesses a clear deadline: 1 January 2027. Consumers will be able to request deletion of personal information collected from or about them, including information obtained from third parties, subject to the statute's exceptions. Online-only businesses with a direct consumer relationship will also need an online submission method such as a privacy request webform.
Build the process now rather than at the deadline: review your intake channels, verification, data sources, deletion workflows, third-party coordination and audit records - and put your privacy request webform in place before 1 January 2027.
Share this post
It's easy to be compliant with CookieHub
Sign up today and create a custom cookie banner for your website
14 day free trial
No credit card required

