CookieHub DSAR Management Platform handling a CCPA deletion request

SB 923: California expands the CCPA right to delete - what to do before 2027

Table of contents

California's SB 923 extends the CCPA right to delete to personal information a business holds about a consumer from any source, and requires online-only businesses to offer a web form or portal for privacy requests. It takes effect on 1 January 2027. Here is what changes and how to prepare.

California has changed the rules for one of the CCPA's most important consumer rights.

On 27 September 2026, Governor Gavin Newsom signed Senate Bill 923, the Expanding Privacy Rights Act. It expands the CCPA right to delete so that consumers can ask a business to delete personal information it holds about them, whether the business collected it from the consumer or obtained it from a third party. It also requires certain online-only businesses to offer an online way to submit privacy requests. The law takes effect on 1 January 2027.

That leaves a few months to review how privacy requests are submitted, verified, tracked, fulfilled and documented. This guide explains what SB 923 changes, who needs to pay attention, and what to do before the deadline - including putting a compliant privacy request webform in place.

Key dates

Date

What happens

27 September 2026

SB 923 signed by the Governor and filed with the Secretary of State (Chapter 482, Statutes of 2026)

Now to 31 December 2026

Review and update your privacy-request processes

1 January 2027

SB 923 takes effect

The California Privacy Protection Agency (CalPrivacy) confirms both dates. SB 923 is not a banner or privacy-policy change: it changes the operational process you use to handle consumer requests. The checklist below covers what to do before January.

What SB 923 changes

SB 923 amends Sections 1798.105 and 1798.130 of the California Civil Code. Two changes matter most for businesses.

1. The right to delete covers information collected from or about the consumer

Until now, the CCPA's deletion right covered personal information the business had collected from the consumer. The amended Section 1798.105 gives consumers the right to request deletion of any personal information the business has collected "from or about" them.

Take a typical customer profile: details submitted through a website form, purchase history, customer-service records, and enrichment data bought from a data provider. Under the expanded right, the fact that some of that information came from a third party no longer takes it outside the deletion request. CalPrivacy describes the change as closing a loophole that let businesses keep personal information obtained from third parties.

This matters most for businesses that enrich customer or prospect records from outside sources - for CRM, marketing, personalization, analytics, lead enrichment or fraud prevention. The question a deletion request asks is no longer "what did this consumer give us?" but "what do we hold about this consumer, and which of it is subject to deletion?"

2. Online-only businesses need an online request method

Businesses that operate exclusively online and have a direct relationship with their consumers currently only have to provide an email address for privacy requests. From 1 January 2027 they must also offer an online method, such as a web form or portal. The webform requirement section covers who it applies to.

What happens when a consumer submits a deletion request?

Treat a deletion request as a complete lifecycle, not an email arriving in an inbox. Be ready to:

  1. Receive the request.
  2. Verify the consumer's identity.
  3. Work out what personal information the request covers, and which exemptions apply.
  4. Locate that information across your systems, and delete or otherwise process it as required.
  5. Coordinate with service providers, contractors and relevant third parties.
  6. Keep the records the law permits, so the information does not reappear.
  7. Document the outcome and your response.

SB 923 requires service providers and contractors to cooperate with the business in responding, and sets specific rules for information obtained from sources other than the consumer.

The response deadline has not changed. Under Section 1798.130, a business must respond to a verifiable consumer request within 45 days of receiving it, extendable once by another 45 days when reasonably necessary, provided the consumer is told within the first 45 days. A request that lands in an unstructured email inbox is hard to verify, assign, track and complete inside that window.

The new CCPA webform requirement

The most immediately actionable part of SB 923 is the online submission requirement. It applies to businesses that:

operate exclusively online, and

have a direct relationship with the consumers they collect personal information from.

From 1 January 2027 these businesses must provide an email address and an online method, such as a web form or online portal, for requests to know, delete and correct. If your business falls into this category, a privacy email address alone will no longer be enough.

A privacy request webform gives consumers a structured way to submit those requests. Instead of leaving them to work out what to put in an email, it guides them through the submission - and it standardizes what you collect at intake.

What the webform should include

A generic "Contact us" form does not do the job. A useful privacy request webform is designed around the request workflow:

Consumer details. Only what you reasonably need for the request and for verification - typically name, email address and an account identifier.

Request type. Let the consumer choose deletion, access, correction or another applicable request.

Verification. Section 1798.130 lets a business require authentication that is reasonable in light of the personal information requested, but it cannot require the consumer to create an account to make the request.

Confirmation. Tell the consumer the request was received and what happens next.

Internal tracking. Record the request date and type, verification status, who is assigned, which systems were checked, what was done, and when you responded.

The expanded right to delete is a data-mapping challenge

For many businesses the hardest part will not be the webform. It will be finding all of the relevant personal information. If information can enter your organization through several sources, your deletion process has to account for each of them.

Data source

Example

SB 923 consideration

Website

Registration information

Review for deletion

CRM

Contact and customer records

Review for deletion

Ecommerce

Purchase history

Review for applicable exemptions

Marketing platform

Lead information

Review and coordinate

Data provider

Enriched customer profile

Third-party source no longer excludes it

Customer support

Tickets and correspondence

Review for applicable exemptions

Analytics

Identifiers and associated data

Review against the data held and the law

SB 923 does not require indiscriminate deletion of every piece of data. The statute keeps its exceptions where retention is reasonably necessary - including certain contractual, security, debugging, legal and research purposes - so have legal and privacy professionals review your specific obligations.

Third-party data: deletion that persists

If a business obtained personal information about a consumer from a source other than the consumer, it complies with a deletion request by keeping a record of the request and the minimum data necessary to make sure the information stays deleted and is not used for any other purpose. It may also keep a confidential record of deletion requests, solely to prevent the consumer's information from being sold, to comply with laws, or for other purposes the CCPA permits.

In practice, deletion is not the same as forgetting the request happened. Without a limited suppression record, deleted information simply comes back the next time a data provider sends it.

How SB 923 changes a typical privacy workflow

Stage

Workflow

Before SB 923

Request → verify → locate information collected from the consumer → delete

From 1 January 2027

Webform or email → verify → identify all information about the consumer → apply exemptions → delete → coordinate with providers and third parties → keep the permitted suppression record → document the response

The process has to find information regardless of how it entered the business.

SB 923 compliance checklist

Use this checklist to prepare for 1 January 2027.

Deletion and data

Confirm your deletion process covers personal information collected from or about consumers.

Identify information received from third parties, and map the systems that hold personal information.

Review the statutory exemptions that apply to you.

Keep permitted suppression records where necessary.

Request intake

Decide whether you are an exclusively online business with a direct consumer relationship.

If you are, add a dedicated privacy request form or portal, and keep the email method too.

Let consumers choose the request type, collect only what the process needs, build in verification, and confirm each submission.

Request handling

Assign ownership of incoming requests.

Track the 45-day response period, with an extension process.

Coordinate with service providers and contractors, and document completed actions.

Website and privacy notice

Review your CCPA disclosures and explain consumer rights clearly.

Make privacy-request instructions easy to find, and test the process as a consumer would.

For the rest of your CCPA obligations, see our CCPA compliance checklist.

Privacy request webform vs. email-only process

Capability

Email-only process

Dedicated privacy webform

Structured intake

Limited

Yes

Standardized request type

Limited

Yes

Confirmation to the consumer

Usually manual

Automatic

Identity verification

Manual

Built into the workflow

Request and deadline tracking

Manual

Built in

Audit trail

Scattered across email

Centralized

Consumer experience

Variable

Consistent

For a business that gets the occasional request, email may seem manageable. As volume grows - or as the scope of each request grows, which is exactly what SB 923 does - the difference becomes significant.

How SB 923 fits into California's wider privacy landscape

California's Delete Request and Opt-out Platform (DROP) gives consumers a single place to send deletion requests to registered data brokers, who have their own obligations under the California Delete Act: since 1 August 2026, registered data brokers must access DROP at least once every 45 days to download and process deletion requests.

SB 923 covers a different relationship - the requests consumers submit directly to businesses covered by the CCPA - but the direction is the same. Consumer privacy requests are becoming more structured, more accessible and more operationally significant. For an overview of the other rights involved, see what rights the CCPA gives consumers.

What small and midsize businesses should prioritize

You do not need a large privacy department to prepare for SB 923, but you do need a repeatable process. Start with five questions:

  1. Where can consumers submit a request? If the online-submission requirement applies to you, have a compliant online method in place before 1 January.
  2. Who receives the request? Do not let requests disappear into a generic inbox.
  3. How do you verify the consumer? Document a reasonable verification process suited to the information involved.
  4. Where does the consumer's data live? Map your CRM, ecommerce platform, marketing systems, support tools, databases and relevant third parties.
  5. How do you prove what happened? Keep records of when each request arrived, how it was handled, what was done, and when you responded.

How CookieHub helps

The CookieHub DSAR Management Platform gives qualifying online businesses the privacy request webform SB 923 asks for, and handles what comes after the submission:

Verified intake. Requests stay inactive until the consumer confirms by email, and are validated with CSRF protection, origin checks, API key validation and rate limiting.

Structured workflows. Support for multiple request types, with deadlines visible in the workflow. Attach internal systems - such as billing, infrastructure or HR tools - to each request and track completion system by system.

Audit logging. Every action is recorded with timestamps, user attribution and request history.

Secure delivery. Disclosure files are encrypted, stored in a secure vault and delivered through time-limited download links.

It is a practical way to add an online privacy request channel without building a DSAR system in-house.

Add a privacy request webform before 1 January 2027

CookieHub DSAR Management gives you a verified intake form, structured workflows, deadline tracking and an audit log - without building a DSAR system yourself.

Frequently asked questions

SB 923 expands the right to delete to personal information a business has collected from or about the consumer, rather than only information collected from the consumer. It also lets a business that obtained the information from another source comply by keeping a record of the deletion request and the minimum data needed to keep the information deleted. It takes effect on 1 January 2027.

For businesses that operate exclusively online and have a direct relationship with the consumers they collect personal information from, yes: SB 923 requires an online submission method, such as a web form or online portal, in addition to an email address. The requirement takes effect on 1 January 2027.

A CCPA deletion request is a consumer's request that a covered business delete their personal information. Under SB 923 the right covers personal information the business has collected from or about the consumer, subject to the statute's exceptions.

45 days from receiving the request. The period can be extended once by another 45 days when reasonably necessary, provided the consumer is told about the extension within the first 45 days. Build deadline tracking into your privacy-request workflow.

SB 923 extends the deletion right to information collected about the consumer, including information obtained from third parties. The statute's exceptions still apply, and a business that obtained the information from another source may keep a record of the request and the minimum data necessary to make sure the information stays deleted and is not used for any other purpose.

On 1 January 2027. Use the time before then to review your deletion procedures, request channels, verification process, data mapping and request tracking.

Conclusion

SB 923 materially expands the CCPA right to delete and gives businesses a clear deadline: 1 January 2027. Consumers will be able to request deletion of personal information collected from or about them, including information obtained from third parties, subject to the statute's exceptions. Online-only businesses with a direct consumer relationship will also need an online submission method such as a privacy request webform.

Build the process now rather than at the deadline: review your intake channels, verification, data sources, deletion workflows, third-party coordination and audit records - and put your privacy request webform in place before 1 January 2027.

Share this post

It's easy to be compliant with CookieHub

Sign up today and create a custom cookie banner for your website

14 day free trial

No credit card required