Skip to content
← Back to blog
Regulation·September 30, 2026·8 min read

California SB 923 makes CCPA deletion cover data you bought, not just data you collected. It starts January 1, 2027.

SB 923 extends the CCPA right to delete to data obtained from third parties, effective January 1, 2027. What that means for enrichment feeds and sync jobs.

California's right to delete used to have an escape hatch: a business could refuse to delete personal information it had bought or received from someone else, on the theory that the consumer's request only reached data collected from the consumer. Senate Bill 923, which Governor Newsom signed on September 27, 2026, closes it. According to the California Privacy Protection Agency (CalPrivacy), the law takes effect January 1, 2027, the same day the ADMT rules start to bite, and it means a deletion request now reaches your enrichment vendor's data, your purchased lead lists and your data partner's feed. Most engineering teams have never mapped where that data sits.

What SB 923 changes

The California Privacy Protection Agency announced on September 27, 2026 that SB 923, the Expanding Privacy Rights Act, requires a business to delete a consumer's personal information regardless of how it was obtained. The agency sponsored the bill and Senator Josh Becker (D-Menlo Park) authored it. Before the change, the deletion right in Civil Code 1798.105 was read as covering information collected from the consumer. The enrolled text of the bill extends it to information collected "from or about" the consumer.

The plain-English version: if a customer asks you to delete their data, "we got that from a data provider" stops being an answer.

Two smaller provisions matter for how you build the fix. According to the bill text on the California Legislature's site, a business that received data from a third party may comply by retaining a record of the deletion request and the minimum data necessary to make sure the person stays deleted, and it may not use that record "for any other purpose." CalPrivacy calls this a suppression list. And online-only businesses with a direct relationship to consumers, who could previously take requests by email alone, must also offer an online method such as a web form or portal.

Executive Director Tom Kemp put the intent in one line: "Now the right to delete will finally do what people expect it to do: deletion, no matter how the business got that information in the first place."

Why the effective date is the real story

Legislative-text summaries of the bill show no separate operative date, and CalPrivacy's own announcement gives January 1, 2027. That fits California's default rule that ordinary statutes take effect on the January 1 following enactment. It also means the deletion change lands on the same day as the automated decision-making rules for employers. A compliance team that had penciled January 2027 as "the ADMT date" now has two workstreams with one deadline, and they draw on the same engineers.

That is a resourcing problem before it's a legal one. Both need someone who knows which systems hold which records, which is precisely the knowledge that tends to live in one senior person's head.

The delete button was never the hard part

The existing right to delete already asks a lot. The business has to act on a verified request within 45 days (extendable once by another 45 with notice), and tell its service providers and contractors to delete too. Teams handle that by wiring a delete endpoint to the primary database and calling it done.

SB 923 breaks that shortcut. Data that arrives from outside doesn't arrive in one table. It gets copied into the CRM, the data warehouse, the analytics tool, the email platform, the model-training snapshot someone took last quarter and a spreadsheet a salesperson exported. A delete against the primary record leaves every copy behind, and until now nobody was obliged to look.

Picture a 40-person B2B software company that enriches each new signup with purchased firmographic and contact data. It stores the enrichment fields on the user row, mirrors them nightly to the warehouse, pushes them to a marketing automation tool, and once a quarter exports a segment to an outbound vendor. Under the old reading, a deletion request from a Californian meant deleting what the person typed into the signup form. Under SB 923 it also means the purchased job title, the inferred company size and the phone number from the vendor, in all four places, and then keeping just enough to make sure the next vendor refresh doesn't put them back.

That last clause is the design problem. Deleting the row is easy. Staying deleted when a nightly sync from a third party re-inserts the same person is what needs engineering.

What the DROP rollout says about doing this at scale

There is a live case study of deletion at scale, and it isn't flattering. California's Delete Act platform, DROP, lets residents send one deletion request to every registered data broker. CalPrivacy reported on August 25, 2026 that more than 500,000 Californians had signed up since the January 1 launch, that 654 data brokers were part of the system, and that brokers had been required to begin processing requests on August 1.

Here's the number worth sitting with. The same announcement said only about a quarter of brokers had reported processing deletion requests by then. Data brokers are businesses whose entire product is personal data, they were told the date months ahead, and roughly three-quarters had not yet reported processing anything. If that's the pace for companies built around the data, a mid-market company with personal information scattered across a dozen tools should assume its own first pass will be slower than expected.

The agency's tone toward brokers has also hardened. Its newsroom lists enforcement actions against data brokers on August 11, August 13 and September 1, 2026, and an Enforcement Advisory on September 3. Those target brokers, not ordinary employers. But they show the agency will move quickly on deletion-related failures once a date has passed.

Where SB 923 doesn't reach you

An honest scoping note, because a partner that says every regulation needs a custom build is selling something. If your company holds only information customers gave you directly, and you don't buy, enrich or receive personal data from other companies, SB 923 changes little. Your existing delete flow probably already covers what the law asks. Add the web form if you're online-only, update the privacy notice and move on. You don't need an engineering engagement for that, and we would tell you so.

Nor is this legal advice. Whether a particular exemption applies to your data is a question for counsel. What we can help with is the system side: finding where the data is and making deletion propagate.

What to do before January

Start with an inventory, not a build. List every source of personal data that doesn't come straight from the person: enrichment APIs, purchased lists, partner feeds, data received in an acquisition. For each, write down which of your systems it lands in. That map is usually the whole first month's work, and it tends to reveal copies nobody remembered.

Then decide, deliberately, what your suppression list holds. The statute limits it to a record of the request and the minimum data needed. A hashed identifier can be enough. A full copy of the profile "just in case" defeats the point, and using the list for marketing exclusion or analytics would fall outside the "no other purpose" limit.

Finally, pick where deletion is orchestrated. One service that owns the request, fans it out to every system holding the data, and records what happened is easier to defend than a checklist of manual steps. It is also the same audit-trail thinking behind logging automated decisions, and if you're already running vendors through the contract requirements the CCPA rules add, your data vendors belong on that same list. For a sense of how the agency treats requests that don't get honored, see the opt-out enforcement actions against Honda and Todd Snyder.

If your data map has gaps and your engineering team is already full with the ADMT work, tell us what your data flows look like and we'll say plainly whether this is a two-week mapping exercise or a real build. For a broader project, see how we scope custom software, or get in touch directly.

Sources

Frequently asked questions.

SB 923, signed September 27, 2026, extends the CCPA right to delete in Civil Code 1798.105 from information collected from the consumer to information collected "from or about" the consumer. Per the California Privacy Protection Agency, a business must delete regardless of how it obtained the data, including from third parties. CalPrivacy says the change takes effect January 1, 2027.

Yes, within limits. Per the SB 923 bill text on the California Legislature's site, a business that received data from a third party may retain a record of the deletion request and the minimum data necessary to keep the person deleted. The record cannot be used for any other purpose. CalPrivacy describes this as a suppression list.

Yes. Per the California Privacy Protection Agency's September 27, 2026 announcement, online-only businesses that deal directly with consumers must provide a web form or online submission method for privacy requests, rather than relying on email alone. The change to Civil Code 1798.130 takes effect January 1, 2027.

CalPrivacy reported on August 25, 2026 that more than 500,000 Californians had signed up for DROP since its January 1 launch and that 654 data brokers were registered. Brokers were required to begin processing requests on August 1, 2026, and about a quarter had reported processing any by that date. It is a useful benchmark for how hard deletion across many systems is.

Much less. The change targets personal information a business obtained from other sources, such as enrichment vendors, purchased lists and partner feeds. A company holding only self-supplied data likely already meets most of what the law asks, apart from the web-form provision for online-only businesses. Whether an exemption applies to specific data is a question for counsel.