On September 27, 2026, Governor Gavin Newsom signed SB 923, the Expanding Privacy Rights Act, which significantly expands the deletion right under the California Consumer Privacy Act. What does this mean for companies subject to the CCPA and how does it compare to data brokers subject to the California DELETE Act?
What SB 923 Changes
Beginning January 1, 2027, consumers will be able to request deletion of covered personal information that a business collected “from or about” them. This is a significant expansion from the current CCPA language that only applies to information collected “from” the consumer. This may include appended contact information, demographic data, marketing segments, identity-resolution data and other information used to enrich a consumer profile. The CCPA’s existing statutory exceptions will continue to apply.
It also brings California’s deletion right more closely in line with laws in states such as Delaware, Indiana, New Jersey and Maryland, which extend deletion rights to personal data obtained about or concerning the consumer, rather than limiting deletion to information provided directly by the consumer.
SB 923 also addresses what happens when a business later receives the same information from another source. For information obtained from a source other than the consumer, the business may retain a record of the deletion request and the minimum data necessary to ensure that the information remains deleted and is not used for another purpose. The business may also maintain a confidential record of deletion requests for purposes permitted by the CCPA, including preventing the consumer’s personal information from being sold.
The California Privacy Protection Agency describes this as allowing businesses to maintain a suppression list so that deleted information is not reintroduced when the business acquires new third-party data.
Current CCPA Regulation section 7022(b)(5) already permits a business, service provider, contractor or third party to retain a record of a deletion request to ensure that the consumer’s personal information remains deleted. SB 923 makes this principle explicit in the statute for information obtained from third parties and permits retention of the minimum data necessary to implement it.
SB 923 also changes the required request-submission methods. An online-only business that has a direct relationship with the consumer will be required to provide an online submission method, such as a webform or portal, in addition to an email address.
How Is This Different From DROP?
DROP is the centralized deletion mechanism created under California’s Delete Act for registered data brokers. Beginning August 1, 2026, data brokers must access DROP at least once every 45 days, download the applicable consumer deletion lists, compare the hashed identifiers against their records, take the required action and report the status of each request.
A second law signed on September 27, 2026, AB 883, shortens the DROP compliance cycle. The current DELETE Act requires data brokers to access DROP and process requests at least once every 45 days. Effective January 1, 2027, AB 883 reduces that period to 30 days. Data brokers will be required to access DROP at least once every 30 days and process downloaded deletion requests, including unverifiable requests that must be treated as opt-outs, within 30 days.
The law also changes the recurring deletion requirement. After processing a deletion request, a data broker must delete subsequently acquired covered personal information at least once every 30 days, unless the consumer requests otherwise or an applicable statutory exception applies. The prohibition on selling or sharing new personal information remains in place unless the consumer requests otherwise or the sale or sharing is permitted under an applicable statutory exception
Even with SB 923’s expansion of the CCPA right delete, the deletion right (and corresponding obligation on the business) under CCPA is very different than that under the DELETE Act.
1. Scope of Covered Entities
The CCPA deletion right applies to businesses subject to the CCPA. DROP applies to businesses that meet California’s definition of a data broker and are required to use the state platform.
A company could be subject to both requirements. For example, a business may maintain information collected through its own consumer-facing operations while separately engaging in activities that qualify it as a data broker.
2. How the Request Is Made
A CCPA deletion request is submitted directly to the business through its designated consumer-request methods.
A DROP request is submitted through the state-operated platform. Data brokers receive deletion lists containing hashed consumer identifiers, such as an email address, phone number, mobile advertising identifier or a combination of name, date of birth and ZIP code.
3. Treatment of First-Party Information
Beginning January 1, 2027, a CCPA deletion request will apply to covered personal information collected from or about the consumer, subject to the CCPA’s exceptions.
The DROP process focuses on personal information collected outside an intentional first-party interaction. The DROP regulations do not require deletion of information collected directly from the consumer through a qualifying first-party interaction. That information remains subject to the ordinary CCPA deletion process.
4. Ongoing Treatment of Newly Acquired Information
Both regimes contemplate retaining limited information to help keep deleted information deleted, but DROP is more prescriptive.
For a matched DROP request, the data broker must retain the minimum personal information necessary for ongoing compliance unless the consumer amends or cancels the request.
For an unmatched request, the data broker must save and maintain the consumer deletion list and compare it against newly collected records before selling or sharing new personal information. If a match is identified later, the broker must take the required action and report the updated status through DROP.
The Delete Act also requires a broker, after processing a consumer’s deletion request, to delete newly acquired covered personal information at least once every 45 days and not sell or share new personal information unless the consumer requests otherwise or an applicable statutory exception applies. Effective January 1, 2027, shortens the recurring deletion period, as well as the DROP access and request-processing periods, from 45 days to 30 days. SB 923 does not import DROP’s 30-day access cycle, hashed-list matching process or status-reporting requirements into the ordinary CCPA process.
5. Multiple Consumers Associated With One Identifier
DROP includes a specific rule for identifiers associated with multiple consumers. If the broker cannot identify a single consumer because several consumers are associated with the matched identifier, the broker must opt the associated consumers out of sale or sharing rather than delete all associated records.
The ordinary CCPA deletion process does not use this DROP-specific response mechanism. Beginning January 1, 2027, SB 923 permits a business handling third-party-sourced information to retain the deletion-request record and minimum data necessary to keep the information deleted, but it does not appear to permit the business to substitute an opt-out of sale or sharing for deletion.
Some other state privacy regimes take a different approach. Colorado, for example, permits a controller to comply with a request to delete third-party-sourced personal data either by using a limited suppression record or by opting the consumer out of all nonexempt processing of that data. The Colorado alternative is broader than a conventional do-not-sell request.
Additional DROP Protections for Elected Officials and Judges
AB 883 also creates additional notice and enforcement provisions for California elected officials and judges. Beginning July 1, 2027, designated state and local government bodies, the Judicial Council and the State Bar must notify covered elected officials and judges that they may submit deletion requests through DROP.
The Attorney General, a county counsel or a city attorney may bring a civil action on behalf of an elected official or judge against a data broker that violates the DELETE Act’s deletion requirements with respect to that person’s information. Available relief includes declaratory and injunctive relief, reasonable attorneys’ fees and actual damages. A court may also award punitive damages for a willful violation.
These provisions do not establish a separate deletion procedure for elected officials and judges. Data brokers must process those requests under the same DROP requirements and implementing regulations.
What Should Companies Do?
Companies should consider the following steps before January 1, 2027:
- Identify third-party data. Determine which systems contain information purchased from data brokers, received from marketing partners or appended through enrichment and identity-resolution services.
- Expand deletion procedures. If you have a specific process for California deletion rights, that addresses only information collected directly from the individual, you must adapt your deletion searches to cover third-party-sourced information in CRM systems, marketing platforms, customer data platforms, data warehouses and vendor-managed environments.
- Review suppression controls. Determine what minimum information is needed to recognize later-arriving data concerning a consumer who submitted a deletion request. The retained information should not be used to reconstruct the profile or for marketing, analytics or other unrelated purposes.
- Keep CCPA and DROP workflows distinguishable. A company may use the same privacy-request platform to administer both, but it should preserve the source of the request, applicable legal regime, scope of information, action taken and any DROP reporting obligations.
- Update request methods and notices. Online-only businesses with a direct consumer relationship should implement the required online submission method and update their privacy notices, procedures and response templates.
- Prepare for the 30-day DROP cycle. Data brokers should update automated downloads, internal matching workflows, service-provider instructions, escalation timelines and status-reporting procedures to accommodate the shorter statutory cycle beginning January 1, 2027.
SB 923 narrows the gap between the CCPA and DROP deletion rights, but it does not close it. Companies subject to both laws will need to maintain parallel compliance frameworks that account for the regimes’ different scope, request channels, matching rules, timing and reporting obligations. Companies subject to the CCPA should now review their deletion processes, including whether they identify and delete information obtained from third parties. Online-only businesses with a direct consumer relationship should also prepare to add an online request method by January 1, 2027. Data brokers must also prepare for AB 883’s reduction of the DROP compliance cycle from 45 days to 30 days.