Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

California’s SB 923 expands the state’s deletion right to personal information a business obtained from third parties, allows a suppression list to help keep deleted information from returning, and requires online-only businesses to offer an online way to submit privacy requests. The law takes effect January 1, 2027. For developers, the practical change is to make deletion workflows account for data provenance and later imports—not just records collected directly from a consumer.

What SB 923 changes—and what it does not

Governor Gavin Newsom signed SB 923, the Expanding Privacy Rights Act, on September 27, 2026. The California Privacy Protection Agency (CPPA), which sponsored the bill, describes it as closing a gap in the CCPA deletion right: previously, businesses were not required to delete personal information obtained from third parties rather than collected directly from the consumer. SB 923 extends the right to that third-party-obtained information, with the change taking effect January 1, 2027.

The law also permits businesses to maintain a suppression list so that a consumer’s deletion decision can be honored when additional third-party data is acquired later. For online-only businesses, it requires an online submission option for privacy requests; the CPPA gives a webform as an example. An email address alone is not the stated online submission option.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SB 923 is an expansion of California’s existing privacy framework, not a separate, all-purpose privacy code. The California Attorney General explains that Proposition 24, the CPRA, amended the CCPA rather than creating a distinct law. The CCPA, as amended, includes rights to know, delete, correct inaccurate personal information, opt out of sale or sharing, limit the use or disclosure of sensitive personal information, and receive non-discriminatory treatment for exercising rights. Exceptions apply to some rights.

What a deletion workflow needs to handle differently

The law establishes an expanded deletion obligation and permits suppression lists; the CPPA announcement does not prescribe a particular software architecture. The following are engineering implications for teams building request-management systems, not a claim that the statute mandates these specific technical designs.

1. Preserve data provenance

A request tool that searches only records tagged as collected directly from the consumer may miss information acquired from vendors, partners, public sources, or other third parties. Keep enough source and system information to connect acquired records to the consumer identity used in request processing. That makes it possible to locate relevant data when an intake request is matched to a consumer.

2. Carry deletion state through later imports

Deletion should be treated as a state that downstream systems and processors can act on, not merely as a one-time removal from the database where a request was first handled. The permitted suppression-list approach is relevant when a later enrichment, synchronization, or vendor import could reintroduce information associated with a consumer who has already requested deletion. Design the workflow so that import and sync processes can check the relevant suppression state before adding or using those records.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Make request intake an explicit workflow

Review the routes available to consumers and the business model they serve. Online-only businesses need an online submission method, such as a webform. A request-management tool should make it clear which channel received a request, what kind of right the consumer is exercising, and how its status changes as the request is handled.

4. Keep different privacy rights distinct

Do not treat every incoming request as a generic deletion ticket. The Attorney General identifies separate rights to know, delete, correct, opt out of sale or sharing, and limit use or disclosure of sensitive personal information. Separate request types help route each case to the relevant data, process, notice, and response steps rather than applying a deletion action to a different kind of request.

Keep the 2026 regulations and 2027 obligations on separate timelines

A separate set of CCPA regulations adopted in 2025 took effect January 1, 2026. The package addresses risk assessments, cybersecurity audits, automated decisionmaking technology (ADMT), insurance, and updates to CCPA rules. Some obligations have later compliance dates, so the package’s effective date should not be mistaken for a single deadline for every requirement.

Milestone Who or what it concerns
January 1, 2026 Effective date of the 2025 CCPA regulation package.
January 1, 2027 SB 923 takes effect. ADMT requirements for significant decisions also begin for covered pre-existing uses.
April 1, 2028 CPPA submission deadline for risk assessment information for assessments conducted in 2026 and 2027.
April 1, 2028 Cybersecurity audit certification deadline for specified businesses with revenue over $100 million.
April 1, 2029 Cybersecurity audit certification deadline for specified businesses with revenue from $50 million to $100 million.
April 1, 2030 Cybersecurity audit certification deadline for specified businesses with revenue under $50 million.

The cybersecurity audit dates apply to specified businesses subject to the audit rules; revenue bands alone do not establish that a particular organization is covered. Confirm applicability before using a date as an implementation deadline.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Risk assessment and audit records

For organizations subject to the 2025 regulations, map covered processing to the applicable risk-assessment and cybersecurity-audit obligations. The regulations provide for submissions and executive attestation, and the CPPA or Attorney General may request assessment reports. A compliance workflow can help preserve the records and ownership needed to prepare those materials, but a tool by itself does not determine whether a business or processing activity is covered.

ADMT for significant decisions

The regulations establish consumer rights and pre-use notice requirements for covered use of ADMT in significant decisions. Covered uses that existed before January 1, 2027 must comply by that date; a new covered use beginning on or after January 1, 2027 must comply when it is used. Developers supporting these workflows should be able to connect a covered use to its notice and request-handling processes, while leaving the legal determination of whether a use qualifies to the organization and its counsel.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Do not confuse ordinary business workflows with the data-broker process

Data brokers have a separate Delete Act and DROP workflow. Under CPPA guidance, qualifying data brokers use the DROP platform for account creation, annual registration, and processing deletion lists. The agency’s 2026 instructions describe account and registration actions, deletion-list processing beginning August 1, and a 45-day period to access DROP and process the first batch. They list a $6,000 2026 annual registration fee, plus electronic payment processing fees, and say independent audits begin January 1, 2028 and recur every three years.

Those registration, fee, and DROP instructions concern data brokers as defined by law; they are not general requirements for every developer or CCPA-covered business. A product that serves both covered businesses and data brokers should avoid presenting the broker-specific workflow as a universal deletion process.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A practical review checklist for compliance-tool teams

Use these questions to assess your own workflow or to evaluate a tool. They are implementation questions, not verified claims about any particular product.

  • Can the system find a consumer’s information across relevant systems and distinguish records by source, including third-party acquisition?
  • Can deletion state reach processors and downstream systems, and can later imports check for a suppression decision?
  • Can consumers submit requests through the required channel for the business, and can staff track request type, status, and handling?
  • Can the organization map relevant processing to risk-assessment and audit records when those regulations apply?
  • For covered ADMT uses, can the workflow support pre-use notices and consumer requests on the applicable timeline?
  • Does the product distinguish the separate DROP process for qualifying data brokers from ordinary business request handling?

SB 923’s announcement does not resolve every question about exemptions, contracts, retention duties, or business-specific recordkeeping. Developers should treat the workflow changes as a planning basis, not as a substitute for determining legal coverage and applicable exceptions with qualified counsel.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.