California Expanded Consumer Data Deletion Rights
A new law broadens privacy protections to cover third-party data and mandates standardized deletion processes.
Updated on Sept. 28, 2026 in Cybersecurity

Live Poll
Do you trust businesses more when they are required to delete your personal data?
Governor Gavin Newsom signed SB 923, which expands the California Consumer Privacy Act to require the deletion of information collected about consumers, even if that data was not sourced directly from them. These provisions will take effect on January 1, 2027.
Why it matters
This update harmonizes California privacy standards with data deletion practices recently adopted in states including Delaware, Indiana, New Jersey, and Maryland. By closing the gap on indirect data collection, the law forces companies to maintain more comprehensive oversight of consumer information lifecycles.
Data brokers must now access the state-operated DROP platform at least every 45 days to process deletion requests. Starting January 1, 2027, the scope of deletion rights expands from information collected directly from the consumer to include all information collected from or about them.
The players
Gavin Newsom
The Governor of California who signed SB 923 into law.
The details
The law leverages the DROP platform, a centralized state-managed system that acts as a clearinghouse for consumer deletion requests. Businesses use these lists to identify and purge personal records from their databases, while retaining only the minimal metadata required to ensure that deleted information is not re-collected or reintroduced into active systems. Online-only firms are specifically required to implement public-facing webforms or portals to facilitate these requests.
Timeline
August 1, 2026: The DROP platform access mandate began for data brokers.
September 27, 2026: Governor Gavin Newsom signed SB 923 into law.
January 1, 2027: Deletion rights and online submission requirements take effect.
The Tech Race
This legislation places California in alignment with a growing coalition of states, including Maryland and New Jersey, that are expanding baseline privacy protections. The move signals a broader shift toward tighter regulatory control over the data broker ecosystem and third-party information sharing.
Starting January 1, 2027, residents will have the right to request deletion of data collected about them, even if they never interacted with the business directly. Consumers will be able to submit these requests via new webforms or portals maintained by online-only companies.
The takeaway
The law forces companies to move beyond direct-consumer data management to include indirect information pipelines. Consumers should prepare to monitor these new online deletion portals when they launch on January 1, 2027.
Further reading
For more on state-level data privacy mandates, see our Cybersecurity section.
Source note: This article includes information reported by Privacy Compliance & Data Security.
Live Poll
Do you trust businesses more when they are required to delete your personal data?








