California Legislature Passes Adjustments to Right to Privacy Laws

US and California flags

If your business collects personal information from California residents, one compliance duty you are likely to face is the right to deletion. Two measures in the 2025-2026 legislative session sought to refine the California Consumer Privacy Act of 2018 (CCPA), as amended by the California Privacy Rights Act of 2020 (CPRA). On September 27, 2026, Senate Bill 923 was signed by the governor, while Assembly Bill 1542 was vetoed because the governor called it “a step too far.”

Senate Bill 923 expands the consumer’s right to deletion. Any general counsel must first determine whether the CCPA even applies to your business, since the CCPA only concerns for-profit businesses doing business in California that meet certain thresholds, such as: (a) annual gross revenues above $25 million; or (b) annually buying, selling, or sharing the personal information of 100,000 or more consumers or households. While many small businesses fall outside these thresholds, businesses that handle large volumes of consumer data can be swept into the statute’s requirements, even without large revenues.

Assuming the law applies to your business, the current right to deletion rests on California Civil Code section 1798.105, which provides a consumer the right to request that your business delete any personal information you collected from them. When your business receives a verifiable consumer request, you must: (a) delete the information from your records; (b) direct your service providers and contractors (such as your cloud host, email marketing platform, or payroll vendor) to delete it; and (c) notify all third parties to whom you sold or shared the information to delete it, unless doing so proves impossible or involves disproportionate effort. Beyond those substantive obligations are transparency requirements: under Section 1798.130 your business must disclose the right to deletion in its privacy policy and offer designated methods for submitting requests, such as a webform or a toll-free number. For smaller operations, this often means a simple, documented intake process, rather than an elaborate system. Larger companies, however, may require more complex systems to comply with this obligation.

Importantly, the right is not absolute, and there are a series of statutory exceptions that permit your business to retain personal information, such as where reasonably necessary to complete a transaction or perform a contract, ensure security and integrity, debug and repair functionality, exercise free speech, comply with the California Electronic Communications Privacy Act, conduct certain research with the consumer's informed consent, enable compatible internal uses, or comply with a legal obligation. There are a number of additional carve-outs, including exemptions for household data, certain student educational records, and information subject to a law enforcement directive. The regulations issued by enforcement agencies help fill in the details governing how requests may be submitted, the timelines your business must meet (confirmation within 10 business days and a substantive response within 45 calendar days, extendable to 90), and the detailed explanation you must provide when you deny a request in whole or in part. These are firm deadlines, so businesses that are subject to the CCPA should have a calendaring practice in place to avoid missing them.

Accompanying this general framework is a distinct deletion regime for data brokers. Beginning August 1, 2026, once a broker has deleted a consumer's data, it must continue to delete that consumer's personal information at least once every 45 days, and it generally may not sell or share newly collected information about that consumer going forward.

Against this backdrop, Senate Bill 923 takes on significance. SB 923 expands the consumer’s right to deletion. The expansion broadens the categories of information subject to deletion, narrows or clarifies the retention exceptions, tightens the obligation to propagate deletion requests to service providers and third parties (including situations in which a business currently invokes the "impossible or disproportionate effort" standard), and strengthens the data broker deletion and enforcement mechanism.

For smaller and larger businesses subject to the CCPA alike, deletion workflow processes deserve renewed scrutiny -- particularly how they pass deletion requests along to service providers, contractors, and third parties. The tightening of the “disproportionate effort” standard raises the compliance bar considerably. In practice, that means knowing exactly which vendors hold your customers’ data and having a reliable way to communicate your obligations to delete it. These businesses’ reliance on the retention exceptions warrants review as well, since the expansion of the deletion right targets the breadth of those carve-outs. An exception a business may have relied on before could now be narrower. Finally, these businesses’ privacy policies and request-handling procedures should be positioned to absorb the changes to disclosure obligations and response requirements without a last-minute scramble. For most small businesses, this is merely a matter of keeping a simple written procedure, current rather than rebuilding from scratch.

SB 923 reflects California's continued expansion of consumer control over personal information, with the right to deletion at the center of the effort. Because enforcement and compliance ultimately turn on the precise statutory language, a business owner should confirm the operative amended text of the new law, ideally with general or outside counsel, before relying on any summary of its effect. The practical goal is not to predict every legislative twist but to keep your deletion process organized enough that tightening the rules becomes a manageable adjustment -- rather than a last minute scramble to ensure the business is in compliance.