A new California privacy law changes who's responsible when a consumer asks you to delete their personal data. Starting January 1, 2027, businesses must honor deletion requests from California residents, regardless of who originally collected the information.
Governor Gavin Newsom signed SB 923, expanding obligations under the California Consumer Privacy Act (CCPA). If you're a compliance officer managing data subject rights, this shift requires rethinking your current deletion workflows.
What Changed
The new law removes a boundary that previously limited deletion obligations. Under existing CCPA rules, you only had to delete personal data your organization collected directly. SB 923 eliminates that limitation. Now, if you hold California resident data, you must delete it upon request, even if a vendor, partner, or third-party collector originally gathered it.
The California Privacy Protection Agency will oversee compliance.
Timeline
- Sunday (signing date): Governor Newsom signed SB 923 into law.
- January 1, 2027: Expanded deletion mandate takes effect.
- Between now and 2027: Businesses must redesign data inventories, vendor agreements, and deletion processes.
You have roughly two years to build the infrastructure this law demands.
Identifying Gaps in Current Practices
This regulatory shift exposes gaps in how most organizations handle data subject rights. Here's what breaks under the new mandate:
Incomplete data inventories. Most companies map data they collect themselves but don't maintain comprehensive records of data received from third parties. Your current inventory likely shows "customer email collected via web form" but not "customer email received from marketing platform via API."
Vendor contract gaps. Standard data processing agreements don't typically require vendors to notify you when they share personal data into your systems, nor do they obligate you to delete data the vendor originally collected. SB 923 makes those gaps your compliance problem.
Siloed deletion workflows. Your deletion process probably routes requests to the teams that collected the data. When data arrives from external sources, you may not have documented which systems received it or which teams control those systems.
Weak data lineage tracking. You can't delete what you can't find. If you don't track how personal data moves between systems, vendors, and business units, you can't fulfill a deletion request that spans all instances of that data.
Expanded Requirements
The CCPA already established deletion rights under Civil Code Section 1798.105. That section requires businesses to delete personal information upon verified consumer request, with specific exceptions for legal obligations, fraud prevention, and internal uses.
SB 923 expands Section 1798.105's scope. The original text tied deletion obligations to data "collected from the consumer." The new language removes that collection limitation, meaning your obligation now extends to any personal data you possess about a California resident, regardless of origin.
This matters because CCPA's definition of "personal information" is broad: any information that identifies, relates to, or could reasonably be linked to a California household or resident. That includes data you received from data brokers, partner companies, or service providers.
The California Privacy Protection Agency will interpret and enforce these expanded requirements. Expect guidance documents before the 2027 effective date, but don't wait for them to start building compliance infrastructure.
Action Items for Your Team
Map third-party data flows now. Document every system, API, and vendor that sends personal data into your environment. For each flow, record: what data elements arrive, how often, which internal systems receive them, and what business purpose they serve. This inventory becomes your deletion roadmap.
Rewrite vendor agreements. Your data processing agreements need new clauses. Require vendors to: (1) notify you when they share California resident data into your systems, (2) provide data manifests showing what they sent, (3) support deletion requests for data they originated, and (4) confirm deletion within defined timeframes. Negotiate these terms during your next renewal cycle, but prioritize vendors who send high volumes of personal data.
Build cross-system deletion capability. Your deletion process must reach every system that could hold California resident data, not just the systems that collected it. If you use a customer data platform, marketing automation tool, or data warehouse that ingests third-party data, ensure your deletion workflow can target records in those systems based on consumer identity, even when your organization didn't create the original record.
Implement data lineage tracking. You need technology that traces personal data from entry point through transformation, storage, and downstream use. Data catalogs, lineage tools, and privacy-specific platforms can automate this mapping. Manual spreadsheets don't scale when you're tracking data from dozens of vendors across hundreds of systems.
Test your deletion process with third-party scenarios. Run tabletop exercises where a consumer requests deletion of data you received from a partner. Can you identify which systems hold it? Can you delete it within the CCPA's 45-day response window? Can you verify deletion across all instances? If not, you've found your implementation gaps.
Watch for federal and state ripple effects. California privacy laws often preview nationwide trends. If you operate in multiple states, design your deletion infrastructure to handle similar mandates elsewhere. Colorado, Virginia, and Connecticut privacy laws.
Start now. Building the data inventory, vendor agreements, and technical infrastructure this law requires takes longer than most compliance teams expect. Start your gap analysis this quarter. Prioritize vendors who send the highest volumes of California resident data. Build your deletion capability incrementally, testing with one system or vendor at a time.
The 2027 effective date sounds distant. It's not. You're designing a new data governance capability, not just updating a policy document. That work starts now.





