Court Rules
All enforcement actions
New LawLow Risk

California Legislature Passes SB 923 (Expanding Privacy Rights Act) to Expand CCPA Deletion Rights

California State LegislatureAugust 28, 2026California Attorney General

Summary

The California Privacy Protection Agency announced that the California State Legislature approved the Expanding Privacy Rights Act (SB 923), which expands the CCPA's right to delete to cover all non-exempt personal information a business holds about a consumer, including data originally collected from third parties. The bill also requires online-only businesses with a direct relationship to consumers to provide online methods, such as webforms, for submitting access, deletion, and correction requests, and expressly permits businesses to retain suppression lists so deleted information stays deleted. The bill, authored by Senator Becker and sponsored by CalPrivacy, now goes to the Governor for consideration.

Remedy

This is prospective legislation, not an enforcement action, so no remedies were imposed. Once effective, SB 923 would require businesses to delete all non-exempt personal information about a consumer upon request regardless of whether the business collected it directly or from a third party, allow businesses to maintain a suppression list so information stays deleted, preserve existing CCPA exemptions (e.g., fraud prevention, peer-reviewed research, legal obligations), and require online-only businesses with a direct consumer relationship to offer an online method such as a webform for submitting privacy requests.

Contract Impact

Although not an enforcement action, SB 923 should prompt a proactive contract review focused on third-party-sourced consumer data. In-house teams should audit data licensing, data broker, co-marketing, and analytics/vendor agreements to inventory what consumer personal information is ingested from third parties, and update data processing addenda so deletion requests propagate downstream to service providers and contractors while expressly permitting suppression lists to keep data deleted. Data retention schedule clauses and any vendor or customer terms that treat third-party-sourced data as outside deletion obligations should be revised, since the bill closes that loophole under the CCPA. Finally, agreements with privacy request-management vendors and website operators should guarantee online submission methods (e.g., webforms) for access, deletion, and correction requests, as the bill requires online-only businesses with a direct consumer relationship to offer more than a plain email address for request intake.

Contract Search Terms

right to deletedeletion requestthird-party datasuppression listwebform privacy requestdata retention policyCCPA complianceconsumer privacy rights requestdata deletion obligationonline request method

Laws Cited

California Consumer Privacy Act (CCPA)Expanding Privacy Rights Act (SB 923)

Violation Types

Entity Details

Entity

California State Legislature

Industry

Other

Official Sources

Source Evidence

Entity Name
"the California State Legislature for approving the Expanding Privacy Rights Act"
Event Date
"August 28, 2026"
Event Type
"will now go to the Governor for consideration"
Laws Cited
"the California Consumer Privacy Act's (CCPA) right to delete to cover all non-exempt personal information collected about them"
Violation Types
"if that information was collected from a third party"
Remedy Summary
"It requires online-only businesses with a direct relationship to the consumer to provide an online method, such as a webform, for consumers to submit privacy requests"

Related Enforcement Actions

CA

California State Legislature

Senator Josh Becker introduced SB 923, the Expanding Privacy Rights Act, sponsored by CalPrivacy. The bill would expand the CCPA right to delete to include personal information obtained from third-party sources, and require businesses to provide multiple methods (e.g., webform) for submitting privacy requests.

CA

Meta Platforms, Inc.

A bipartisan coalition of 33 state attorneys general, led by Minnesota AG Keith Ellison, began trial against Meta Platforms, Inc., alleging the company knowingly designed and deployed harmful features on Facebook and Instagram that drive children and teens to use the platforms compulsively, while falsely assuring parents and the public that its platforms were safe for young users. The states also allege Meta illegally collected personal information from children under 13 without parental consent, violating COPPA. The trial opened before Judge Yvonne Gonzalez Rogers in the U.S. District Court for the Northern District of California, with the states seeking monetary penalties and injunctive relief.

CA

Paramount Skydance Corporation

A coalition of 12 state attorneys general, led by Colorado AG Phil Weiser, obtained a temporary restraining order from a federal court in California to halt the proposed $110 billion merger of Warner Bros. Discovery, Inc. by Paramount Skydance Corporation. The lawsuit alleges the merger violates Section 7 of the Clayton Act by substantially lessening competition in film distribution, anticipated blockbuster film distribution, and licensing cable TV channels.

CA

California Privacy Protection Agency

The California Privacy Protection Agency (CalPrivacy) joined a coalition of 18 Attorneys General and state agencies in opposing the proposed SECURE Data Act, a federal privacy bill that would preempt stronger state privacy laws like the CCPA. The coalition argues the bill would weaken consumer privacy protections, limit enforcement remedies, and undermine California's Delete Request and Opt-out Platform (DROP).

CA

Meta Platforms, Inc.

A bipartisan coalition of state attorneys general began trial against Meta Platforms, Inc., alleging the company knowingly designed addictive features on Facebook and Instagram that harm children and teens, deceived parents about platform safety, and illegally collected personal information from children under 13 without parental consent in violation of COPPA. The states seek monetary penalties, an injunction to stop unlawful practices, and other relief. The trial is being litigated in the U.S. District Court for the Northern District of California.

CA

General Motors

$12.8M

California Attorney General Rob Bonta, along with multiple district attorneys and the California Privacy Protection Agency, announced a $12.75 million settlement with General Motors for illegally selling hundreds of thousands of Californians' location and driving data to data brokers Verisk and LexisNexis without notice or consent. The settlement includes the largest CCPA penalty to date, a five-year ban on selling driving data to consumer reporting agencies, and requirements to delete retained data and implement a robust privacy program.