California SB 923: the deletion workflow for 2027.
A deletion request can clear a customer account while leaving purchased enrichment data untouched. California SB 923 changes that boundary. The implementation task is to make deletion follow the person across data sources, then test what happens when the next supplier file arrives.
Regulatory snapshot
Approved and filed on September 27, 2026, SB 923 is Chapter 482. Its chaptered text amends Civil Code sections 1798.105 and 1798.130. CalPrivacy's announcement confirms the January 1, 2027 effective date. This article reflects the sources checked on September 30, 2026.
What changed
The amended deletion right reaches information collected from or about the consumer. For third-party-sourced data, a business may retain the deletion request and minimum data necessary to keep the information deleted and prevent other use.
The request-channel change is specific: businesses operating exclusively online with a direct relationship to the consumer must offer an email address and an online method, such as a form or portal. Email remains required under that exception. See sections 2 and 3 of the enacted law.
What did not change
Deletion is still subject to verification and statutory exceptions. Section 1798.105 retains grounds for necessary retention, including legal obligations and proportionate security purposes. Do not turn a suppression record into a retained customer profile.
Who needs the scope review?
Start with the existing CCPA applicability analysis. The agency's general FAQs describe covered for-profit businesses doing business in California and the revenue, data-volume and sale-or-sharing revenue tests. They also identify separate duties for service providers and contractors. Those FAQs provide background, not the updated SB 923 request-channel wording.
Financial-services teams should assess each dataset. Section 1798.145 contains exemptions for information handled subject to GLBA and for qualifying FCRA-regulated activities, among others. A bank or insurer label alone does not establish that every marketing or enrichment record is exempt. Counsel should record the applicable provision and facts.
An operational checklist with owners and evidence
The following controls are implementation recommendations, not additional statutory requirements. Use them to test the revised workflow and document decisions through your regulatory change-management process.
- Privacy counsel: approve a decision sheet for each affected processing activity. Record coverage, any retention basis, the information retained and its permitted use. Route ambiguous cases to a named reviewer rather than letting a ticket system infer an exemption.
- Data engineering: map purchased lists, enrichment feeds, derived tables and destinations. Preserve a source-to-system inventory and sample query results. Include less visible copies used by analytics teams; a successful account deletion says little about a separate prospect warehouse.
- Privacy operations: revise request handling and closure criteria. Keep a test case showing how one verified request reaches each relevant system and recipient. Record unresolved tasks explicitly; a queue entry is not evidence that deletion occurred.
- Security and data owners: design the restricted suppression mechanism. Document the identifiers needed for matching, access permissions and prohibited downstream uses. Test a fresh import against the suppression control and retain the result without recreating the deleted profile.
- Digital product owner: test the request channels against the business's actual operating model. Keep screenshots, routing evidence and an end-to-end test through acknowledgement and case creation. Test the email and online paths separately where the online-only exception applies.
- Vendor management: reconcile recipient instructions with acknowledgements and exceptions. Keep the supplier, date, scope and outcome together. Agree who investigates a supplier response that covers only one dataset when several feeds are involved.
A test case worth running
Consider a fictional retailer that deletes a customer's account but refreshes its prospect database every week. Counsel has determined the purchased enrichment record is within scope and no deletion exception applies. Engineering removes the record, then loads a test supplier file containing the same person under a different vendor identifier.
The useful question is whether the control prevents reintroduction without preserving unnecessary profile fields. A failed match should produce an investigation, not a silent reactivation. Retain the test design, approved matching approach, outcome and remediation owner. This is an illustrative control test, not a reported client result.
Where RegReview and RegMatcher fit
For an agreed source scope, RegReview can support monitoring and review of relevant updates. RegMatcher can support mapping source provisions to procedures, controls and evidence. Confirm source configuration during scoping; this article does not claim a preconfigured SB 923 feed.
Keep legal scope decisions and release approval with accountable people. As our comparison of GRC and regulatory intelligence explains, identifying a change and proving completion are different parts of the workflow. Discuss a source-to-control review for your privacy change program.
What to watch before January
Assign a privacy owner to check for relevant agency publications or further statutory changes before release. Recheck the controlling text at sign-off. Schedule the import test before the implementation deadline, with enough time to repair failed matching and incomplete recipient workflows.
Primary sources
- California Legislature: SB 923 chaptered text and status
- CalPrivacy: September 27, 2026 announcement and effective date
- California Civil Code section 1798.145: exemptions
- CalPrivacy: general CCPA background and applicability FAQs
General information, not legal advice. Confirm current law, applicable exemptions and the facts of each processing activity with qualified counsel.
