California CCPA Deletion Rights
Coverage from Nixon Peabody, Wilson Sonsini, and others

California’s Consumer Privacy Act gives consumers a right to request deletion of covered personal information.
SB 923 extends that right to information collected about a person from sources beyond the person themselves, including third parties. The rules also address how requests can be submitted, how deletion instructions should pass through business and vendor processes, and what limited information may be retained to keep deleted data from being restored or reused. Together, these requirements connect a consumer’s deletion request to the practical systems businesses use to manage personal information.
If you read one thing
It directly explains SB 923’s deletion scope, downstream safeguards, and request-channel requirements in one focused account.
Best explainer
Its broader legislative overview places SB 923’s indirect-data deletion and downstream duties in the context of California’s privacy package.
The evidence
It adds the specific requirement that covered online-only businesses provide two request channels, including an online method.
Deletion rights reach indirectly sourced information
SB 923 extends CCPA deletion rights to covered personal information collected about consumers from third-party or other indirect sources, subject to existing exceptions. The change is enacted but takes effect January 1, 2027.
Deletion must persist across downstream systems
Businesses must carry deletion requests through relevant third-party workflows, while retaining only the request record and minimum information needed to keep deleted data from returning or being reused. This makes suppression and downstream handling central to making the expanded right effective.
Online-only businesses must add an online request channel
Covered businesses operating exclusively online with a direct consumer relationship must provide an online method, such as a form or portal, in addition to email for privacy requests. The requirement is part of the enacted changes taking effect January 1, 2027.
$15,000 USD
maximum penalty per intentional violation per affected child
“They must provide high-privacy default settings for identified children, limit collection, sale, sharing, and retention of children’s personal information, provide specified transparency and privacy-rights tools, and take reasonable steps to prevent specified harms. The law restricts default profiling and collection, sale, or sharing of a child’s precise geolocation, and prohibits dark patterns that induce children to provide unnecessary personal information or give up privacy protections. The attorney general or public prosecutors may seek penalties of up to $5,000 per negligent violation and $15,000 per intentional violation, per affected child.”
two years
retroactive application period
“Effective January 1, 2027, it applies retroactively for two years, potentially allowing businesses to seek dismissal or withdrawal of pending or recently filed claims within that period, including claims in arbitration.”
July 1, 2028
effective date of SB 354
“Effective July 1, 2028, it governs how insurers, reinsurers, producers, and certain service providers collect, use, share, retain, and delete consumers’ personal information.”
30 days
data-broker deletion-request processing interval
“Data brokers must access the portal and process deletion requests every 30 days, rather than every 45 days.”
$1,500 dollars
maximum fine per violation
“Violations could carry a fine of up to $1,500 per violation, up to one year in county jail, or both. The bill states that it would create no private right of action.”
The new article reiterates that SB 923 extends CCPA deletion rights to third-party-sourced information and requires downstream deletion, without establishing a material change to the Topic.
Previously
California's 2026 laws expand CCPA deletion rights to information obtained from third parties and shorten data brokers' processing interval for state opt-out requests. The package also adds requirements concerning children, AI, surveillance, and sector-specific data; several provisions take effect in 2027 or later. Governor Gavin Newsom vetoed a proposal to restrict sales and sharing of sensitive personal information.
