Clym Logo

SB 923 and the CCPA: Deletion Now Covers Data You Didn't Collect

Published
AS
AuthorAdam Safar
9 min read

CCPA 2027 deletion changes

Starting January 1, 2027, CCPA deletion requests cover data obtained about a consumer from third parties, and online-only businesses must provide a web request form.

Summarize full article with:

When a customer asks you to delete their data, where do you look? For most companies, the answer is the systems the customer touched: their account, order history, and newsletter subscription.

Starting January 1, 2027, that won't be enough in California. Changes to the California Consumer Privacy Act (CCPA) mean a deletion request will also reach information you bought, received from partners, or added through enrichment tools.

In this post, you'll learn what the CCPA changes mean in practice, which teams they touch, and how to get your process ready in the time that's left.

Key takeaways
  • From January 1, 2027, CCPA deletion requests cover personal information collected from or about a consumer.

  • Data from brokers, partners, enrichment tools, and identity resolution services can fall within a deletion request.

  • Businesses may keep a minimal suppression record so deleted third-party data doesn't quietly return.

  • Online-only businesses can no longer rely on email alone and need an online request form or portal.

  • Marketing, sales, and data teams hold most third-party data, so this isn't just a legal project.

What are the CCPA changes coming in 2027?

Two CCPA changes take effect on January 1, 2027, under SB 923, which Governor Newsom signed on September 27, 2026. First, the right to delete covers personal information collected "from or about" a consumer, not only from them. Second, online-only businesses must offer an online way to submit privacy requests, not just an email address.

Today

From January 1, 2027

What a deletion request covers

Personal information collected from the consumer

Personal information collected from or about the consumer, including third-party sources (the CCPA's existing exceptions still apply)

How online-only businesses accept requests

An email address can be enough

An online method, such as a web form or portal, in addition to email

The California Privacy Protection Agency (CalPrivacy), which sponsored the bill, summed up the intent. "Now the right to delete will finally do what people expect it to do: deletion, no matter how the business got that information in the first place," said Executive Director Tom Kemp in the agency's announcement.

The 45-day response window and the existing deletion exceptions don’t change. If you’d like a refresher on how CCPA deletion requests work in practice, our guide walks through the process in more detail.

Why third-party data turns deletion into a data problem

The hard part of the new rule isn't legal interpretation. It's answering one question for every record you hold: where did this come from?

Most organizations add to customer records from sources customers never see. Here is where third-party data usually enters:

  • Data enrichment: demographic, interest, or household data appended to CRM and loyalty profiles.

  • Purchased or rented lists: prospect lists bought from data brokers or list providers.

  • Partner and co-marketing data: leads shared by event sponsors, affiliates, or joint webinar partners.

  • Identity resolution: services that link devices, emails, and offline records into a single profile.

  • B2B contact enrichment: sales tools that fill in job titles, direct phone numbers, and work emails.

  • Acquisitions: customer databases inherited when you buy another company.

WHERE THIRD-PARTY DATA ENTERS YOUR BUSINESS

B2B data deserves extra attention. The temporary exemption for business-to-business contact information under the CPRA amendments ended on January 1, 2023, so a California sales prospect has the same deletion rights as a shopper.

Consumers are already asking third parties to remove data they hold about them. Californians submitted roughly 450,000 deletion requests through the state's DROP platform by August 2026, according to IAPP reporting.

That platform only covers registered data brokers. Our guide to DROP requirements takes a closer look at how the system works, while SB 923 extends the same expectation to every business covered by the CCPA.

A quick example helps here. Say a retailer appends household income and interest segments to loyalty profiles through an enrichment vendor. Today, a deletion request might clear the loyalty account but leave those segments in the marketing platform. From 2027, the segments are in scope too.

A CCPA data map can help you identify where this third-party data comes from, where it’s stored, and which systems you may need to include in your deletion process.

Which teams the CCPA changes affect

Privacy and legal teams will lead the response, but other teams buy, import, and use most third-party data. Each one has a decision to make before January 1, 2027.

Team

Where third-party data shows up

Decision to make

Marketing

Enrichment tools, purchased lists, ad audiences, email platforms

Which sources do we still need, and can we find and delete data from each one?

Sales and RevOps

B2B contact enrichment, CRM imports, intent data

How do deletions reach the CRM, and how do we stop records being re-enriched?

IT and data engineering

Data warehouse, customer data platform, identity graphs

Can we trace a record's source and run one deletion across systems?

Privacy and legal

Notices, request procedures, vendor contracts

What goes in the suppression record, and how do we document exceptions?

Customer support

Requests that arrive by email, chat, or phone

How do requests reach the official workflow without getting lost?

Procurement

Data vendor and service provider contracts

Do contracts require vendors to support deletion and suppression?

A shared workflow helps six teams work from one request record. See how Clym supports data subject request management.

How to stop deleted data from coming back

Deleting a record once isn't the finish line. If an enrichment refresh, list import, or CRM sync brings the same person back next month, the deletion hasn't really worked.

SB 923 addresses this directly. For information obtained from a source other than the consumer, a business may keep a record of the deletion request and the minimum data necessary to make sure the consumer's information stays deleted and isn't used for another purpose.

Marketers will recognize the idea as a suppression list: a short record of people who must not be re-added. The challenge is keeping that list useful without turning it into a second copy of the data you just deleted.

THE SUPPRESSION LIFECYCLE_ PREVENTING DATA RE-IMPORT

What to put in a suppression record

  • Keep only the identifiers you need to match future records, such as an email address or customer ID.

  • Consider hashing those identifiers so the list can match records without exposing them. However, keep in mind that hashed emails are generally still personal information under the CCPA, because they can be matched back to a person.

  • Restrict access, and block the list from use in marketing, analytics, or profile building.

  • Check incoming data against the list before it reaches your CRM or marketing platforms.

  • Document why each field is kept, in line with your CCPA data retention rules.

The goal is the smallest record that still does the job. That aligns with the CCPA's broader data minimization principle and keeps your suppression list from becoming a liability of its own.

Why your vendors need to be part of the plan

A deletion request doesn't stop at your own systems. If a service provider or contractor holds the consumer's data, your process must reach them, and they must be able to act.

Regulators have made clear that relying on a vendor doesn't shift responsibility. In May 2025, CalPrivacy fined retailer Todd Snyder $345,178, partly because a misconfigured tool stopped consumers' opt-out requests from working for 40 days.

Before January 1, 2027, confirm three things with each vendor that holds California consumer data:

  1. They can find and delete the data you sent them, plus anything they added about the same person.

  2. They can apply your suppression list, or tell you when a deleted person reappears.

  3. Your contracts spell out deletion support and how quickly they must confirm it.

Why your privacy request process needs an online front door

Online-only businesses with a direct consumer relationship can currently offer just an email address for privacy requests. From January 1, 2027, they also need an online method, such as a web form or portal, for access, deletion, and correction requests.

Expect the new form to bring in more requests, not just tidier ones. "The webform option will make it simpler for consumers to submit privacy requests while also encouraging more Californians to exercise the rights they already have," said CalPrivacy Deputy Director Maureen Mahoney.

For larger organizations, the bigger win is consistency. A structured form gives you complete requests, proportionate identity verification, and a clear start to the 45-day response timeline, instead of requests scattered across inboxes.

Getting the front door wrong is a risk in itself. In March 2025, CalPrivacy fined Honda $632,500, in part for asking consumers for more personal information than needed to exercise their rights.

If you’re reviewing your intake process, our CCPA DSR form guide explains what information to ask for and what you may want to leave out.

What a privacy request form needs that a marketing form doesn't

It's tempting to reuse the form builder in your website or marketing platform. Those tools are built to capture leads, though, and a privacy request form has a different job. Before you launch one, check that it:

  • Never adds the person making the request to a marketing list or CRM as a new lead
  • Supports every request type you must offer, including access, deletion, correction, and opt-out
  • Matches identity verification to the request, asking for less on opt-outs and more on sensitive data
  • Applies the right deadline based on where the consumer lives
  • Keeps a record of each request and how you handled it
  • Sends responses through a secure channel, not as a plain email attachment

Clym's Governance Portal gives consumers an online place to submit privacy requests, hosted under your own domain. The Control Center then keeps assignments, deadlines, and verification logs in one record across multiple websites, which makes it easier to show what happened with each request.

How the CCPA changes line up with other state privacy laws

California isn't breaking new ground here. According to CalPrivacy, SB 923 brings California's deletion right in line with the standard already in place in four other states:

That's good news for you. If you build source tracking, suppression, and vendor deletion once, the same process supports requests from several states rather than a California-only workaround.

What gets easier when you manage third-party data well

Treat this as a data quality project as much as a privacy one, and the benefits go beyond California:

  • Cleaner data: fewer duplicate, outdated, or unexplained records in your CRM.

  • Less wasted spend: you stop paying to enrich people who've asked to be deleted.

  • Faster responses: requests move through one workflow instead of long email chains.

  • Better evidence: you can show what you searched, deleted, and suppressed for each request.

  • More trust: customers see deletion that actually works the first time.

A 90-day plan to prepare for the 2027 CCPA updates

With roughly 12 weeks to go, a phased plan keeps the work manageable.

Phase

Focus

Key actions

Weeks 1 to 3

Find your sources

List every system and vendor that adds personal information about consumers, and name an owner for each.

Weeks 4 to 8

Close the gaps

Extend deletion searches, set up a minimal suppression record, update vendor contracts, and add an online request method if you only offer email.

Weeks 9 to 12

Test and document

Run test requests end to end, update your privacy notice and playbooks, train support teams, and document your DSR activity.

Quick self-check for your team

  1. Can we name every source that adds personal information to our customer records?

  2. Does our deletion search reach CRM, marketing, and vendor-held data?

  3. Do we have a suppression record, and is it limited to what we need?

  4. Would a deleted person be blocked if they reappeared in a list import?

  5. Do our vendor contracts cover deletion of data they hold?

  6. If we operate only online, do we offer more than an email address for requests?

Any "no" answer is a good place to start your 90 days.

Conclusion

The 2027 CCPA changes are short on words but big on operations. A deletion request will follow the data wherever it came from, so you need to know your sources, keep deleted people from coming back, and bring your vendors along. Online-only businesses also need a proper online front door for requests.

The upside is real: cleaner data, less wasted enrichment spend, and a process that works across several states. You don't have to fix everything at once. Start by identifying where your customer data comes from, then build from there.

Frequently asked questions

No. Businesses generally still have 45 days to respond to a verifiable consumer request, with one possible 45-day extension when reasonably necessary. What changes is the scope of a deletion request, which from January 1, 2027, can include personal information obtained about the consumer from third parties.

Under the CCPA regulations, businesses must confirm receipt of a request to delete, know, or correct within 10 business days. They must respond within 45 calendar days and act on opt-out requests within 15 business days. They must also keep records of consumer requests for at least 24 months.

Yes. The CCPA's temporary exemption for business-to-business contact information ended on January 1, 2023. From 2027, a California prospect can ask you to delete details you bought or enriched about them, such as a job title or direct phone number, subject to the CCPA's existing exceptions.

Yes, within limits. For data obtained from other sources, SB 923 lets a business keep a record of the request and the minimum data needed to keep the consumer's information deleted. Businesses can't reuse that record for any other purpose, such as marketing, analytics, or profile rebuilding.

Not because of SB 923. The new online-method requirement applies to businesses that operate exclusively online and have a direct relationship with consumers. Other businesses already have to offer at least two request methods, including a toll-free number, though many add a web form anyway.

A deletion request generally needs to reach the service providers and contractors that hold the consumer's data. In practice, confirm that each vendor can find and delete the data, apply your suppression record, and confirm completion within your response window before January 1, 2027.

Adam Safar

Head of Digital Marketing

Adam is the Head of Digital Marketing at Clym, where he leverages his diverse expertise in marketing to support businesses with their compliance needs and drive awareness about data privacy and web accessibility. As one of the company’s original team members, Adam has been instrumental in shaping its journey from the very beginning. When he’s not diving into marketing strategies, Adam can be found cheering on his favorite sports teams or enjoying fishing.

Find out more about Adam