CCPA 2027 deletion changes
Starting January 1, 2027, CCPA deletion requests cover data obtained about a consumer from third parties, and online-only businesses must provide a web request form.
Starting January 1, 2027, CCPA deletion requests cover data obtained about a consumer from third parties, and online-only businesses must provide a web request form.
When a customer asks you to delete their data, where do you look? For most companies, the answer is the systems the customer touched: their account, order history, and newsletter subscription.
Starting January 1, 2027, that won't be enough in California. Changes to the California Consumer Privacy Act (CCPA) mean a deletion request will also reach information you bought, received from partners, or added through enrichment tools.
In this post, you'll learn what the CCPA changes mean in practice, which teams they touch, and how to get your process ready in the time that's left.
From January 1, 2027, CCPA deletion requests cover personal information collected from or about a consumer.
Data from brokers, partners, enrichment tools, and identity resolution services can fall within a deletion request.
Businesses may keep a minimal suppression record so deleted third-party data doesn't quietly return.
Online-only businesses can no longer rely on email alone and need an online request form or portal.
Marketing, sales, and data teams hold most third-party data, so this isn't just a legal project.
Two CCPA changes take effect on January 1, 2027, under SB 923, which Governor Newsom signed on September 27, 2026. First, the right to delete covers personal information collected "from or about" a consumer, not only from them. Second, online-only businesses must offer an online way to submit privacy requests, not just an email address.
Today | From January 1, 2027 | |
|---|---|---|
What a deletion request covers | Personal information collected from the consumer | Personal information collected from or about the consumer, including third-party sources (the CCPA's existing exceptions still apply) |
How online-only businesses accept requests | An email address can be enough | An online method, such as a web form or portal, in addition to email |
The California Privacy Protection Agency (CalPrivacy), which sponsored the bill, summed up the intent. "Now the right to delete will finally do what people expect it to do: deletion, no matter how the business got that information in the first place," said Executive Director Tom Kemp in the agency's announcement.
The 45-day response window and the existing deletion exceptions don’t change. If you’d like a refresher on how CCPA deletion requests work in practice, our guide walks through the process in more detail.
The hard part of the new rule isn't legal interpretation. It's answering one question for every record you hold: where did this come from?
Most organizations add to customer records from sources customers never see. Here is where third-party data usually enters:
Data enrichment: demographic, interest, or household data appended to CRM and loyalty profiles.
Purchased or rented lists: prospect lists bought from data brokers or list providers.
Partner and co-marketing data: leads shared by event sponsors, affiliates, or joint webinar partners.
Identity resolution: services that link devices, emails, and offline records into a single profile.
B2B contact enrichment: sales tools that fill in job titles, direct phone numbers, and work emails.
Acquisitions: customer databases inherited when you buy another company.
B2B data deserves extra attention. The temporary exemption for business-to-business contact information under the CPRA amendments ended on January 1, 2023, so a California sales prospect has the same deletion rights as a shopper.
Consumers are already asking third parties to remove data they hold about them. Californians submitted roughly 450,000 deletion requests through the state's DROP platform by August 2026, according to IAPP reporting.
That platform only covers registered data brokers. Our guide to DROP requirements takes a closer look at how the system works, while SB 923 extends the same expectation to every business covered by the CCPA.
A quick example helps here. Say a retailer appends household income and interest segments to loyalty profiles through an enrichment vendor. Today, a deletion request might clear the loyalty account but leave those segments in the marketing platform. From 2027, the segments are in scope too.
A CCPA data map can help you identify where this third-party data comes from, where it’s stored, and which systems you may need to include in your deletion process.
Privacy and legal teams will lead the response, but other teams buy, import, and use most third-party data. Each one has a decision to make before January 1, 2027.
Team | Where third-party data shows up | Decision to make |
|---|---|---|
Marketing | Enrichment tools, purchased lists, ad audiences, email platforms | Which sources do we still need, and can we find and delete data from each one? |
Sales and RevOps | B2B contact enrichment, CRM imports, intent data | How do deletions reach the CRM, and how do we stop records being re-enriched? |
IT and data engineering | Data warehouse, customer data platform, identity graphs | Can we trace a record's source and run one deletion across systems? |
Privacy and legal | Notices, request procedures, vendor contracts | What goes in the suppression record, and how do we document exceptions? |
Customer support | Requests that arrive by email, chat, or phone | How do requests reach the official workflow without getting lost? |
Procurement | Data vendor and service provider contracts | Do contracts require vendors to support deletion and suppression? |
A shared workflow helps six teams work from one request record. See how Clym supports data subject request management.
Deleting a record once isn't the finish line. If an enrichment refresh, list import, or CRM sync brings the same person back next month, the deletion hasn't really worked.
SB 923 addresses this directly. For information obtained from a source other than the consumer, a business may keep a record of the deletion request and the minimum data necessary to make sure the consumer's information stays deleted and isn't used for another purpose.
Marketers will recognize the idea as a suppression list: a short record of people who must not be re-added. The challenge is keeping that list useful without turning it into a second copy of the data you just deleted.
Keep only the identifiers you need to match future records, such as an email address or customer ID.
Consider hashing those identifiers so the list can match records without exposing them. However, keep in mind that hashed emails are generally still personal information under the CCPA, because they can be matched back to a person.
Restrict access, and block the list from use in marketing, analytics, or profile building.
Check incoming data against the list before it reaches your CRM or marketing platforms.
Document why each field is kept, in line with your CCPA data retention rules.
The goal is the smallest record that still does the job. That aligns with the CCPA's broader data minimization principle and keeps your suppression list from becoming a liability of its own.
A deletion request doesn't stop at your own systems. If a service provider or contractor holds the consumer's data, your process must reach them, and they must be able to act.
Regulators have made clear that relying on a vendor doesn't shift responsibility. In May 2025, CalPrivacy fined retailer Todd Snyder $345,178, partly because a misconfigured tool stopped consumers' opt-out requests from working for 40 days.
Before January 1, 2027, confirm three things with each vendor that holds California consumer data:
They can find and delete the data you sent them, plus anything they added about the same person.
They can apply your suppression list, or tell you when a deleted person reappears.
Your contracts spell out deletion support and how quickly they must confirm it.
Online-only businesses with a direct consumer relationship can currently offer just an email address for privacy requests. From January 1, 2027, they also need an online method, such as a web form or portal, for access, deletion, and correction requests.
Expect the new form to bring in more requests, not just tidier ones. "The webform option will make it simpler for consumers to submit privacy requests while also encouraging more Californians to exercise the rights they already have," said CalPrivacy Deputy Director Maureen Mahoney.
For larger organizations, the bigger win is consistency. A structured form gives you complete requests, proportionate identity verification, and a clear start to the 45-day response timeline, instead of requests scattered across inboxes.
Getting the front door wrong is a risk in itself. In March 2025, CalPrivacy fined Honda $632,500, in part for asking consumers for more personal information than needed to exercise their rights.
If you’re reviewing your intake process, our CCPA DSR form guide explains what information to ask for and what you may want to leave out.
It's tempting to reuse the form builder in your website or marketing platform. Those tools are built to capture leads, though, and a privacy request form has a different job. Before you launch one, check that it:
Clym's Governance Portal gives consumers an online place to submit privacy requests, hosted under your own domain. The Control Center then keeps assignments, deadlines, and verification logs in one record across multiple websites, which makes it easier to show what happened with each request.
California isn't breaking new ground here. According to CalPrivacy, SB 923 brings California's deletion right in line with the standard already in place in four other states:
Delaware, under the Delaware Personal Data Privacy Act
Indiana, under the Indiana Consumer Data Protection Act
Maryland, under the Maryland Online Data Privacy Act
New Jersey, under the New Jersey Data Privacy Act
That's good news for you. If you build source tracking, suppression, and vendor deletion once, the same process supports requests from several states rather than a California-only workaround.
Treat this as a data quality project as much as a privacy one, and the benefits go beyond California:
Cleaner data: fewer duplicate, outdated, or unexplained records in your CRM.
Less wasted spend: you stop paying to enrich people who've asked to be deleted.
Faster responses: requests move through one workflow instead of long email chains.
Better evidence: you can show what you searched, deleted, and suppressed for each request.
More trust: customers see deletion that actually works the first time.
With roughly 12 weeks to go, a phased plan keeps the work manageable.
Phase | Focus | Key actions |
|---|---|---|
Weeks 1 to 3 | Find your sources | List every system and vendor that adds personal information about consumers, and name an owner for each. |
Weeks 4 to 8 | Close the gaps | Extend deletion searches, set up a minimal suppression record, update vendor contracts, and add an online request method if you only offer email. |
Weeks 9 to 12 | Test and document | Run test requests end to end, update your privacy notice and playbooks, train support teams, and document your DSR activity. |
Can we name every source that adds personal information to our customer records?
Does our deletion search reach CRM, marketing, and vendor-held data?
Do we have a suppression record, and is it limited to what we need?
Would a deleted person be blocked if they reappeared in a list import?
Do our vendor contracts cover deletion of data they hold?
If we operate only online, do we offer more than an email address for requests?
Any "no" answer is a good place to start your 90 days.
The 2027 CCPA changes are short on words but big on operations. A deletion request will follow the data wherever it came from, so you need to know your sources, keep deleted people from coming back, and bring your vendors along. Online-only businesses also need a proper online front door for requests.
The upside is real: cleaner data, less wasted enrichment spend, and a process that works across several states. You don't have to fix everything at once. Start by identifying where your customer data comes from, then build from there.
No. Businesses generally still have 45 days to respond to a verifiable consumer request, with one possible 45-day extension when reasonably necessary. What changes is the scope of a deletion request, which from January 1, 2027, can include personal information obtained about the consumer from third parties.
Under the CCPA regulations, businesses must confirm receipt of a request to delete, know, or correct within 10 business days. They must respond within 45 calendar days and act on opt-out requests within 15 business days. They must also keep records of consumer requests for at least 24 months.
Yes. The CCPA's temporary exemption for business-to-business contact information ended on January 1, 2023. From 2027, a California prospect can ask you to delete details you bought or enriched about them, such as a job title or direct phone number, subject to the CCPA's existing exceptions.
Yes, within limits. For data obtained from other sources, SB 923 lets a business keep a record of the request and the minimum data needed to keep the consumer's information deleted. Businesses can't reuse that record for any other purpose, such as marketing, analytics, or profile rebuilding.
Not because of SB 923. The new online-method requirement applies to businesses that operate exclusively online and have a direct relationship with consumers. Other businesses already have to offer at least two request methods, including a toll-free number, though many add a web form anyway.
A deletion request generally needs to reach the service providers and contractors that hold the consumer's data. In practice, confirm that each vendor can find and delete the data, apply your suppression record, and confirm completion within your response window before January 1, 2027.