California’s 2026 legislative session produced several privacy changes that matter for businesses covered by the California Consumer Privacy Act (CCPA). SB 923 expands the right to delete beginning January 1, 2027, while AB 1542, which would have prohibited selling or sharing sensitive personal information, was vetoed. Other privacy-related measures signed at the end of the session include AB 2561, AB 883, and SB 690.
Add the rules already scheduled for January 1, 2027, and the new year brings practical changes to how businesses handle consumer requests, opt-out signals, and automated decisions. Here is what changed, what did not, and what to do now.
What passed: SB 923 expands the right to delete
Governor Newsom signed SB 923, the Expanding Privacy Rights Act, on September 27, 2026. The bill was sponsored by the California Privacy Protection Agency (CalPrivacy) and takes effect on January 1, 2027. It makes two main changes.
- Deletion now reaches data from any source. Until now, the right to delete applied to personal information the business collected from the consumer, which left room to argue that data bought from brokers or other third parties fell outside it. From January 1, 2027, the right covers personal information the business collected from or about the consumer, whatever its source. Businesses may keep a suppression list so that deleted information stays deleted when new third-party data arrives.
- Online-only businesses need an online request method. A business that operates exclusively online and has a direct relationship with consumers must make an online method, such as a web form or portal, available for privacy requests, in addition to an email address.
What it means in practice: deletion workflows built around first-party systems will miss enriched or purchased data. Your data inventory needs to record where personal information came from, and your deletion process needs to find it in marketing, analytics, and data-enrichment systems. Existing notification duties still apply: the business must notify its service providers and contractors, and must notify third parties to which it sold or shared the information unless that proves impossible or involves disproportionate effort.
What did not pass: AB 1542 was vetoed
AB 1542 would have amended the CCPA to prohibit businesses from selling or sharing consumers’ sensitive personal information. Governor Newsom vetoed the bill on September 27, 2026.
What it means in practice: California’s existing model remains in place. Consumers can opt out of the sale or sharing of personal information and, where the statutory right applies, can limit certain uses and disclosures of sensitive personal information. Separately, processing sensitive personal information triggers a privacy risk assessment under the CCPA regulations, subject to a narrow exception for certain employee and independent-contractor data.
Other privacy-related laws signed in 2026
- AB 2561 (signed September 27, 2026) prohibits operating systems and applications from undoing a user’s affirmatively configured privacy setting without the user’s consent, subject to statutory exceptions, including where a law, court order, or subpoena requires it.
- AB 883 (signed September 27, 2026) amends the Delete Act to shorten, from 45 days to 30 days, the cycle in which registered data brokers must access the Delete Request and Opt-out Platform (DROP) and process deletion requests. It also requires that specified elected officials and judges be told how to use DROP to delete their information, and it authorizes the Attorney General, a county counsel, or a city attorney to bring civil actions on their behalf against data brokers that violate its deletion requirements. The 30-day cycle applies once the law takes effect on January 1, 2027; the elected-official and judge provisions become operative on July 1, 2027.
- SB 690 (signed September 30, 2026; effective January 1, 2027) eliminates the private right of action for specified pen-register and trap-and-trace claims under California Invasion of Privacy Act (CIPA) section 638.51 arising from conduct on websites and online or mobile applications, and leaves enforcement of those claims to the Attorney General. Other CIPA claims, such as wiretapping and eavesdropping claims, remain available, and CCPA obligations are unaffected.
Already scheduled for January 1, 2027
- Browser opt-out signals. Under AB 566, the California Opt Me Out Act, businesses that develop or maintain browsers must include a built-in, consumer-configurable opt-out preference signal. More visitors are likely to send signals such as Global Privacy Control, and businesses that sell or share personal information must process qualifying opt-out preference signals as valid opt-out requests.
- Automated decision-making technology (ADMT). Requirements for businesses that use ADMT to make significant decisions about consumers, including a pre-use notice, a right to opt out (subject to exceptions), and a right to access information, apply from January 1, 2027.
- The first cybersecurity audit period. For businesses that meet the audit criteria and had more than $100 million in annual gross revenue in 2026, the first audit covers January 1, 2027, to January 1, 2028, with the audit report and certification due April 1, 2028.
- Monetary thresholds may change. CalPrivacy adjusts the CCPA’s revenue threshold, fines, and damages amounts for inflation in January of every odd-numbered year, so the next adjustment is due in January 2027.
Five actions to take before January 1, 2027
- Extend deletion to every source. Map where third-party and enriched data is stored, and update deletion workflows, suppression records, and vendor notifications to reach it.
- Add an online request method if your business operates exclusively online and has a direct relationship with consumers.
- Test your opt-out signal handling end to end, including how your website and its tags respond to opt-out preference signals such as Global Privacy Control.
- Inventory automated decisions about financial or lending services, housing, education, employment or independent contracting, or healthcare, and prepare pre-use notices, access processes, and, as applicable, opt-out or human-appeal processes.
- Confirm whether the cybersecurity audit applies, and in which revenue group. If you are in the first group, your audit period starts January 1, 2027. Later groups are determined by 2027 and 2028 revenue. See who needs the audit.
Also, review any processing of sensitive personal information: with AB 1542 vetoed, the right to limit and the privacy risk assessment requirement remain important compliance obligations.
Frequently asked questions
Does SB 923 cover data we acquired before 2027?
The bill does not limit the expanded right to data collected after January 1, 2027. Plan on the assumption that deletion requests received on or after that date will reach personal information you hold about the consumer from any source, including data acquired earlier, subject to the CCPA’s existing exceptions.
Did California ban selling sensitive data?
No. AB 1542 was vetoed on September 27, 2026. The CCPA continues to provide a right to opt out of the sale or sharing of personal information and a separate right to limit certain uses and disclosures of sensitive personal information where that right applies.
Will the $26,625,000 threshold change?
It may. CalPrivacy adjusts the CCPA’s monetary amounts for inflation in January of every odd-numbered year. The current threshold, in effect since January 1, 2025, is $26,625,000. Check CalPrivacy’s website for the amounts in effect from January 2027.
Key takeaways
- Starting January 1, 2027, SB 923 (signed September 27, 2026) extends deletion to personal information from any source and requires online-only businesses to offer an online request method.
- AB 1542 was vetoed: the opt-out and right-to-limit model remains in place for sensitive personal information.
- January 1, 2027, also brings wider use of browser opt-out signals, ADMT requirements, and the first cybersecurity audit period for the largest qualifying businesses.
This article provides general information and is not legal advice. Content validated through October 6, 2026. It reflects laws enacted and regulations in effect as of that date.
Sources
- CalPrivacy, “California Expands Privacy Protections by Strengthening Deletion Rights” (September 27, 2026): California Privacy Protection Agency
- Governor of California, legislative updates of September 27, 2026: Governor Newsom Legislative Update
- Governor of California, legislative update for SB 690, September 30, 2026: SB 690 Legislative Update
- California Legislative Information, bill texts and histories for SB 923, AB 1542, AB 883, AB 2561, SB 690, and AB 566: California Legislative Information
- CalPrivacy, CCPA Updates, Cybersecurity Audits, Risk Assessments, ADMT, and Insurance Regulations: CalPrivacy CCPA Updates
- California Civil Code § 1798.199.95, inflation adjustments: California Legislative Information
See Also
- CCPA Cybersecurity Audit: Who Needs One and When It’s Due
- CCPA Privacy Risk Assessment: What It Is, With an Example
- Download page for CCPA/CCRA Cheat Sheet
- Download page for CCPA/CCRA Data Sheet
