California SB 923 Expands CCPA Deletion Rights to Third-Party Data from 2027
California's SB 923, effective January 1, 2027, will extend CCPA deletion obligations to data sourced from third parties, meaning apps that enrich user profiles with external data must comply with deletion requests covering those records too. Online-only businesses will also be required to provide a dedicated form or portal for user requests to know, delete, or correct their data, moving beyond simple email-based processes. Compliance experts and developers note that most small teams currently lack the infrastructure to manage suppression lists across vendor systems or track third-party data sources. The law has exposed a gap in available tooling, as existing privacy compliance solutions are considered fragmented and incomplete. Developers are now exploring dedicated privacy workflow tools that could automate deletion requests, manage vendor suppression lists, and maintain audit trails to meet the new requirements.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.



Discussion (0)
Log in to join the discussion and vote.
Log in