CLIENT ALERT
California's fall 2026 privacy roundup: Expanded CCPA deletion rights and more
October 5, 2026
Read time: 5 min
Before the September 30, 2026, deadline, California Governor Gavin Newsom acted on several privacy-related bills passed by the California legislature, including:
- SB 690, which eliminates the private right of action under the California Invasion of Privacy Act (CIPA) for certain online activities.
- SB 923, which expands deletion rights under the California Consumer Privacy Act (CCPA) to cover third-party-sourced data.
- AB 883, which shortens data broker deletion cycles.
- SB 354, an insurance-sector bill that includes new, sweeping privacy requirements.
The governor vetoed one of the session’s landmark bills, AB 1542, which would have banned outright the sale and sharing of sensitive personal information.
Companies should assess whether these laws require updates to deletion workflows, consumer request mechanisms, data broker processes, and, for insurance-sector organizations, broader privacy compliance programs.
SB 690: CIPA amendments
SB 690 eliminates the private right of action for CIPA pen-register and trap-and-trace claims based on website and app tracking but does not touch §§ 631 or 632 claims.
After a multiyear push to curb the influx of CIPA litigation, Governor Newsom signed SB 690, which eliminates the private right of action for violations of the pen-register and trap-and-trace statutes for conduct occurring on an internet website, online app, or mobile app. The amendment is effective January 1, 2027, and applies retroactively to claims commenced within two years of its passage. Businesses should temper expectations: Claims under §§ 631 and 632 are unaffected. Recognizing these gaps, the governor released a message encouraging the legislature to implement even more limitations on CIPA’s private right of action in upcoming legislative sessions.
SB 923: The expanding privacy rights act
Businesses must extend CCPA deletion rights to cover third-party-sourced data.
Under the CCPA, California consumers can request deletion of their personal information, subject to certain exceptions. Currently, this right covers only information collected directly “from” the consumer. Effective January 1, 2027, SB 923 expands the deletion right to reach both directly collected information and indirectly collected data, aligning California with other state privacy laws.
SB 923 also updates the CCPA to require online-only businesses with direct consumer relationships to provide both an email address and a web form or portal for consumer requests. Before, the CCPA required only an email address for online-only businesses.
AB 883: Faster Delete Request and Opt-Out Platform (DROP) cycles
Data brokers must shorten their DROP response cycle, from 45 to 30 days.
Governor Newsom signed AB 883, which amends the DELETE Act to shorten the response cycle for the DROP, from 45 to 30 days.
AB 1542: Sensitive data sales and sharing
Governor Newsom vetoed AB 1542, which would have banned outright the sale and sharing of sensitive personal information. The CCPA’s existing framework for sensitive data remains unchanged.
The governor stated that while he supported the bill’s objective, the ban was “a step too far.” The veto leaves the CCPA’s existing framework surrounding sensitive data in place, including consumers’ right to limit certain uses and disclosures of sensitive personal information.
SB 354: Insurance privacy
Effective July 1, 2028, this bill substantially revises California’s insurance privacy framework to include expanded privacy requirements.
Key changes include expanded privacy notice requirements, data-minimization and retention obligations, sharing restrictions, consent requirements, consumer access and deletion rights, and third-party service provider contract requirements. The statute also generally preempts inconsistent state privacy laws for covered insurance-related personal information.
Practical steps to consider
In response to these new laws, companies should consider the following steps:
SB 690:
- Evaluate tracking technologies. Because SB 690 will not stem the tide of CIPA claims on its own, companies should continue to proactively evaluate their use of non-necessary technologies that deploy without user consent.
- Check pending lawsuits. Companies fighting existing CIPA claims should review the complaints to determine if SB 690 has any impact.
SB 923:
- Expand deletion workflows. Companies should identify systems holding indirectly sourced data (from data brokers, enrichment providers, etc.) and ensure that information can be located and deleted in response to the updated deletion right.
- Establish suppression-list processes. Companies should ensure there is a process in place to maintain information necessary to prevent deleted data from reintroduction through third-party interactions.
- Review downstream processes. Companies should work with their service providers and contractors to ensure they can receive and execute deletion instructions within required timelines.
- Update request-intake mechanisms. Online-only businesses should confirm they offer both an email address and a web form or portal for CCPA requests.
AB 883:
- Update DROP processes. Registered data brokers should prepare for the new 30-day cycle and assess whether their current systems and vendors can support recurring deletion at that cadence.
SB 354:
- Begin gap assessments. Organizations subject to SB 354 should assess their current privacy program against the new requirements and determine what gaps must be remedied before the law becomes operational. Given the scope of changes and the effective date of July 1, 2028, affected organizations should start implementation now.
If you have questions about how these changes affect your organization’s privacy compliance program, please reach out to your regular McDermott lawyer or a member of our Data, Privacy & Cybersecurity Group.