Home
/
Blog
/
Practical guidance
Practical guidance
October 6, 2026
5 minutes
min read
California

SB 923: What California's new deletion rules mean for ecommerce brands

Starting January 1, California's SB 923 requires online-only brands to offer a web form for privacy requests, and deletion requests now cover data brands got about a customer from outside sources like visitor-ID and enrichment tools.

Travis Roderick
Head of Growth
customer shopping online
In this article
Stay ahead of changes like this.
TrueVault keeps your privacy workflows current as laws evolve.

SB 923 takes effect January 1, 2027. It widens California's right to delete and requires online stores to offer a web form for privacy requests. Below is what we're handling for TrueVault customers, plus the short list we need from you.

‍

TrueVault

Stay current on every state privacy change — without the overhead.

A customer in Sacramento writes in and asks you to delete her data. Support finds her in Shopify, removes her from Klaviyo, and closes the ticket.

Three weeks later, the visitor-ID tool on your site matches her browser to her email again, and she lands back in your abandoned-browse flow. Her birthday is also still sitting in a profile field that a data-append service filled in last spring.

Under the CCPA today, you weren't required to delete that second batch of data. The right to delete covered information you collected from her. Information you got about her from somewhere else sat outside it. Starting January 1, it doesn't.

The two changes

Governor Newsom signed SB 923 on September 27. The California Privacy Protection Agency, which now goes by CalPrivacy, sponsored it. It does two things.

Online-only stores need an online way to submit requests. Until now, if you sell only online and have a direct relationship with your customers, an email address was enough. From January 1, you also need an online method, like a web form or portal. Brands with physical stores still need two or more methods, including a toll-free number. That part hasn't changed.

A deletion request now reaches data you got from other sources. The statute's wording moves from information collected "from" the consumer to information collected "from or about" the consumer. If you added to a customer's record with outside data, that data is now covered by their request.

The law also gives you a way to keep that customer deleted. For data that came from somewhere other than the customer, you can hold on to a record of the request and the minimum data needed to make sure their information stays out of your systems and isn't used for anything else. CalPrivacy calls this a suppression list. It's what stops next month's data refresh from putting them right back.

If you already handle deletion requests from Delaware, Indiana, Maryland, or New Jersey, this should look familiar. CalPrivacy points out that those states already require deletion regardless of where the data came from. California is catching up to them.

‍

Where outside data hides in an ecommerce stack

Plenty of brands would tell you they don't use third-party data. Then you look at the apps list. These are the usual places it comes from:

  • Visitor identification tools that match anonymous site traffic to an email address so you can send browse-abandonment emails.
  • Data append or enrichment services that fill in a missing name, mailing address, birthday, or demographic field.
  • Collab and giveaway lists shared by a partner brand after a joint promotion.
  • Co-op mailing lists, if you send a print catalog.
  • Wholesale or retail partners that pass customer details back to you.

Each one is a place a deletion request now has to reach. Most of them are also a way a deleted customer can come back.

What we're handling

If you're a TrueVault customer, a good chunk of this is already covered and here’s a few examples:

Your privacy policy. We'll update the TrueVault-hosted policies to describe the wider right to delete before January 1. You don't need to edit anything or republish.

The web form. Your TrueVault privacy center already gives customers an online form for submitting requests. If it's live and linked from your site, the new web form requirement is covered.

Deletion requests. When a request comes in, TrueVault walks you through each system in your data map. For connected tools like Shopify, Klaviyo, and Meta, it can handle the deletion for you. Deadlines and request history are tracked, so you have a record of every request you closed.

Finding the outside data. Our vendor documentation has over 2,500+ vendor documents and flags apps and pixels collecting customer data that teams tend to forget about. That's the fastest way to spot a visitor-ID tool someone added two years ago.

A short survey. Like we do with every law change that needs input from you, we'll send a few questions about where your customer data comes from. Your answers tell us what to adjust in your setup.

What we need from you before January 1

  • Tell us where outside data comes in. Answer the survey in your dashboard, or add the tools to your data map yourself. If an enrichment service isn't in your map, it won't show up as a step when a deletion request comes in.
  • Decide how deleted customers stay deleted. Ask those vendors whether they support suppression or exclusion lists, and check with your counsel on exactly what you keep.
  • Check your footer. Make sure the privacy links on your site point to the request form, and not only to a privacy@ inbox.
  • Brief your support team. The CCPA already expects the people answering privacy questions to know the rules. Update the saved replies in Gorgias or Zendesk so nobody tells a customer they’re fully deleted while an enrichment record is still sitting in Klaviyo.

Questions you might have

Does the 45-day deadline change? No. You still have 45 days to respond, plus one 45-day extension if you tell the customer within the first window.

We only collect data straight from customers. Does this affect us? The deletion change mostly won't. The web form requirement still applies if you sell only online. And it's worth one look at the data map before you decide nothing outside is coming in.

Doesn't keeping a suppression record mean we didn't really delete the customer’s data? The law allows it. The record has to stay limited to the minimum needed, and it can only be used to keep their data deleted. Your counsel can tell you what "minimum" looks like for your setup.

Do the existing exceptions still apply? Yes. SB 923 doesn't impact them.

If you're not sure what's in your stack

That's normal. Apps get installed for one campaign and never removed. Reach out to your CSM and we'll go through your data map with you, tool by tool, before January.

Not a TrueVault customer yet? Book a demo and we'll show you where outside data tends to come in.

Sources: CalPrivacy announcement · SB 923 chaptered text (LegiScan) · Bill status (CalMatters Digital Democracy)

TrueVault Data Flows

Know exactly where personal data moves in your stack.

See which vendors process what data — and whether your workflows reflect the rules that apply today.

This post explains what SB 923 changes for ecommerce teams. It isn't legal advice. Your counsel can tell you how it applies to your business.

‍

TrueVault

Privacy work that stays current — without adding more chaos.

TrueVault helps lean ecommerce teams keep privacy workflows current as vendors, tracking tools, and privacy laws keep changing.

About the author
Travis
Roderick

Travis leads Growth at TrueVault, helping ecommerce teams understand and act on state privacy requirements before they become problems.

More from the blog

Keep reading