Blog

California’s 2027 Privacy Bills Explained (SB 923, SB 690, and AB 2561)

Julie Rubash, General Counsel and Chief Privacy Officer
September 2, 2026
California's 2027 Privacy Bills Explained (SB 923, SB 690, and AB 2561)

Do you want to receive these privacy recaps in your inbox each week? Subscribe here or follow us on LinkedIn.

Three privacy bills passed the California Legislature this past week and will now go to the Governor for signature. None carries an urgency clause or an express operative date, so all three, if signed, will take effect January 1, 2027 under the state constitution’s default rule for regular-session statutes.

Keep reading to learn more, along with my analysis and takeaways.

United States

SB 923 – Expanding the CCPA Right to Delete

SB 923 does three things. 

First, it expands the right to delete. Today, that right reaches only personal information a business collected from the consumer. The bill extends it to information collected from or about the consumer, capturing data the business obtained from third-party sources. 

Second, for that newly covered data, a business is deemed in compliance with a deletion request if it retains a record of the request and “the minimum data necessary” to ensure the information remains deleted and is not used for any other purpose. The CCPA’s existing exceptions permitting retention are unchanged. 

Third, it changes how requests come in. A business operating exclusively online with a direct consumer relationship, which today need only provide an email address, must also make available an online method “such as a web form or online portal.”

Takeaway


For a company running a nationwide program, the useful question is where the capability each change requires can be drawn from. You may largely have two of the three already, from your multistate work rather than your California work. 

Deletion scope is the first point. Virginia (and many other states modeled after Virginia) already reach data “provided by or obtained about the consumer.” If you built to that broader standard, your deletion workflow already covers broker-sourced records and California is catching up to you. The work falls on companies that scoped deletion narrowly to California’s own text, which is an easy trap, given the law’s reputation as the strictest. 

The deemed-compliance provision is the second. Twenty of the 24 comprehensive laws (Colorado by rule, the rest by statute) already let a controller holding third-party-sourced data comply by retaining the deletion request and the minimum data necessary to keep the consumer deleted, most using language nearly identical to Virginia’s. SB 923 imports that architecture almost word for word. What it does not import is the alternative route. Sixteen of those states let a controller instead opt the consumer out of further processing, and New Jersey allows outright deletion as its second path. California’s version offers only the suppression record, which would place it alongside Delaware, Maryland and Indiana as single-path states. If you standardized on the opt-out alternative, it will not carry over. Registered data brokers have the most operationalized version of all under the Delete Act, retrieving and processing DROP requests at least every 45 days and maintaining suppression information so deleted data is not reacquired. SB 923 does not supply an operational cadence or endpoint though. It says the information must “remain deleted,” but does not prescribe how often incoming data must be screened or how long the suppression record must be maintained. Those are implementation choices a business will need to make and document. 

The intake change is the California-specific one, though it is narrower than it first looks. Requiring a website mechanism is not itself novel. Texas, for one, already requires such a mechanism if a controller maintains a website. But Texas, like California today, exempts controllers operating exclusively online with a direct consumer relationship. SB 923 narrows that exemption. Online-only businesses still avoid the toll-free mandate, but must now add an online method in addition to the email address. If you are online-only and relying on email-only intake because of that carve-out, a web form or portal is a net-new build. It’s the least conceptually interesting change in the bill, and the one most likely to require engineering time before January.

SB 690 – Narrowing CIPA’s Private Right of Action

SB 690 amends a single provision of the California Invasion of Privacy Act: the section giving private plaintiffs a damages remedy. Going forward, only the Attorney General may bring an action under that section against a private actor for a violation of § 638.51 (CIPA’s bar on using a pen register or trap and trace device without a court order) if the conduct is alleged to have occurred on a website or a mobile or online application. The change is retroactive, reaching back two years from “the operative date”, a term the bill never defines, to sweep in claims in actions already commenced. 

Nothing else in CIPA is amended, and the private remedy is otherwise untouched: $5,000 per violation or treble actual damages, with no requirement that a plaintiff show actual damages. 

Takeaway


This is welcome relief for businesses, but it addresses only one track. The CIPA litigation wave against website analytics, session replay and ad-tech integrations primarily runs on two theories: § 631 wiretap and “third-party eavesdropper” claims, and § 638.51 pen register claims premised on collecting routing and identifier data. 

SB 690 disarms only the second track. The § 631 branch, which is the older and still larger source of filings, survives intact.  Earlier versions of the bill exempted processing for a “commercial business purpose” from the wiretap and eavesdropping sections outright, but the July 2026 Assembly amendment struck that approach entirely. So this bill is not a reason to stand down. Analytics, session replay and ad-tech integrations still carry § 631 exposure, and the controls built to mitigate risk (whether that’s consent, enhanced disclosures, or moving your tags to server-side solutions, as appropriate) should stay where they are. 

The narrowing is also a California-specific development, not a national trend worth building a baseline around. Comparable claims are brought under other states’ wiretapping and eavesdropping statutes, and SB 690 touches none of them.

AB 2561 – Barring Silent Resets of Privacy Settings

AB 2561 prohibits an operating system or an application from undoing a user’s affirmative configuration of a privacy setting without the user’s consent, subject to exceptions for state or federal law, a court order, or a subpoena. “Privacy setting” is defined broadly as any user-configurable option in an application’s privacy or similarly labeled menu governing how personal information is collected, used, shared, disclosed, retained or processed. 

Businesses stay free to discontinue services or stop offering privacy options, so long as the change maintains or increases existing protections. Consent and personal information carry their CCPA meanings. The prohibition sits in the Business and Professions Code as a new standalone chapter, not in the CCPA.

Takeaway


AB 2561 addresses the software-update-resets-your-settings problem, which no comprehensive state privacy law explicitly reaches. The closest analogues regulate re-asking, not silent reversion. The CCPA makes a business wait at least 12 months after an opt-out before requesting authorization to sell or share again, and Colorado’s rules bar treating the later absence of an opt-out signal as consent to opt back in. Both presuppose that the setting persists. 

So, regarding the opt-outs the law already compels, AB 2561 largely reinforces obligations a business probably already had, even if they weren’t explicit. Businesses that quietly re-enabled sale after a valid opt-out were likely never compliant in spirit, even if the law didn’t explicitly say so. The practical impact of the bill is its effect on settings beyond opt-out. Its definition of “privacy setting” reaches any user-configurable option in a privacy or similarly labeled menu that governs personal-information processing, potentially including settings for first-party ad or content personalization, direct marketing, and similar optional controls or user preferences. A comprehensive privacy law may never have required you to offer those controls in the first place, much less imposed a general persistence rule once you did. Once you do offer one, you cannot silently undo it, and that is what nothing in a multistate compliance program will have caught. Its placement outside the CCPA cuts two ways: the bill gives the California Privacy Protection Agency no enforcement authority and specifies no standalone penalty or enforcement mechanism of its own, but it is also not gated by the CCPA’s “business” thresholds, so an app or OS developer below those thresholds is still covered. 

Anyone in scope should double-check whether any update, migration, default-restore or experiment silently returns a user’s privacy toggles (whatever they may be) to their original state.

A Little More Privacy, if You Please

A Little Privacy, Please weekly recaps are provided for general, informational purposes only, do not constitute legal advice, and should not be relied upon for legal decision-making. Please consult an attorney to determine how legal updates may impact you or your business.

Latest Blog Posts

California’s 2027 Privacy Bills Explained (SB 923, SB 690, and AB 2561)

September 2, 2026

SB 923, SB 690, and AB 2561 update California's...

CPPA Fines Two Data Brokers as Colorado Proposes ADMT and Chatbot Safety Rules

August 18, 2026

CPPA fines two data brokers under the Delete Act...

Latest White Papers

Connecting Legal & Marketing Teams on Consent and Preferences

February 4, 2025

Break down data silos and unlock better collaboration. Marketing...

Navigating Sensitive Data in the U.S.

February 4, 2025

Download our comprehensive guide to learn how different states...

Enterprise Guide To Cookie management & Tracker List Curation

July 1, 2024

How to review the tracking tech on your websites...

Keep in touch

Sign up for our newsletter to keep up with privacy news for adtech and martech,
plus occasional company news.

Let's explore what we can do together.

We'll be in touch within 48 hours

    First name *

    Last name *

    Email address *

    Company *

    Message *

    * indicates required fields