In the final days of September, California Governor Gavin Newsom acted on three bills that reshape businesses’ privacy compliance obligations and litigation exposure. He signed Senate Bill 923 (SB 923), expanding consumers’ rights to request deletion of personal information under the California Consumer Privacy Act (CCPA); signed Senate Bill 690 (SB 690), eliminating the right to bring private claims for pen register and trap and trace violations under the California Invasion of Privacy Act (CIPA); and vetoed Assembly Bill 1542 (AB 1542), which would have barred the sale or sharing of sensitive personal information with third parties, leaving California’s policy unchanged.
SB 923: Expanded deletion rights and request methods
SB 923 takes effect on January 1, 2027, and amends California Civil Code Sections 1798.105 and 1798.130. As amended, Section 1798.105 applies to businesses that collect personal information about California consumers and gives consumers the right to request deletion of information collected directly from the consumer. As amended, Section 1798.105 now requires that companies delete information obtained from third parties as well. This expansion means businesses can no longer treat third-party sourced data as outside the scope of a deletion request, and they will need to account for that data in their intake, search, and deletion workflows. For example, when a business receives a consumer data deletion request, it must notify third parties with whom it shared or sold the information and direct them to delete it. Businesses may retain only a record of the request and the minimum amount of data necessary to ensure the information remains deleted and unused. SB 923 also amends Section 1798.130 to require online-only businesses with direct consumer relationships to provide both an email address and an online method, such as a web form or portal, for submitting disclosure, correction, and deletion requests.
SB 690: Removal of the private right of action
SB 690 amends California Penal Code Section 637.2, removing the private right of action in pen register and trap and trace cases, giving the attorney general sole enforcement authority. SB 690 has a two-year retroactive application, barring all suits within the two years before its effective date, January 1, 2027. As a result, businesses defending pending or recently filed pen register and trap and trace claims—including those in arbitration—may have grounds to seek dismissal or withdrawal of actions that fall within the retroactive window, potentially eliminating a significant source of current litigation exposure.
SB 690 is not a cure-all. It does not legalize the underlying conduct and is limited to only a subset of claims under the California Invasion of Privacy Act (CIPA). Plaintiffs may still bring individual and class claims under other sections of CIPA for wiretapping and eavesdropping. Other claims, including those under other state law equivalents and the federal Electronic Communications Privacy Act (ECPA), remain available to potential plaintiffs as well. For a more detailed look at the impact of the legislation, read our recent alert on what SB 690 means for businesses facing CIPA litigation.
Alongside his signature, Newsom expressed hope that this legislation would reduce vexatious suits, particularly those based on law that was not created with “today’s complex technological landscape in mind.”[2] He also called for more legislation to further reduce the number of “rapacious” suits under the CIPA.[3] While Newsom is leaving office at the end of his term on January 4, 2027, his message may encourage the legislature to continue amending CIPA. Businesses should continue to pay close attention to further developments in CIPA legislation and legal precedent.
AB 1542: Veto leaves California obligations unchanged
- If enacted, AB 1542 would have prohibited the sale or sharing of sensitive personal information, such as precise geolocation, Social Security numbers, or genetic data, with third parties. Newsom’s veto leaves California law unchanged; however, similar legislation has been signed into law in Connecticut,[4] Delaware,[5] New Jersey,[6] Maryland,[7] and Oregon,[8] demonstrating why businesses should continue monitoring developments outside California.
- The veto leaves intact two existing consumer rights under the CCPA: the right to opt out of the sale or sharing of personal information, including sensitive personal information, and the right to direct a business to limit its use and disclosure of sensitive personal information to the purposes reasonably necessary to provide the requested goods or services (and the other limited purposes the statute permits). It also preserves a business’s corresponding obligation to notify consumers of their right to limit the use or disclosure of sensitive personal information beyond those permitted purposes.
What businesses should do now
Next steps for businesses before SB 923 and SB 690 take effect on January 1, 2027, involve working with legal counsel to review and update their policies and litigation strategy, including:
- Update consumer data collection and deletion policies to ensure proper deletion of data collected directly from the consumer and data collected from third parties upon request.
- Establish procedures to maintain suppression lists using only the minimum necessary data, and ensure all other data remains deleted.
- Online-only businesses with direct consumer relationships should confirm they offer an email address and online method for disclosure, correction, and deletion requests.
- Businesses facing pending or threatened pen register or trap and trace actions should work with counsel to seek a voluntary withdrawal of claims that fall within the retroactive application window of SB 690.
- Businesses with public-facing websites should monitor the rapidly developing legal landscape on tracking technology claims and take proactive steps to reduce their litigation risk by limiting data collection and sharing, implementing and disclosing user consent features transparently, and reviewing vendor agreements to limit downstream data usage, etc.
Nixon Peabody’s Cybersecurity & Privacy team helps businesses assess and reduce website tracking risks; respond to CIPA, ECPA, CDAFA, and related litigation; and build practical data governance programs. We continue to monitor SB 690 and can help clients prepare for its impact.
- Drake Trent, a Law Clerk in Nixon Peabody’s Privacy & Technology Group, assisted with the preparation of this alert.
[Back to reference] - Message from Governor Newsom to the Cal. Senate on S.B. 690 (Sept. 30, 2026)
[Back to reference] - Id.
[Back to reference] - Conn. Gen. Stat. Ann. §42-520 (West)
[Back to reference] - DE LEGIS 463 (2026), 2026 Delaware Laws Ch. 463 (H.B. 380)
[Back to reference] - N.J. Stat. Ann. §56:8-166.12 (West)
[Back to reference] - Md. Code Ann., Com. Law §14-4707 (West)
[Back to reference] - Or. Rev. Stat. Ann. §646A.578 (West)
[Back to reference]

