Find a lawyerOur capabilitiesYour career
Locations
Our capabilities
News

Select language:

Locations
Our capabilities
News

Select language:

hamburger menu showcase image
  1. Our thinking
  2. Blogs
  3. A Fresh Take
  4. California’s End-of-Session Privacy Package
4MIN

California’s End-of-Session Privacy Package

Subscribe
Oct 1 2026

California Governor Newsom continued his end-of-session legislative push by signing a fresh round of privacy legislation, expanding consumer data deletion rights, tightening compliance timelines for data brokers, creating a new privacy framework for the insurance industry, and protecting users’ affirmative privacy settings in apps and operating systems.

However, not every privacy proposal received the governor’s signature. AB 1542 would have restricted the sale or sharing of sensitive personal information. Governor Newsom vetoed the bill, leaving intact California‘s existing approach, which generally regulates how sensitive personal information may be collected, used, and disclosed rather than limiting its sale or sharing.

SB 923: CCPA Deletion Rights, Expanded 

Under existing law, the California Consumer Privacy Act (CCPA) grants consumers the right to request the deletion of personal information directly collected from them by a business. SB 923 substantially expands the reach of this deletion right by granting consumers the right to request deletion of any personal information a business has collected “from or about” them, regardless of whether the information was obtained directly from the consumer or from a third party. This is intended to close a perceived gap in existing law, under which businesses could continue to retain and use personal information acquired from third-party sources even after fulfilling a deletion request. 

Where personal information was obtained from a source other than the consumer, a business may retain a record of the deletion request and the minimum data necessary to ensure the information remains deleted and is not used for any other purpose. Businesses may also continue to rely on the CCPA’s existing exceptions that permit retention where reasonably necessary for purposes such as complying with legal obligations, maintaining security and integrity, or preventing fraudulent or illegal activity.

SB 923 also modifies how consumers submit privacy requests. Businesses that operate exclusively online and have a direct relationship with consumers must provide both an email address and an online submission method, such as a web form or online portal, for deletion, correction, and access requests.

AB 883: Tightening the Delete Act

AB 883 changes legal requirements for data brokers in two important respects. 

First, the bill shortens the processing cycle for California's Delete Request and Opt-Out Platform (DROP). Data brokers must now access the DROP portal and process deletion requests every 30 days, down from 45 days. Data brokers also may not sell or share new personal information about those consumers that have submitted a deletion request unless the consumer requests sale or sharing or an exception applies.

Second, beginning July 1, 2027, state and local elected officials and judges must be informed of their ability to use the DROP mechanism by the Secretary of State, local filing officers, the Judicial Council, and the State Bar of California for their respective jurisdictions. The Attorney General and local prosecutors may bring civil actions against data brokers that fail to process those individuals‘ deletion requests as required. Available remedies include injunctive relief, actual damages, attorney‘s fees, and, for willful violations, punitive damages.

AB 2561: Privacy Settings Changes Require User Consent

AB 2561 prohibits operating systems and applications from undoing a user‘s affirmative privacy-setting choices without the user’s consent. The law applies to user-configurable settings that govern the collection, use, sharing, disclosure, retention, or other processing of personal information, such as options found in an application’s privacy menu. The bill is aimed at situations where a user has deliberately selected a privacy preference and a subsequent software update, product change, or other system action reverses that choice without authorization. Resetting location-sharing permissions, advertising-tracking settings, or similar privacy controls to their default “on” position following an update is the type of conduct the bill seeks to prevent.

Nonetheless, AB 2561 contains some important limitations. Operating systems and applications may modify settings where required by law, court order, or subpoena, and businesses remain free to discontinue products or privacy features so long as doing so either preserves existing privacy protections or increases them by reducing the collection, use, sharing, or retention of personal information.

SB 354 (Insurance Information and Privacy Protection Act): A New Privacy Regime for Insurance Data

SB 354 establishes a standalone privacy framework governing personal information collected and used in the insurance context. It overhauls California‘s insurance privacy rules, creating a comprehensive framework governing how insurers, reinsurers, producers, and certain service providers collect, use, share, retain, and delete consumers’ personal information effective July 1, 2028. The law introduces data-minimization requirements, detailed privacy notices, consumer rights to access, correct, and delete information, restrictions on data sharing, consent requirements for many non-insurance uses, retention and vendor-management obligations, and significant enforcement authority for the Insurance Commissioner. 

Takeaways

California continues to raise the bar on technology and data oversight, adding to its recent regulatory expansion on AI, online youth safety, and privacy that we analyzed previously. In this latest round of legislation, it signals its continued attention to privacy: expanding consumer privacy and data deletion rights and strengthening compliance obligations related to the handling of personal information.

To receive the latest insights on US legal developments, subscribe to the Freshfields A Fresh Take Blog.

Tags

regulatory frameworkdata cybersecurity and tech regulationregulatory and compliance advisoryinsurancetechnology

Authors

San Francisco, New York

Beth George

Head of US Litigation, Arbitration and Global Investigations
San Francisco

Christine Chong

Senior Associate
New York

Noorie Chowdhury

Law Clerk
New York

Justin P'ng

Practice Resource Attorney (Data, Cyber, and Tech Regulatory)
Latest Insights

Latest Insights

NAVIGATE TO
About usLocations and officesYour careerOur thinkingOur capabilitiesNews
CONNECT
Find a lawyerAlumniContact us
NEED HELP
Fraud and scamsComplaintsTerms and conditions
LEGAL
AccessibilityCookiesLegal noticesTransparency in supply chains statementResponsible procurementPrivacy

Select language:
Select language:
© 2026 Freshfields. Attorney Advertising: prior results do not guarantee a similar outcome