California Vetoed a Ban on Selling Your Sensitive Data. Here Is What It Signed Instead.
On Sunday 27 September 2026, Governor Gavin Newsom vetoed a bill that would have prohibited businesses from selling or sharing Californians' sensitive personal information, the category covering health data, precise location, biometrics and similar. Maryland and New Jersey have banned those sales outright in the past year, and Connecticut, Oregon and Virginia have prohibited selling precise geolocation. California, the state that invented modern American privacy law, chose not to follow. Days earlier, the same governor signed two bills that quietly give Californians the strongest deletion rights in the country. Here is what was killed, what passed, and what each one means for anyone trying to get their data removed.
What was vetoed?
The bill sought to close what its supporters described as a loophole in the California Consumer Privacy Act. The CCPA currently gives consumers the right to limit how businesses use and disclose sensitive personal information. It does not prohibit the sale of that information outright, so the protection depends on each person knowing the right exists and exercising it, company by company. The vetoed bill would have flipped that default and banned the sale entirely, which is the model Maryland and New Jersey adopted.
The practical consequence is that in California the burden stays on you. Your health, location and biometric data can still be sold unless you have told each specific business not to. Legal commentators noted the veto marks a shift, with California no longer the state setting the pace on privacy while others move past it.
What was signed?
Two bills that matter directly to data removal, and the first one is a bigger deal than the coverage suggests.
SB 923 expands the CCPA's right to delete. Until now, a deletion request required a business to erase the personal information it had collected from you directly. Information it had bought or obtained from third parties, which is most of what a data broker holds, sat outside that obligation. SB 923 changes the scope to all personal information the business holds about you, regardless of where it came from. It also requires businesses to offer online request methods.
AB 883 amends the Delete Act. Registered data brokers currently have to check the state's Delete Request and Opt-Out Platform and process deletion requests at least once every 45 days. AB 883 shortens that to at least once every 30 days, and adds a new enforcement pathway. We covered how the platform works, and its limits, in what California's DROP actually deletes.
Why SB 923 is the one to pay attention to
Because it goes at the exact mechanism that makes data removal feel futile. A broker that never dealt with you directly could previously respond to a deletion request by pointing out that it collected nothing from you. It bought the profile. Under SB 923, that distinction no longer protects the data. If a covered business holds it, a valid request reaches it.
Two honest limits. First, it applies to California residents and to businesses covered by the CCPA, which means thresholds on revenue or data volume, so not every small operator is caught. Second, it does not touch the public-records exemption. A broker can still rebuild a profile from a fresh property deed or voter file after deleting the one you asked about, which is the structural reason removal remains ongoing work, explained in public record or data broker, the difference matters.
What about the 30-day change?
A meaningful tightening rather than a transformation. The 45-day cycle meant a request could sit for six weeks before a broker was even obliged to look at it. Thirty days is faster, and the new enforcement route gives the state's privacy agency more to work with against brokers that ignore the platform. It only applies, though, to brokers that registered in the first place. The agency believes thousands have not, which is why a registered-broker platform can only ever cover part of your exposure, as we set out in California fined a data broker for blocking opt-outs.
Where does the rest of the country stand?
Increasingly ahead of California on sensitive data, and behind it on deletion. Maryland and New Jersey ban the sale of all sensitive data. Connecticut, Oregon and Virginia ban the sale of precise geolocation. Roughly 23 states now have comprehensive privacy laws of some kind. None of them, so far, has a deletion right as broad as SB 923 or a centralized broker deletion platform like DROP. So a Californian has the strongest deletion tools and weaker restrictions on sales, while a Marylander has the reverse. Our overview of who has what is in which states let you delete your data.
What should you actually do?
If you live in California, use both new tools. Register with DROP if you have not, since the cycle is now 30 days. And when SB 923 takes effect, send deletion requests to the businesses and brokers you care about, because the request now reaches data they bought about you rather than only data you handed over. Also use your existing right to limit sensitive data use, because the veto means nobody is going to do that for you.
Wherever you live, the pattern underneath all of this is the same. Rights are getting stronger, and every one of them still requires you to find the company, send the request, wait, and then repeat when the listing rebuilds from public records. Consumer Reports found that opt-outs done by hand or by automation cleared roughly 27 percent of exposed listings, while removals handled by real people who monitor and refile reached about 70 percent. Stronger laws widen what a request can reach. They do not send the request for you.
Stronger rights, same amount of legwork
SB 923 means a deletion request can now reach data a broker bought about you. Someone still has to send it, to every broker, and again when the listing comes back. A free scan shows which sites publish your name, address and household, and our team of real people files the requests and keeps checking.
Run my free scan Start free trialFrequently asked questions
Does the veto mean my sensitive data is unprotected in California?
Not unprotected, but the protection is opt-in rather than automatic. The CCPA still gives you the right to limit the use and disclosure of sensitive personal information. You have to exercise it with each business, which is what the vetoed bill would have made unnecessary.
When does SB 923 take effect?
Check the bill text for the operative date, since California laws signed in September typically take effect the following January unless specified otherwise. The right to delete your directly collected data already exists, so there is no reason to wait to start sending requests.
Can I use SB 923 if I live outside California?
Not as an enforceable right. In practice many national brokers apply California-style processes everywhere rather than run separate systems per state, so a request citing it may be honored anyway. Your own state's law determines what you can actually compel.
Why would the governor veto a privacy bill?
Veto messages typically cite existing protections, implementation concerns or economic impact, and reporting noted the CCPA already offers a right to limit sensitive data use. Whatever the reasoning, the effect is that the burden of restricting those sales stays with the individual.