In this article

Sign up for our newsletter

Share this article

Like the weather in Kansas and unlike a zebra’s stripes, data privacy regulations are always changing. At least we can count on those changes to emerge consistently out of California.

On September 27, 2026, Governor Newsom signed SB 923, officially expanding the California Consumer Privacy Act’s (CCPA’s) right to delete and mandating online-only businesses provide consumers with a webform or portal to submit their privacy requests. Many businesses are already compliant with the changes, but certainly not all–and they’ve only got a few months to change that. SB 923 goes into effect on January 1, 2027.

Building a form can take an afternoon, but the hard part about managing subject rights requests compliantly isn’t slapping a webform on a privacy page. With no time to lose before the law goes into effect, let’s dive into what SB 923’s CCPA amendments entail, the pitfalls businesses should avoid when striving for compliance, and the right way to keep up with California’s shifting privacy requirements.

What SB 923 Changes

Broadly, SB 923 amends two parts of the CCPA: how consumers submit requests and what they can ask you to delete.

Online-Only Businesses Now Need an Online Request Method

Under the amended CCPA, a business that "operates exclusively online and has a direct relationship with a consumer" must provide an email address and "make an online method, such as a web form or online portal, available." That covers requests to know, delete, and correct personal information. Until now, an email address was enough.

The Right to Delete Gets Wider

Californians’ right to delete now covers personal information a business collected "from or about" a consumer, not only what it collected from them directly. That pulls in data businesses bought from brokers, received from vendors, or inferred. However, after receiving a deletion request, businesses are allowed to maintain a record of the request and the minimum data needed to ensure they don’t repopulate the requester’s data from third parties in their systems again.

What These Two Changes Mean for You

Taken together, these amendments mean that consumers will be able to make more subject rights requests more easily and those requests will cover more data than they did before.

The California Privacy Protection Agency (CalPrivacy) expects the webform to make requests "simpler for consumers to submit" and to encourage "more Californians to exercise the rights they already have," in the words of Deputy Director Maureen Mahoney. If you take requests online, plan for more of them, reaching into more of your systems.

How can you best meet the new volume, scope, and requirements created by SB 923? First, let’s look at two key pitfalls to avoid.

Pitfall 1: Letting Your CMS Handle Subject Rights Requests

If your website runs on a CMS like HubSpot, its form builder looks like the obvious fix. You can publish a form in minutes. But marketing forms are built to capture leads, and that works against a privacy request.

In HubSpot, a form submission creates or updates a contact record. The setting that marks new contacts as marketing contacts is on by default. Unless someone changes it, a person asking you to delete their data can land in your database as a fresh marketing contact. That’s not the same as retaining minimum data for a suppression list.

Some platforms offer purpose-built privacy tools. HubSpot's data privacy request page is free on all plans and a real step up from a generic form. But it shares the core limit of any CMS-native tool: it acts on data stored in HubSpot. Your CRM, data warehouse, support desk, ad platforms, and vendors are out of reach. Now that deletion covers third-party data, much of what's in scope lives in exactly those places.

The workflow has gaps, too. HubSpot's privacy page handles deletion and export requests, with no request types for correction or opt-outs. You enter due dates by hand instead of having them set by jurisdiction. Exported data goes to a HubSpot user, who then has to get it to the consumer securely. And the CCPA regulations require you to keep request records for 24 months, while HubSpot's standard audit log keeps 30 days.

And of course, other form builders with even fewer connections to your consumer data stores suffer from the same issues. Support ticketing tools, project management tools, Google forms, and the like will all fail to account for the full scope of consumer data in your organization’s systems and will also demand the required maintenance needed to keep up with evolving data privacy laws.

Pitfall 2: Vibe-Coding Your Own Request Form

The other shortcut is asking an AI tool to build a subject rights request form. You'll have something working by lunch. But what you've actually signed up for is a compliance engine that you own and maintain.

That engine has to get verification right. The CCPA regulations scale identity verification to the type of request and the sensitivity of the data. They also bar you from requiring verification for opt-out requests.

It has to run on the right timelines. Under the CCPA, you must confirm receipt within 10 business days and respond within 45 calendar days, with one 45-day extension if you tell the consumer why. Opt-outs get 15 business days. The GDPR and other state laws run on different timelines, which our guide to DSAR response deadlines breaks down.

It has to reach every system. A deletion isn't finished until the data is gone everywhere it lives and you've notified your service providers and contractors (Civil Code § 1798.105(c)). If your form just forwards an email, someone has to do all of that by hand, on deadline.

Perhaps most significantly it has to keep up with the law.

Privacy laws in Indiana, Kentucky, and Rhode Island took effect on January 1, 2026, and SB 923 will change the CCPA again in 2027. A form built from a prompt reflects the law on the day you wrote the prompt.

Then there's security. Veracode's 2025 GenAI Code Security Report found security flaws in 45% of AI-generated code samples, and the models failed to prevent cross-site scripting 86% of the time. A subject rights form collects names, email addresses, and sometimes ID documents. A flaw there exposes the very data consumers asked you to protect.

How Osano Handles Subject Rights Fulfillment

To avoid these pitfalls, their risk, and the compliance burden they incur, businesses should look for a purpose-built solution.

Osano's subject rights management covers the whole workflow, from the form a consumer fills out to the record you keep afterward.

  • Forms that fit the requester. Osano forms use geolocation to show the request types each person's jurisdiction grants, including correction and opt-outs. Embed them on your site, link to a hosted version, or route emailed requests to the form.
  • Maintained by privacy experts. As laws change (like with SB 923), the Osano team reviews how its subject rights management capability functions and updates the tool.
  • Verification built in. Requesters verify their email through a magic link and can upload ID when you need it. Osano automatically rejects duplicate requests and requests left unverified for 21 days. By default and in compliance with California law, Osano doesn’t require verification for simple opt-out requests.
  • Deadlines set for you. Osano applies the regulatory due date for each jurisdiction, lets you set an earlier internal target, and flags overdue requests.
  • Reach beyond one platform. More than 200 automated data store integrations search your systems when a request arrives, and over 100 integrations permit automatic deletion. For niche or proprietary systems without an integration, Osano assigns action items to the people who own them.
  • Secure delivery and records. A secure messaging portal, encrypted in transit and at rest, handles messages and file exchange. An activity log shows who did what and when, and Osano retains request records for 730 days, which covers the CCPA's 24-month requirement.

Subject Rights Management from a Partner with Skin in the Game

When a regulator asks how you handled a request, your CMS vendor won't be in the room. Neither will the AI tool that wrote your code. Neither one has anything riding on your compliance.

Osano does. Our No Fines, No Penalties guarantee covers up to $500,000 in regulatory fines or penalties resulting from the Osano platform. That gives us every reason to keep your subject rights workflow current as laws like SB 923 take effect.

January 1, 2027, is just a few months away. Book a demo to see how Osano handles subject rights requests from intake to deletion.

Get a demo of Osano today

US Data Privacy Checklist

Follow our checklist to build the foundation for US data privacy law compliance.

Download Your Copy
2025 Law Checklist Resource Listing
Share this article