SB 923 took the headlines last weekend, but it wasn't the only privacy bill Governor Newsom signed on September 27. Two smaller ones matter if your business sells visitor data or ships an app: one tightens the clock on data broker deletions, and the other stops software from quietly flipping a user's privacy choices back.
What Happened
AB 883, by Assemblymember Josh Lowenthal, amends section 1798.99.86 of the Delete Act and became Chapter 507 of the Statutes of 2026. Since August 1, 2026, every registered data broker has had to log into DROP, the state's Delete Request and Opt-Out Platform, at least once every 45 days and process the deletion requests waiting there. AB 883 swaps every one of those 45-day periods for 30 days. That covers how often a broker checks DROP, how long it has to delete, how quickly an unverifiable request must be handled as an opt-out of sale or sharing, and how often it re-deletes a consumer's newly collected data afterward.
The bill also adds a new section, operative July 1, 2027, aimed at public officials. The Secretary of State, local filing officers, the Judicial Council, and the State Bar must tell elected officials and judges they can use DROP. If a broker then fails to delete a judge's or official's data, the Attorney General, a county counsel, or a city attorney can sue on that person's behalf for injunctive relief, actual damages, and attorney's fees, with punitive damages available for willful violations. That sits on top of the existing $200 per request, per day administrative fine.
AB 2561, by Assemblymember Avelino Valencia, became Chapter 478 and adds sections 22710 and 22711 to the Business and Professions Code. An operating system or an application can no longer undo a user's affirmative configuration of a privacy setting without the user's consent, unless a law, court order, or subpoena requires it. A "privacy setting" is any user-configurable option in a privacy menu (or one labeled similarly) that governs how the app collects, uses, shares, or keeps personal information. A business can still retire a feature or drop a setting, so long as the change keeps existing protections in place or increases them.
Neither bill carries an urgency clause, so both take effect January 1, 2027.
What Website Owners Should Do
If you're a registered broker, rebuild your DROP schedule around 30 days now. A team that pulls the list on day 40 and deletes by day 45 has a process that stops being legal on New Year's Day, and the re-deletion sweep has to speed up too. If you run a site that sells or shares visitor data, AB 883 doesn't change your own obligations, but the brokers downstream of your tags now purge faster, and a visitor's opt-out still has to stop the flow at your site.
For AB 2561, audit your release process. Any mobile or desktop app with a privacy menu needs a guard so updates, migrations, and settings resets carry a user's choices forward rather than restoring defaults. Browsers likely fall within the bill's definition of an application, and from the same date AB 566 requires them to offer an opt-out preference signal setting; AB 2561 means a browser update shouldn't switch that signal off once a user turns it on.
Where Privisy Fits
Privisy can't process DROP requests for you; that work happens inside your own data systems. What a scan does show is the tracker traffic through which your visitors' data reaches ad-tech vendors and brokers, and whether your site actually stops selling and sharing when a visitor's browser sends Global Privacy Control. As more browsers ship that setting and the law keeps it switched on, more of your California traffic will arrive carrying it.
See What Your Site Shares Before 2027
Privisy audits your trackers, opt-out mechanisms, and GPC handling against the CCPA rules in force today and the ones taking effect next.
Get Your Audit