DEV Community

Richard Smith
Richard Smith

Posted on

What California's New Privacy Law Means for Developers Building Compliance Tools

I spent some time reading through California's SB 923, and the implications for anyone building privacy compliance tools are worth talking about.

Starting January 1, 2027, deletion requests under CCPA will cover third-party data too. If your app enriches user profiles using external sources, those records now fall under the same deletion obligations. And if you're running an online-only business, a simple email address won't cut it anymore—companies need an actual form or portal for requests to know, delete, or correct.

This is a genuine gap in the market. Most small teams handling user data aren't set up to maintain suppression lists across every vendor system, track which third-party sources feed their databases, or build out the request infrastructure from scratch. The compliance burden is real, but the tooling is scattered at best.

I'm thinking about what a focused privacy workflow tool could look like—one that connects deletion requests to vendor suppression lists, flags gaps in request intake, and keeps a record of what's been handled. It's the kind of thing that probably should exist but doesn't feel like it's been done cleanly yet.

Has anyone been working on something in this space? I'm curious whether others see the same opportunity or if I'm overestimating the demand side of this.

Top comments (3)

Collapse
 
carbonlayer profile image
CarbonLayer •

The core idea is promising, but the legal framing needs fixing before this is published. As of the California Legislature’s current bill history, SB 923 was presented to the Governor on September 2, 2026; the official page does not list a later action. So don’t call it a “new law” or state the January 1, 2027 date as certain. Say “if signed, SB 923 would…” and check the bill’s status again before publishing. Official bill history

The summary also needs tighter scope: the online-submission requirement applies to online-only businesses with a direct consumer relationship—it’s an online method in addition to email. The bill would expand deletion rights to information collected “from or about” a consumer, with exceptions and a narrowly limited record that can be retained to keep the data deleted. That’s more precise than saying companies need suppression lists across every vendor system.

Editorially, this reads as an opportunity hypothesis, not evidence of a market gap yet. Add who the proposed tool is for, how the workflow would handle identity matching and vendor follow-through, and what existing tools fail to do. Then validate demand with interviews or concrete examples. The best angle is “What SB 923 could mean for privacy-tool builders”—conditional, specific, and less likely to age badly.

Some comments may only be visible to logged-in visitors. Sign in to view all comments.