Submission + - California Legislature Passes Delete Act Regulating Data Brokers (iapp.org)
An anonymous reader writes: The California State Legislature passed Senate Bill 362, the Delete Act, which is designed to streamline consumers' ability to request the deletion of their personal information collected by data brokers. The bill now awaits the signature of Gov. Gavin Newsom, D-Calif., though he reportedly has given no indication whether he will sign the bill, according to CBS News. Newsom has until 14 Oct. to sign the bill.
Should it become law, the Delete Act would empower the CPPA to develop a system by 2026 that allows residents to make a single data deletion request across the nearly 500 registered data brokers operating in the state. The CPPA would also be charged with enforcing provisions of the Delete Act, such as requiring data broker registration and ensuring brokers delete an individual's personal information every 45 days upon receipt of a verified request. [...] The Delete Act was first introduced by state Sen. Josh Becker, D-Calif., who previously said the legislation patches a loophole in the California Consumer Privacy Act that allowed for consumers to request individual data brokers delete information obtained directly from them but did not require entities to delete personal information aggregated from other sources.
Should it become law, the Delete Act would empower the CPPA to develop a system by 2026 that allows residents to make a single data deletion request across the nearly 500 registered data brokers operating in the state. The CPPA would also be charged with enforcing provisions of the Delete Act, such as requiring data broker registration and ensuring brokers delete an individual's personal information every 45 days upon receipt of a verified request. [...] The Delete Act was first introduced by state Sen. Josh Becker, D-Calif., who previously said the legislation patches a loophole in the California Consumer Privacy Act that allowed for consumers to request individual data brokers delete information obtained directly from them but did not require entities to delete personal information aggregated from other sources.