This website uses cookies

Read our Privacy policy and Terms of use for more information.

CyberEyeQ Weekly #41: California makes broker data deletable

A quieter week for brand-new instruments — China sat out Golden Week and Washington ran on a stopgap budget — but California handed privacy teams a 1 January 2027 deadline, and five comment windows close within eleven days.

At a Glance

  • California rewrites deletion rights — SB 923 makes the CCPA right to delete reach data bought from brokers; effective 1 January 2027.

  • Treasury opens stablecoin state path — First GENIUS Act interim final rule; comments due 30 November.

  • Federal funding cutoff Tuesday — CMS Medicaid/CHIP rule on minors' gender-transition care takes effect 13 October.

  • France's NIS2 bill slips again — Plenary reported pulled from the Assemblée agenda; no new date.

  • CIRCIA rule at the White House — Final incident-reporting rule under OIRA review since 1 October.

  • Two FedRAMP RFCs close tomorrow — RFC-0033 and RFC-0034, 9 October.

Critical Actions

  1. California signs its privacy package: SB 923 extends the right to delete to third-party data — Until now a business did not have to delete personal information it obtained from a third party. SB 923 (Sen. Becker; sponsored by the CPPA) applies deletion regardless of where the data came from, lets businesses keep a suppression list so deleted data stays deleted, and requires online-only businesses to offer an online submission method — an email address alone no longer suffices. Effective 1 January 2027 (85 days). Companion bills in the package (AB 883, AB 2561, SB 690, SB 354) are not yet verified against bill text. Action: map every broker and partner data feed to your deletion workflow and add a web-form intake channel. Source: California Privacy Protection Agency

  2. Federal Medicaid/CHIP funding for minors' gender-transition care ends 13 October — CMS's final rule ends federal funding for puberty blockers, cross-sex hormones and surgical procedures for children and youth; funding continues for up to six months for children currently on hormone therapy. Mental-health coverage is unaffected, and CMS says the rule applies only to federal funding. Action: reconcile claims edits and coverage policies before Tuesday (5 days). Source: CMS

  3. Treasury's first GENIUS Act rule sets how states certify stablecoin regimes — The interim final rule (91 FR 61688, 30 September) sets forms and procedures for state regulators to certify "substantially similar" regimes, letting state-qualified issuers with up to $10 billion outstanding opt for state regulation. The Committee generally has 30 days to decide a complete filing; no certifications will be accepted until Paperwork Reduction Act approval. Action: model state versus federal regulation and decide whether to comment by 30 November (53 days). Source: Federal Register

Enforcement Watch

  • FDA — Draeger VentStar Resus Neo (Class I, 2 Oct); BD Alaris infusion sets (Class I update, 5 Oct) — Cracked neonatal breathing-circuit hoses can restrict ventilation; BD disclosed worse-than-stated infusion performance at low flow rates. Details as reported by our tracker from FDA postings — check lot scope in the recall database. Source: FDA recalls

  • South Korea FSC — sector-wide security sweep — After a wave of bank data leaks, the President ordered an investigation on 4 October and the FSC directed financial firms to run comprehensive security inspections and tighten access controls. Secondary-source only; breach figures unverified. Check: FSC

Deadline Watch

  • 9 Oct — FedRAMP RFC-0033 and RFC-0034 comments close (US, 1 day).

  • 13 Oct — CMS Medicaid/CHIP rule effective; CMS RAPID pathway comments close; OCC/FDIC CRA NPRM comments close (US, 5 days).

  • 16 Oct — Brazil ANPD regulatory-agenda consultation closes (8 days).

  • 17 Oct — China minors' internet regulation draft comments (9 days).

  • 19 Oct — FDA generative-AI device discussion paper feedback; ICO anonymisation/PETs consultation (11 days).

  • 25 Oct — China TC260 ASMM/DSMM drafts comments (17 days).

  • 26 Oct — UK Cyber Security and Resilience Bill, Lords Report (18 days; date not firmly confirmed).

  • 31 Oct — Italy NIS2 basic security measures; Japan FSA essential-infrastructure order comments (23 days).

  • 30 Nov — Treasury stablecoin IFR comments (53 days).

  • 1 Jan 2027 — California SB 923; FedRAMP CR26 mandatory adoption (85 days).

Around the World

  • France — Our tracker reports the Assemblée plenary on the NIS2-transposing loi Résilience (PJL 1112), set for 7 October, was pulled from the agenda with no new date; the dossier's last recorded step is the 10 September 2025 committee text. Withdrawal unverified against the agenda. Source: Assemblée nationale

  • United States — CISA sent the final CIRCIA rule to OIRA on 1 October; CISA 2015 information-sharing protections were extended only to 11 December. EO 14434 (91 FR 63129) requires proposed statutory AI-definition language by 28 November; reports of a "Super Intelligence Force" remain unverified. Source: Federal Register

  • China — No central regulator published during Golden Week (1–8 Oct); open items are the minors' internet draft (17 Oct) and TC260 maturity models (25 Oct). Source: CAC

Deep Dive

United States (California) · Privacy

The deletion gap SB 923 closes

For years a privacy request told a quiet lie. A consumer asks a business to delete their data, the business deletes what it collected directly — and keeps what it bought. The CCPA's right to delete, as the CPPA describes it, did not require deletion of personal information obtained from a third party. SB 923, signed in late September and effective 1 January 2027, removes that distinction.

The operational problem is not the deletion itself; it is that third-party data keeps arriving. Data bought from brokers and partners refreshes on a schedule, so a record deleted on Monday can re-enter your systems on Friday. The suppression-list provision is the answer — you may retain the minimum needed to keep a deleted consumer deleted. That turns deletion from a one-off task into a standing control, and it pulls vendor contracts, ingestion pipelines and identity resolution into the compliance perimeter. Here is what organisations should do between now and 1 January…

The analysis continues for CyberEyeQ Pro subscribers. Unlock the full deep-dive recommendations, all five weekly action items, source documents, and jurisdiction-specific compliance checklists.

logo

Subscribe to Pro to read the rest.

Become a paying subscriber of Pro to get access to this post and other subscriber-only content.

Upgrade

A subscription gets you:

  • Deep dives of each updated regulation
  • Source verification documents
  • Extended jurisdiction-specific analysis
  • Compliance deadline tracker
  • Regulation crosswalk