The conventional wisdom: If you run an online business, adding a contact form to your privacy page satisfies California's subject rights request requirements. It's just a form. Use your CMS, wire it to email, and you're done.
Why we disagree: That approach was barely adequate under the old CCPA, and it won't survive SB 923's January 1, 2027, effective date. The new law doesn't just require a webform for online-only businesses, it expands the right to delete to cover data collected "from or about" a consumer, not just data they gave you directly. Your marketing form can't reach broker data, vendor feeds, or inferred attributes sitting in your data warehouse. More fundamentally, treating subject rights fulfillment as a form problem instead of a data operations problem sets you up for systematic non-compliance.
The evidence
Start with what happens when you use a standard CMS form builder. In HubSpot, form submissions create or update contact records. The default setting marks new contacts as marketing contacts. A California resident submits a deletion request through your form, and your system welcomes them into your marketing database. You've just turned a privacy request into a lead capture event.
HubSpot offers a dedicated data privacy request page that avoids this trap, but it illustrates the deeper issue: CMS-native tools act on data stored in that CMS. Your support desk tickets, analytics platforms, advertising accounts, and third-party processors remain untouched. Under SB 923, deletion now covers personal information your business collected from data brokers, received from vendors, or inferred about the consumer. Civil Code § 1798.105(c) requires you to notify your service providers and contractors after a deletion. A form that forwards an email leaves all of that work to a person working against a 45-calendar-day deadline.
The compliance gaps multiply from there. The CCPA regulations require 24 months of request records. Standard CMS audit logs keep 30 days. The regulations scale identity verification to request type and data sensitivity, and they prohibit requiring verification for opt-out requests. Your form builder doesn't know any of this. You must confirm receipt within 10 business days and respond within 45 calendar days, with one 45-day extension if you explain why. Opt-outs get 15 business days. The GDPR runs on different timelines. Your form has no concept of jurisdiction-specific deadlines.
Then there's the AI shortcut. Veracode's 2025 GenAI Code Security Report found security flaws in 45% of AI-generated code samples, with models failing to prevent cross-site scripting 86% of the time. You're collecting names, email addresses, and sometimes ID documents. A vulnerability there exposes the data consumers asked you to protect.
What to do instead
Treat subject rights fulfillment as a cross-system data operation, not a form submission. You need:
Jurisdiction-aware intake. Use geolocation to show requesters only the rights their jurisdiction grants. California residents see deletion, access, correction, and opt-out. Residents of states without correction rights don't see that option. This prevents confusion and reduces invalid requests.
Verification that matches the law. Email verification through a magic link for most requests. ID upload when you're dealing with sensitive data. No verification requirement for opt-out requests, per CCPA regulations. Automatic rejection of duplicate requests and requests left unverified for 21 days.
Deadline management by regulation. The system applies the regulatory due date based on jurisdiction, lets you set an earlier internal target, and flags overdue requests. You're not calculating calendar days versus business days by hand.
Cross-system reach. Automated integrations that search your data stores when a request arrives and execute deletions across platforms. For systems without an integration, assign action items to the people who own them and track completion. The workflow isn't finished until you've notified service providers and contractors per Civil Code § 1798.105(c).
Secure delivery and retention. A messaging portal encrypted in transit and at rest handles file exchange. An activity log shows who did what and when. Request records retained for 730 days to cover the CCPA's 24-month requirement.
Maintenance as laws change. SB 923 goes into effect on January 1, 2027. Privacy laws in Indiana, Kentucky, and Rhode Island took effect on January 1, 2026. A form built from a prompt reflects the law on the day you wrote the prompt. You need a team reviewing regulatory changes and updating the system accordingly.
When the conventional wisdom IS right
A simple form makes sense in exactly one scenario: you're a small business with all consumer data in a single system, you operate in only one jurisdiction, and you have staff capacity to manually execute every step of fulfillment on deadline.
That describes almost no one. The moment you add a second data store, a second jurisdiction, or a third-party processor, the manual approach becomes a compliance risk. And SB 923's expansion of deletion scope means "all consumer data in a single system" now includes data you bought from brokers and received from vendors. If you're an online-only business with a direct consumer relationship, you need a webform by January 1, 2027. But the webform is the easy part. The hard part is building the data operations behind it to fulfill requests accurately, on time, and across every system where consumer data lives.
The California Privacy Protection Agency expects the webform requirement to make requests "simpler for consumers to submit" and to encourage "more Californians to exercise the rights they already have," according to Deputy Director Maureen Mahoney. Plan for more requests, reaching into more of your systems. Your form is just the front door. What matters is whether you've built the house behind it.





