Account cancellation.
What changed between versions
Section 3273.91(b)(1) was changed from requiring the platform to 'permit a user to complete a deletion' (with optional two-factor authentication confirmation) to requiring the platform to 'provide a user with the steps necessary to complete an account deletion request, which shall include deletion of the user's personal information.' This shifts the obligation from allowing completion to actively providing a defined process that must cover personal data deletion.
New Section 3273.91(e) provides that a user logging into an account after submitting a deletion request does not, by itself, revoke that request. This prevents platforms from using a subsequent login as grounds to cancel a pending deletion.
Section 3273.91(c) was broadened from prohibiting only 'dark patterns' used to obstruct or interfere with account deletion, to prohibiting any obstruction or interference with a user's ability to delete their account, with dark patterns listed as one non-exhaustive example. This significantly expands the range of prohibited platform behaviors.
Section 3273.91(d) removed the requirement that the user be 'logged in' for a deletion request to qualify as a verified consumer request under CCPA. It now applies to any request submitted under subdivision (b), and adds an explicit requirement that the request be processed in accordance with all CCPA requirements.