The Right to be Forgotten: California's AB 656 and New GenAI Guidance
Modern data protection is defined by a paradox: as users gain more control over their "digital trace," technologies like Generative AI and sophisticated cyber-attacks are making that trace harder than ever to manage.
This insight examines three converging trends: California's aggressive push for user deletion rights, new European guidance on AI ethics, and the rise of the "silent breach."
California Strengthens the "Kill Switch" (AB 656)
California continues to lead the U.S. in privacy enforcement. With Governor Gavin Newsom signing AB 656 into law in October 2025, the state has moved beyond simple "opt-outs." This law requires large social media platforms to provide a clear and accessible "Delete Account" option, to refrain from dark patterns that obstruct deletion, and to delete the user's personal information once the account deletion is confirmed. For data brokers, California's separate Delete Act (SB 362) already provides a centralized deletion mechanism that brokers will be required to honor.
Crucially, AB 656 clarifies a long-standing gray area: deletion means erasure. Covered platforms can no longer simply "deactivate" a profile while retaining the underlying personal data for "analytical purposes," beyond the narrow exceptions the CCPA itself allows. When a user leaves, their data must go with them. For organizations operating in the U.S., this signals a shift toward a European-style "Right to be Forgotten."
GenAI: Innovation Within Ethical Boundaries
While California focuses on deletion, the European Data Protection Supervisor (EDPS) is focusing on the creation of data through Generative AI.
The latest EDPS guidance (revised in October 2025 and addressed to EU institutions) reinforces a critical message: The AI revolution is not exempt from privacy law. Whether data is generated, inferred, or used to train models, GDPR principles still apply. Key focus areas include:
- Transparency: Users must know when they are interacting with an AI or when their data is being used to "improve" a model.
- Data Laundering: The EDPS warns against using synthetic outputs to "launder" personal data from training sets. AI cannot be used as a workaround for privacy obligations.
The Rise of the "Silent Breach"
Perhaps the most alarming trend for CISOs today is the shift from "loud" hacks to "Silent Breaches." Unlike traditional ransomware that encrypts your files and demands payment, a silent breach is a long-term infiltration. Attackers embed themselves within a network for months, slowly siphoning data and monitoring internal communications. These attacks often bypass traditional perimeter defenses and root themselves in compromised credentials or sophisticated rootkits.
In a silent breach, the longer the attacker stays inside, the more data they access, potentially turning a minor security event into a catastrophic, multi-year compliance failure.
Strategy for the Road Ahead
- Audit Your Deletion Workflows: Don't wait for an enforcement action. Ensure that "Delete Account" actually triggers a full data erasure across all your sub-processors.
- Integrate Privacy into the AI Lifecycle: Perform Data Protection Impact Assessments (DPIAs) before deploying GenAI tools. Establish clear guardrails for what data can be fed into these models.
- Invest in Detection, Not Just Prevention: The era of "perimeter-only" defense is over. Invest in anomaly detection and threat hunting to identify silent breaches before they become permanent residents in your network.
Conclusion
From the legislative halls of California to the regulatory offices of the EU, the message is clear: rights without enforcement and technology without governance are no longer acceptable. Organizations must evolve as fast as the threats do, shifting from a reactive "compliance" mindset to a proactive "governance and resilience" strategy.
This article is general information from Data Protection Matters, not legal advice. We aim to be accurate, but it may contain errors or omissions and we give no warranty as to its accuracy or completeness. It reflects the position at the time of writing; privacy laws change and vary by jurisdiction. Verify against official sources, seek advice for your own situation, and rely on it at your own risk.
