Issue · Technology

Technology (Consumer Data Protection)

Every technology bill, vote, and legislator stance in California, automatically classified by Maddy, our AI policy reader.

Total bills
39
2025-2026 Regular Session
Top supporter
Gail Pellerin
100% support rate
Top opponent
Diane Dixon
0% support rate
Ranked legislators
10
5 support · 5 oppose
Key legislators

Who's moving consumer data protection in California

Legislators moving consumer data protection in California
Legislator Party Stance Support rate Votes
Gail Pellerin
Gail Pellerin House · District 28
D
Strong +
100% 37
Buffy Wicks
Buffy Wicks House · District 14
D
Strong +
100% 35
Isaac Bryan
Isaac Bryan House · District 55
D
Strong +
100% 32
Rebecca Bauer-Kahan
Rebecca Bauer-Kahan House · District 16
D
Strong +
100% 30
Aisha Wahab
Aisha Wahab Senate · District 10
D
Strong +
100% 29
Diane Dixon
Diane Dixon House · District 72
R
Strong −
0% 36
Ali Macedo
Ali Macedo House · District 33
R
Strong −
0% 34
Carl DeMaio
Carl DeMaio House · District 75
R
Strong −
0% 28
Kelly Seyarto
Kelly Seyarto Senate · District 32
R
Strong −
0% 27
David Tangipa
David Tangipa House · District 8
R
Strong −
0% 24
Showing 31–39 of 39 bills

All technology bills

failed · California · Senate Feb 2, 2026

SB 468: High-risk artificial intelligence systems: duty to protect personal information.

Existing law, the California Consumer Privacy Act of 2018 (CCPA) , grants a consumer various rights with respect to personal information that is collected or sold by a business. The CCPA defines various terms for these purposes. The California Privacy Rights Act of 2020 (CPRA) , approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency (agency) and vests the agency with full administrative power, authority, and jurisdiction to enforce the CCPA. Existing law requires, on or before January 1, 2026, and before each time thereafter that a generative artificial intelligence system or service, as defined, or a substantial modification to a generative artificial intelligence system or service, released on or after January 1, 2022, is made available to Californians for use, regardless of whether the terms of that use include compensation, a developer of the system or service to post on the developer's internet website documentation, as specified, regarding the data used to train the generative artificial intelligence system or service. This bill would impose a duty on a covered deployer, defined as a business that deploys a high-risk artificial intelligence system that processes personal information, to protect personal information held by the covered deployer, subject to certain requirements. In this regard, the bill would require a covered deployer whose high-risk artificial intelligence systems process personal information to develop, implement, and maintain a comprehensive information security program, as specified, that contains administrative, technical, and physical safeguards that are appropriate for, among other things, the covered deployer's size, scope, and type of business. The bill would require the program described above to meet specified requirements, including, among other things, that the program incorporates safeguards that are consistent with the safeguards for the protection of personal information and information of a similar character under applicable state or federal laws and regulations. Existing law, the Unfair Competition Law, establishes a statutory cause of action for unfair competition, including any unlawful, unfair, or fraudulent business act or practice and unfair, deceptive, untrue, or misleading advertising, and establishes remedies and penalties in that regard, including injunctive relief and civil penalties. This bill would specify that a violation of the above-described provisions relating to the duty of a covered deployer to protect information, including the requirement that a covered deployer maintain the comprehensive information security program described above, constitute a deceptive trade act or practice under that law. Existing law, the Administrative Procedure Act, governs the procedure for the adoption, amendment, or repeal of regulations by state agencies and for the review of those regulatory actions by the Office of Administrative Law. This bill would authorize the agency to adopt regulations pursuant to the act to implement these provisions, and would exempt, notwithstanding that provision, any regulations adopted by the agency to establish fees from the act. The bill would define various terms for these purposes. The California Privacy Rights Act of 2020 authorizes the Legislature to amend the act to further the purposes and intent of the act by a majority vote of both houses of the Legislature, as specified. This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
failed · California · Senate Feb 2, 2026

SB 44: Brain-computer interfaces: neural data.

The Confidentiality of Medical Information Act governs the disclosure of medical information by an employer, a provider of health care, a health care service plan, or a contractor, as those terms are defined. The California Consumer Privacy Act of 2018 (CCPA) authorizes a consumer to direct a business, as defined, that collects sensitive personal information about the consumer to limit its use of the consumer's sensitive personal information, as specified, and defines "sensitive personal information" to include personal information that reveals a consumer's neural data. The CCPA also authorizes a consumer to request that a business delete any personal information about the consumer which the business has collected from the consumer, as prescribed. The California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency and vests the agency with full administrative power, authority, and jurisdiction to enforce the CCPA. This bill would require, under the CCPA, a covered business to use neural data only for the purpose for which the neural data was collected and would require a covered business to delete neural data when the purpose for which the neural data was collected is accomplished. The bill would define "covered business" to mean a person who makes available a brain-computer interface to a person in this state and would define "brain-computer interface" to mean a system that allows direct communication and control between a person's brain and an external device. This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
passed both · California · Senate Aug 28, 2026

SB 420: Property tax: welfare exemption: detention facilities.

The California Constitution authorizes the Legislature to exempt from taxation, in whole or in part, property that is used exclusively for religious, hospital, or charitable purposes, and is owned or held in trust by a nonprofit entity. Pursuant to that authority, existing law provides for a welfare exemption under which property used exclusively for an exempt purpose and owned and operated by specified entities, including foundations, limited liability companies, or corporations meeting certain statutory requirements is exempt from taxation. This bill would specify that for the purposes of the welfare exemption provisions above, "property used exclusively for religious, hospital, scientific, or charitable purposes" shall not include property, or any portion thereof, operated as a detention facility, as defined. The bill would declare that the above provision is declarative of, and not a change in, existing law.
died · California · Senate Aug 13, 2026

SB 435: California Consumer Privacy Act of 2018: personal information: exemptions.

The California Consumer Privacy Act of 2018 (CCPA) grants to a consumer various rights with respect to personal information that is collected by a business, including the right to delete personal information. The California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency and vests the agency with full administrative power, authority, and jurisdiction to enforce the CCPA. The CCPA excludes from the definition of "personal information" publicly available information. Existing law defines "publicly available" for these purposes to include 3 types of information. One type is information that a business has a reasonable basis to believe is lawfully made available to the general public by the consumer or from widely distributed media. This bill would revise that part of the definition of "publicly available" by removing the condition that the business have a reasonable basis to believe the information is lawfully made available. The CCPA also includes in that definition of "publicly available" information made available by a person to whom the consumer has disclosed the information if the consumer has not restricted the information to a specific audience. This bill would delete that part of the definition of "publicly available." This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
passed both · California · Assembly Aug 28, 2026

AB 302: Pupil and parental communication: extracurricular activities: addictive feeds.

Existing law requires the governing board of a school district that maintains one or more schools containing any of grades 7 to 12, inclusive, to establish a policy regarding participation in extracurricular and cocurricular activities by pupils in those grades as a condition for the receipt of specified school funding allocations. This bill, commencing with the 2027–28 school year, would prohibit a school district, county office of education, or charter school from excluding a pupil from participating in any extracurricular activity, including sports and clubs, due to the pupil not having or using addictive feeds, as defined. Existing law provides that parents and guardians of children enrolled in public schools have the right and should have the opportunity, as mutually supportive and respectful partners in the education of their children within the public schools, to be informed by the school, and to participate in the education of their children, as specified, including by, among other things, to be notified on a timely basis if their child is absent from school without permission. This bill, commencing with the 2027–28 school year, would prohibit a school district, county office of education, or charter school from using addictive feeds, as defined, as the only means of contacting pupils or pupils' parents or guardians.
vetoed · California · Senate Mar 2, 2026

SB 274: Automated license plate recognition systems.

Existing law prohibits a public agency, which includes the state, a city, a county, a city and county, or any agency or political subdivision of the state, a city, a county, or a city and county, including, but not limited to, a law enforcement agency, from selling, sharing, or transferring automated license plate recognition (ALPR) information, except to another public agency, and only as otherwise permitted by law. Existing law defines ALPR information as information or data collected through the use of an ALPR system. This bill would provide that "public agency" does not include a transportation agency, a public transit operator, or a local department of transportation or public works department, as specified. The bill would, beginning January 1, 2026, require new, updated, expansions of, or addendums of contractual agreements with ALPR vendors, manufacturers, or suppliers to mandate that no default access is provided to any national ALPR database and that an agency's collected scans are by default not accessible to any other agency, and would impose new requirements on sharing between California state law enforcement agencies. The bill would authorize a law enforcement agency to use ALPR information only for purposes of locating vehicles or persons when either are reasonably suspected of being involved in the commission of a public offense. The bill would prohibit a public agency from retaining ALPR information for more than 60 days after the date of collection if it does not match information on an authorized hot list, as defined, and as of January 1, 2026, would require a public agency to delete all ALPR information that has been held for more than 60 days and does not match information on an authorized hot list within 14 days. By imposing new requirements on public agencies, which include local agencies, this bill would impose a state-mandated local program. Existing law defines an ALPR operator as a person that operates an ALPR system, which does not include a transportation agency. Existing law defines an ALPR end-user a person that accesses or uses an ALPR system, which does not include, among other things, a transportation agency. This bill would additionally exclude from the definitions of "ALPR operator" and "ALPR end-user" a public transit operator, a local department of transportation or public works department, or an airport or airport operator, as provided. Existing law requires an ALPR operator and ALPR end-user to maintain reasonable security procedures and practices, including operational, administrative, technical, and physical safeguards, to protect ALPR information from unauthorized access, destruction, use, modification, or disclosure. This bill would require those security procedures and practices to include safeguards for managing which employees can see the data from their systems, as specified, and requiring data security training and data privacy training for all employees that access ALPR information. Existing law requires an ALPR operator and ALPR end-user to implement a usage and privacy policy that includes, among other things, a description of the job title or other designation of the employees and independent contractors who are authorized to access and use ALPR information. This bill would require the usage and privacy policy to identify what purpose employees and independent contractors access and use ALPR information for. The bill would also require the Department of Justice to, contingent upon an appropriation of sufficient funds, conduct annual random audits on a public agency that is an ALPR operator or ALPR end-user to determine whether they have implemented and are adhering to that usage and privacy policy. Existing law requires an ALPR operator that accesses or provides access to ALPR information to require that ALPR information only be used for the authorized purposes described in the usage and privacy policy and to maintain a record of that access that includes, among other things, the purpose for accessing the information. This bill would instead require that record of access maintained by the ALPR operator to include the case file number or task force name, as applicable, that justifies the search query, and would provide that no queries shall be allowed without a log entry with a valid and current case file number or task force name from the agency conducting the query. The bill would include findings that changes proposed by this bill address a matter of statewide concern rather than a municipal affair and, therefore, apply to all cities, including charter cities. The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement. This bill would provide that, if the Commission on State Mandates determines that the bill contains costs mandated by the state, reimbursement for those costs shall be made pursuant to the statutory provisions noted above.
signed · California · Assembly Oct 13, 2025

AB 1043: Age verification signals: software applications and online services.

Existing law generally provides protections for minors on the internet, including the California Age-Appropriate Design Code Act that, among other things, requires a business that provides an online service, product, or feature likely to be accessed by children to do certain things, including estimate the age of child users with a reasonable level of certainty appropriate to the risks that arise from the data management practices of the business or apply the privacy and data protections afforded to children to all consumers and prohibits an online service, product, or feature from, among other things, using dark patterns to lead or encourage children to provide personal information beyond what is reasonably expected to provide that online service, product, or feature or to forego privacy protections. This bill, beginning January 1, 2027, would require, among other things related to age verification with respect to software applications, an operating system provider, as defined, to provide an accessible interface at account setup that requires an account holder, as defined, to indicate the birth date, age, or both, of the user of that device for the purpose of providing a signal regarding the user's age bracket to applications available in a covered application store and to provide a developer, as defined, who has requested a signal with respect to a particular user with a digital signal via a reasonably consistent real-time application programming interface regarding whether a user is in any of several age brackets, as prescribed. The bill would require a developer to request a signal with respect to a particular user from an operating system provider or a covered application store when the application is downloaded and launched. This bill would prohibit an operating system provider or a covered application store from using data collected from a third party in an anticompetitive manner, as specified. This bill would punish noncompliance with a civil penalty to be enforced by the Attorney General, as prescribed. This bill would declare its provisions to be severable.
signed · California · Senate Oct 8, 2025

SB 361: Data brokers: data collection and deletion.

The California Consumer Privacy Act of 2018 (CCPA) grants a consumer various rights with respect to personal information that is collected or sold by a business, including the right to request that a business disclose specified information that has been collected about the consumer, to request that a business delete personal information about the consumer that the business has collected from the consumer, and to direct a business not to sell or share the consumer's personal information, as specified. The CCPA defines various terms for these purposes. The California Privacy Rights Act of 2020 (CPRA) , approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency (agency) and vests the agency with full administrative power, authority, and jurisdiction to enforce the CCPA. Existing law requires a data broker to register with the agency, and defines "data broker" to mean a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship, subject to specified exceptions. Existing law requires a data broker, in registering with the agency, to pay a registration fee in an amount determined by the agency and provide specified information, including, among other things, the name of the data broker and its primary physical, email, and internet website addresses, and whether the data broker collects the personal information of minors, consumers' precise geolocation, or consumers' reproductive health care data. This bill would require a data broker to provide additional information to the agency, including whether the data broker collects consumers' names, dates of birth, ZIP Codes, email addresses, phone numbers, login or account information, various government identification numbers, mobile advertising, connected television, or vehicle identification numbers, citizenship data, union membership status, sexual orientation status, gender identity and gender expression data, biometric data, and up to 3, but no fewer than one, of the most common types of personal information that the data broker collects, as provided. The bill would also require a data broker to provide information regarding whether, in the past year, the data broker shared or sold consumers' data to a foreign actor, as defined, the federal government, other state governments, law enforcement, as provided, or a developer of a GenAI system, as defined. The bill would make changes to the administrative fines and costs that apply to data brokers who fail to register. Existing law requires, beginning January 1, 2026, the California Privacy Protection Agency to establish an accessible deletion mechanism that, among other things, allows a consumer, through a single verifiable consumer request, to request that every data broker that maintains any personal information delete any personal information related to that consumer held by the data broker or associated service provider or contractor. Existing law requires, beginning August 1, 2026, a data broker to access the accessible deletion mechanism at least once every 45 days and, among other things, process a denied request to delete personal information as an opt-out of the sale or sharing of the consumer's personal information under the CCPA, as specified. This bill would require a data broker to process the above-described denied request within 45 days of receiving the request. Existing law requires the agency to create a page on its internet website where registration information provided by data brokers and the accessible deletion mechanism is accessible to the public. This bill would prohibit the agency from making accessible to the public on its internet website information regarding whether the data broker collects consumers' names, dates of birth, zip codes, email addresses, phone numbers, mobile advertising, connected television, or vehicle identification numbers, and the most common types of personal information that it collects. This bill would declare that it furthers the purposes and intent of the CPRA for specified reasons.
signed · California · Assembly Oct 8, 2025

AB 566: California Consumer Privacy Act of 2018: opt-out preference signal.

The California Consumer Privacy Act of 2018 (CCPA) grants a consumer various rights with respect to personal information that is collected or sold by a business, as defined, including the right to direct a business that sells or shares personal information about the consumer to third parties not to sell or share the consumer's personal information, as specified. The California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency and vests the agency with full administrative power, authority, and jurisdiction to enforce the CCPA. This bill would, beginning January 1, 2027, prohibit a business from developing or maintaining a browser, as defined, that does not include functionality configurable by a consumer that enables the browser to send an opt-out preference signal, as defined, to businesses with which the consumer interacts through the browser, as prescribed. The bill would require a business that develops or maintains a browser to make clear to a consumer in its public disclosures how the opt-out preference signal works and the intended effect of the opt-out preference signal. The bill would grant a business that develops or maintains a browser that includes this functionality immunity from liability for a violation of those provisions by a business that receives the opt-out preference signal. The bill would authorize the agency to adopt regulations as necessary to implement and administer those provisions. This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
Showing 31 to 39 of 39 bills
Previous 1 2 3 4