California Student Data Privacy Law (AB 1159)

GoodLawCalifornia AB 1159California, United StatesLow threat
Signed; Chapter 182, Statutes of 2026
  1. Introduced
  2. Passed House
  3. Passed Senate
  4. Became Law

Stage 4 of 4: Became Law

Restricts how education technology companies exploit student records, including a direct ban on using covered student data to train generative AI.

Latest update

Signed by Governor Newsom and chaptered as Chapter 182, Statutes of 2026

What it does

AB 1159 expands California's student privacy laws to operators and contractors that know their services are used or designed for school purposes. It prohibits targeted advertising based on student information, restricts sale, disclosure, profiling, retention, and sensitive-data collection, and bars covered information and persistent identifiers from being used to train generative AI or develop AI systems. It extends similar protections to higher education from July 1, 2027 and gives students actually harmed by violations a route to sue.

What’s at stake

Educational records can expose identity, behavior, health, beliefs, location, searches, and other intimate details. Students usually cannot meaningfully refuse the tools their schools select. This law limits secondary exploitation of that data instead of demanding that students surrender additional identity information to gain access.

Our take

This is what a genuine privacy law looks like: it reduces collection, reuse, profiling, advertising, retention, and AI training. It does not pretend to protect users by first identifying and sorting everyone. The standard should be simple—school technology serves the student, and the student is not its data supply.

Timeline

Signed by Governor Newsom and chaptered as Chapter 182, Statutes of 2026Latest

Introduced in the Assembly

Sponsor

Assemblymember Dawn Addis