California Student Data Privacy Law (AB 1159)
- Introduced
- Passed House
- Passed Senate
- Became Law
Stage 4 of 4: Became Law
Restricts how education technology companies exploit student records, including a direct ban on using covered student data to train generative AI.
Latest update
Signed by Governor Newsom and chaptered as Chapter 182, Statutes of 2026
What it does
AB 1159 expands California's student privacy laws to operators and contractors that know their services are used or designed for school purposes. It prohibits targeted advertising based on student information, restricts sale, disclosure, profiling, retention, and sensitive-data collection, and bars covered information and persistent identifiers from being used to train generative AI or develop AI systems. It extends similar protections to higher education from July 1, 2027 and gives students actually harmed by violations a route to sue.
What’s at stake
Educational records can expose identity, behavior, health, beliefs, location, searches, and other intimate details. Students usually cannot meaningfully refuse the tools their schools select. This law limits secondary exploitation of that data instead of demanding that students surrender additional identity information to gain access.
Our take
This is what a genuine privacy law looks like: it reduces collection, reuse, profiling, advertising, retention, and AI training. It does not pretend to protect users by first identifying and sorting everyone. The standard should be simple—school technology serves the student, and the student is not its data supply.
Timeline
Signed by Governor Newsom and chaptered as Chapter 182, Statutes of 2026Latest
Introduced in the Assembly
Sponsor
Assemblymember Dawn Addis
Suggest a bill or correction
Know a bill we should track, or spot something out of date? Email the bill name, the jurisdiction and a link to an official source.
