California lawmakers passed a student privacy bill to shield children and young adults from commercial tracking and AI training practices. Assembly Bill 1159, also known as the California Learner Personal Information Protection Act, awaits Governor Gavin Newsom’s signature. If signed, the law will close legal loopholes that tech companies use to collect, share, and monetize student data from preschool through college.
What Happened
On August 31, 2026, the California State Legislature passed Assembly Bill 1159, introduced by Assemblymember Dawn Addis. The bill, which was officially enrolled on September 4, restricts how educational technology platforms collect and handle student data. Under previous California laws, privacy protections only applied to online services marketed "primarily" for schools. AB 1159 eliminates this loophole, holding any platform accountable if the operator knows the service is being used for school and was designed or marketed for educational purposes.
The legislation also targets the use of artificial intelligence in classrooms. It prohibits companies from using a student's personal information or "persistent unique identifiers" to train generative AI systems. It also enacts the Higher Education Student Information Protection Act (HESIPA), extending these data protections to college students starting July 1, 2027. This stops companies from targeting young adults with high-cost loans and predatory offers. Finally, the bill allows affected students to file civil lawsuits against companies that violate their data rights.
The Bigger Picture
This legislative action comes as technology in classrooms outpaces school district regulations. As we previously reported, school monitoring software and digital learning programs frequently operate under outdated federal privacy frameworks. A 2025 study showed that while over half of all teachers and students use AI tools, fewer than half of school principals reported having an official policy to govern that usage.
Without these policies, school districts risk sharing data unintentionally. When teachers use unvetted tools, they risk exposing sensitive student information to commercial entities. For example, Anthropic recently released Claude for Teachers and encouraged educators to upload student diagnostics and rosters. While the company promises not to use this data to train its models, experts warn that inputting student records without a formal, district-negotiated agreement violates privacy regulations and puts teachers in legal jeopardy.
Technical studies also reveal that written privacy contracts do not always match what apps do behind the scenes. A study of EdTech apps used in schools revealed that 52 percent of the applications collected unauthorized data, and 36 percent sent that information directly to advertisers. Similar concerns are playing out in courts. A federal class action lawsuit accuses the widely used learning platform i-Ready of secretly transmitting student names, grades, and demographic details to third parties for advertising purposes. Its developer, Curriculum Associates, denies the claim. Meanwhile, the founder of the scholarship app Scholly filed a whistleblower complaint alleging that student lender Sallie Mae retaliated against him for objecting to plans to sell minors' financial and demographic data.
What This Means for Families
For parents and educators, California's legislative update signals that student data is no longer a free commodity for AI developers or commercial advertisers. As districts continue to manage classroom app sprawl, families must recognize that even well-meaning tools can leak personal details.
If signed into law, AB 1159 will give parents and college students the ability to take legal action. The option to bring civil lawsuits against non-compliant tech vendors means companies must actively monitor and restrict their own data collection practices, rather than hiding behind confusing terms-of-service agreements.
What You Can Do
- Ask your child's principal or school district if they have vetted generative AI platforms and what agreements they have in place to prevent student data from being used for AI training.
- Check the privacy settings on the educational apps your child uses at home and opt out of data sharing or personalized tracking where possible.
- Encourage your school board to implement strict vendor review processes so teachers do not have to rely on unvetted tools for classroom management.