California has enacted a privacy law that bans education technology companies from using student data to train artificial intelligence. The legislation, signed by Governor Gavin Newsom, changes how tech firms handle the personal information of millions of students. This measure aims to close loopholes that previously allowed tech platforms to gather student profiles for commercial use.
What Happened
According to the official text of Assembly Bill 1159, companies can no longer use "covered information," which includes persistent unique identifiers, to train generative AI or develop broader commercial AI systems. This law, authored by Assemblymember Dawn Addis, expands on California's existing student data privacy regulations. As we previously reported, the bill passed the legislature with strong backing from educator and nurse unions. Now officially law, it directly targets how companies like Canvas and Duolingo handle student grades and learning records.
The Bigger Picture
The new law addresses loopholes in California's 2014 student privacy law. Previously, companies like Google and YouTube argued that because their services were not "primarily" designed for classrooms, they were exempt from strict student data limits, even though millions of kids use them for school. The updated law, as detailed by the Privacy Rights Clearinghouse, closes this gap by covering any company that knows its products are used in schools and designs or markets products to students.
The legislation also establishes the Higher Education Student Information Protection Act, and extends K-12 style privacy protections to college students starting July 1, 2027. It also limits tracking of sensitive information like immigration status and reproductive health.
Nationally, federal protections remain fragmented. While the Children's Online Privacy Protection Act (COPPA) requires companies to obtain parental consent before collecting data from children 12 and under, teenagers aged 13 to 17 are largely unprotected. A recent report on data brokers shows that teen data is bought and sold just like adult data. Although the U.S. House of Representatives recently passed the Kids Internet and Digital Safety (KIDS) Act, which includes a "COPPA 2.0" update to expand protection to teens, those federal rules are not yet active law.
What This Means for Families
For parents and educators, the law changes how daily classroom tools operate. When schools use apps for grading and schoolwork, companies cannot feed that student data into public AI models.
The law does not break personalized learning tools. While companies cannot use student data for broad AI development, they are still allowed to use collected information to support that specific student's education.
However, a major gap remains outside the classroom. If a teenager downloads a tutoring or scheduling app on their own, California's new school-centric rules do not apply. This leaves teens vulnerable to commercial data profiling when they use tech independently at home.
What You Can Do
Educators should review the privacy policies of any apps they recommend to students to make sure they align with California's new guidelines.
At home, parents can protect teenagers by manually restricting data tracking. Since federal teen protections are still pending, turning off personalized ads in device settings is a practical step.
For families with college-bound students, it is also worth checking if university digital portals already comply with the upcoming 2027 higher education data protections.