California has enacted a new privacy law that restricts how educational technology platforms handle student information. Under the law, technology companies cannot use student essays, coursework, and personal data to train artificial intelligence models. This establishes some of the nation's strictest limits on student data as classrooms rely more on digital learning tools.
What Happened
In September 2026, Governor Gavin Newsom signed Assembly Bill 1159, which prevents educational software companies from capitalizing on student data. The bill bans edtech operators from using student data, including homework and unique online identifiers, to train or develop generative AI models.
The law also limits the collection of sensitive student information. According to the Privacy Rights Clearinghouse, companies cannot track, store, or share information regarding a student's immigration status, sexual orientation, gender identity, or reproductive healthcare.
AB 1159 closes a loophole that tech companies previously used to bypass state regulations. Past privacy laws only applied to software designed "primarily" for classroom use. The new law, as reported by CalMatters, applies to any tech company that knows its products are being used in schools, as long as those products are designed or marketed for educational purposes. This means platforms like Canvas and Duolingo must comply. The broader rules take effect next year, while specific protections for college students under the Higher Education Student Information Protection Act start on July 1, 2027.
The Bigger Picture
Schools are rapidly adopting AI tools for grading and student feedback. For example, Henry County Public Schools in Kentucky recently deployed Gemini for Education to help teachers provide feedback on student writing. School administrators in Fayetteville, Arkansas, also had to address public concerns about using AI to grade state ATLAS tests.
While districts adopt these tools to save teachers time, parents and privacy advocates worry about where student data ends up. As we previously reported, school districts must balance the utility of AI with student privacy.
These concerns stem from real disputes. A class-action lawsuit filed by California families alleges that the learning platform i-Ready tracked student metadata, such as "erratic mouse movements" and time spent on questions, and shared that information with third-party data brokers. Although the platform's developer, Curriculum Associates, denies these claims and states on its website that it does not sell student data, independent research shows a gap between corporate policies and reality. An investigation commissioned by the Utah State Board of Education tested educational apps and found that more than half had at least one conflict between their actual practices and their written privacy agreements.
What This Means for Families
California's new law shifts the burden of privacy protection from families to tech companies. Instead of parents needing to manually opt out of complex agreements, software providers must protect student data by default.
The law also allows families to take legal action. Under AB 1159, a student or parent can file a civil lawsuit directly against a tech operator if the company fails to comply.
What You Can Do
Parents can take several steps to protect their children's data. First, contact your school district's IT department or principal to ask if classroom digital tools comply with the latest state privacy laws. Next, keep track of the learning platforms your child uses at home and review their privacy settings, particularly for AI features. Finally, encourage your local school board to establish clear, written guidelines for how teachers use AI in grading, ensuring that a human educator always makes the final decision.