California enacted AB 1159 on September 10, 2026. The law substantially expands student privacy obligations for education technology providers providing services to early learners, K-12, and higher-education students. It amends the K-12 Pupil Online Personal Information Protection Act (KOPIPA), and Early Learning Personal Information Protection Act (ELIPA). It also creates the Higher Education Student Information Protection Act (HESIPA), to be codified beginning at Cal. Bus. & Prof. Code § 22587, covering operators of qualifying online services used for higher-education purposes. The law also creates a private right of action for students and their parents or guardians against operators and other covered entities.
Reflecting a growing concern about how educational technology platforms use student data, AB1159 expands the scope of existing laws to cover not only operators but also their downstream subcontractors / service providers and adds specific restrictions on use of student data for AI training and development. AB 1159 also adds new data retention, deletion, and deidentification requirements that will increase operational and technical complexity for many edtech companies. The new early learning and K-12 requirements take effect January 1, 2027. HESIPA takes effect July 1, 2027.
Key Changes in More Detail
AB 1159 makes several significant changes to KOPIPA and ELPIPA. Most changes to KOPIPA and ELPIPA are substantially similar, and the new HESIPA is largely similar to both KOPIPA and ELPIPA:
Expanded Scope. AB 1159 covers not only an operator, but also any entity working on its behalf. The trigger for what services is also expanded. The law previously covered operators with actual knowledge its service is primarily used for school purposes and whose service was designed and marketed for those purposes.” The law expands the scope of covered services by removing the qualifier “primarily” to include any service used for school purposes and by replacing “designed and marketed” with “designed or marketed.” As a result, mixed-use and general-audience services may be covered where the operator knows the service may be used for any school purposes and if the service is either designed or marketed for that use.
Restrictions on AI Training and Development. The other significant change under these laws is that covered student data cannot be used to train a generative AI system or service or develop an AI system. "Train” is defined broadly to include model development, model testing, and fine-tuning.
There is an exception to those and other restrictions in this section allowing "operator's use of information for maintaining, developing, improving, or diagnosing the operator’s site, service, or application." The scope of this exception is unclear.
A narrow reading of this exception could permit the development of AI systems incorporated into a school-facing service, but not the training of generative AI models. By contrast, a broader reading could permit the training of generative AI models offered as part of a school service, so long as the training is limited to developing or improving that service.
While the statutory language is contradictory and, at best, unclear, interpreting it to categorically prohibit edtech providers from using student data to improve AI functionality that a school has authorized as part of a service could have significant consequences. Such an interpretation could limit California schools’ ability to use AI to operate more efficiently and restrict providers’ ability to improve the performance and safety of AI tools that schools make available to students, including tools used to educate students on the appropriate use of AI.
Restrictions on Sensitive Information Collection. AB 1159 specifically restricts an operator’s collection, use, and disclosure of covered information concerning a student’s reproductive or sexual health, immigration status, sexual orientation, or gender identity, subject to the statute’s express terms and exceptions.
Unlike KOPIPA and ELPIPA, HESIPA adds precise geolocation information to its list of prohibited categories of sensitive information. The enacted text does not explain why that category appears only in HESIPA. As with the AI restrictions, there is a broad exception to these restrictions for an operator’s use of information for maintaining, developing, supporting, improving, or diagnosing the operator’s service that arguably allows for some limited use.
Deidentification Standards and School or LEA Requirements. AB 1159 builds on existing laws’ deidentification exceptions and related requirements for proper deidentification by giving schools and local educational agencies (LEAs) a role in determining whether an operator’s deidentification process is sufficient. Operators must make their deidentification processes available for review by the applicable school or LEA before using deidentified data. Schools and LEAs are not required to conduct a review, but if they do, the operator cannot treat the applicable data as deidentified unless the school or LEA determines that the process is sufficient. Where a school or LEA maintains its own deidentification policy or standard, the operator must follow that policy or standard.
Written Retention Policies and School or LEA Retention Limits. A written data retention policy will need to be maintained and implemented, and provided to students, their parents or guardians, and school personnel upon request. The policy must describe why covered information is collected and retained, and the timeframe for deletion. AB 1159 will also require operators to not exceed a school or LEA’s retention period for the same information.
Unlike with deidentification processes, the law does not require an operator to make its retention policy available to schools or LEAs for review prior to processing. As a practical matter, operators should be prepared to follow applicable retention schedules that schools and LEAs provide through DPAs or other vendor requirements and to configure retention periods accordingly.
Deletion and Access Rights. AB 1159 continues to allow operators to comply with deletion and access requirements under FERPA and CCPA. The law also continues to allow students to download, export, save or maintain their own personally created data or documents.
AB 1159 creates new deletion and access rights to address a narrow set of student information that is subject to exceptions from the CCPA’s deletion and access requirements. For deletion, these include student’s grades, educational scores, or educational test results that the operator holds on behalf of a LEA. For access, these include certain educational standardized assessment information. Once a student has been unenrolled from the LEA for at least 60 days, a parent, guardian, education rights holder, or the former student, if 18 or older, may request deletion or disclosure to the student of such information which the operator must honor, subject to more limited exceptions. Before deleting the information, the operator must obtain documentation that the student is no longer enrolled in the LEA.
Fines and Enforcement
AB 1159 creates a new private right of action. A student, or their parent or other guardian, will be able to sue individually or on behalf of a class to recover the greater of actual damages or $500 per plaintiff, per violation, plus injunctive relief, punitive damages, and attorney's fees. The law also provides a notice-and-cure period, giving operators 60 days after receiving written notice to correct an alleged violation before a private suit can be brought.
Class claims require the operator to identify or reasonably attempt to identify similarly situated students, notify them that a remedy is available upon request, provide or agree to provide the requested remedy, and stop the violation. Plaintiffs must also furnish a copy of the complaint to the Attorney General within 10 days of filing.
While the law does not contain an express public enforcement provision, we would expect violations to be actionable by the Attorney General and other public prosecutors under California's Unfair Competition Law (UCL), which treats a violation of any law as an unlawful business practice. The California AG took that approach in its 2025 action against Illuminate Education, pleading KOPIPA violations as unlawful business practices under the UCL. Under the UCL, the AG and authorized prosecutors can seek injunctive relief and civil penalties of up to $2,500 per violation.
What to do now
Companies subject to KOPIPA should begin assessing the technical and operational changes needed to comply before January 1, 2027, including:
Reassess scope. Review school-facing and mixed-use products to determine whether the company has actual knowledge of student use and whether each product is designed or marketed for school purposes. Consider sales and marketing materials and the information received through customer contracts, sales and onboarding processes, product configurations, and other school-specific interactions when conducting that assessment.
Map AI uses. Determine where student data is used in AI training or development. Assess whether each use is restricted to serving only school purposes, including whether any model trained on student data is only deployed in connection with the school services.
Update sensitive data inventories. Identify and restrict collection and/or use of reproductive/sexual health, immigration status, sexual orientation, or gender identity. And in the case of higher ed, precise geolocation information.
Document retention and deidentification practices. Establish and operationalize a retention schedule tied to the purposes for which covered information is collected and document the company’s deidentification standards. Ensure both are suitable for sharing with schools and LEAs upon request, accurately reflect the company’s actual practices, and are consistently followed.
Build school and LEA-level configurability. Develop the technical functionality needed to configure retention periods and deidentification standards at the school or LEA level, where required.
Update rights-request workflows. Update processes for handling deletion and access requests to include education data of students subject to CCPA exceptions. The process should verify the requester’s identity and authority and, for deletion requests, require documentation that the student has been unenrolled for at least 60 days.
Susan Hintze is the Founder and Co-Managing Partner at Hintze Law PLLC. Recognized by Chambers, Legal 500, & Best Lawyers. Susan serves on the International Association of Privacy Professionals (IAPP) Board of Directors and is an IAPP Westin Emeritus Fellow. She is also co-chair of the firm’s Regulatory Defense Group and Kids + Teens Group. Susan has provided legal counsel to tech and e-commerce clients for over 25 years, of which, over 20 years have been focused exclusively in the area of privacy, AI, online safety, disinformation, and cybersecurity.
Emily Litka Sanford, Of Counsel at Hintze Law PLLC, is co-chair of the Kids & Teens Group and a member of the Artificial Intelligence + Machine Learning Group and focuses her practice on global AI, privacy, and online safety laws and regulations. She regularly counsels on risk during product development, the development and operationalization of privacy programs, the preparation of data protection impact assessments, and the development of internal AI & privacy policies and processes.
Hintze Law PLLC is a Chambers-ranked and Legal 500-recognized, boutique law firm that provides counseling exclusively on AI, privacy, and data security. Hintze attorneys and data consultants support technology, ecommerce, advertising, media, retail, healthcare, and mobile companies, organizations, and industry associations in all aspects of AI, privacy, and data security.
