Newsom Vetoes the Sensitive-Data Sale Ban and Keeps the Limit-My-Use Button

Table of Contents

Governor Gavin Newsom vetoed Assembly Bill 1542 on September 27, the same weekend he signed the bill that expands California’s right to delete. AB 1542, by Assemblymember Chris Ward, would have amended the California Consumer Privacy Act to ban the sale and sharing of sensitive personal information by covered businesses. The Legislature had already passed it. Newsom sent it back.

“While I support the author’s goal of protecting the sensitive personal information of Californians, a categorical ban on sharing that information is a step too far,” he wrote. He pointed to existing law that lets residents limit the use and disclosure of sensitive information, and said he worried about “unintended consequences if consumers are removed entirely from the decision process.” Reporting on the veto message also cited budget limits on implementing and enforcing a ban.

The Senate voted 31 to 4 on August 28. The Assembly voted 44 to 19 on August 30. The California Privacy Protection Agency’s board had voted to support the bill. Newsom did not.

What stays legal

CCPA sensitive personal information includes precise geolocation, health information, racial or ethnic origin, religious beliefs, union membership, the contents of mail and messages, genetic data, biometric identifiers, and information about sex life or sexual orientation. Government identifiers such as Social Security numbers sit in the same bucket. Under current law a business may sell or share those fields unless the consumer opts out or uses the “limit the use of my sensitive personal information” right. AB 1542 would have flipped that to a prohibition, with the usual statutory exceptions still to be fought over in regulations.

Maryland and New Jersey already ban the sale of sensitive data. Connecticut, Oregon, and Virginia have barred the sale of precise geolocation. Consumer Reports policy analyst Matt Schwartz called the veto a gift to data brokers and said the practice enables stalking, identity theft, and predatory targeting. The Association of National Advertisers treated the veto as avoiding collateral damage to ordinary advertising and service uses that a total ban would have swept in.

The choice Newsom kept

Newsom’s letter treats the limit right as the safeguard and the ban as the overreach. That right only works if the consumer finds it, the business honors it, and downstream buyers do not reattach the same fields from another file. CalPrivacy has spent the last year enforcing data-broker registration and deletion failures. A limit request that dies at the first broker is the gap advocates wanted the statute to close.

The same signing window shows where Newsom was willing to move. SB 923, effective January 1, 2027, requires deletion of personal information a business obtained from a third party, not only data it collected from the consumer, and forces online-only businesses to offer a web form. He also signed bills on honoring privacy choices and insurance data. The deletion right got a signature. The sale ban did not.

For a CCPA business, the operating rule on Monday is the rule from Friday. Sensitive data may still be sold or shared. The limit link still has to work. A suppression or opt-out that covers only first-party collection will not satisfy a regulator who is already reading broker flows, and it will not satisfy a customer who used the right Newsom said he was protecting.

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.