Explore Legal.io

For Clients
Legal.io company logo
Hire Talent
Find the best fit for any legal role
For Members
The best legal jobs, updated daily
Benchmark compensation for any legal role
Learn and grow with our community
Connect with peers at exclusive events
Tools to streamline legal work
Advertise on Legal.io
Post a job for free
Reach more qualified applicants quickly
Advertise with Us
Reach a targeted audience

For Clients

Hire Talent
Legal.io company logo
Find the best fit for any legal role
New Hire
Get highly qualified candidates in days
Popular Roles
Data & Tools
Budget Calculator
Plan and manage your legal budget
Salary Insights
Compensation data for legal roles
Vendor Directory
The ultimate list of legal tech tools

California Extends Data Privacy Protections to Brain Waves with SB 1223

California has become the second state after Colorado to extend data privacy protections to brain waves after Gov. Gavin Newsom signed into law SB 1223, amending the CCPA to define neural data as persona-sensitive information, effective immediately.


  • California adds neural data to CCPA's protections, classifying them as sensitive personal information.
  • California I the second state following Colorado to regulate neural data, setting a precedent for broader protections.

  • The law comes with compliance changes for Big Tech companies operating out of the state, especially for those rolling out neurotech consumer products.

California Gov. Gavin Newsom signed SB 1223 into law, amending the California Consumer Privacy Act (CCPA) to include neural data as personal sensitive information, according to a Law.com report. The bill, authored by State Senator Josh Becker, comes into effect immediately.

This makes California the second state after Colorado to define brain waves as sensitive personal information, following an amendment to the Colorado Privacy Act (CPA), ensuring that consumer neurotechnological data is protected similarly to biometric and health data. Both SB 1223 and the Colorado bill were sponsored by the nonprofit NeuroRights Foundation.

Why this matters: 

  • According to a NeuroRights Foundation report, there are currently 30 consumer-grade tools on the market that collect neural data.

  • Under this new legislation, companies collecting brainwave data, particularly from devices measuring cognitive or neural activity, must now adhere to stricter privacy protocols.


What SB1223 Provides

  • Neural data, or "brain waves," care defined as "information that is generated by measuring the activity of a consumer's central or peripheral nervous system, and that is not inferred from nonneural information." 

  • Neural data will have the same protections under the CCPA as consumer's genetic data, biometric data, precise geolocation data, and credentials to access financial accounts.

  • Only neural data collected by non-invasive medical grade neurotechnologies will be subject to this bill.

The CCPA and, by extension, SB 1223 apply to businesses with an annual gross income of $25 million or more, if the business buys, sells, or shares the personal information of at least 100,000 California residents, and if the business derives at least 50% of its annual revenue from selling or sharing California residents' personal information.

Mixed Response

  • Neural data definitions in both California and Colorado are too ambiguous and don’t focus enough on “cognitive” or “mental” privacy, according to Nita Farahany, professor of law and philosophy at Duke Science and Society.

  • Farahany wrote in a post that SB 1223 should also include protections for data from heart rate, eye-tracking, and even fitness wearables.

  • Jared Genser, a former DLA Piper partner who now serves as the general counsel of NeuroRights Foundation, said non-neural data is not necessarily as dire and revealing as neural data which is collected by invasive neurotechnologies, so it did not need to be covered by the bill.

  • "Specifically, neural data in California matches the scientific definition of data that can only be captured by medical-grade neurotechnologies and it excludes non-neural inferential data captured from outside the body, which is much less sensitive," Genser said.

What Does This Mean for Silicon Valley?

For Silicon Valley, where neurotech development is expanding under companies such as Meta or Apple, this regulation adds a layer of complexity. While the list of companies rolling out neurotechnologies subject to SB 1223 largely consists of "only a handful of the smaller neurotech companies that meet" thresholds of CCPA compliance, this is likely to change in the near future.

According to Genser, the first company to roll out neurotech subject to the CCPA will be Meta, with the launch of its Orion AR glasses, which need to be combined with a neurotechnology wristband. Companies working on brain-computer interfaces, EEG devices, and neurofeedback tools will need to overhaul their data handling and consent practices in response to this new legislation.

Legal.io Logo
Welcome to Legal.io

Connect with peers, level up skills, and find jobs at the world's best in-house legal departments

More from Legal.io

Google to Mandate Disclosures of AI Content in Political Ads

Ahead of the election season, the tech giant is taking steps to put proper disclaimers on its political content.

Google to Mandate Disclosures of AI Content in Political Ads
Strategic Shifts and Modest Growth: NLJ 500 Key Trends

The results show modest growth in attorney headcounts among the largest U.S. law firms, with significant changes in firm rankings driven by strategic expansions and market dynamics.

Strategic Shifts and Modest Growth: NLJ 500 Key Trends
Law Firms
Onit Bolsters Executive Team to Enhance Legal Workflow Solutions

Onit, a provider of legal workflow solutions, has announced the addition of new senior executive leadership team members to drive strategic growth and customer success.

Onit Bolsters Executive Team to Enhance Legal Workflow Solutions
Hack the Legal Marketing Game

In the digital age, your website is the modern equivalent of a business card.

Hack the Legal Marketing Game
Law FirmsCareer
Surge in Data Breach Class Actions in 2023

One of the key factors contributing to the surge is the increased sophistication of cybercriminal activities.

Surge in Data Breach Class Actions in 2023
Legal.io Newsletter - April 23, 2021

Published weekly on Friday, the Legal.io Newsletter covers the latest in legal, talent & tech.

Legal.io Newsletter - April 23, 2021
TechnologyLegal SoftwareCareer
What Skills Do You Need to Get Started in Legal Operations? 

Legal Operations is a growing field, creating opportunities for an increasing number of talented individuals from a range of disciplines. Do you have what it takes to join this cutting edge department? Let’s take a look at the skills you need to get established in Legal Operations today!

What Skills Do You Need to Get Started in Legal Operations? 
Legal OperationsTechnologyLaw Firms
Herbert Smith Freehills and Kramer Levin Announce $2B Merger

Herbert Smith Freehills and Kramer Levin Naftalis & Franke plan to merge to create one of the largest law firms in the world with more than $2 billion in revenue, 2,700 lawyers and 640 partners across 25 offices.

Herbert Smith Freehills and Kramer Levin Announce $2B Merger
Law Firms
Legal.io Logo
Welcome to Legal.io

Connect with peers, level up your skills, and find jobs at the world's best in-house legal departments