California Governor Gavin Newsom vetoed AB 1542, rejecting a ban on selling sensitive personal information. This decision keeps California from aligning with states like Maryland and New Jersey, which have enacted such bans. For your legal and privacy teams, this creates a compliance challenge that needs immediate attention.
What Changed
AB 1542 aimed to amend the California Consumer Privacy Act (CCPA) to stop companies from selling sensitive personal information. With the veto, California maintains its opt-out framework, allowing data sales unless consumers opt out. This contrasts with Maryland and New Jersey, where blanket bans exist. States like Connecticut, Oregon, and Virginia have also banned sales of precise geolocation data.
Consumer Reports criticized the veto, calling it "a gift to data brokers, scammers, and spammy marketers." They warn that ongoing sales of sensitive data can lead to stalking, identity theft, and predatory targeting.
Key Findings
California's opt-out model vs. other states' prohibitions. Your organization must now navigate different rules based on user location. Maryland and New Jersey offer blanket protection, while California requires consumers to opt out. This means your Consent Management Platform (CMP) and data flows must adapt to these segmented compliance obligations.
Economic concerns influence legislative decisions. Newsom's veto suggests a focus on economic impact over consumer protection. This indicates that California may prefer incremental changes rather than broad bans in the near future.
Sensitive data sales are under scrutiny nationwide. Despite California's veto, states like Maryland, New Jersey, Connecticut, Oregon, and Virginia are restricting sensitive data sales. The trend is clear: restrictions are coming, and it's a matter of which model will dominate and when California might revisit the issue.
Varying definitions of "sensitive" data. The CCPA defines sensitive information to include precise geolocation, Social Security numbers, financial account credentials, biometric data, and health information. Maryland and New Jersey have similar definitions but different scopes. Your data inventory must align with these definitions to ensure compliance across jurisdictions.
Consumer expectations are rising. Consumer Reports' reaction highlights a growing belief that sensitive data shouldn't be sold, regardless of opt-out options. Even if your California operations are compliant, consider the reputational risks and consumer trust issues that may justify voluntary restrictions.
What This Means for Your Team
If you assumed California would lead privacy legislation, this veto challenges that view. You're now managing a patchwork of regulations where some states allow sales with opt-out rights, others ban all sensitive data sales, and some prohibit specific categories like precise geolocation.
Your data governance framework must accommodate state-specific prohibitions. A consent record valid in California may not meet Maryland or New Jersey standards. If you're selling precise geolocation data, you're already non-compliant in Connecticut, Oregon, and Virginia.
Expect renewed legislative efforts in California. Consumer Reports plans to work with policymakers to strengthen privacy standards. Monitor potential successor bills to AB 1542 and prepare for possible changes that address Newsom's concerns.
Action Items by Priority
Audit your sensitive data sales by state. Identify which sensitive personal information categories you're selling, to whom, and under what legal basis. Cross-reference this against prohibitions in Maryland, New Jersey, Connecticut, Oregon, and Virginia. Stop sales or implement state-specific suppression logic if needed.
Update your CMP configuration. Ensure your CMP distinguishes between California's opt-out model and Maryland/New Jersey's prohibition model. A "Do Not Sell My Personal Information" link for California users isn't suitable for Maryland or New Jersey, where sales are outright prohibited.
Review vendor contracts for data sharing. While AB 1542 would have banned sales, your vendors may still share sensitive data under other legal bases. Ensure your Data Processing Agreements specify state prohibitions and require vendors to comply with them.
Map your data flows for cross-state exposure. If a California user's precise geolocation is shared with a vendor who resells it in Connecticut, you could face liability under Connecticut law. Your data flow maps must track sensitive data from collection through every transfer.
Prepare for California's next legislative session. Advocacy groups are pushing for stronger protections. Monitor new bills in early 2025 and engage with industry coalitions. If a revised AB 1542 addresses Newsom's concerns, it may pass.
Reassess your data minimization strategy. Avoid collecting or selling sensitive data unless essential. If you're selling sensitive data mainly for ad revenue, weigh the compliance costs and reputational risks against the benefits, especially as more states impose bans.




