California’s latest legislative session delivered a wave of privacy developments, with Governor Gavin Newsom signing a broad set of measures affecting consumer rights. But one proposal did not make it across the finish line: AB 1542, which would have prohibited the sale or sharing of sensitive personal information with third parties. This article examines the governor’s veto of AB 1542 and what it means for the direction of privacy policy and for businesses and consumers subject to California law.

In explaining the veto, the governor characterized a categorical ban on sharing that information as “a step too far,” reasoning that existing law already requires companies to give consumers the option to limit such sharing and that removing consumers from the decision-making process entirely could have unintended consequences. He also cited the bill’s broad application to businesses and the significant implementation and enforcement costs it would impose, none of which were accounted for in the 2026 Budget Act.

Background and Path Forward

AB 1542 would have provided that a business, service provider, or contractor “shall not sell or share sensitive personal information to a third party,” subject to specified exceptions. This prohibition would have layered a default prohibition on top of California’s current approach, which relies principally on consumer choice and context-specific limits.

Governor Newsom’s veto is significant because other states have recently adopted similar prohibitions. For example, Maryland and New Jersey have adopted bans on the sale of sensitive data. Meanwhile, Connecticut, Virginia, and Oregon have prohibited the sale of specific types of sensitive data, including precise geolocation data. Earlier this year, Oregon also banned the sale of personal data pertaining to a minor consumer under age 16. Each of these laws includes various limitations and exceptions, contributing to an emerging patchwork of such prohibitions.

One major question raised by Governor Newsom’s veto is whether it will deter more states from pursuing such legislation. If a ban on selling and sharing sensitive data is “a step too far” for California, will other states be willing to take that step?

The Rules Left in Place After the Veto

Governor Newsom’s veto leaves intact California’s preexisting laws relating to the sale and sharing of sensitive personal information. The key features of the existing regulatory regime are as follows.

Right to Opt Out. The California Consumer Privacy Act (CCPA)gives consumers the right to direct a business not to sell or share their personal information, including sensitive personal information, on request and at any time. See Cal. Civ. Code § 1798.120.

Purpose Limitation. Cal. Civ. Code § 1798.100(c) requires that a business’s collection, use, retention, and sharing of personal information (including sensitive personal information) be reasonably necessary and proportionate to achieve the purpose for which the information was collected or processed, or another disclosed purpose compatible with the context of collection.

Right to Limit. Cal. Civ. Code § 1798.121 gives consumers the right to direct a business to limit the use and disclosure of sensitive personal information to what is necessary to provide the goods or services reasonably expected by an average consumer, to specified statutory business purposes, and to purposes authorized by regulation. Once a consumer exercises that right, the business may not use or disclose sensitive personal information for other purposes unless the consumer subsequently consents. Notably, the right to limit does not apply to sensitive personal information that is collected or processed without the purpose of inferring characteristics about the consumer.

Practical questions for businesses to consider before selling or sharing sensitive personal information of California consumers

The veto did not change any existing California rule, so the real planning question for businesses is not “what does California require” but “how do we operate across states that are diverging.” California has declined to adopt a categorical ban; Maryland, New Jersey, and others have moved in the opposite direction. Businesses that sell or share sensitive personal information must decide whether to run state-by-state processes or converge on a single, nationwide standard. The following questions help frame that decision.

  1. What sensitive data do we actually sell or share, and to whom? Businesses should consider building the inventory before choosing a strategy. Map flows by data category (precise geolocation, health, biometric, racial or ethnic origin, sexual orientation, immigration status, children’s and teens’ data) and by recipient, including ad tech and analytics partners whose receipt of data may constitute a “sale” or “share” even where no money changes hands.
  2. Which state rules attach to each of those flows? Consider sorting flows into three buckets: jurisdictions where the sale is flatly prohibited, those requiring opt-in consent, and those relying on opt-out. Then stress-test the sorting against definitional variation. States differ on what counts as a “sale,” what qualifies as “sensitive,” and even on the radius that makes geolocation “precise.” A single consistent approach may need to be calibrated to the strictest applicable version of each definition.
  3. How much does the business actually rely on these sales? Quantify the revenue and operational value attributable to sensitive-data sales, net of the cost of maintaining state-specific controls, vendor diligence, and enforcement risk. Where the value is modest, a nationwide no-sale policy for sensitive categories may be the cheaper and more durable answer.
  4. Can we reliably determine which state’s law applies to a given consumer? Assess whether residency or location is determined accurately, how IP-based inference performs against VPNs and travel, what happens when signals conflict, and how the default resolves when residency is unknown.
  5. Are minors and teens handled separately? Age-based rules are the fastest-moving part of the patchwork and are frequently stricter than the general rule. Oregon, for example, bars the sale of personal data of consumers under 16 outright, while California requires affirmative authorization. Confirm whether age signals are collected and how actual knowledge is assessed.
  6. Will the approach hold up as the law changes? The veto reflects one governor’s cost and timing judgment in one session, not a settled policy direction, and similar bills are likely to return in California and elsewhere. Businesses should develop data inventories, mapping of data flows, vendor and customer contract terms, consent mechanisms, and operational controls needed to identify and block transfers that a given state may treat as prohibited, as durable, adaptable programs, designed to flex as the legal landscape evolves, rather than needing to be rebuilt each time a new standard emerges.

The bottom line

Governor Newsom’s veto of AB 1542 means California has not adopted a categorical prohibition on the sale or sharing of sensitive personal information, and its existing rules continue to apply. But the veto does not reverse the broader trend. As mentioned above, Maryland and New Jersey bar the sale of sensitive data outright, and Connecticut, Virginia, and Oregon have banned sales of particular categories, such as precise geolocation, with Oregon adding a ban on selling the data of consumers under 16. Businesses should not treat the veto as a reason to stand still. The decision is whether to build a process that manages the patchwork state-by-state or to adopt a single nationwide approach, and, in either case, to design a compliance program that can flex as the legal landscape evolves rather than needing to be rebuilt each time a new standard emerges.

So, has the tide turned? No. California simply declined to swim with it during this session.