Law note · California
California Consumer Privacy Act, publicly-available-information exemption (as amended by AB 1008)
What it asks of an app
- Do not treat personal data scraped from a third-party aggregator, directory, or re-posting site as publicly available under the CCPA merely because it appears on a public page; the exemption requires the consumer's own act or a government source.
- Never treat biometric information a business collected about a consumer without that consumer's knowledge as publicly available, regardless of source.
- If you meet CCPA's revenue or volume thresholds, personal data you collect by scraping still triggers the Act's business obligations, including when it feeds AI training.
When LexLint raises it
crawls_webtrains_modelsprocesses_biometrics
What we found
Section 1798.140(v) defines publicly available narrowly: lawfully available government records, information a business has a reasonable basis to believe the consumer themselves lawfully made available to the public or through widely distributed media, or information made available by a person to whom the consumer disclosed it without restricting the audience, and it expressly excludes biometric information a business collected about a consumer without the consumer's knowledge.
Because the exemption keys to the consumer's own act or a government source, personal data scraped from an aggregator, directory site, or re-poster the consumer did not control is not automatically publicly available, so a scraper meeting CCPA's revenue or volume thresholds becomes a regulated business over that data.
AB 1008 (2024) amended this section to add AI systems capable of outputting personal information to the list of formats personal information can take, and added the biometric carve-out; its enacted text contains no clause addressing automated mass extraction or web scraping by name, and an earlier claim that it does is not supported and is not carried into this document.