Normal view

It’s easier for Californians to escape data brokers following a Markup investigation

The Markup and CalMatters showed how website code could make it harder for Californians to exercise their right to remove personal data. Now much of that code has disappeared.

A woman wearing glasses speaks into a microphone during a congressional hearing while holding a blue pen in one hand. A nameplate reading “MS. HASSAN” sits in front of her as other attendees appear out of focus in the background.

Sen. Maggie Hassan pressed data brokers to make it easier to opt out of their systems, citing an investigation by The Markup and CalMatters, published in partnership with WIRED. U.S. Sen. Maggie Hassan speaks during a Senate Finance Committee on Capitol Hill in Washington, D.C. on March 14, 2025. Photo by Ben Curtis, AP Photo

More data brokers have changed their practices in response to reporting from The Markup and CalMatters as well as a subsequent Senate investigation.

Data brokers — companies that collect and sell access to often-sensitive information on consumers — are required to register in the state of California and provide a way for consumers to request their data be deleted. 

Last year, an investigation by The Markup and CalMatters, published in collaboration with WIRED, showed that many of those companies placed code on the web pages for making those requests that prevented them from appearing in search results. The “no-index” code tells search engines like Google not to catalog those pages, making it less likely that anyone would see them. Experts said that’s a hurdle for Californians looking to exercise their legal rights. 

Last year’s investigation found 35 data brokers were using the code, 12 of whom soon removed it and allowed their pages to appear in search results.

Today, only eight of those 35 brokers are still hiding their deletion pages, according to another review done by The Markup and CalMatters this week. That includes five major data brokers who came under Senate investigation.

After The Markup and CalMatters published their report, the top Democrat on the Senate Joint Economic Committee minority, New Hampshire Democratic Sen. Maggie Hassan, sent letters to five data brokers questioning them about their practices.

Four of the companies — IQVIA Digital, Comscore, Telesign Corporation and 6sense Insights — engaged with the Senate committee about their practices and agreed to make their pages visible in search, according to a report the committee later released. The report also estimated that consumers have lost more than $20 billion from fraud and identity theft related to broker data breaches. 

In an addendum to their initial findings released last week, the committee said that the fifth company facing questioning, Findem, also belatedly removed its “no-index” code, making its deletion pages visible in search engines. 

One of the data brokers no longer hiding its opt-out page, BrightCheck, has a broken opt-out page and no longer appears on California’s broker registry.

Data brokers that hid opt-out pages from search engines

Of 499 brokers registered with the state of California, The Markup and CalMatters in August 2025 found 35 instructing search engines to ignore pages with instructions on how consumers can remove their data. As of May 2026, only eight had such instructions. 
Chart: Tomas Apodaca · Source: California Privacy Protection Agency 2025 Data Broker Registry

Of the eight brokers still hiding their deletion pages, only one, a company called Fideo, responded to a request for comment about whether they would continue using the code on their pages.

Jason Soni, a spokesperson for Fideo, which uses data for crime and fraud prevention purposes, said the company intentionally “chose not to display the application page itself in Google search results for technical and consumer experience reasons.” Consumers, he said, can make requests starting “from our homepage and public privacy resources, which provide the right context, routing, and instructions for privacy requests,” instead of starting at the application page. 

“Americans deserve a choice over whether their personal data is collected, used, and sold for profit or not,” Hassan said in a statement released alongside the amended report. “Data brokers like Findem have a responsibility to provide that choice with clear, user-friendly opt-out functions and straightforward privacy policies.

Websites break California privacy law at ‘industrial scale,’ survey finds

Tech companies like Google, Facebook and Microsoft are ignoring data controls mandated under California law, researchers say.

The reflection of people walking along a sidewalk is seen on a glass window of a storefront with the Microsoft logo on it. Yellow taxis, trucks and cars can also be seen in the reflection.
Photo by Zamek, VIEWpress via Getty Images

A new audit has found that websites across the internet may be failing to abide by California privacy law, ignoring a requirement to not track visitors who set a privacy control. 

The report, from researchers at webXray, a firm headed by a former Google privacy engineer, said the findings suggest major companies may be simply ignoring the law, and could point to “industrial-scale noncompliance with California requirements.”

The stakes are potentially high. WebXray estimates that if the California Privacy Protection Agency fined all of the websites it found failing to comply with the law, it could result in billions of dollars in penalties. 

“While we don’t have comment on the finding of this specific report,” Tom Kemp, executive director of the privacy protection agency, said in a statement, “we do appreciate that the report brings visibility to the importance of opt out rights.” 

Under California law, businesses are required to respect a signal called the Global Privacy Control. If users navigate the web with the control turned on — either through a setting in the browser or a third-party tool — it tells websites not to sell or share their personal information.

The California Consumer Privacy Act requires businesses to acknowledge the control and to not track people who use it. The state privacy agency has fined companies millions for failing to honor the control, among other violations. 

To understand whether the law is truly being respected, the researchers visited more than 7,000 popular websites from a California internet address. According to the report, major tech companies continued to track users, even with the signal turned on.

Google continued to track users in 86% of cases despite receiving the signal, according to the report. When visitors traveled to the websites while using the signal, the sites still frequently set a cookie from Google to follow those visitors.

Similarly, according to the report, Microsoft failed to honor the signal in 50% of instances. 

The report found that trackers from Facebook parent company Meta don’t just ignore the signal — they fail to check for it at all, leading to tracking 69% of the time despite the signal. 

All of those failures could be remedied with slight changes to the tracking code to respect the signal, the engineers said in the report. 

“They don’t make any substantive effort to comply,” said Tim Libert, founder and chief executive of webXray. 

The report also found that third-party tools that purport to help businesses place advertisements that comply with the law still frequently failed to honor the anti-tracking signal. In one case, a product did not honor those requests more than 90% of the time, the report found. 

The tech companies dispute the idea that they are failing to abide by the law. 

“As outlined in our Privacy Statement, when we receive a GPC signal, we opt the user out of sharing personal data with third parties for personalized advertising, and our advertising systems are designed to reflect that choice,” Courtney Ramirez, a Microsoft spokesperson, said in a statement. “Certain Microsoft cookies are necessary for operational purposes, and may therefore be placed and read even when a GPC signal is detected.” 

Jackie Berté, a spokesperson for Google, said the company complies with the law and that the audit was “based on a fundamental misunderstanding of how our products work.”

A spokesperson for Meta didn’t immediately respond to a request for comment. 

“The idea that I misunderstand anything is a demonstrable falsehood,” Libert said, pointing out his work on cookie policy at Google. 

“I would assert that, when I was there, I knew more about it than anybody else,” he added. 

Background checks to curb dating app violence advance in California legislature

Bill addresses an issue investigated by The Markup last year.

A close-up view of a person holding a white cell phone with both their hands. A ray of light softly illuminates the person's left hand.
Lauren Justice for CalMatters

A California bill to protect people on online dating apps from violence has critics arguing that the measure would put a “scarlet letter” on certain users.

But that’s a feature, not a bug in the proposal. 

The state Senate’s public safety committee this week passed a bill that would require online dating services to run criminal background checks on California users. If the user is a registered sex offender or has been convicted of a violent felony, domestic violence, an assault or a hate crime, the dating service must “place a flag” on the user’s profile to let others know.

Bill author, state Sen. Caroline Menjivar, said that “dating apps have not provided an adequate level of safety for their users.” At the hearing she cited a 2019 Columbia Journalism Investigations survey that found that more than a third of women polled said they were sexually assaulted or raped by someone they met on a dating app.

The Markup last year published an investigation that showed people accused of sexual violence managed to stay on the apps even after victims reported them.

Menjivar, a Van Nuys Democrat, added: “If women, mostly women, continue to be raped or murdered — like another woman (who) was murdered and her body was set on fire last year after a man met her on a dating app — those are the incidents we’re looking to prevent.”

But besides labeling users with a “scarlet letter,” implementing the policy would require dating platforms to collect a significant amount of personal data to avoid misidentifying users, argued Jose Torres, a deputy executive director for the industry group TechNet.

In a rare break with his Democratic colleagues, Sen. Scott Wiener of San Francisco voted against the bill, saying it might have “significant unintended consequences in terms of people’s privacy.” But Wiener’s opposition, along with Republican Sen. Kelly Seyarto of Murrieta, was not enough to stop the bill from advancing out of the six-member committee, according to the Digital Democracy database from CalMatters, of which The Markup is a part. 

With four Democratic lawmakers giving the green light, Menjivar said she plans to amend the measure in response to criticism related to the categories of crime and operational challenges — and that legislators are “going to see a dramatically different bill” when it’s presented to the privacy committee on April 20.

The Markup wins SABEW Award for Best in Business Journalism

The 18-month-long investigation about how Tinder, Hinge, and their corporate owner kept rape under wraps won in the technology reporting category.

Graphic of a screenshot of The Markup's story "Dating App Cover-Up: How Tinder, Hinge, and Their Corporate Owner Keep Rape Under Wraps" next to the text "WINNER," the headline of the story, and the Society for Advancing Business Editing and Writing’s Logo
The Markup

The Markup’s collaborative investigation “Dating App Cover-Up: How Tinder, Hinge, and Their Corporate Owner Keep Rape Under Wraps” has won in the Society for Advancing Business Editing and Writing’s 2025 Best in Business Awards. The story was produced in partnership with the Pulitzer Center’s AI Accountability Network and was copublished with The Guardian and The 19th.

The 18-month-long investigation about how Tinder, Hinge, and their corporate owner kept rape under wraps won in the technology category. The award recognizes excellence in digital journalism covering all aspects of technology, including culture, policy, and economic impact.

Judges said that the collaborative investigation “draws readers into the dark hole of dating apps’ safety practices, along with how the industry’s dominant player turned a blind eye to the predators roaming its products. With urgency and moral clarity, reporters Emily Elena Dugdale and Hanisha Harjani shine a light on how an investor-pressured Match Group concealed accusations of sexual violence on its dating platforms.”

The Markup previously won four SABEW awards in the 2022 Best in Business Awards.

The most recent investigation is based on a review of hundreds of pages of internal company documents, thousands of pages of court records and securities filings, and dozens of interviews with company insiders and sexual violence survivors. In it, reporters Emily Elena Dugdale and Hanisha Harjani reveal that the Match Group, the world’s largest dating app company, had known about violence on its apps for years and failed to disclose that information with the public.

The investigation centers on a Denver cardiologist, who was sentenced to 158 years in prison after being convicted of drugging and/or sexually assaulting 11 women. We found Match Group was aware of his behavior for years — and yet he remained on its apps, swiping and assaulting.

Innovative product testing, led by statistical journalist Natasha Uzcátegui-Liggett, found banned Tinder users, including those reported for sexual assault, can easily rejoin or move to another Match Group dating app, all while keeping most key personal information the same.

Ten months after the investigation, Uzcátegui-Liggett checked if the accounts created by The Markup in February, which had the same name, birthday, and profile photos of banned accounts, had been eventually banned by Match Group or its moderation systems. Every account checked was still in good standing.

The reporting team overcame many obstacles. Survivors were reluctant to speak, potential whistleblowers cited NDAs. In Colorado, a district court judge sought to prevent us from accessing critical records—including testimony from police officers and Tinder and Hinge messages read in open court.

In December, six women who were attacked by the cardiologist filed a lawsuit, accusing Match Group of “accommodating rapists across its products” through “negligence” and a “defective” product. The 54-page complaint extensively cites our investigation. 

In California, state lawmakers said they are preparing legislation to reform the industry. On Feb. 20, 2026, Democratic state senator Caroline Menjivar introduced a bill that would require dating apps to conduct criminal background checks for California users.

Congratulations to all of this year’s SABEW Awards honorees.

It was John Wayne’s political club. Now it’s spending millions on online influence

The Lincoln Media Foundation has spent big to push ‘local’ conservative messaging

A close view shows a person using a laptop displaying a news website with a headline and photo on the screen. Another laptop sits nearby on the desk, and the scene is set in a modern office environment with glass walls and overhead lighting.
Photo via iStock

A conservative organization with decades of influence in California has quietly turned attention, and millions of dollars, to a national initiative of right-leaning news operations, records show. 

The Lincoln Club was established in the early 1960s by a group of California business leaders. Since then, it’s been a quiet but formidable force in state and local politics, pushing right-leaning causes and candidates. 

But in the past few years, an affiliated organization, the Lincoln Media Foundation, has massively increased its incoming revenue as it pushes online content with a conservative slant under the guise of local news in markets around the country. 

According to Internal Revenue Service disclosures, the foundation had a little more than $400,000 in net revenue for the fiscal year ending in 2021, all of it from contributions. 

By the fiscal year ending in 2024, the most recent disclosure available, that revenue had ballooned almost 10 times, to nearly $4 million. 

Lincoln Media Foundation grew rapidly

The foundation's annual revenue in dollars.
Source: Lincoln Media Foundation IRS filings via ProPublica

In the same period, the Lincoln Club itself grew more modestly, not quite doubling its revenue to just over $3 million, according to records.

According to independent research and promotional material produced by the club’s media foundation, its money has gone toward creating a network of websites across the country, with the hopes of influencing the public and swaying voters in key states.  

Many of the sites, first flagged by the researcher Max Read of the Institute for Strategic Dialogue, say they are locally organized, with names like The Angeleno and The Keystone Courier.  CalMatters and The Markup recently explored another site linked to the organization, called the California Courier, using the same name as an unrelated Armenian newspaper. The Courier produces a steady stream of often unattributed articles about political controversies throughout the state and pays Facebook to promote those posts and videos on similar topics. 

Critics say the group is attempting to influence the public with the veneer of local news that fails to offer clear disclosures about the messenger. 

Kevin DeLuca, an assistant professor of political science at Yale University who has studied similar news sites, sometimes called “pink slime” news, told The Markup and CalMatters earlier this year that such sites may not be outright lying. Still, the sites often fall short of traditional journalistic standards, failing to properly attribute stories and funding, or heavily pulling and slanting press releases.

Jim Miller, a labor activist and co-author of a progressive history of San Diego, called the tactic “a menacing example of the use of stealth.” 

“If you don’t think you can win an argument in a transparent debate publicly,” he said, “you try to disguise the messenger as much as you can.”

Neither the club nor the foundation responded to requests for comment or interviews with executives about its work.  

The Lincoln Club

The Lincoln Club of Orange County was established in the 1960s by wealthy local businessmen eager to spread pro-business Republican ideas locally and nationally. Those businessmen donated handsomely to sympathetic candidates and causes. 

The club became a power player in Southern California politics when Republicans had more leverage in the Golden State. The group still boasts online of having counted among its ranks famous California political figures like Richard Nixon and John Wayne. 

A 1972 article in The New York Times described it as a group “made up largely of millionaires” who “boast that, without their efforts and generosity, [Nixon] would not be occupying the White House today.” The Times article described the group as an organization with “many secrets” that shunned publicity but successfully influenced the political scene. 

“I think they were very influential back in the ‘60s and ‘70s,” said Steve Earie, professor emeritus of political science at the University of California, San Diego.

By 1996, as the Los Angeles Times reported at the time, the group’s financial power had waned in the face of internal battles, but the club continued to wield influence. 

The group, according to legal documents, partly funded the 2008 anti-Hillary Clinton documentary that became the subject of the landmark Citizens United Supreme Court decision that opened the door to unlimited spending by corporations and unions on elections. 

In 2012, the group was described as the key architect of Proposition 32, a ballot measure that would have severely curtailed the power of unions in the state by limiting their ability to collect and spend funds for political purposes. The ballot measure ultimately failed. 

Although its light may have dimmed from 50 years ago, the Lincoln Club still exerts influence in California politics.

“If you look on their website, they don’t start it talking about helping businesses, the quality of life,” Earie pointed out. “They talk about ‘preserving the American way of life.’ And that’s as much cultural as it is economic.”

A new strategy

Despite its old Republican roots, the group appears to have moved into a 21st-century online influence strategy with the Lincoln Media Foundation. 

According to a promotional video, the foundation uses targeted web ads to broadcast its message where it can reach key voters in battleground states. 

In one recent LinkedIn post accompanying a video explanation of its work, the group says it acts as a corrective to “material omissions, alternative sets of facts, and outright lies” by the media.

“Our country can’t stay free if we’re not informed with the truth,” the video reads, describing the group as a “megaphone” for “unbiased truth.” The video says it delivers that information through 27 publications in seven states, reaching millions through online advertising.  

In reality, even the video is far from unbiased — a stream of germ-like images of “DEI” and “Russiagate” float by in front of the voiceover.

The launch of the foundation, and the disclosures showing it’s well-funded, suggest a new turn for the decades-old group, from one trying to influence politics through candidates to one willing to broadcast its message directly through online influence.

“Unfortunately, it’s a pretty good strategy,” Miller said. 

Recently, headlines published by websites linked to the group have slammed everyone from Democratic school board officials in Orange County to Pennsylvania Gov. Josh Shapiro, while approving of President Trump’s foreign policy. 

The accompanying stories are then pushed on social media platforms to what the video describes as the most influential two percent of voters in the country and as a key part of the group’s strategy. 

Meta, Facebook’s parent company, has rules against “inauthentic activity” on its platforms, although a spokesperson for the company told The Markup and CalMatters that sites linked to the organization weren’t breaking those rules. 

Lincoln Media Foundation isn’t alone in using the strategy to spread its views. Most famously, a right-leaning group called Metric Media has produced sites across the country pushing a right-wing message. As sites with murky attribution and sourcing practices proliferate, experts worry that artificial intelligence tools like ChatGPT could supercharge their tactics. 

“It’s going to make these pink slime sites even harder for people to know that what they’re reading is not from a human source and not really local investigative journalism,” DeLuca says. 

Even with its rapid growth, the Lincoln Media Foundation is only a slice of the hundreds of millions of dollars spent yearly on similar causes, according to a tally by some observers. Not all of those groups use the language of local news to spread their message.

The strategy works, the foundation’s video promises. 

“It’s ad-delivered truth, inoculating lies, and preserving freedom from the inside out,” the video says.

California colleges spend millions on faulty AI systems: 'The chatbot is outdated’

Community colleges are spending millions on AI-powered chatbots that students say often give inaccurate answers. Many might see upgrades this year.

An illustration in green, red, blue and yellow tones that shows a desktop computer screen with an open window tab that resembles a Pokemon battle scene. At one end of the screen is a pixelated student and at the other is a wolf that represents a chatbot. The illustration includes a bubble text that reads "where can students get free food on campus?" alongside other bubbles of text with red exclamation points.
Illustration by Adriana Heldiz; iStock

California community college districts are spending millions of dollars on artificial intelligence-powered chatbots intended to help students navigate admissions, financial aid and campus services. 

However, they struggle to consistently provide clear and accurate answers, leaving students frustrated and seeking help from others on unofficial social media channels.

In testing by The Markup and CalMatters, they often answered general questions correctly but struggled with more specific ones. East Los Angeles College’s bot couldn’t even correctly name its own president.

Contracts for these chatbots can be pricey and last for years. Three community college districts that responded to a Markup and CalMatters survey reported annual costs ranging from about $151,000 to nearly half a million dollars. At the Los Angeles Community College District, the state’s largest community college system, contracts and amendments approved since 2021 total about $3.8 million through 2029, according to district board documents.

Community college districts that responded to The Markup and CalMatters have contracted with chatbot platforms such as Gravyty and Gecko, which district officials say handle thousands of conversations each month, many outside regular office hours, helping to reduce calls and save students unnecessary trips to campus.

Some of these chatbot platforms rely on manually maintained libraries of frequently asked questions and campus websites to answer questions, which can lead to errors when information is outdated or questions fall outside the system’s database. 

However, officials are working to improve them. Districts like the Santa Monica Community College District have moved to ChatGPT-integrated AI systems that scrape the college’s website to generate answers, which officials say seem more reliable. In the Los Angeles district, officials say they plan to transition to a new AI chatbot platform as early as late spring.

Looking for answers

Improvements to the chatbot couldn’t come soon enough for students like Pablo Aguirre, a computer science major at East Los Angeles College and an information technology intern at the Los Angeles college district office.

Aguirre mostly avoids the chatbot himself because, he said, it might provide unreliable or outdated information. He recalled using the bot to find financial aid information, but said he gave up after it kept asking him questions instead of giving him a clear answer.

“I just didn’t find it as useful,” Aguirre said. He usually turns to Google, social media platforms like Reddit and the college’s website when looking for answers.

“Online, some pages don’t work,” Aguirre said, recalling a 404 error message on the college’s website. Even when pages load, he said, it can be difficult to find the right one, such as when he was trying to figure out where to sign up for Extended Opportunity Programs and Services, a state-funded program that supports disadvantaged students. “That’s where I just jump on Reddit,” he said.

Students walking onto campus at Fresno City College on Oct. 3, 2022. Photo by Larry Valenzuela, CalMatters/CatchLight Local
Students walking onto campus at Fresno City College on Oct. 3, 2022.
Larry Valenzuela, CalMatters/CatchLight Local

Aguirre’s experience isn’t unique. Reanna Carlson, a commercial music major at Fresno City College and student government vice president, said her college’s chatbot, dubbed Sam the Ram after its mascot, repeatedly gave her unclear or incorrect answers to basic questions about campus services. Her district, the State Center Community College District, has a nearly $870,000, three-year contract for Gravyty, formerly Ocelot, through June 20, 2026, according to district board documents. Officials pointed out that the contract comes with other services, including tools that let staff engage in live chats or send text messages to students.

“I think the chatbot is outdated and can’t navigate the services we provide on campus effectively,” Carlson said. “I don’t think it’s the most beneficial option when it comes to asking questions.”

Oddly, Carlson got accurate information on the availability of free food at her campus’ Ram Pantry only when accidentally adding a typo to her query. Repeated Markup and CalMatters testing confirmed the same outcome, though the bot sometimes lists links that include the food pantry after clicking an adjacent “sources” button.

“If it weren’t for the amazing staff on campus that constantly remind students of our services, I’d be lost,” Carlson said.

A screenshot of a conversation with a college chatbot.
Screenshots via Fresno City College website

Testing chatbots

When The Markup and CalMatters tested community college chatbots, they generally returned quick, accurate responses to common questions but were less consistent with more specific ones.

For example, when asked, “Who is the current president of ELAC?” East Los Angeles College’s chatbot incorrectly named Alberto Román, who left the position last year to become the district’s chancellor. In another test, when asked, “What is the financial aid office’s current schedule?” the bot provided incorrect hours and dates.

East Los Angeles College campus in Monterey Park on March 14, 2024.
Jules Hotz for CalMatters

East Los Angeles College’s chatbot claims to support several languages, including English, Spanish, Chinese and Vietnamese. But The Markup and CalMatters found inconsistencies when asking it in Spanish, “Do I need a Social Security number to enroll?” Instead of answering the question, the system directed users to visit the registrar’s office to update their Social Security number. When asked the same question in English, the bot pivoted to discussing financial aid.

Fresno City College’s chatbot, powered by the same AI provider as East Los Angeles College’s system, Gravyty, showed similar problems when asked whether a Social Security number is required to enroll. It also often failed to direct students to the correct offices and, in some cases, listed incorrect locations and hours.

Concerns with chatbots have surfaced elsewhere. In New York City, reporting by The Markup and THE CITY found that a city-run AI chatbot provided guidance that could lead to illegal behavior, prompting Mayor Zohran Mamdani to terminate it in February.

'Good answers with fewer errors'

Santa Monica College’s chatbot, powered by Gecko, was more successful in answering most questions. The single-college district uses a ChatGPT-integrated chatbot that scans the college’s website, which staff regularly update and monitor. The district has contracted with Gecko since 2019 and renewed its annual contract for the tool late last year for $57,000, according to district board documents. It initially showed a major hiccup: when asked about mental health counseling, the bot did not mention the campus’ Center for Wellness and Wellbeing. It does now.

A screenshot of a conversation with a college chatbot.
Screenshots via Santa Monica College website

District officials say chatbots’ problems stem from how the tools are configured and the information they draw from, rather than the technology itself.

The Los Angeles district originally adopted its chatbot through Ocelot, which later merged with Gravyty The same chatbot platform is also used on the California Student Aid Commission website.

Betsy Regalado, one of the district’s associate vice chancellors, said the current system relies on a manually maintained library of frequently asked questions that staff at each of the district’s nine colleges help maintain and review at least once or twice a year for accuracy. She added that chatbots are primarily geared for the public rather than enrolled students, who can access more detailed personal information through their campus portal.

“The current chatbot that we have uses a library of questions. If you don’t have that question in that library, then those poor people don’t get an answer or they won’t get an accurate answer,” Regalado said.

She said the district plans to transition all nine colleges to Gravyty’s platform as early as late spring at no additional cost under its existing contract, which runs through 2029. The new system will use AI to scrape college and external websites to generate responses.

“We’re ready for the modernization of (the chatbot) and the change to generative AI. That is the new world out there,” Regalado said.

A Santa Monica College sign is viewed just over bushes, with a row of palm trees behind it, in front of a building on a college campus.
Santa Monica College in Santa Monica on April 16, 2025.
Alisha Jucevic for CalMatters

Santa Monica College’s chatbot similarly initially relied on a manually loaded library of common questions and answers before transitioning to its fully AI system, according to Esau Tovar, the college’s dean of enrollment services. In an email, he said the bot “was never designed to address all aspects of the student journey,” but to answer general questions from students.

Tovar said the bot draws responses from the college’s website, meaning accuracy depends on how current and complete that information is. As a result, the college prioritizes keeping its website up to date so the bot provides “good answers with fewer errors” rather than “great answers with potentially more errors.”

Widely used, cautiously trusted

Acknowledging limitations, community college districts justify the costs by pointing to heavy student use, which would cost significantly more if performed by call center staff around the clock.

Regalado said the Los Angeles district colleges average 5,000 to 7,000 interactions per month. Other districts reported similar monthly use, including 5,000 interactions at the State Center Community College District, which includes campuses in Fresno and nearby counties, and 4,000 conversations at Santa Monica College. Regalado said that as long as the chatbot remains heavily used, her district would continue to support it.

Tovar said the chatbot provides 24-hour support regardless of time zone or location, which he said is helpful for international students when they are out of the country. He said that answering the tens of thousands of questions the chatbots receive around the clock would cost significantly more if handled by staff.

“Every technology has a cost. We would simply not be able to assist all students if they could only reach us using traditional methods,” Tovar said.

But high usage and expanded access do not always translate into trust, especially when students need precise answers to delicate topics.

Bryan Hartanto, a civil engineering major at Santa Monica College from Indonesia, said the college’s newer chatbot system is smoother and can be a useful starting point, especially for students more comfortable communicating in languages other than English. But as an international student he worries that following inaccurate guidance could jeopardize his visa status.

“Maintaining status as an international student right now is very, very sensitive,” Hartanto said. “I would still rely on human or email communication.”

Martin Romero is a contributor with the College Journalism Network, a collaboration between CalMatters and student journalists from across California. CalMatters higher education coverage is supported by a grant from the College Futures Foundation.

He saw an abandoned trailer. Then, he uncovered a surveillance network on California's border

Southern California residents are noticing new license plate readers that appear to be operated by the Border Patrol. Some have had confusing encounters with agents.

A roadside device mounted on a small trailer sits on the shoulder beside a two-lane road as a blurred van drives past, with utility poles, trees, and rocky hills in the background under a clear sky.
An automated license plate reader sits along Old Highway 80 near Boulevard in the Jacumba Hot Springs area of San Diego on Feb. 7, 2026. Zoë Meyers for CalMatters

On a cracked two-lane road on the eastern edge of San Diego County, James Cordero eased his Jeep onto the shoulder after something caught his eye. It looked like an abandoned trailer. Inside he found a hidden camera feeding a vast surveillance network that logs the license plate of every driver passing through this stretch of remote backcountry between San Diego and the Arizona state line. 

Cordero, 44, has found dozens of these cameras hidden in trailers and construction barrels on border roads around San Diego and Imperial counties: one on Old Highway 80 near Jacumba Hot Springs; another outside the Golden Acorn Casino in Campo; another along Interstate 8 toward In-Ko-Pah Gorge. 

They started showing up after California granted permits to the Border Patrol and other federal agencies to place license plate readers on state highways in the last months of the Biden administration. Now as many as 40 are feeding information into Trump administration databases as the Democratic-led state chafes over the federal government’s massive deportation program.

The cameras are raising concerns with privacy experts, civil liberties advocates and humanitarian aid workers who say California should not be supporting the surveillance and data-collection program, which they view as an unwarranted government intrusion into the lives of Americans who’ve committed no crime. Moreover, they say the program conflicts with state law. 

Supporters say the devices allow law enforcement to quickly identify and locate people they suspect of serious crimes. They also argue the cameras help agencies spot patterns in drug and human trafficking, and could be used to help locate missing persons, such as children or other vulnerable people. 

 “If you’re not doing anything illegal, why worry about it?” said long-time Jacumba resident Allen Stanks, 70.   

“Everyone is talking about privacy, OK. Stop putting everything on Facebook. ‘Here’s a picture of my food.’ Who cares?” said Stanks.  

Some locals, however, suspect the cameras are behind some unusual encounters they’ve had in recent months with officers from Border Patrol and its parent agency, Customs and Border Protection. In one case agents questioned a grandmother – a lawful permanent resident  – about why she went to a casino, according to her grandson. 

Cordero has a different concern. On his days off, he leads volunteers into the far reaches of the county, leaving water, food and clothing for migrants. He fears his colleagues could be detained by agents.

“I’m not so much worried about myself, but I’m worried about a lot of our volunteers that come out,” said Cordero. “I don’t want them to have to deal with any of the nonsense of being tracked or being pulled over and questioned.” 

A person wearing a baseball cap and plaid shirt stands with arms crossed beside a rusted metal post outdoors, with shrubs and a clear blue sky in the background.
James Cordero, water drop coordinator for Al Otro Lado, in the Jacumba Hot Springs area of San Diego on Feb. 7, 2026. Cordero is concerned about the use of new automated license plate readers along the U.S.-Mexico border in California.
Zoë Meyers for CalMatters

He has good reason to be nervous. During the first Trump administration, federal officials prosecuted volunteers from the humanitarian group “No More Deaths” for leaving water and supplies for migrants in the Arizona desert. The volunteers faced charges, including “abandonment of property” and felony harboring, though the convictions for some were later overturned.

Border Patrol provides little information about its use of license plate readers on its website. In 2020, the Department of Homeland Security issued a report that describes the technology in general, but doesn’t specify where it’s being used. The Markup and CalMatters reached out to Border Patrol and Homeland Security officials for comment, but did not receive a response. 

“There’s no transparency, that’s the worst part,” Cordero said. 

The Homeland Security report says some readers are capturing license plate numbers, as well as the make and model of the vehicle, the state the vehicle is registered in, the camera owner and type, the GPS coordinates for where the image was taken, and the date and time of the capture. 

The “technology may also capture (within the image) the environment surrounding a vehicle, which may include drivers and passengers,” the report states. It also says feds can access license plate readers operated by commercial vendors. 

Mapping hidden cameras

Earlier this month, the Electronic Frontier Foundation and a coalition of 30 organizations sent a letter to Gov. Gavin Newsom and the California Department of Transportation urging them to revoke state permits and remove the covert readers operated by federal agencies like Customs and Border Protection and the Drug Enforcement Agency along California border highways.

The San Francisco-based privacy and civil rights advocacy organization, also known as EFF, mapped out more than 40 hidden license plate readers in Southern California, most of them along border roadways. It contends the devices bypass a 2016 state law that spells out how law enforcement agencies can use automated license plate readers, which are often referred to as ALPRs.

“By allowing Border Patrol and the DEA to put license plate readers along the border, they’re essentially bypassing the protections under (California law),” said Dave Maass, the director of investigations for EFF. “That is a backdoor around it.”

Maass said he believes Cordero’s concerns about the agency surveilling humanitarian volunteers may be valid. 

“They claim they might be looking for smugglers or they might be looking for cartel members, but that’s not who they’re collecting data on,” said Maass. “(The program) is primarily collecting data on people who live in the region. 

Maass said there’s no way to be certain which agency is installing each camera, but his organization checked with all other agencies operating in the area, such as the San Diego and Imperial sheriff’s departments, the California Highway Patrol, and Cal Fire, among others.

Close-up of a camera unit mounted inside a recessed compartment on a white roadside trailer, with rocky hills and vegetation blurred in the background.
A portable roadside camera trailer sits on the shoulder beside a highway stretching through low, brush-covered hills, with a traffic cone placed near its hitch and trucks visible in the distance.
First: An automated license plate reader sits along Old Highway 80 outside the Jacumba Hot Springs area of San Diego on Feb. 7, 2026. Last: An automated license plate reader sits along Interstate 8 in the southeastern area of San Diego County on Feb. 7, 2026. Photos by Zoë Meyers for CalMatters
A two-lane road curves through a tree-lined valley toward sunlit mountains, with long evening shadows stretching across the landscape.
Automated license plate readers have been placed along Old Highway 80 in the Campo community of San Diego County, on Feb. 7, 2026.
Zoë Meyers for CalMatters

The camera models currently installed on state highways in the border region are the same as ones the Border Patrol purchased in large amounts, according to Maass. Records obtained from Caltrans by EFF from 2016 appear to show Drug and Enforcement Administration and Border Patrol requesting permits to install the same devices in other parts of San Diego County, according to Maass. 

Customs and Border Protection did not respond to a request for comment. The governor’s office did not comment. The Drug Enforcement Agency also did not respond to a request for comment. 

Caltrans approves ALPR requests

By day, Cordero works in water-damage restoration, the crews residents call after floods and burst pipes. Comfortable with emergencies, he’s the type of guy you’d hope to run into if your car broke down in the middle of nowhere. 

“People are literally dying out here,” Cordero says of his volunteer work, done through the nonprofit Al Otro Lado, a legal services organization that also provides humanitarian support to refugees, migrants and deportees on both sides of the U.S.-Mexico border. “All we’re trying to do is prevent people from dying.” 

In response to questions from The Markup and CalMatters, a spokesperson for Caltrans provided a written statement that the state agency has approved eight permits for license plate readers from federal agencies, like Customs and Border Protection and the Drug Enforcement Administration, to be stationed in state highway rights-of-way.

“Caltrans does not operate, manage, or determine the specific use of technology or equipment installed by permit holders, nor does it have access to any of the collected data,” the statement read in part. 

Caltrans said federal immigration agencies haven’t requested permits for the cameras since June 2024. They did not say how long a permit lasts. Between 2015 and 2024, their records indicate Customs and Border Protection and the Drug Enforcement Administration requested 14 permit applications for “law enforcement surveillance devices.” Of the 14, eight were approved, four were cancelled by the applicants and two did not result in projects in state right-of-way, the agency said.

In California, license plates are tracked not only by the federal government and law enforcement, but also by schools and businesses, including some Home Depots and malls. While schools and businesses may not agree to pass that information on to the federal government, local police with access to those cameras may do so.

California law prevents state and local agencies from sharing license plate data with out-of-state entities, including federal agencies involved in immigration enforcement. A Markup and CalMatters investigation in June 2025 revealed that southern California law enforcement agencies, including sheriff’s departments in San Diego and Orange counties, haveshared automated license plate reader data with federal agencies in violation of state law.

A person wearing a cap, sunglasses, and a plaid shirt crouches beside a roadside trailer device, holding a phone up to photograph or inspect its rear panel, with brush and dirt terrain in the background.
James Cordero, a water drop coordinator for Al Otro Lado, photographs the camera on an automated license plate reader outside the Jacumba Hot Springs area of San Diego on Feb. 7, 2026.
Zoë Meyers for CalMatters

Newsom vetoed a bill to strengthen California license plate reader law last fall. Two days later, Attorney General Rob Bonta filed a lawsuit against the city of El Cajon for multiple violations ofthe license plate sharing prohibition. Since 2024, the attorney general’s office has sent letters to 18 law enforcement agencies, including the Imperial County Sheriff’s Office, the San Diego Police Department, and the El Centro Police Department.

Local agencies continue to share license plate data with federal immigration authorities, and not just along the border. The San Pablo Police Department in Northern California, one of the law enforcement agencies that received letters from the attorney general’s office, shared license plate data with the  Border Patrol as recently as last month, according to records obtained by Oakland Privacy head of research Mike Katz-Lacabe. Some cameras are easy to spot, but Katz-Lacabe said that local police have concealed cameras that scan license plates for more than a decade, sometimes behind the grill of police cruisers or inside speed limit trailers or in a fake saguaro cactus.

“This has been the practice for years,” he said.

On a recent Saturday, Cordero was dressed for the remote border terrain – flannel, hiking boots, a San Diego Padres cap pulled low against the sun. His dirt-caked Jeep is built for places roads don’t go. On this particular weekend, supplies at one of the drop sites had already been used, indicating people may be crossing in the area. 

Cordero has gotten good at finding stuff out here. In the remote Ocotillo washes, where the scrubs claw at people’s shins, he recently found what he believes to be the remains of a human finger.

A year earlier, Cordero found a phone contact list next to human remains. He and his wife, Jacqueline Arellano, were able to use the phone list to notify the person’s family in Arizona about where their missing loved one fell.

That’s why when, months ago, he first saw the abandoned trailer along the side of the road on Old Highway 80, he had to stop to take a closer look. 

“It took me passing by a few times before I realized what it was,” said Cordero. 

Pulling over grandma

An Associated Press investigation published in November revealed that Border Patrol had hidden license plate readers in ordinary traffic safety equipment. The data collected by the agency’s plate readers was fed into a predictive intelligence program monitoring millions of American drivers nationwide to identify and detain people whose travel patterns the algorithm deemed suspicious, according to the AP’s investigation.

Sergio Ojeda, a community organizer with the mutual aid group Imperial Valley Equity and Justice said CBP apparently believed his grandmother’s driving patterns were suspicious because they interrogated her about the amount of time she spends at local casinos in the area. 

“She was outraged about it,” said Ojeda. His grandmother, a resident of Imperial Valley with legal status, was crossing the border when agents asked her about her trips to casinos. 

“She asked them back, ‘Is something wrong with that? Am I not supposed to be doing that or why are you questioning me about this?’ and they were like “Oh, no, it just seems suspicious,” Ojeda recounted. 

Ojeda said he was equally concerned, and he doesn’t enjoy the feeling of being watched just because he lives near the border. “It’s how I feel every day,” he said. “Driving around, I joke with my co-workers: ‘Which chapter of 1984 is this?’” 

Following Markup investigation, Congress finds data brokers cost consumers tens of billions of dollars

A congressional investigation estimates broker breaches have cost consumers $20 billion in identity theft. Major brokers now promise to make it easier to opt out of their databases.

Sen. Maggie Hassan kicked off an investigation into data brokers in response to CalMatters reporting. Hassan speaks during a Senate Finance Committee on Capitol Hill, March 14, 2025. Ben Curtis, AP Photo

Breaches at data brokers have cost American consumers more than $20 billion, Congress’s Joint Economic Committee revealed Friday as part of an investigation triggered by The Markup and CalMatters. 

The estimated losses stem from identity theft linked to just four recent data breaches involving major brokers, the committee said in a report. 

Released by the committee’s Democratic minority, the document repeatedly cited reporting into data brokers from The Markup and CalMatters, done in collaboration with WIRED. 

The committee followed up directly on the Markup and CalMatters’ reporting, which in August showed how data brokers were hiding from search engines legally-mandated pages where Californians can request that the brokers delete or stop selling their data. 

Shortly after that story was published, New Hampshire Democratic Sen. Maggie Hassan, ranking member of the committee, sent a letter pressing some brokers to explain their practices. In response, the report revealed, four major data brokers engaged with congressional staff and changed their practices to make it easier for consumers to control the use of their data. 

Data brokers and the ‘no-index’ tag

Data brokers, as defined in the California law that requires brokers to provide consumers the so-called “opt out” pages, are companies that gather data on consumers, then sell that data to other companies who do not have a direct relationship with the consumers. Typically, companies buy such information from data brokers for marketing purposes.

Brokers can gather the data from information like public records, or more invasive methods like tracking online activity. Though brokers hold potentially sensitive information on consumers, many Americans are unaware they exist. 

Under the California law, data brokers that reach a certain size are required to register and provide a clear way for consumers to request that their information be removed, that it not be sold or that they get access to it. But The Markup and CalMatters’ August story examined how several data brokers used code called the “no-index” tag on pages where consumers could exercise their right to opt out. 

The tag is used to tell search engines not to index the page, meaning the information may not be returned in search results. The story noted that this created a barrier for consumers looking to block brokers from using their data. Many of the data brokers quickly removed the tag as the story was published. 

In response to that initial reporting, Hassan independently contacted five major brokers, asking for more information about their practices. Only one registered broker, called Findem, declined to engage with staff or change its practices, the report said. 

“Following Ranking Member Hassan’s requests, most companies took action to make their opt out and other privacy pages more visible for individuals, including by removing ‘no index’ code, adding opt-out links in more prominent locations, and publishing blog content that explains how consumers can exercise their privacy rights,” the report reads. “Ranking Member Hassan welcomes these actions as supporting greater protection for consumers against scams and other harms.”

Billions in losses

The report goes on to estimate the potential losses incurred by consumers because of recent data broker breaches, pegging the number at $20.8 billion. 

Congressional staff found that hundreds of millions of people were exposed by just four major data broker breaches in the last 10 years. The breaches counted were a 2017 Equifax incident, impacting 147 million people, as well as others involving Exactis in 2018, 230 million people, National Public in 2023, 270 million people and TransUnion in 2025, 4 million people. 

Using estimates of the number of people who experience identity theft after breaches, as well as an assumed median loss of $200 from thefts, the report arrived at the nearly $21 billion figure. 

The report calls for action to prevent such losses in the future, including by filling gaps exposed by The Markup and CalMatters’ reporting on brokers. 

“The Committee’s findings underscore the need for clear, easy access to opt-out options and more rigorous oversight within the data broker industry. Especially given the Committee’s calculation that U.S. residents have lost more than $20 billion in recent data breaches, additional action is needed to protect Americans from scams connected to data brokers,” the report reads. “At a minimum, opt-out options should be easy to locate and use.” 

A new state website allows Californians to remove their personal information from hundreds of brokers at once. The Markup and CalMatters have a guide to using the website here.

California tried to protect students’ data. Tech companies found loopholes

A legislative battle is under way over gaps that allow companies to collect and sell students’ personal information.

A young student sits at a table, headphones on, looking at a computer screen in a classroom. The students head peals over the top of the screen as their attention is focused on the computer.
Students in a classroom in Sacramento on May 11, 2022. Miguel Gutierrez Jr., CalMatters

For every aspect of a student’s life, there’s a tech company trying to digitize it. Inside the classroom, online tools proctor exams, create flashcards and submit assignments. Outside, technology coordinates school sports, helps bus drivers find the right route and maintains students’ health records. 

California has a number of laws aimed at protecting children’s data privacy, but those laws have exceptions that allow many tech companies to continue packaging and selling students’ personal information.

This year, Assemblymember Dawn Addis, a San Luis Obispo Democrat, is carrying a high-profile state bill that would add new protections for students. She says it’s important, especially as the Trump admin is trying to collect data about California residents’ immigration status, gender identity, and their use of certain public benefits.

Historically, California has been a leader in data privacy. In 2014, California passed a landmark student privacy law that prohibited technology companies from selling students’ data, targeting students in advertising, or disclosing their personal information. Then in 2018, the state passed another unprecedented bill that required all companies give California users certain privacy rights, such as a chance to opt out of data collection and delete some of their information. 

But as technology evolved and proliferated, privacy laws repeatedly fell short in protecting California’s students — at the same time that the federal government has tried to collect increasing amounts of personal information, Addis said.   

Her bill would restrict how AI companies use student data and create new data protections for college students. Some of Sacramento’s most powerful players are paying close attention to the measure, including the California Labor Federation, which supports the bill, and the California Chamber of Commerce, which opposes it. Combined, these two groups spent nearly $8 million on campaign donations to state legislators or other political activities in 2024, according to the CalMatters Digital Democracy database. TechNet, a trade association that represents many of the most powerful tech companies, also opposes the bill. 

The proposal, Assembly Bill 1159, would close certain loopholes in the state’s 2014 education privacy law, but experts say it may not be enough to prevent companies from selling students’ data. 

A privacy expert struggles to keep her information private

Jen King is a privacy and data policy fellow at Stanford’s institute for AI, where she studies the tricks that companies use to gather users’ data and prevent them from opting out, sometimes known as “dark patterns.” In her personal life, she’s vigilant about avoiding online data tracking and maintains a landline in her Bay Area home to avoid giving out her cell phone number. 

King doesn’t want her children’s information available online or for any company to sell, though sometimes it happens before she can stop it. 

In the fall, King got an email about a platform called TeamSnap, which her 12-year-old son’s cross country coaches were using to manage the team’s roster. The company wanted her information, including her name, date of birth, gender, email address, and phone number. Once she logged in to the platform, she could see some of her son’s information, such as his name, email, and date of birth, were already listed. Photos and personal information from all of her son’s teammates were also available for her to see. 

“I was super irritated,” she said. “You don’t need my birth date — I’m a freaking parent.” She acknowledged some personal information could be useful for a coach but said that other questions seem designed to help the platform sell information to data brokers and ultimately, to advertisers. 

Her 17-year-old son’s data is also on TeamSnap, she later learned, because his robotics team uses it. This month, when King tried to show The Markup and CalMatters her TeamSnap account, a pop-up appeared, asking her if the company could track her activity across other apps and websites.

Federal law requires companies to get parental consent before knowingly collecting or selling data from children 12 and under, but once a child turns 13, their data is generally treated much like an adult’s information, especially when that child is interacting with tech platforms outside of school. TeamSnap’s privacy policy says it doesn’t knowingly collect personal information about users under 13 “without express parental consent,” though it says in some cases a team or organization may provide information on behalf of the child. 

The policy also says that TeamSnap has “not sold the personal information of any consumer for monetary consideration” in the last 12 months, but that its “use of cookies and other tracking technologies may be considered a sale of personal information under the CCPA (California privacy law).” Information sold to advertisers and marketers included users’ names, contact information, purchase history and geolocation, the policy says.

California privacy law specifically requires certain large for-profit companies to get consent to collect data from anyone under 16. Often, consent happens when a user first opens a website and a pop-up appears, asking if the website can sell your data or track your cookies. 

If a teacher, coach, or other authority figure tells a student that they have to use a website or an app, then the student cannot realistically opt out, King said. They may be too young to understand how to opt out, she added. “Most 15-, 16-year-olds don’t have any idea what this is about.” 

Even older college students may have little agency in the technology they use, especially if it’s required for class or residential life. At Stanford, for example, King said her undergraduate students are often required to create Facebook accounts for student groups. 

The same is true for parents. King said she reluctantly gave TeamSnap her personal information, including her name, email, date of birth, and the landline number for her home, because it was the only way to get updates about her son’s team.

How companies get around California’s education privacy laws

In 2014, California became the first state in the country to regulate education technology companies directly, but being first comes with its drawbacks. “We didn’t have examples of what best practice was,” said Amelia Vance, the president of the Public Interest Privacy Center, a nonprofit organization. The law only applies to products that “primarily” serve K-12 schools and that are designed and marketed for students. 

Many tech companies argue that their products aren’t primarily intended for students or at least that they were not designed or marketed that way. The language-learning app DuoLingo, for example, has a version for schools, but the app is also popular for adults. Apps or technologies serving extracurricular programs or sports teams can claim they weren’t designed and marketed for the classroom, or that their use isn’t mandatory, said Vance. “You have this sort of black hole where there haven’t been protections.” 

Addis’ bill expands the number of education technology companies that fall under the state’s student privacy laws, but the language is murky when it comes to apps or online services used outside of class. 

In the case of TeamSnap, Addis’ communications director Alexis Garcia-Arrazola said the company would “most likely” fall under the scope of the bill if its technology is marketed to schools, if schools direct students to use it, and if the sports team is sponsored by the school.  

Public records show that Piedmont Unified School District in Alameda County, Tamalpais Union High School District in Marin County, and Santa Monica Malibu Unified School District all purchased versions of TeamSnap, but only the Santa Monica Malibu district responded to questions about any privacy restriction imposed on the company. Brandyi Phillips, the chief communications officer for the Santa Monica Malibu schools, said the district has an annual subscription with TeamSnap, which is only available to sports staff and parents. She said there’s an agreement with the company “to protect District information and to prevent unauthorized access” but did not clarify if that agreement prevents the district from selling students’ information. 

Berkeley Unified School District, where King’s children attend school, did not respond to questions about any contracts, purchase orders or agreements with TeamSnap. 

Locally, school districts and colleges have the power to negotiate the privacy terms of any contract they make with a technology company, but many websites and apps offer free versions that a teacher or coach might recommend without getting formal approval from their district. 

Last year, the California State University system signed a nearly $17 million contract with Open AI, the company that operates ChatGPT, including an agreement that the company will not train its models on student data. Advocates for Addis’ bill say the same privacy restrictions should apply to any AI company with access to California student data, regardless of whether the company has an agreement with the student’s school district or college.

Are privacy laws getting stricter or looser?

Addis’ bill comes as privacy laws in California and across the country are in flux. In 2020, California voters approved a proposition to create a new state agency to enforce data privacy rules and regulate the businesses that collect data. Advocates for the proposition contributed over $6.7 million to the campaign, compared to just over $50,000 contributed by the opposition, according to state data. The state agency that the proposition formed, now known as CalPrivacy, released new rules this year, restricting the use of automated decision-making technology, such as the use of AI to make admissions or hiring decisions. Those rules were originally stricter but businesses, lawmakers and Gov. Gavin Newsom pressured the CalPrivacy board to water them down.

In Washington D.C., Congress is considering changing federal law to limit how companies interact with children under 17. Separately, Congress is considering a bill that would require social media companies to prevent and mitigate children’s sexual exploitation, bullying, and self-harm. California Attorney General Rob Bonta is concerned that one version of the social media bill contains language that could erode existing protections in California law.

Bonta’s office is responsible for enforcing many of the state’s existing privacy laws. In November, he said the state worked with Connecticut and New York to reach $5.1 million in settlements against Illuminate, an education technology company that uses data to track and evaluate students’ progress, such as their testing scores and developmental milestones. The company had a data breach, exposing “sensitive information” from over 434,000 California students, the state attorney general’s office said in a statement.

It was the first time California successfully went after a company for violating the state’s landmark 2014 education privacy law.

To increase enforcement, Addis’ bill contains a new provision — the right for students and parents to sue tech companies in certain cases for privacy violations. Business and technology groups have opposed the bill, arguing that the new regulations and the right to sue would stifle investment in AI-powered learning tools.

King said that giving consumers the right to sue is often the only way to increase enforcement. Otherwise, the onus is on individual consumers to find concerning practices and try to opt out. 

Despite being an expert in data privacy, King said that she struggled at first to figure out how to delete her TeamSnap account, only later to discover that she needed to send an email to the company. She laughed at the irony, since it’s these kinds of dark patterns in user design that fuel part of her research. 

In academia, the strategy of trapping customers is sometimes called the “roach motel,” she explained, a reference to a popular television ad from the late 1970s for a cockroach trap. 

“You can check in,” she said, “but you can never check out.” 

Blacklight, our privacy inspector tool, now tracks X and TikTok pixels

We’ve updated Blacklight, our popular privacy tool, to check for TikTok and X trackers.

Illustration of the Blacklight logo, with a purple swish behind it. On the bottom right hand corner is a star-shaped sticker with the words "UPDATE" and a wrench icon.
Gabriel Hongsdusit

Since 2020, readers have used Blacklight, our pioneering website privacy inspector tool, to run more than 18 million scans. Previously, Blacklight detected tracking pixels from Google and Meta. Today, we’re announcing that it can scan for two more digital trackers: TikTok and X pixels.

Scan a website

A tracking pixel is a small piece of code added to a website that sends information about the site’s users to the platform that operates the pixel. That can include details of a user’s activities, such as their browsing activity, purchases and searches. A website that embeds a pixel often does so to inform its advertising campaigns on the platform that create the pixel. When its pixel is embedded across many websites, the platform can compile a user’s data to build a detailed profile of their interests, behavior and other personal information. These profiles allow other businesses to buy ads from the platform to target categories of users — though this data can also be used for other purposes.

When you look up a website in Blacklight, it will now report if it finds the TikTok pixel or X pixel. More detailed information about the specific data being passed through pixels is also available by clicking on “Learn more” in the top right of the results, then clicking the link to “download an archive.”

To develop these new features, we partnered with a group of computer science students in Brandeis University’s Capstone in Software Engineering course. These students – Yiyou “Felix” Fan, Jiawen “Zena” Hu, Hengye Li, Hongchen “Steven” Yang and Yiquan “Frank” Zhang – researched and developed the features with the support of our product team.

Blacklight’s pixel detection features have already powered our Pixel Hunt investigations, which revealed that sensitive personal user information was being shared from government websites with Meta and Google, leading to lawsuits, removal of pixels from sites and increased government scrutiny. These new features give a fuller picture of the digital privacy landscape by exposing tracking pixels from two more companies.

We hope these new features will help you better understand what happens to your data as you navigate the internet. While Blacklight can’t say exactly what companies like TikTok and X do with our data, it can provide a starting point for deeper investigation into how that data is stored, shared and used across the web.

Do you have questions, suggestions or need help understanding your Blacklight results? You can always reach us at blacklight@themarkup.org

Mamdani to kill the NYC AI chatbot we caught telling businesses to break the law

New York mayor says terminating the ‘unusable’ bot will help close a budget gap

A person in a dark coat and light blue tie speaks at a wooden podium outdoors, smiling slightly as a microphone stands in front of them, with the pale yellow facade and white railing of a government building blurred in the background.
New York City Mayor Zohran Mamdani speaks at a press conference at Gracie Mansion in New York City, on Jan. 12, 2026. Michael M. Santiago, Getty Images

This article is co-reported with THE CITY, a non-profit newsroom that serves the people of New York. Sign up for its newsletter, The Scoop.

In a press conference this week on New York City’s $12 billion budget gap, Mayor Zohran Mamdani zeroed in on the previous administration’s artificial intelligence chatbot as one of “a number of different things we’re going to pursue for savings.”

The chatbot, which was released by the Eric Adams administration in fall of 2023, was meant to provide business owners with an accessible way to check city rules and regulations. But as first documented by The Markup and THE CITY, the bot provided answers that, if followed, would lead to illegal behavior by businesses, like taking a cut of employees’ tips.

A spokesperson for the mayor, Dora Pekec, confirmed in a text message that the new administration plans to take down the chatbot. She said a member of the Mamdani transition team had seen reporting on the bot from The Markup and THE CITY and presented it to the mayor as a possible place to save funds. 

At the press conference, Mamdani blamed Adams for the budget shortfall, saying he had been handed “a poisoned chalice.” To close the deficit, he said he would raise taxes on the wealthy and corporations and look “under the hood” of the city’s budget for potential savings. 

When pressed by reporters on what he might cut, he singled out the chatbot.

“The previous administration had an AI chatbot that was functionally unusable,” Mamdani said. “It was costing the administration around half a million dollars. That, in and of itself, is not something that can bridge this kind of a gap, but it’s an indication of the ways in which money has been spent while refusing to account for the actual costs of what these programs are.”

The bot, built using Microsoft’s cloud computing platform, was part of an ambitious overhaul of digital services in New York called MyCity. The project was meant to streamline access to government but was criticized for relying on outside contractors

It wasn’t clear how much it cost to maintain the chatbot. Just building the bot’s foundations reportedly cost nearly $600,000, close to the figure Mamdani provided. Pekec said they didn’t yet have a date for taking down the bot. 

A broken bot

Testing by The Markup and THE CITY in 2024 showed that, despite promises from the Adams administration, the chatbot would confidently provide incorrect and potentially harmful information to visitors, even on high-stakes topics.

When asked about housing policy, for example, the bot suggested landlords could discriminate against tenants with Section 8 vouchers. Despite being an intended resource for business owners, the bot didn’t know the minimum wage, and told users it was fine to refuse to accept cash for payment despite a city law to the contrary, enacted in 2020.

After The Markup and THE CITY’s initial report was published, readers continued peppering the bot with sometimes farcical questions, which it continued failing to answer properly. The Adams administration defended the bot, saying it would improve over time. 

“We’re identifying what the problems are, we’re gonna fix them, and we’re going to have the best chatbot system on the globe,” Adams said at a press conference. “People are going to come and watch what we’re doing in New York City.”

City administrators soon added disclaimers to the bot advising users to “not use its responses as legal or professional advice.” They also improved some of the bot’s answers, but also appeared to limit the kinds of questions the tool was willing to answer. 

Today, the bot advises visitors to “ask an NYC government question only” and cautions that “responses may occasionally produce inaccurate or incomplete content.” Visitors must agree to accept the bot’s limitations before using it.

Update (Feb. 4, 2026): The city has taken down the chatbot, writing on the bot’s web page that its “beta test has ended” and directing visitors to NYC.gov for government information.

❌