Normal view

There are new articles available, click to refresh the page.
Before yesterdayThe Markup - All Stories

Who’s buying your personal data: Disney, GM, your insurer and bank. Here’s what they get

16 September 2026 at 12:00

Consumers asked a major data broker for their files. What they got back shows interest in how fat they are, how much they drink, and how likely they are to get a mammogram, among many other characteristics.

An illustration of a cartoon figure with a star-shaped head as they walk throw a row of trees, where unidentified hands hold up post-it notes with personal information about the star-shaped figure.

This story is coreported with Consumer Reports

The Arkansas-based data broker Acxiom claims it has data on billions of people around the world, including where they live and how they might spend their money. It says it can even deduce their political leanings, weight, and interest in medical procedures.

But what exactly does the company know?

For Tracey Reed, a nonprofit worker in Oregon, it knew enough to compile a 58-page dossier charting the purported history of her income, employment, and education, not to mention her spending, including everything from her online shopping to charitable giving. Although much of the information was incorrect, she said, the company attempted to log where she lived, complete with latitude and longitude coordinates. And it listed dozens of companies to which it had sold data or inferences about her.

“I think it’s pretty gross that people are treated like sources of wealth to be mined,” she said. “And that’s what these data profiles are, like, ‘Here’s a guide for how to squeeze this person and get money out of them.’”

I think it’s pretty gross.

Tracey Reed, Oregon resident who obtained her data broker file

Reed obtained her data as part of a project by Consumer Reports’ consumer advocacy team to encourage consumers to request their personal information from companies like Acxiom to see how well new state privacy laws are working. By examining the dossiers that come back — more than 100 so far — the nonprofit hopes to better understand what information data brokers are able to collect and to whom they sell it. (Consumer Reports said that its membership arm uses information derived from data brokers, including Acxiom, to understand consumer interests, including the likelihood of becoming a Consumer Reports member, but does not use the information to set prices for its products or share the information with the brokers.)

Consumer Reports shared its data requests with CalMatters and The Markup. Acxiom is notable among the various brokers in the requests for its size, leading industry role — and because it provided detailed data back to consumers.

Acxiom and its connections to other companies have been subjects of press accounts for years, but the records obtained by Consumer Reports offer granular new details about its practices, including the many particular inferences it makes, some of them remarkably specific.

Across the reports CalMatters and The Markup reviewed, Acxiom uses the data it had collected to make predictions in more than 3,000 distinct categories about people’s financial lives and behavior, from the ages and genders of their children, to their estimated “alcohol usage,” to how likely they were, on a scale of 1 to 100, to be in the market for a new Tesla Cyber Truck.

The project was enabled by new laws enacted in a handful of states in recent years that allow consumers to get a look at what brokers have on them.

In each of the profiles, Acxiom made detailed — sometimes to the point of bizarre — ”inferences” about consumers, attempting to chart the likelihood they’d be associated with various characteristics.

Some of those inferences would clearly be valuable to retailers looking to sell products to new or repeat customers. The data broker estimated for consumers, on a zero to 100 point scale, the likelihood that they would spend money at businesses from Nike to Buffalo Wild Wings to PlayStation, or the likelihood that they owned any of dozens of different car models. 

Other inferences went so far as to estimate how likely the person would be to respond to an offer to consolidate a student loan, how likely they’d be to give to charity, or what body mass index percentile they might fall into. Also rated were the chances the person was experiencing food insecurity, had a primary care physician, would get a mammogram, could pay for medical expenses, or showed online interest in the Army. (For more on what’s in Acxiom’s files and how it impacts you, see our accompanying visual explainer.)

The most revelatory finding in the Acxiom reports, according to the privacy experts we interviewed, is the list of specific companies that bought consumer data — more than 100 in total. Several relatively new state privacy laws, including those in Minnesota and Oregon, require companies to disclose not only the types of consumer information they collect but also the other companies to which they are ultimately sold.

Among those in the Acxiom files: several of the nation’s largest insurers, banks, and pharmaceutical companies, including GEICO, State Farm, Citi, JPMorgan Chase, US Bank, and Janssen Pharmaceuticals. Big online sellers were frequent customers, too, including General Motors, Hilton, Kohl’s, MLB.com, Southwest Airlines, T-Mobile, and the Walt Disney Corporation. And several smaller companies repeatedly fined and sued by federal and state regulators, including several direct-mail companies, showed up in the Acxiom files, including Affinion Benefits Group (now called CXLoyalty/Tenerity), Endurance Warranty Services, and Mailers Haven. 

Who’s buying your data from Axciom?

Consumer Reports volunteers requested their personal data from data broker Acxiom. These are the companies the reports identified as buyers of their data.
Chart: Derek Kravitz, Consumer Reports,&nbsp;<span class="block-byline datawrapper-1Mz9g-1nrs9uk">Ryan Tate, CalMatters and The Markup</span>

Of the more than 100 businesses we found that used Acxiom, only a few large companies responded to requests for comment. Those few responses broadly defended their use of the data as an important marketing tool. CalMatters and The Markup are publishing the remaining responses here.

“We leverage consumer data to help improve the efficiency and effectiveness of our marketing outreach,” said Farmers Insurance spokesperson ​​​​​Luis Sahagun, “and are committed to responsible use of any consumer information we may obtain from third parties.”

Marketing lists, loan offers, and patient risk scores

Companies often use personal data like Acxiom reports to identify potential new customers and find out about their household finances and key life events, such as the birth of a child or the death of a spouse. In turn, banks, insurers, and pharmaceutical companies can group, or “segment,” customers into small buckets — a new parent or widower, for example — and tailor advertisements or offers down to just a handful of people. 

Case in point: HealthVerity, a Philadelphia-based venture capital-backed startup that markets itself as the nation’s “largest healthcare data ecosystem,” was listed as a buyer in every Acxiom report we reviewed. It sells deidentified patient data to companies and government agencies, including the Centers for Disease Control and Prevention and, in several case studies posted on its website, insurers and pharmaceutical companies buy HealthVerity’s patient data to find medical research participants, build marketing lists, and link patient health records across different data sources.

But HealthVerity also markets an insurance underwriting product that helps produce “risk scores” and predictions for health, life, disability, and workers’ compensation insurers. And as part of its product list, HealthVerity offers another marketing product with more than “1,000 attributes from providers typically not available, such as Acxiom, Epsilon, Adstra and others. With these sources, you gain more granular demographics, including race data, consumer behavior, online activity, socio-economic profiles, lifestyle and digital media preferences.”

Acxiom’s privacy disclosures clearly state that its data can’t be used for insurance underwriting under the federal Fair Credit Reporting Act but HealthVerity’s products could fall outside that legal definition, as it’s billed as a “healthcare analytics” company, not a credit reporting agency, experts say. HealthVerity didn’t respond to a request for comment.

“There are a lot of holes in this Swiss cheese of privacy law,” said Ari Ezra Waldman, a professor of law at the University of California, Irvine, who studies the data economy.

U.S. privacy law can protect personal data in some contexts — say, when your FICO score and current debts are used for a credit check. But for certain kinds of health data, those laws can fall short. For example, while the federal Health Insurance Portability and Accountability Act of 1996, or HIPAA, protects most kinds of patient health information, daily measurements of someone’s heart rate, step count, and sleep held by a tech company like Apple or Garmin don’t have the same restrictions.

Other companies with spotty track records in handling consumer data show up repeatedly in the Acxiom and Epsilon files. OneMain Financial, a subprime personal lender, shows up as a buyer in several reports; in March, OneMain was sued by 13 state attorneys general for allegedly packing its loans with an estimated $826 in hidden fees and interest per borrower. 

Centene Corporation, the largest Medicaid managed care company in the world, has been sued by California and several other states for allegedly inflating its pharmacy costs and then overcharging state Medicaid plans. 

Janssen Pharmaceuticals, the Johnson & Johnson subsidiary listed in every Acxiom report we reviewed, has paid out billions of dollars in settlements for allegedly violating federal laws regarding off-label drug marketing and physician kickbacks. 

When personal data is used to market costly financial products, the effects on vulnerable consumers can be disastrous, such as when personal, home, or auto loans are targeted to those in financial trouble, often with onerous terms, said Lena Cohen, a staff technologist at the nonprofit Electronic Frontier Foundation who has studied the data broker industry. 

“The extremely personal data we see in these files doesn’t appear out of nowhere,” Cohen said. “There is a network of companies and tech that have to share this data for a data broker to collect it. And it can have real harms.”

The personal data reports also contain dozens of examples of inaccurate info that data brokers glean from public records. Those errors “poke a hole in the argument that we need these surveillance systems for advertising to work,” Cohen said. 

There are a lot of holes in this Swiss cheese of privacy law.

Ari Ezra Waldman, University of California, Irvine School of Law

Many of the early participants in the Consumer Reports effort are particularly mindful about protecting their privacy, and Reed, the Oregon consumer, is no exception. She is so aware of her personal data that she still uses a flip phone. “I hate marketing and advertising,” she said. “I always have ad-block and I try to be conscious of my own data privacy.”

That didn’t stop Acxiom from attempting to catalog her habits. Some information was wrong, and some was right. Her listed addresses seemed to mix her up with her parents, for one. But the company was correct about her spending habits.

The Acxiom reports also include what critics say are artful examples of the company employing coded language to otherwise describe racial, ethnic, and health information that would otherwise be protected from disclosure and use by federal and state laws. One report scores a consumer’s “assimilation level” as “3+ generations in the US.” Others rate “health conscientiousness,” the “likelihood to be a smoker,” and “social setting behavior.”

“We don’t actually know what goes into these kind of vague terms,” Waldman said. The assimilation score is likely “getting at things like race, ethnicity, immigration status, things that we don’t normally like to discriminate on.” But the vague terms used by data brokers “are there to hide the true nature of what’s going on — and to sanitize it, to legitimize it.”

Sherry Hamilton, a spokesperson for Acxiom, said in an emailed statement that the company works to ensure “all data is sourced ethically, used responsibly, and protected securely.” She said the company works with “data suppliers” credentialed by Acxiom to ensure users are given “appropriate notice and choice” in how their data is collected.

The reports collected by Consumer Reports and viewed by CalMatters and The Markup were furnished to provide unfiltered transparency, she said, while clients the company works with are given a more refined, and accurate, data set. 

She added that health-related categories in the data do not indicate a person has an illness but only that they “may be interested in information about a condition, treatment, or product” and that assimilation level is “a household-level score and does not indicate an individual’s race, ethnicity, or immigration status.” Under the law, she said, companies that purchase Acxiom data may not use it to determine qualification or the price of credit and insurance. 

“Acxiom is fundamentally committed to ethical data practices,” Hamilton said.

A multi-billion-dollar industry

Acxiom dates its start back to the 1960s, as an American analytics company called Demographics Inc. According to the New York Times, the company in its early years mined telephone directories to help the Democratic Party find voters’ addresses and mail them campaign material. Since then, the company has ballooned into a data-gathering behemoth. 

Acxiom’s massive data stockpile translates to massive revenue. According to its latest quarterly report, Acxiom’s parent company, Interpublic, took in $2.5 billion in one quarter this year.

But Acxiom is just one part of an even-more-sprawling industry harvesting consumer data with little oversight, and one that few people even know about.

The sale of personal information has become common enough that many companies legally qualify as data brokers even if they are not known as such and focus on other activities. They are part of a sector generally valued at hundreds of billions of dollars and expected to grow. Data brokers are now major political players, too, spending big money on lobbying to influence legislation. 

To build their databases, data brokers broadly rely on three types of data, according to Justin Sherman, a scholar-in-residence at the Electronic Privacy Information Center who formerly ran a research program on data brokers at Duke University. Those ways are data obtained directly, indirectly, and through inference.

Companies may get data directly by, say, gathering it through an app that they offer their customers, or buying a smaller company and integrating that data into their systems. Some of these companies may resell that data to brokers for their databases as well.

Public information, like property records, marriage certificates, and court filings are some of the means data brokers can use to gather data indirectly. Acxiom itself has acknowledged getting data through these means. 

Inferences are the ways a data point might lead a broker to determine something else about a person, Sherman points out. Those inferences can be especially invasive. If a person has a Christian news app, the company might infer their religion, or a gay dating app might lead them to infer a person’s sexual orientation. Companies might not be able to collect data on children legally, but they can infer which households might have a toddler.

If a data broker has a person’s geolocation data, they might see them visit a military base, or a school, or a medical specialist.

“From that I can derive all kinds of information about other characteristics: finance, health, demographics, religion,” Sherman said.

The data a broker obtains can be accurate or not, and may cause problems for the person being profiled either way. If it’s accurate, the data can give companies an unsettlingly detailed window into someone’s life.

But if it’s not accurate, the person might face harmful consequences, too. Faulty data on their driving practices, for example, could lead to unfairly increased insurance rates

And most consumers have little recourse to stop companies from collecting their data.

Data brokers and the law

Absent a comprehensive federal privacy law, some states have taken measures into their own hands. 

Four states — California, Oregon, Vermont, and Texas — have passed transparency laws that require companies to register as data brokers if they meet certain requirements. Some laws, like in California, require data brokers to provide consumers with a way to access and delete their information. California this year rolled out a new website enabling residents to tell hundreds of brokers to stop tracking them and selling their information; CalMatters and The Markup have a guide for how to file that request.

Lawmakers are increasingly worried that personal information collected by brokers and others will fuel discriminatory pricing; at least 30 states this year, including California, have considered bills regulating how companies offer multiple prices for the same product. 

But compliance with the regulations is uneven: a report this year by Privacy Rights Clearinghouse and the Electronic Frontier Foundation found that hundreds of companies appeared in one state’s database but not others’, despite similar registration requirements. 

It’s not clear how many companies that qualify as data brokers under these laws fail to register in a database at all. “The data broker industry is way underregulated,” Sherman said. 

The companies’ practices, he points out, raise serious questions about the boundaries of privacy rights and civil liberties.

There’s little to stop brokers from amassing profiles through more and more invasive means, then passing that data to whoever they see fit. Government agencies, meanwhile, have been known to purchase data from brokers as well. With this method, agencies like the National Security Agency have reportedly been able to bypass getting a warrant for information on a person. 

In response to criticism, data brokers argue that their practices are legal, and that they get consent to transfer and sell consumers’ data. If you sign up for a store’s loyalty program, for example, the fine print might include allowing the company to give your data to outside parties. But as Sherman points out, few people have ever heard of these companies, or could remember agreeing to having their data sold. 

“The notion that a data broker gets consent to sell someone’s data to clients flies in the face of years of academic peer-reviewed research, polling, news reporting, and people’s personal experiences,” Sherman said. “People are not actually consenting to this, so that notion is fanciful.”

Data brokers have detailed files on you. Here’s what’s in them — and how it impacts you

Data brokers collect thousands of details about your finances, health and habits. See what’s in your profile, who buys it and how companies use it.

Two purple hands: one holds a phone reading “COVERAGE: REJECTED. HAVE A NICE DAY!,” the other holds a cereal box labeled “CEREAL, PRIZE INSIDE!” with a sticky note reading “BMI 31” circled in red.
Catherine Twomey for Consumer Reports/CalMatters

This story is coreported with Consumer Reports

In several states, new privacy laws are forcing brokers to disclose the companies that bought your data. So we asked for volunteers to request their personal data reports from the world’s largest data brokers. Hundreds of people responded.

Each report typically contained a detailed profile: names, addresses, Social Security numbers — along with more than a thousand educated guesses and predictions about your traits and habits.

 Your data isn’t just sitting there. These reports show that it’s constantly accumulating, endlessly analyzed, and routinely sold off — to more than 100 of the largest companies in the U.S., among many others.

What’s in your data report?

A lot. These profiles show the last time you logged into your computer and how much you’ve spent on clothes, furniture, and dining out over the past several years.

Data brokers like Acxiom, Epsilon and others routinely sweep up the digital trail you leave behind and turn it into thousands of predictions about you and your purported traits, including things like: 

  • How many children you have, and their ages and genders
  • Whether you’re “blue collar” or “white collar”
  • If you’ve ever been a victim of fraud

But much of the data is wrong. One report listed six different guesses about someone’s age.

Your profile starts with who you are.

Data brokers maintain files on almost everyone. Acxiom says it has profiles of roughly 95% of U.S. adults. Epsilon claims to have data on “virtually every marketable U.S. household.”

Data brokers source data from public records, commercial databases, and other brokers.

They compile those records into a file that follows you throughout your life — and even after you die.

Your devices give you away.

Your phone’s “advertising ID,” your smart TV’s tracking identifier, your home’s IP address, and your car’s vehicle ID number — data brokers can have them all. 

These identifiers let their clients match you to your online behavior — across every phone, tablet, computer, car, and television you own.

You’re assigned an economic value.

While data brokers typically don’t have access to your bank account, they can guess what you earn, what you’ve saved, and what you’re worth.

This is all “modeled” behavior based on where you live, your previous purchases, and what similar consumers to you are worth.

Your identity and health are inferred.

Without access to your medical records, data brokers infer how well you sleep, if you smoke, your body mass index, and if you have health insurance.

They can also guess your religion, ethnicity, political leanings, and even the exact ages of your children.

These inferences are then sold to pharmaceutical companies, healthcare firms, and insurers.

What you’ll do next is already predicted.

Data brokers score your likelihood to buy things from hundreds of brands. They predict what car you’ll buy next, where you like to eat, and whether you’re in the market for cryptocurrencies.

You’re assigned a ‘lifetime value score’ and a ‘profit margin’ label

Your data is valuable to companies. 

A bank can use it to send you a credit card offer — with a better (or worse) sign-up bonus based on your profile. A home insurer can target you for new add-on coverage. Your favorite clothing store can use it to personalize the price of a sweater just for you.

To this end, Epsilon predicts your income, investments and “life cycle,” grouping people into one of 26 “NICHES” codes, such as “Easy Street,” “Mid Life Munchkins” and “Big Spender Parents.” It also categorizes people into how profitable they are to companies, using labels like “Best Profit Margin.”

Acxiom calculates a “lifetime value score” estimating your profitability as a customer. 

For auto, home, and health insurers, this score ranges from 0 to 200,000, with higher scores suggesting you’re more profitable. 

Acxiom then attaches dozens of labels to you, such as “Seniors ages 64+ years, with a medium ability to pay for medical expenses,” “3+ Generations in the US,” and “Completed High School.”

Here’s who’s buying your data.

The reports don’t just show what was collected. They name every company that purchased your profile.

Across the reports we reviewed, we identified hundreds of buyers.

Who’s buying your data?

Consumer Reports volunteers requested their personal data from data brokers Acxiom and Epsilon. These are the companies the reports identified as buyers of their data.
Chart: Derek Kravitz, Consumer Reports

Here’s what buyers do with your data.

Once your profile reaches corporate buyers, it becomes the raw material for decisions that directly affect your day-to-day financial life.

Insurers use it to gauge the health of your company’s employees and then prepare health insurance quotes and premiums. 

Personal lenders use it to identify you as someone who may need a financial lifeline or is in the market for a car. But these loans may have bad terms and high interest rates.

Banks use it to market financial add-on products you may not need, like identity protection and credit monitoring.

Opting out is harder than you think.

Data brokers get most of their data from other companies, not directly from you. 

You never signed up. 

It’s debatable whether you even meaningfully consented.

And opting out only removes your data from one broker — it doesn’t erase the copies that have already been sold to dozens of others.

For more on who’s buying your personal information from data brokers, and what they’re getting, see our full investigation.

How TikTok and Google ended up with information about doctors’ appointments around the world

Doctoralia sent information about specialists and appointment dates to social media companies.

An illustration in green, blue and white tones that depicts a medical appointment webpage with fill-out boxes, including a "enviar" button, surrounded by several pixels.
Illustration by Adriana Heldiz, The Markup

Healthcare appointment site Doctoralia, which serves millions of people in Latin America and Europe, sent sensitive information about their medical appointments, including the specialties and names of doctors, to social media companies including TikTok, Google, and LinkedIn, according to a review of its websites. 

The Markup and Agência Pública, an investigative journalism nonprofit in Brazil, reviewed multiple website domains operated by the company, which provides services similar to those ZocDoc offers in the United States, letting people looking for healthcare easily search for a variety of providers in the area, then book appointments. As part of a series on web tracking, the review looked at network traffic between Doctoralia domains in multiple countries and popular social media sites.

According to the traffic logs, embedded online trackers followed visitors in Brazil, Colombia, Mexico, and other countries from nearly the second they started to search for care, then sent that data to the tech industry for advertising purposes. 

If a visitor searched for a gynecologist based in Sao Paolo, Brazil, for example, the website sent searches for provider specialties and other information to Google through its marketing platform. If a visitor continued through to book an appointment, name and other information on the doctor, as well as the date and time of the appointment, was sent to the company.

The path taken in seeking medical care can itself provide clues about health issues that should remain private.

Brazilian gynecologist

Similar data was shared across other countries with other tech giants as well, according to the review. As in Brazil, searches for specialists in Colombia were sent to social media companies. If a user in Cartagena, for example, booked an appointment with a dermatologist, the provider’s name, as well as the data and time of the appointment, were sent to LinkedIn. The same happened with searches for any other specialists. 

If a web user in Bogotá booked an appointment with a doctor through Doctoralia, whether a psychologist, dermatologist, or other care provider, information on that appointment was also shared with TikTok. The same happened for users in Mexico. 

Doctoralia said it would conduct a detailed review of its online practices but noted it does not monetize patient data.

Still, experts said the information sharing violates privacy expectations and possibly Brazilian law.

“Even without a stated diagnosis, the path taken in seeking medical care can itself provide clues about health issues that should remain private to the patient,” said a Brazilian gynecologist who uses Doctoralia and spoke to Pública and The Markup on condition of anonymity.

For example, a search for gynecology, obstetrics or reproductive care may be related to trying to conceive, a possible pregnancy, infertility, choosing a contraceptive method or concern after a risky sexual encounter, the gynecologist added. In the doctor’s view, even though inference is not the same as diagnosis, the expectation of confidentiality in the relationship between patient and professional should also apply in the digital environment.

“When someone looks for a doctor, a test or a clinic, they are looking for care, guidance, help,” he said. “So there is a legitimate expectation of privacy.”

Was it illegal? Doctoralia promises a “detailed” review

The tracking on Doctoralia started before any personal information such as email addresses or names was entered, but the trackers often tied users to unique IDs. Social media companies say they can tie users’ social media profiles to browsing behavior through such identifiers. 

The tracking also happened across providers and borders in Latin America, with some experts telling The Markup and Pública that government agencies may want to scrutinize the practices. 

In Brazil, for example, a law provides for stringent privacy rights, especially for healthcare data. 

“Obviously there is a risk here of permanent tracking based on unique IDs and building profiles that people are not aware of,” said Rafael Zanatta, co-director of Data Privacy Brazil, an advocacy organization. “There could be a massive violation of those fundamental rights.”

Chiara de Teffé, a professor of digital law at the Federal University of Rio de Janeiro, said the protections provided by Brazil’s General Data Protection Law are not limited to diagnoses and medical records. “Behavioral information may receive enhanced protection when, because of its context and the way it is processed, it reveals or allows inferences about aspects of someone’s health,” she says.

Brazil’s Federal Council of Medicine, the agency in charge of regulating and licensing medical professionals, meanwhile, told Pública and The Markup that “booking an appointment does not involve medical confidentiality” and “there is no sensitive data of any kind when a patient seeks a specialist.”

But the country’s National Supplementary Health Agency, which regulates private insurance, said “the medical specialty sought and other appointment-booking information may reveal aspects of a person’s health.”

Arsenia Nikolaeva, a spokesperson for Doctoralia parent company Docplanner, said in a statement that the trackers were used to monitor the company’s own social media campaigns and that Doctoralia “does not use these tools to sell personal data or to operate a commercial data product” and isn’t paid by social media companies for data. But the company said it would review its practices.

“We take the questions raised very seriously and are conducting a detailed technical and legal review of the matters described, including the relevant technical configurations,” Nikolaeva said in an email. “We remain committed to protecting personal data across all the markets in which we operate, and to acting appropriately based on the outcome of that review.”

The social media companies say they have rules against sending sensitive information, including health data, through their trackers. In practice, however, businesses have frequently been caught sending such information. 

Sofie Diskin, a spokesperson for Google, said the company has “strict, long-standing policies against collecting private health information or advertising based on sensitive information” and provides customers with tools to help them avoid collecting health data.

A spokesperson for LinkedIn, Brionna Ruff, said the company’s policies “prohibit installation” of its signature tracker, the Insight Tag, on pages that collect sensitive data, and that the company doesn’t want such data. 

TikTok didn’t respond to a request for comment.

Despite the tech companies’ policies, however, healthcare businesses have frequently been caught transmitting sensitive data, leading to regulatory scrutiny and a wave of lawsuits in the United States

A close-up view of a unidentifiable doctor holding a stylus to tap on a tablet next to patient during a consultation.
Photo via iStock

Pixel tracking

Since 2022, The Markup has been reporting on the pervasive use of “pixels,” tracking technology that social media companies use to follow web users.

Across the internet, invisible trackers embedded on websites report information on web users to major social media companies. 

Companies like Meta, Facebook and Instagram’s parent company, freely offer the code for pixels to businesses and organizations, who place it on their sites. That code can then log data on visitors and transmit it back to the companies. 

Those businesses can then target social media ads to customers who interacted with their site. If a person visited the page for a product but didn’t purchase it, for example, a business can send that visitor ads on Facebook for similar products they might be interested in instead. Meta takes payment from the business for the targeted ads. 

The use of pixels is widespread, underpinning the economy of the internet by letting businesses target people who they want to reach, including those who might be the most interested in their products. 

But tech companies and businesses that rely on pixels have been hammered with criticism e for tracking sensitive personal data. The practice has sparked lawsuits, demands from lawmakers, and regulatory scrutiny. 

While social media companies say they don’t want to receive information on health or finances, for example, in practice it happens frequently. 

In previous articles, The Markup has found pixel tracking in several potentially sensitive areas, including education, finances, and healthcare. Among other instances, the reviews have found pixels transmitting information from tax filing companies and the Department of Education’s financial aid service. 

It isn’t the first time that companies have been in hot water for tracking health data. In 2022, a review by The Markup showed that Facebook was receiving sensitive medical information on appointments for major hospitals. The investigation led to lawsuits and several hospitals quickly changing their practices. 

In separate investigations, The Markup found trackers sending information from abortion pill providers and major drug store chains to Meta and other social media companies. (Doctoralia appeared to use Facebook trackers but sent less sensitive information to the company than to others in cases The Markup reviewed.)

Meta and other social media companies have said in the past that they do not want sensitive information sent to them through tools like the pixel. They also say they use tools to automatically identify and filter out potentially confidential information.

But ultimately, the companies are operating inside a black box. While it’s not clear in any particular case what happens after the data is sent, companies can use it to target ads and power their algorithms in the future. 

Privacy in Latin America

Doctoralia’s parent company, Docplanner Group, founded in Poland in 2012, says it operates a sprawling platform across 13 countries, from Turkey to Chile, letting 100 million people book 25 million appointments per month across countries, cultures, and languages. 

The countries where Doctoralia operates have a patchwork of laws that provide varying protections for web users. In Mexico versus Colombia, for example, different laws and regulatory agencies govern how data is shared and protected.

Not all of the Doctoralia domains that The Markup and Pública tested sent data to social media companies, either. If a visitor to the Spanish version of Doctoralia searched for an appointment, for example, the search was not sent to outside companies in our testing. Doctoralia is based in Spain, where data is protected under the European Union’s General Data Protection Regulation.

In Germany, where Docplanner offers a similar platform, a pop-up allows visitors to turn off any tracking cookies. In the Latin American countries, by contrast, a pop-up informs readers of cookies but doesn’t immediately offer them a way to turn them off. 

Unlike the unified law in the European Union, the most stringent privacy protections in Latin America comes from one country, Brazil, which has a comprehensive national privacy law, the General Data Protection Law. 

Under the law, companies that process data are required to do so with full transparency on how the data will be used, and users must be given an ability to opt out.

The law also gives special protections to “sensitive” types of data, including demographic and health-related information. If a company handles that data, they must ask for it conspicuously and prominently. Failure to comply with the law can result in action from Brazil’s regulatory body, the National Data Protection Authority. 

Zanatta, who works with the Authority as part of a government advisory board, said the tracking highlighted by The Markup and Pública would be something for regulators to examine. “There could be many legal problems here for sure,” he said.

Defense tech has unleashed a new weapons boom in Southern California

2 September 2026 at 12:00

An analysis of defense contracts charts the rise of defense spending — often in heavily Democratic districts

Illustration by Miguel Gutierrez Jr., CalMatters

The business of military contracting is booming in Southern California. 

The total value of defense contracts won by companies in Los Angeles County more than doubled in the last 10 years after adjusting for inflation, according to an analysis by The Markup and CalMatters. In the same period, the defense budget rose by about 19% in adjusted dollars.

The $15 billion in contracts won in LA County last year went largely to old-school defense contractors with headquarters elsewhere, like Boeing. But startups claimed a growing share of the pie, selling defense systems like low-cost missiles, drones, surveillance satellites, AI tools and much more. In 2025, 10 startups in the LA area were crowned “unicorns,” becoming companies valued by investments at more than $1 billion, according to the Los Angeles Business Journal. Most of those 10 companies were aerospace or defense businesses. 

In 2015, 14 of the top 100 defense contracts won in California went to businesses focused on drones or space, according to the Markup and CalMatters analysis. By 2025, that share was up to 21. The shift is similar if measured by dollars, from 13%to 18%. 

Details like whether you count obligations for where businesses are based or where the projects are launched all affect those numbers. By some counts the increases in contract dollars could be larger. 

The contracts have been kindled by a surge of venture capital. Private investment in aerospace and defense since 2008 has fueled massive gains, according to a report from The Aerospace Corporation, a federally-funded nonprofit. 

But all the new money is now causing awkward political tensions. 

The war in Iran, which has depleted American munitions, is poised to drive demand even higher. The Trump administration’s latest budget proposal includes a record-setting $1.5 trillion for the military. Meanwhile, the Defense Department has signed off on the earliest contracts for the “Golden Dome,” a proposal to build a missile-defense system above the United States that may eventually cost hundreds of billions of dollars. 

Most of the Golden Dome winners are based in or have ties to the Southern California area. 

“You saw this huge rise in capital and now you’re seeing just much, much bigger government budgets for space,” said Sam Wilson, a researcher at the Aerospace Corporation. 

The collision of venture capital and military spending has alarmed some advocates, who see a frightening trend toward privatization and the risk of a space arms race. Even Congressional Democrats are pushing back against the spending.

That’s noteworthy because it has tended “to be a bipartisan, equal effort to increase the budget” of the military, said Lindsay Koshgarian, director of the National Priorities Project, which tracks defense spending. “I think we are maybe seeing the limits of that now.”

Despite the pushback, some of the congressional districts that saw the largest defense contract increases in recent years are beneficiaries of signature Trump-era projects. Many are in solidly blue Los Angeles County, and among the most Democrat-leaning districts in the country. 

California’s 36th Congressional District includes El Segundo, a high-tech defense hub outside Los Angeles. In the district’s 2024 House race, incumbent Democrat Ted Lieu took nearly 70 percent of the vote over a Republican challenger. The increase in defense contracts between 2015 and 2025 in that district alone was more than $3.3 billion.

Another district, California’s 43rd, is represented by Maxine Waters, who in 2021 signed on to the proposed No Militarization of Space Act, which described the Space Force as an unnecessary waste of resources and sought to abolish it.

Trump recently proposed to double the budget of the Space Force, another potential boon to the area. Meanwhile, Waters’ district has seen its share of obligated defense department spending grow over the last decade by more than $1.6 billion, or more than 500%, adjusted for inflation. Waters’ office didn’t respond to a request for comment.

Los Angeles County congressional districts where defense contracts grew

Defense contracts have grown sharply in LA County over the past 10 years, including in 11 of the area’s 17 Congressional districts. All went for Kamala Harris in 2024, often by a wide margin, even though President Donald Trump’s Space Force buildup has been a key driver of local defense growth.
Defense contracts have grown sharply in LA County over the past 10 years, including in 11 of the area’s 17 Congressional districts. All went for Kamala Harris in 2024, often by a wide margin, even though President Donald Trump’s Space Force buildup has been a key driver of local defense growth.
Chart: John Osborn D'Agostino, CalMatters · Source: USAspending, The Downballot

Defense contracts in Los Angeles County congressional districts

Most US congressional districts in Los Angeles County saw an astonishing rise in defense contract dollars between 2015 and 2025. They’re also among the most liberal districts in the country.
Most US congressional districts in Los Angeles County saw an astonishing rise in defense contract dollars between 2015 and 2025. They’re also among the most liberal districts in the country.
Chart: John Osborn D'Agostino, CalMatters · Source: USAspending, The Downballot

Seamus Daniels, who studies the defense budget at the Center for Strategic and International Studies, said the proposed $1.5 trillion dollar defense budget for fiscal year 2027 “would surpass the peak of defense spending during World War II.” 

The administration is seeking that money in place of traditional Democratic priorities, like healthcare funding, he points out. “The budget requests of the second Trump administration have been contentious because, while they have sought to increase defense spending dramatically, they’re also aiming to cut non-defense spending,” Daniels said.

Koshgarian said Democrats have largely been open to an increased defense budget, especially if it brings money to their congressional districts. But that may be changing.

“That tension is definitely real, even in left districts,” she said. “But I think we’re reaching a level of extremity now that that might be starting to flip.”

A new chapter

There’s no question California has become a major player in defense technology.

Every year, the Silicon Valley Defense Group, an industry nonprofit promoting military technology, releases a list of the top 100 tech-forward national security companies. When they charted the companies’ headquarters by state for 2026, they found that 47 were based in California, more than five times those in the number two state, Colorado. 

It wasn’t always that way for California. 

The state became a hub of manufacturing during World War II, building the planes en route to the Pacific Theater. During the Cold War, it was home to pioneering aerospace firms like Lockheed, Northrop, and Convair. But by the 1990s, the collapse of the Soviet Union gutted defense spending and consolidation stripped the region of its leadership, eventually sending Lockheed Martin’s headquarters to Maryland and Northrop Grumman’s to Virginia. Many were sounding the industry’s death knell. The nonprofit RAND Corporation noted that military aerospace sales peaked in 1987. They had declined by 32 percent just six years later.

The seeds of a comeback were sown when the Predator drone, built by General Atomics of San Diego, first took flight above the California desert in 1995. The craft, armed with Hellfire missiles, became the symbol of the War on Terror.

Then came the private investment surge, and an administration with new priorities.

As far back as the first months after Trump’s first inauguration, in 2017, aerospace industry 

investors were celebrating massive stock gains. Government contracts have since turned defense companies like Costa Mesa-based Anduril into multi-billion-dollar operations.

Venture capital meets military dollars

Southern California likely benefits from the fact that the Space Force’s seed funding arm is based in El Segundo, where it decides where to send hundreds of millions of government dollars. The arm often chooses to fund companies in or around the small, seaside city, which has built buzz as ground zero for defense tech.

When Defense Secretary Pete Hegseth recently went on tour to promote the “Arsenal of Freedom,” a plan to massively increase munitions building, he told the workers at a Long Beach company, Rocket Lab, that “dominance of space” was key to the military’s future. 

“This company, you right here, are front and center, as part of ensuring that we build an arsenal of freedom that America needs,” he said.

The partnership between private venture dollars and public defense contracts often unfolds like this: First, a startup comes up with a business plan for a product or service with military applications. 

SpaceWERX, the El Segundo-based Space Force venture arm, selects some of these projects for early seed funding. Since 2021, SpaceWERX has awarded 380 contracts worth more than $461 million to businesses in California, more than any other state, SpaceWERX spokesperson Matthew Clouse said.

Private investors often follow on, seeing SpaceWERX money as a “demand signal,” said Arthur Grijalva, director of SpaceWERX. Billions have flowed into California-based companies in recent years this way. 

Some local politicians have spent years pushing for similar investment in local military applications. El Segundo Mayor Chris Pimentel said he and his team traveled north in the state to personally court financiers while dealing with an enormous business dip early in the pandemic.

“It really paid off with large dividends,” he said. “We started showing up and being in the room with some of the larger venture funds and saying, ‘we can make these things happen down here. We can build stuff.’”

“Agnostic of politics and agnostic of individual ideologies, our core belief is that this is where the future has been made historically,” he said, pointing to Southern California’s long aviation history. 

Some companies that take Defense Department contracts, like Elon Musk’s SpaceX, which started in the Los Angeles area, are now valued at billions. SpaceX’s recent initial public offering became, by far, the biggest IPO of all time in June. 

Other small space companies are rapidly building with government contracts. True Anomaly, a space defense company, was founded in Colorado in 2022 but now has its largest office in Long Beach. “When you’re building this type of company, it’s frankly somewhat of a necessity to have a footprint here,” said Chief Financial Officer Mark Seidel.

The company has worked on Space Force missions and was recently announced as a contractor for the Golden Dome project. In April, a $650 million funding round put the company at a valuation of more than $2 billion. 

The increasing spending, while bringing jobs to some parts of the country, continues to rile critics.

“We very much risk getting into a space arms race, where China invests more, so we invest more so China invests more and we invest more,” Koshgarian said. “Where does it stop?”

Data from usaspending.gov for Defense Department obligations to organizations listing a California address. Awards may be to California businesses for projects in another area. Download our data here. 

Brazil gives parents social media controls for their kids. Should the US?

California is leading on kids’ data privacy in the U.S. but still lags internationally.

A group of students lying in the grass near a sidewalk, looking at a cellphone while a man runs past them.
The California Legislature is considering bills to safeguard children from chatbots and curb addictive social media for kids. Students of Saint Monica Preparatory hang out after school in Santa Monica. May 24, 2023. Photo by Zaydee Sanchez for CalMatters

This story was produced in partnership with Agência Pública as part of a series on how regulatory solutions adopted in Brazil could point the way for the U.S. Reporting by Colin Lecher, Maria Martha Bruno and Natala Viana.

Alarming trends in teen mental health and increased social media use led California to pass a new wave of laws to protect kids online. 

The state enacted protections to prevent children’s data from being sold, to give kids an opportunity to delete what they post, and to require businesses that target children to manage potential risks. Future legislation could ban social media altogether for many teens.

Some of those regulations face legal challenges, but together, the laws amount to some of the strictest privacy safeguards for children in the United States. 

California’s laws are considered stronger than the federal Children’s Online Privacy Protection Act, or COPPA, which is geared toward protecting children’s privacy. Under that law, website operators must obtain parental permission before collecting information on kids under 13 if their site is targeted toward, or knowingly collects information about children.

California’s laws expand the ages protected and place further restrictions on product design. To some extent, California sets childrens’ privacy policy for the entire country, since companies may choose to provide California’s more stringent protections to children nationwide rather than carve out protections just for the most populous U.S. state. 

But despite policies that are extensive when compared to the rest of the country, California’s regulations still lag well behind those of other countries. As California passed various child privacy laws, countries like Brazil passed comprehensive legislation that overlaps with some California policies, while going even further. 

Experts say the United States and California face unique hurdles in passing children’s privacy laws that other countries don’t. Among those are First Amendment challenges, different conceptions of privacy, and — maybe most importantly — a tech industry that sees strict privacy laws as an existential threat to its future. 

A child privacy push

California has led the way nationally for a decade on protecting kids online, and more recently has picked up more steam. 

“California, everything there is changing and changing fairly dramatically within the last just four years,” said Ed Howard, Senior Policy Advocate for the Children’s Advocacy Institute at the University of San Diego.

Like the federal law, the California Consumer Privacy Act, passed in 2018, requires companies to obtain parental permission to collect data on kids under13. But it also protects teens between 13 and 16 by forcing companies to make them consent before their data can be gathered. 

In 2022, the Legislature enacted the California Age-Appropriate Design Code Act. That law requires companies to estimate ages, then ensure they provide, by default, strict privacy protections for underage users. The law also limits the use of so-called “dark patterns,” which provide an illusion of choice for users while steering their behavior in certain directions.

“If there’s a product that’s likely to be accessed by children, it has to be, by design and by default, safe for them,” said Assemblymember Buffy Wicks, an Oakland Democrat who worked on that legislation.

Wicks also authored a measure that next year will require companies to include a “signal” system that will tell businesses a device user’s approximate age. The law would be among the strictest in the country, although a series of legal challenges by the tech industry have left it partly defanged.

Another law, the Protecting Our Kids from Social Media Addiction Act of 2024, bans social media companies from showing minors “addictive” feeds without parental consent and limits the hours when companies can send notifications to teens. The law, which goes into effect in 2027, has already survived legal challenges. 

A person, with white hair and wearing a gray suit, stands in front of a podium with a microphone on it while they speak.
Assemblymember Josh Lowenthal at the dais during an Assembly floor session at the state Capitol in Sacramento on Aug. 21, 2025.
Photo by Fred Greaves for CalMatters

Bills now before the Legislature would ban kids under 16 from “addictive” social media entirely, in a step that has earned the ire of some online privacy groups over fear it would end online anonymity by requiring age verification at sign-up. 

More recently, the state has begun regulating artificial intelligence, passing a law to impose mental health safeguards on chatbots. That legislation was passed in response to a series of troubling incidents, including the death of California teenager Adam Raine, who talked about suicide with ChatGPT for months before eventually taking his own life. The death is just one in a series of several incidents involving teens that have alarmed legislators

Raine’s mother, Maria, recently testified in front of Senate Privacy, Digital Technologies, and Consumer Protection Committee, calling for stricter protections. ChatGPT, she said, was “a homework helper [that] turned into a confidant, then a suicide coach.”

Under a law enacted last year, AI chatbots are required to disclose that they are not real people and companies must take reasonable steps to prevent children from seeing graphic content. 

The Legislature is considering bills to further govern how chatbots can interact with kids online. Those would require AI companies to make annual risk assessments on potential mental health harms and create controls that let parents limit how kids interact with bots. 

The flurry of legislation is a marked contrast to the federal picture, as Congress has repeatedly failed to agree on terms for national laws. 

This session, lawmakers are considering the Kids Internet and Digital Safety (KIDS) Act, which would expand several privacy laws. Among them would be applying COPPA protections to everyone under 18 and prohibiting targeting online ads toward children and teens. 

But the act faces criticism from child safety advocates for not forcing strong enough legal obligations on tech companies, and from civil rights organizations over free speech concerns. The act may be doomed as the House and Senate argue over its provisions

International, comprehensive

For years, advocates have pointed to research linking teens’ mental health to social media use in arguing for stronger protections. A substantial proportion of teens say social media has damaged their mental health, and heavy social media use is linked to increased risk of anxiety and depression

Recently, Meta and YouTube were found liable in a landmark lawsuit accusing them of knowingly creating platforms with features that were addictive and harmful to children and teens. That suit argued that internal documents showed how the company was aware of the damage their services could do, but allowed kids to use them anyway. 

Other countries have taken a more comprehensive route than the United States, passing packages of laws specifically meant to cover children’s data and social media use.  I look at what’s happening in the U.K., I look at what’s happening in Australia,” said Wicks, who said she’s recently met with British and Greek policymakers about children’s privacy issues.

“We steal good ideas when we see them from other places,” she said, saying the Age-Appropriate Design Code Act was “wholesale borrowed from the UK.”

In Brazil, the ECA Digital comprehensive children’s privacy act became law this year despite tech industry lobbying

The act forbids companies from targeting ads to children based on their online behavior. It also requires parental supervision tools and defaults to the most protective privacy settings for kids. It also bans potentially addictive features like autoplay and infinite scroll for kids. 

Some legal experts see how provisions of that law and others could be imported to the United States, possibly through a state like California. 

Mariana Olaizola Rosenblat, a policy advisor on technology and law at the NYU Stern Center for Business and Human Rights, pointed out that there’s already some consistencies between regulations in Brazil and California.

“I think there’s quite a bit of overlap, but where they diverge is mostly because of specific constitutional features of the U.S. legal system,” she said. The First Amendment has often been used in legal challenges brought by the tech industry against laws limiting what content their algorithms show. 

Olaizola Rosenblat, who has studied global privacy laws, said provisions in the ECA Digital, like a requirement that social media sites offer parental supervision tools, could be imported to the U.S., too. Those tools allow parents to control features and content their kids see, including by setting limits on messaging, screen time, automatic playback, and rewards. She points out that California has also passed provisions like privacy-by-default settings for child users and limits on advertising.

International laws can often go further in placing limits on the content that minors might see because the countries don’t have the same guaranteed speech rights. “They’re able to regulate that in a way that I don’t think the U.S. can under the First Amendment,” she said. 

Texas Tech University researcher Marina Petric said this amounts to “First Amendment fundamentalism.”

“The U.S. narrative has been embedded into the architecture of digital platforms as though it were a universal standard,” she said. “Those who reject this premise are portrayed as supporters of censorship. But freedom of expression defined by one side and applied only to some is not freedom of expression — it is a tool of power.”

Ultimately, there are ways to take pieces of international laws and import them, Olaizola Rosenblat said. There are at least parts of laws like the ECA Digital that are compatible with legal rights in the U.S. 

Our system is uniquely vulnerable to the power of that money.

Ed Howard, University of San Diego

Howard adds that the structure of the U.S. government makes it easier to pass individual laws than major packages all at once. He also points out that privacy issues are constantly evolving, and slow-moving bodies like Congress have trouble keeping up. 

But both Howard and Olaizola Rosenblat believe the major barrier to a stricter children’s privacy law is a single issue: the influence of tech industry cash.

“The thing that is by a wide margin, the biggest reason, is the power of money in our system and the fact that our system is uniquely vulnerable to the power of that money,” Howard said.

In 2025, tech companies pushing for fewer regulations on AI and cryptocurrency poured more than $39 million into political spending and lobbying, according to a CalMatters analysis. The companies say the money goes toward supporting candidates that protect their industry, but critics say the companies are exerting undue influence.

As part of its spending, Meta gave $150,000 to the California Democratic Party and $20 million to a new political committee. While lawmakers questioned how best to regulate AI last year, the company spent far more than any other previous year. Meta said the money was “to help elect state political candidates in California — no matter their party affiliation — that support and defend the American tech industry.”

That’s only the tip of the iceberg. Tech companies spend tens of millions more every year lobbying Congress. 

“I think the main problem is the tech lobby, which is very successful in the U.S. and maybe not as successful in other jurisdictions like Brazil,” Olaizola Rosenblat said. “Because they know that the most threatening thing to them would be a federal law in the U.S.”

While other countries get lobbied, the U.S. is a uniquely gigantic market, and California is the tech industry’s home base. Tech giants are willing to push back hard against laws that threaten their business model in the country, and that includes for laws aimed at protecting kids. 

“When it comes to privacy, every business has a financial stake in there being very little privacy,” Howard said.

Kaiser Permanente nurses say technology is making their jobs — and patient care — worse

9 July 2026 at 12:00

Call center nurses at the health giant said workplace surveillance tools and AI prioritize speed and cost savings over quality and safety.

A person wearing a red shirt and a headset sits in front of a desk and types into a keyboard, in a dimly lit room with a window overlooking a residential street.
Kaiser Permanente advice nurse Raquel Alvarez Sanchez works from her home office in Santa Rosa on April 6, 2026. Kaiser Permanente nurses have raised concerns about the growing use of AI to monitor their work ahead of upcoming contract negotiations. Photo by Chad Surmick for CalMatters

Kaiser Permanente nurses who answer advice and triage calls say their duty of care for patients is being increasingly threatened by workplace surveillance.

Seven current and former nurses told The Markup that those who spend more than 15 minutes on a call with a patient routinely face criticism from Kaiser management or get called into performance evaluation meetings. Call time, they said, factors into monthly performance scores they receive.

In addition to tracking call length, they said Kaiser uses software that tries to predict on a daily basis whether they’re being unproductive or failing to answer calls quickly. Artificial intelligence systems have also been used to rate their empathy and tone of voice.

Their comments come as the California Nurses Association begins negotiating a new contract with Kaiser this month with AI a likely issue. Kaiser nurses went on strike against AI for one day in March and picketed against AI last fall. The CNA is bargaining for 25,000 nurses, including 1,000 in call centers. 

At the same time, California lawmakers are considering several bills regulating AI in the workplace, including one that would protect from retaliation doctors and nurses who override automated care recommendations.

Kaiser defended its use of AI, saying it deploys the technology with human oversight and with patient safety in mind. It said it does not use “average handle time” to assess performance.

Kaiser Permanente is the largest private employer in California, providing healthcare services to more than 9 million people in the state and to 3 million other Americans. That means the company’s use of artificial intelligence could set important precedents for managing workers with AI. It could also have a big impact on patient care, providing an early example of how the healthcare sector balances cost-cutting automation with human presence or touch.

Raquel Alvarez Sanchez, a Kaiser Permanente advice nurse in Vallejo since 2010, said she was on a call with a patient who was suicidal last year that took more than an hour because she had to wait for police to arrive before hanging up. She tried to make the man feel cared for, even though she was cognizant that staying on the call that long would throw off her average call time for weeks and could lead to questions from management. Sanchez, a union steward, said she’s accompanied colleagues to performance evaluation meetings, where they were found to have done everything right on a call — except staying on the line for more than 15 minutes. She said she hasn’t seen nurses get fired for doing that, but she fears that continued pressure can lead nurses to quit or retire early.

“I think at some point all of the nurses have been talked to about their average handle time,” she said. “The only thing I can think of is they’re doing it for profit.”

Another nurse who spoke with The Markup on condition of anonymity due to fear of retribution described how that surveillance affected a call with a patient last year. Initially she thought her patient, an elderly woman who just received a terminal cancer diagnosis, was suicidal, but quickly came to understand that she was in shock and really needed somebody to talk to.

The nurse wanted to take time to show compassion or comfort to the woman, who acts as a caretaker for her daughter, but she stopped herself out of fear it would hurt her monthly performance score and lead to a reprimand from her manager. She became a nurse to provide people with compassionate care, but “I had to ask myself: Am I going to get disciplined for going off script or saying more than what is necessary?”

A person wearing a red shirt and a headset sits in front of a desk and types into a keyboard, in a dimly lit room with a window overlooking a residential street.
Kaiser Permanente advice nurse Raquel Alvarez Sanchez works from her home office in Santa Rosa on April 6, 2026. Kaiser Permanente nurses have raised concerns about the growing use of AI to monitor their work ahead of upcoming contract negotiations.
Photo by Chad Surmick for CalMatters

Kaiser Permanente says its performance evaluations help improve patient outcomes. A company spokesperson said, “Kaiser Permanente does not use Average Handle Time to assess agent performance or enforce call time metrics. Any tools used in contact center settings support our quality assurance efforts and have human review and oversight.” In a statement provided to The Markup and CalMatters, spokesperson Vincent Staupe added that Kaiser uses AI responsibly, with human oversight, and by “prioritizing patient safety, privacy, and equity,” but he said, “As a large organization, we do not share specific information about internal technology systems for security and operational reasons.”

Is technology putting patients at risk?

It’s not clear how patient care is affected by algorithmic management, nor is the impact of limiting the length of triage and advice calls on patients. Kaiser call center nurses can’t say for certain whether the pressures they face results in adverse outcomes for patients because their contact with patients ends after they hang up the phone. A 2024 public records request by CalMatters to the California Department of Managed Health Care found no complaints by patients against Kaiser related to call times. But nurses insist the risk to patient safety and quality of care is real. 

Consumer Watchdog patient advocate Michele Ramos said many Kaiser patients begin their care on the advice line. They later complain to her, mostly about things that happen in Kaiser facilities, but “I can see now where a lot of the problems” start, given the call constraints nurses are under. 

Ramos said the time pressures may fit a broader pattern at Kaiser of putting costs over quality. The health giant was hit with a record fine, $50 million, as part of a settlement over findings from the California Department of Managed Health Care that it delayed behavioral health appointments beyond statutory limits and too often moved patients into group rather than individual therapy. Kaiser also settled with the U.S. Department of Labor after investigations into its substance use and mental health services. Kaiser faced criticism in 2002 for paying bonuses to call center workers who aren’t nurses for keeping calls short, though call center nurses who spoke with The Markup and CalMatters said they encountered no such practices today.

“Kaiser’s been known through the years to manage dollars over managing care, and I think this would be a contributor to that, which is only going to fail patients,” Ramos added.

Nurses said they are pressured to stay under 15 minutes even for the sorts of calls that often take more time, like diagnosing a patient with multiple symptoms, chronic illnesses, new parents in need of advice and assurance, people who desire extended health education, or people who are overwhelmed after receiving life-altering news who could use some compassion. Nurses say calls that involve interpreters often take 30 minutes or more. About four in 10 Californians speak a language other than English and half of them do not speak English well, according to a state environmental health agency.

“The amount of time that Kaiser is giving us to complete a call is sometimes not safe,” said one nurse, who asked to remain anonymous due to fear of retaliation.

“People can get hurt,” said Charlotte Capulong, who has worked in nurse call centers for 22 years and helped organize Kaiser nurses against the AI tone-of-voice tool. Capulong said nurses felt harassed by managers in meetings she attended as a union rep, even if they successfully carried out all other duties of their jobs except completing calls within 15 minutes.

“You aren’t calling Comcast. We’re dealing with life here,” she said.

The Kaiser Permanente logo with the location address is displayed on a brick building. Leaves from a nearby tree can be seen in the blurred foreground.
Kaiser Permanente Sacramento Medical Center in Calif. on Monday, Aug. 15, 2022. More than 2,000 mental health physicians striked throughout Northern California over staffing issues leading to patients waiting longer to access help. Photo by Rahul Lal, CalMatters

Nurses are instructed to stick to a script on phone calls and give no more than two to three pieces of advice, Capulong and other nurses said, which means they may sometimes need to decide whether to withhold advice or face a performance evaluation hearing.

The nurses say artificial intelligence could make the surveillance nurses encounter on the job worse.

In summer 2024, Kaiser began testing an AI tool that attempts to assess empathy and tone in the voices of nurses and patients, according to nurses who spoke with The Markup and CalMatters. In response, nurses circulated and signed a petition in favor of the right to patient privacy, more transparency,  and the right to exercise their professional judgement and encouraged management to involve nurse’s input and feedback. The signature campaign used the same tag line that nurses used at protests outside San Francisco hospitals earlier that year: “Trust nurses, not AI. The AI tests ended in November 2024, but union representatives were told that managers may bring the program back in the future. 

Nurses reported feeling harassed by existing surveillance, “and that was intensified when they said we’re going to use AI to evaluate our calls and grade us,” said Sanchez.

Another nurse speaking on condition of anonymity said “AI did not understand our job and would grade us wrong all the time.”

A Kaiser spokesperson declined to respond to questions about the AI tool or answer questions about the use of AI and other automated systems in the company’s call centers and healthcare facilities, including for evaluating nurse performance or whether patients were informed about the use of AI to evaluate their empathy and tone.

Nurses also said they get little time between calls even if that call involves speaking with a patient who is suicidal, experiencing a mental health episode, or near death. In years past, nurses got around 10 minutes to finish writing notes in a patient’s chart or collect themselves after a particularly tough call. Today they say they typically get 30 seconds or less when lines are busy, although more at slow times, like late at night, or if they get a manager’s permission after a particularly challenging call. The overall pace they say, can lead to mistakes like missing important cues into a patient’s wellbeing.

CNA reps declined to talk about specific provisions they intend to seek related to AI ahead of their talks with Kaiser this summer.

How surveillance and AI shape nursing

Critics say excessive workplace monitoring can lead to lower morale as employees feel less trusted and autonomous, relegated to being no more than algorithm monitors. UC Berkeley Labor Center Technology and Work Program director Annette Bernhardt has warned that algorithmic management can turn people into fleshy robots, echoing complaints from an Amazon factory worker who The Markup and CalMatters interviewed last year. A 2023 academic survey of call centers in four developed countries found that using AI for management or monitoring left workers with less time between calls and more likely to feel emotionally drained by their work. Nearly half of respondents said that AI tools made their jobs more stressful. A prior study by the same researchers, Virginia Dolleghast of Cornell University and Sean O’Brady of McMaster University found that performance monitoring leads to higher rates of emotional exhaustion.

Dolleghast, who has studied the impact of surveillance technology on call center workers for more than a decade, said what Kaiser call center nurses are experiencing is part of a broader trend: Across different industries, persistent surveillance is increasing stress levels for workers who are resolving complex, emotionally-charged issues. 

“Stress and burnout can lead to more mistakes across a range of areas, and in the healthcare setting that is much higher risk because you’re dealing with people’s lives and their health,” she said.

The converse can be true: Workers who are given more discretion to decide the pace and timing of their work experience higher levels of job satisfaction and less absenteeism.

A wide view inside a 911 dispatch center with rows of computer stations and overhead screens displaying call and dispatch information. In the foreground, two dispatchers wearing headsets sit at adjacent monitors, focused on their screens. Color-coded alert lights rise from several desks, and other staff members work in the large, softly lit room.
The 9-1-1 call center at the San Francisco Department of Emergency Management in San Francisco, on Aug. 2, 2019.
Photo by Eric Risberg, AP Photo

Nurses nationwide are more frequently encountering artificial intelligence and similar software systems in the workplace. Half of more than 2,000 nurses who responded to a 2024 survey by the National Nurses United union said their employer uses algorithmic systems to analyze health records. Such systems can do things like determine how fragile a patient is or predict how many hours of care they will need. Two-thirds of the surveyed nurses said their own assessments had at some point disagreed with a computer-generated prediction. Six out of 10 respondents said they don’t trust their employer to prioritize patient safety when using AI.

Pa Vue has worked as a nurse in call centers for the better part of the past decade. She said she and other Kaiser nurses routinely have conversations with managers about call efficiency and receive evaluation scores once a month. She recalls having a score reduced for repeating advice to a patient that she worried had unusual symptoms and possible heart issues.

As a union representative in some performance meetings, Vue has seen managers raise efficiency questions about calls they deem too long. She’s also seen nurses receive lower performance scores if they go against software recommendations based on their professional opinion or make an appointment for a patient without consulting a doctor.

She believes that efficiency aims accelerated by technology can hinder a nurse’s ability to focus and reduce the quality of care that patients pay for.

“I’m not against the use of AI as long as it’s beneficial to the patient but in this particular use [empathy and tone monitoring] it’s to increase productivity and improve efficiency and cut costs. Kaiser is forgetting we aren’t just a call center for customer support, we’re nurses, and we’re there to take care of patients,” she said.

As AI improves and businesses push workers to use it, unions are, in turn, increasingly demanding that employers address issues raised by AI when bargaining for new contracts. Surveillance technology has become a common way for managers to collect data about workers in a number of industries, used for everything from improving safety to hunting for ways to increase profit gains or train AI to do a job.

At Kaiser, AI is a key issue not only among nurses but also for mental health workers, 2,400 of whom are in contract negotiations in Northern California with Kaiser Permanente. Kaiser therapists have said they are concerned about use of therapy session transcripts to train AI models and about the health-care giant using AI to take their jobs. National Union of Healthcare Workers spokesperson Matt Artz told The Markup that contract negotiations are ongoing.

How Kaiser uses AI

Kaiser Permanente is exploring or using AI in many parts of the healthcare experience far beyond nurse call centers. Kaiser uses AI to identify patients in hospitals at risk of adverse events by evaluating data on their electronic health records. An AI system called Preventus is used to determine when to discharge patients. Doctors and therapists use Abridge to record interactions and translate speech to text during in-person visits with patients instead of taking notes. Remote monitoring with AI for patients that need extra care has been tested at Kaiser Permanente facilities in the Bay Area, according to nurses who encountered the technology in the course of doing their jobs.

National Nurses United and CNA President Cathy Kennedy sees the use of AI to detect nurse empathy as part of a long series of steps by Kaiser to limit their autonomy and make them more efficient. She believes AI threatens to automate and fragment the work that nurses do, and companies developing and deploying AI systems should establish that those systems are effective and equitable before deploying them.

A person dressed head to toe in blue scrubs looks towards a Kaiser Permanente as they walk across an intersection.
Kaiser Permanente in Oakland on Aug. 2, 2022.
Photo by Martin do Nascimento, CalMatters

Notification of new tech deployments is part of the nurse union’s contract with Kaiser but sometimes nurses don’t receive notification, CNA says. So union leaders are attempting to track the number of AI models in use at Kaiser Permanente, advising its members to inform them when they encounter new tech. This paves the way for CNA to push back as it did with the empathy and tone AI last summer or as it did when it stopped a pilot program that would have replaced nurses that sit at the bedside of confused patients with cameras.

Debru Carthan, a Kaiser radiologist, is on the front line of worker-management fights over AI at the company. A member of Service Employees International Union, she is also part of the Coalition of Kaiser Permanente Unions, where she sits on a committee to discuss use of AI and emerging technology at Kaiser. The coalition also has a “see something, say something,” campaign for frontline workers to report when they notice AI deployments; the coalition says that too often management quietly implements AI into workflows without notice or worker input. She worries that the AI tone detector used on advice nurses could discriminate against nurses from different cultures and has come to believe that the use of AI in healthcare generally has more to do with money and corporate greed than patient care.

California lawmakers have responded to worker AI concerns both inside and outside the healthcare sector. They tried and failed last year to address how AI impacts workers like call center nurses. Assembly Bill 1018 and Senate Bill 7, two bills endorsed by the CNA, would have required employers to inform workers before using automated systems on the job to do things like promote or discipline workers or evaluate job performance, but Gov. Gavin Newsom vetoed SB 7, and, facing strong opposition from companies including Kaiser Permanente, AB 1018 failed to pass for the third consecutive year

Earlier this year, lawmakers reintroduced a new version of Senate Bill 7, now called Senate Bill 947. Another bill would prohibit employers using AI to predict the emotional state of their employees. Yet another bill would protect doctors and nurses from retaliation if they override recommendations generated by an automated system and require healthcare providers to supply employees with an inventory of automated systems once a year. Kaiser declined to share a list of AI systems in use when asked by The Markup and CalMatters.

Altogether CNA and the affiliated California Labor Federation support roughly half a dozen bills to regulate use of AI in the workplace. Calling AI a central issue in the next presidential election, members of the California Labor Federation and labor leaders from Democratic primary states held a press conference in Sacramento earlier this year to say that if Newsom wants to become president then he needs to pass laws protecting workers from AI. “It’s an ongoing fight, and it’s a fight well worth having,” Kennedy said. “Whenever there are other unions in discussion about artificial intelligence we are in solidarity with them.”

The nurse that withheld compassion to a terminal cancer patient she thought was suicidal said she believes monitoring and scoring systems turn nurses into automatons that check boxes.

“I used to use humor as a way to help patients heal, and I don’t feel comfortable doing that here because I know the calls are being recorded. You can always tell when a patient appreciates the humor or your personal compassion, but I don’t feel like call centers have tolerance for that because that’s not part of the script,” she said. “That really takes away from the whole point of being a nurse and what patients come to know from nurses.”

This story was reported with contributions from Lam Thuy Vo and Ana Ibarra.

Californians can protect their personal data with one click. Help us test if it works

A new state tool lets you tell data brokers to stop tracking you. Will they comply? Help us investigate.

An illustration shows a person using a laptop in front of a blurred California privacy website, with yellow pixel-like blocks scattered across the image to suggest digital data. The stylized artwork uses a limited color palette and visual elements that evoke online privacy and information security.

Hello there,

Our names are Colin and Mohamed, and we’re both journalists at CalMatters and The Markup.

If you haven’t heard yet, California is offering a new way for people to protect their data — and we want your help tracking its rollout and effectiveness.

Data brokers are largely unknown companies that make a business out of collecting often-sensitive data on consumers. That data can include where you and your family are at all times, what you buy, what medications you’re taking and much more.

Starting at the beginning of this year, the California Privacy Protection Agency allowed residents of the state to sign up for the Delete Request and Opt-out Platform, or DROP. The tool lets consumers send an instant request to hundreds of data brokers, asking them to delete their data and stop tracking them. 

The brokers are required to start processing those requests in August. We reported on the tool’s launch, and as new requests are processed, we’ll keep following the story. 

CalMatters and The Markup want to keep tabs on whether data companies comply with DROP, and that’s where we need your help. 

Californians have the right to know about the personal information a business collects about them and to control how it is used and shared. We’ll walk you through how to exercise those rights with some of the largest data brokers in the country and how to share what they tell you with us. Then, after the DROP deadline, we’ll walk you through how to do it again, and we’ll help you figure out if the information companies have about you changed, grew, or was deleted.

If you live in California, get started by following the steps in this article.

If you don’t live in California, but have friends or family in California who would be interested in helping us investigate, please share this article with them.

We appreciate the help!

Colin and Mohamed

Your medical provider might be recording your mental health care visits

Mental health providers are increasingly using AI technology to record conversations, raising privacy concerns among patients and practitioners.

An illustrated composite image shows two people in conversation, one taking notes while the other appears distressed. Audio waveforms, a microphone icon and the word “REC” are layered over the scene, suggesting a recorded or transcribed discussion.
Illustration by Roxsy Lin, American Community Media

In 2024, Kaiser Permanente announced the rollout of Abridge. Described in a press release as “ambient listening technology,” the AI-powered scribe is designed to help clinicians including mental health providers securely capture clinical notes during patient visits.

But what the description fails to indicate is that the tool records entire medical appointments, including deeply personal mental health sessions.

During these sessions, mental health professionals are required to obtain patients’ consent before using the tool. However, as shared by multiple providers, that consent process does not include explanations about how the information is handled. Nor does it say how long and where recordings are stored, or who has access to the data.

This happens in part because that information has not been shared with providers, despite their attempts to obtain it.

‘Empty assurances’

Ilana Marcucci-Morris chose not to use the platform with her patients. She is a licensed clinical social worker with Kaiser psychiatry in Oakland, California. She is also a member of a bargaining committee. In that role, she regularly meets with various Kaiser representatives, including Northern California’s director of mental health.

Marcucci-Morris describes how, during those meetings, she and other committee members have asked questions about patient privacy protections, HIPAA compliance, and the safeguards in place for the use of these technologies.

According to her, the response from leadership has often been empty assurances: “We are compliant. That’s it. That’s all you need to know. We vet the technology, therapist. Don’t worry. That’s not your job. We have tech experts. That’s their job,” Marcucci-Morris said in an interview with American Community Media.

“They won’t show us, right? And my feeling is, if you have nothing to hide and you’re doing it totally […] ethically, then you would show us, prove it. They can’t, and they won’t, and they declined to when we ask.”

Ligia Pacheco is a psychiatric social worker who provides remote therapy services for Kaiser patients in Southern California. She said Kaiser also refused her requests to provide further explanations.

In an interview with American Community Media, Pacheco recalled how a coworker once raised concerns to a supervisor. The response: that “it’s unprofessional for you to provide your personal beliefs on AI in our work setting.”

For Pacheco, “that leads to just low morale, no space to advocate for patients. We’re supposed to be the voice of patients who are coming in their most vulnerable state. And we can’t even be that voice for them, so we feel discouraged.”

“Patient after patient after patient”

Providers have been required to see more patients in recent years. That creates intense pressure to keep up with documentation and workloads, Marcucci-Morris highlighted.

“You’re just like seeing patient after patient after patient after patient with barely enough time to go to the bathroom, eat a snack […] get some fresh air,” she said.  

According to Marcucci-Morris, refusing to manage the increased patient volume can be treated as a failure to meet job expectations. It may also lead to disciplinary action.

As a union steward, she said she often represents colleagues during workplace investigations related to delayed documentation or difficulties managing heavy caseloads. In those situations, she said management frequently recommends the use of Abridge to save time and avoid further discipline.

In her view, the providers she knows who use the technology are not doing so because they support or trust it. Rather, it is because they feel pressured to protect their jobs and comply with workplace demands.

“I consider that to be coercive because you’re putting someone in a position to either lose their job or use the software. That’s another choice that’s under duress,” she explained.

Provider, patient concerns

Brian Hoberman is chief information officer for The Permanente Medical Group. In a Kaiser press release, he said, “Abridge’s advanced technology supports our doctors’ well-being by reducing the documentation burden.”

He added, “We implemented this new technology after careful review and diligent testing and found it to be well received by patients and doctors…”

For at least one patient interviewed for this story such assurances fall short.  

“I fear that this kind of information that’s being recorded now can get into the wrong hands,” said the patient, who asked not to be identified for privacy reasons. “I may not want my employers, I may not want my family members, I might not want people to know some of these very kind of intimate conversations and deep conversations I have with my doctors [and] with my mental health provider.”

Adriana Webb is a social worker at Kaiser Panorama City in Los Angeles. “I work with patients who have sensitive medical diagnoses, like […] HIV and AIDS, and a lot of times my patients don’t even want that in their chart.”

A spokesperson for Kaiser Permanente insisted in an emailed response to American Community Media that clinicians are required to gain patient consent prior to using Abridge. “No one is recorded without their knowledge and consent,” the statement read.

It added that recordings are stored for no longer than 14 days, and that data processing meets all HIPAA requirements as well as Kaiser Permanente’s own privacy and security standards.

“Abridge helps clinicians spend more time focused on patients and less time on administrative tasks,” it said.

Weaponizing mental health data

According to Nicole Alvarez, senior analyst for technology policy at the Center for American Progress, “a record of someone’s lowest moments can be used against them in ways that, you know, […] a high blood pressure reading cannot.”

She said mental health data can be especially sensitive because of the stigma surrounding mental health conditions. For patients, that stigma carries real-world consequences in areas such as employment, child custody cases, immigration matters, and security clearances. She emphasized that, like other forms of personal data, mental health information can be weaponized against individuals.

Agreements between health systems and AI vendors can vary widely, she said. This includes terms related to whether audio recordings or transcripts can be used to train AI models, whether patient data is de-identified, how long the data is retained, whether it can be shared with other clients, and what happens to the information once a contract ends.

Kaiser insists any data it collects is not used to train AI models.

Still, in Alvarez’ experience, patients often have little visibility into these arrangements. She argued that health systems have a responsibility to clearly disclose how patient information is being handled and used.

Alvarez also emphasized that, in most cases, patients have the right to refuse recordings. But, she said, the opt-out process is not always clearly presented. According to her, consent options may range from direct questions at check-in to language buried in intake paperwork, making it important for patients to carefully review forms and disclosures.

She said meaningful consent requires patients not only to know they are being recorded and that they can decline, but also to understand how their information may be stored, shared, or used afterward.

Coercive consent

Pacheco experienced this during a personal appointment at Kaiser. Her doctor did not ask for permission to use the app and instead informed her that it would be used. After a moment, she decided to refuse the platform’s use. Although the doctor stopped the recording, she felt a noticeable discomfort in the doctor’s demeanor afterward.

She later decided to change doctors.

Situations like this are a concern for Marcucci-Morris, who said the company’s approach to obtaining consent for the use of Abridge during appointments can feel manipulative and coercive. In her view, providers are trained to present the tool in a way that places the needs of patients and doctors in opposition to one another.

She explained that patients are often told the system will help doctors with documentation, reduce burnout, and allow them to spend more time with their families. As a result, patients may feel guilty declining the use of the tool because they do not want to make their provider’s job harder.

She believes this framing pressures patients into agreeing rather than allowing them to make a fully comfortable and independent decision.

According to Kaiser, Abridge is available in “40 hospitals and more than 600 medical offices in eight states and the District of Columbia,” part of a larger embrace of AI technology by the health care industry. Abridge operates in more than 14 languages.

American Community Media reached out multiple times to Abridge AI Inc. for comment but received no response. According to the company’s website, Abridge describes itself as a “Business Associate” to providers. Patients are advised to consult providers’ privacy policies for information on how their data is protected.

“Therapy is most effective in privacy and when trust is achieved through two human beings,” said Marcucci-Morris. For her, “healing occurs when human empathy is offered sincerely as part of any sort of mental health treatment relationship.”

She added, “I believe recording a therapy session changes human behavior.  It changes the patient’s demeanor.”

The form asked my permission to share my health data. Then it wouldn’t let me say no.

27 May 2026 at 12:00

Dark patterns force patients to share their data with big healthcare networks, even when the privacy form they’re signing explicitly says they can opt-out.

Illustration of Alice from Alice in Wonderland, dressed in a patient gown, falling down a rabbit hole surrounded by buttons that say “I accept” and privacy policies
Gabriel Hongsdusit

When Paula Stannard, one of the federal government’s top healthcare privacy officials, visited her eye doctor this year, she was asked to sign a form, acknowledging she’d received a privacy notice about how the office would use her health data. 

“Had I received the notice of privacy practices? No,” she told an audience at one of the nation’s largest health industry conferences in March.

“I did not want to tell them who I was and why they should not be doing that,” said Stannard, who is director of the Office for Civil Rights at the U.S. Department of Health and Human Services. “But I did write a note that says, ‘I have not received this. I am not acknowledging receipt.’” 

Stannard’s story is all too common.

Over the last year, I’ve interviewed more than 20 patients, healthcare providers, experts and advocates about the privacy forms they must sign to get care at their providers’ offices.

Time and again I was told the same thing: Across the country, from large hospital systems to small, private clinics, patients are being asked to sign waivers blindly without knowing exactly what they’re signing.

When patients ask to see more, staff usually don’t have an easy way to show them. When patients do get the forms, it tells them all the ways their medical data will be shared and reused, and some of the ways patients can refuse. But electronic systems make it impossible to opt out on the spot, requiring follow up emails.

Records sharing between unaffiliated providers through these networks can benefit patients by making their scattered records more visible to the provider who is treating them. 

But it can also harm patients.

Patients seeking an abortion may not want records to travel with them from a state where that treatment is legal to one where it is criminalized.

In other cases, companies, such as GuardDog, have admitted to accessing patient records “under the guise of treatment” and funneling them to personal injury law firms.

Researchers have also found healthcare workers snooping through electronic health records. Other dangers include data breaches and serious potential for misuse, such as domestic abusers stalking their partners though the pediatric records of their children.

There’s not much patients can do to limit the risks of their data being available across networks, except by aggressively pursuing opt-outs when providers offer them. Turns out, that can be pretty hard to do. 


Gale Oleson is a retired dermatologist in Missouri who recalled visiting the emergency room after a hand injury.

“They hand me the signature pad,” he said. “They said, you have to sign this so we can do the procedure. And I said, well, I don’t know what the heck I’m signing. Is it like you get my house today? You know, you could be taking my car, you know, signing over my life insurance. And they just laugh, you know?

“… In those situations, I’ve had them either turn the screen to me or I request that they print out a copy for me to review and they’ve always done it, but it’s always a ‘I forgot how a printer works’ kind of thing.”

Experts have a name for this practice: “Dark patterns,” which are manipulative design choices that steer people into doing things or making decisions they otherwise would not make. It’s easier to check the box to say that you’ve received the privacy notice, even if you haven’t. It’s easier to sign the digital signature box, even if you can’t see what you’re signing.

The alternative — saying you didn’t get the privacy notice, or asking repeatedly to see what you’re signing — sounds like a simple request, but can be scary for patients. Many of the patients I’ve interviewed, including a lawyer who works as a privacy advocate, told me they’re afraid that speaking up or pushing back against terms they don’t agree to will make health providers categorize them as inconvenient patients and make it harder to get the care they need.

As a privacy researcher, I’ve experienced this hesitation myself. Last year, I wrote about the epic lengths I went through to get a copy of the consent forms I signed when my toddler needed surgery. When my child was strapped to a movable bed, the surgeon standing there at the ready, I was asked to verify my signature on a consent form. When I asked if I could have a copy of it, a nurse said she wasn’t allowed to give it to me — and sent me to a ghost office at another hospital to search for it. In the moment, I let it go, so I wouldn’t hold up the surgery. Later, after asking multiple people for help, I was finally able to get a copy

To experience more of what patients have to deal with and test whether they’re able to successfully get the information they need, say no, or opt-out of having their data shared, I checked out over a dozen health care systems myself by registering and going to appointments in Iowa, New Jersey, New York, Ohio, Oregon, South Carolina and Virginia.

One telehealth appointment with a provider showed me how easily dark patterns force patients to share their data with big healthcare networks, even when the privacy form they’re signing explicitly says they can opt-out. 

In October 2025, I booked a telehealth appointment with a women’s health clinic in Virginia, after a source was frustrated with the clinic’s check-in process. During registration, I was asked to sign their notice of privacy practices. It’s the same type of form that Stannard never got, but was asked to say she did.

The notice told me that I was giving them permission to let my physician share my health data with a health information exchange, a network that allows providers to search my medical records, like lab results or medical history, from other health organizations when they treat me. These networks can be regional, state-wide or national in reach. The privacy notice says that by signing the form, “you agree to have your medical information shared.” 

It also says I have two other choices:

  • Say no by following instructions on the opt-out form, but there’s no link to the form. 
  • Say yes now and kick off the opt-out process later by sending an email. An email address is provided.

But when I got to the end of the privacy notice, I wasn’t allowed to say no. I had only one choice: “I accept.” After that, there’s a spot to type my name “to accept the policy,” check a box that I understand that I’m electronically signing, and a big button to “Continue.”

The last part of a web form. It starts with an unselected button for “I accept.” Next it reads “Please enter your full name in the textbox below to accept the policy” with an empty box underneath. Next there’s an empty checkbox with text next to it that reads, “I understand that by typing my name and clicking on “Continue”, I am electronically signing this document”. Finally, there’s a button at the bottom that reads “Continue”.

I ignored the accept button and tried clicking “Continue.” An error message told me I couldn’t move forward unless I hit “I accept.”

Fields in the form are highlighted in red, with a warning message that reads, “This form is mandatory. Please accept the form to continue.” Another note says “Incomplete required questions.”

I was at a crossroads. The privacy notice literally describes “Say No Thanks” as a choice, but doesn’t let me pick it.

At this point, most of the patients I’ve interviewed would probably click “I accept” and move on, even if they wanted to keep their information private. But I was researching what patients have to do for healthcare systems to honor their wishes around consent and privacy, so I stopped filling out the form.

Instead, I emailed the address on the privacy notice. I was surprised that an employee got back to me that day, shared the opt-out request form, and confirmed that “registration is required to opt-in.” She also told me her company, which manages this consent process for the information exchange, will process my opt-out after I sign it and they’re able to process it. The risk is that they might not do it before my appointment. I emailed her back and asked what we should do about this, since the original privacy notice says, “Please note, your opt-out does not affect health information that was disclosed through HIE [health information exchanges] prior to the time that you opted out.” How could we make sure none of my information is shared? 

The next day, she replied that her company would proactively opt me out of the information exchange, that I should still complete the opt-out form she sent me, and that “You should now be able to complete your check-in, and the setting will remain unchanged.”

When I went back to check in for my appointment, I clicked “I accept,” because the health services company assured me nothing will change. Just to be safe, I wrote “I opt out of HIE” and my initials, “AR” into the box where I’m supposed to write my name.

When I wrote to a manager of the women’s clinic about this, they stood by Privia’s process and said that Privia makes themselves available for patients who want to opt-out.

“This is a dark pattern,” said Lior Strahilevitz, a legal scholar at the University of Chicago who has published papers on privacy and dark patterns and teaches health law. In fact, Strahilevitz sees multiple dark patterns in the patient registration process I went through.

One is called an “obstruction dark pattern,” which means the design makes it harder for patients to make any choice except the one healthcare providers want. 

Another dark pattern was “visual interference” where the interface makes it hard on the patient. “The patient’s going to have to face inordinate burdens in order to make an autonomous choice,” he said, because they will need to go “outside the user interface, outside the screens, in order to exercise your opt-out rights.”

Lucia Savage, former chief privacy officer at the federal health IT office, called the Office of the National Coordinator for Health IT, said that problems like this can happen when people carelessly put physical forms online. “This isn’t really a design at all,” she said. “This is just a bunch of paper pasted onto a web page. Could you even really call it design?”

So, is all of this legal?

Legal experts point out that only one element of the check-in process violates the spirit of health privacy law, and it’s not the part I expected.

In Virginia, where I had my appointment, it’s legal for providers to opt patients in at registration and give them a way to opt-out later.

Some states, like Florida and New York, require providers to get a patient’s explicit consent before they can share or access a patient’s data from information exchanges. Other states, like Arizona and Maryland have laws that allow data-sharing through health information exchanges by default, as long as providers tell patients and give them a way to opt-out. Some states have not passed any additional regulations, which means they follow the federal baseline. Federally, under the Health Insurance Portability and Accountability Act (HIPAA), sharing a patients’ data in a health exchange is legal.

According to Sarah Jaromin, a health policy specialist at the National Conference of State Legislatures, in Virginia, there is no current state policy with explicit opt-in or opt-out requirements.

Craig Konnoth, a law professor at the University of Virginia who specializes in health and civil rights looked at the privacy notice I was asked to accept. “You have the choice as to whether your data is going to be used. In this particular situation, ‘we are going to use your data until you file in the opt-out paperwork’ — then that’s actually kosher,” he said. 

What experts say violates the spirit of the law, however, is requiring that patients sign the privacy notice itself. 

When I was checking in, the privacy notice forced me to add my signature and click “I accept” before I could click “Continue.”

“What becomes problematic for me is that you can’t actually proceed. The design forces you to do something that the HIPAA privacy rule does not require you to do,” said Stacey Tovino, a professor who teaches HIPAA privacy law at the University of Oklahoma College of Law. (Full disclosure: As a part of my role as Director of Sociotechnical Research at The Markup and CalMatters, I am combining a broader journalistic investigation with a small ethnographic research studying on digital patient intake procedures, The Markup paid Tovino to consult on the HIPAA implications of my findings, but she did not participate in data-collection or editorial decision-making.)

Nothing in HIPAA requires them to make you sign the notice,” said Tovino. “If they don’t obtain the signature they simply have to document why they didn’t get it.”

There’s an important nuance here. At a doctor’s office, patients usually have to sign and give consent to treatment and financial responsibility policies before they can actually get medical care. But when it comes to privacy notices, HIPAA only requires healthcare providers to ask that patients acknowledge receiving it. Patients should be able to ignore it. 

Many of the privacy-focused patients I interviewed, including those who also work as doctors and nurses, deliberately decline to sign a notice of privacy practices if it contains terms they disagree with. But when modern check-in technology refuses to let a patient move forward without agreeing to the notice of privacy practices, is that legal?

Emily Hilliard, press secretary at the U.S. Department of Health and Human Services (HHS), confirmed that the HIPAA privacy rule does not require providers to get a patient’s consent to their privacy notice, but it also does not “prohibit covered entities from requiring individuals to acknowledge, or agree to the terms of, an NPP.”

In other words, requiring patients to agree to a privacy notice before getting treatment is legal.

“Likely because HHS never envisioned this happening, HIPAA does not explicitly prohibit a covered entity from requiring an acknowledgement of receipt of the notice of privacy practices as a condition of treatment,” said Adam Greene, a partner at the law firm Davis Wright Tremaine who focuses on health information, privacy and security.

“HHS has heard about widespread problems with the acknowledgment of receipt of the notice of privacy practices becoming an obstacle to patient care and a cause of confusion,” he said. “In 2021, they issued a proposed rule that, amongst other things, proposed deleting the requirement for an acknowledgment of receipt of the notice of privacy practices.” The rule was never finalized, but it is back on the agenda this year. 

Stannard confirmed that at HHS, “we are in the process of finalizing the rule which includes some additional requirements for the notice of privacy practices.”

The current proposed rule includes, “Eliminating the requirement to obtain an individual’s written acknowledgment of receipt of a direct treatment provider’s Notice of Privacy Practices.”

Experts say patients should be able to opt out immediately — not eventually

Legal experts say that regulators can fix this problem with one fell swoop: make it a rule that companies must let patients opt-out right away, at the same moment they’re notified that they can.

“Amend these [federal] regulations to say covered entities shall not impose an undue burden on people trying to opt out. Covered entities shall not make it functionally problematic. Covered entities shall not, in registration documents, force people to proceed, thus waiving their right to opt out at the earliest possible time,” Tovino said.

She suggested that when a company notifies someone of their right to opt out, the next sentence should include a link to do so.

Savage agreed that this change would “absolutely” be a substantial intervention. “I believe that’s something OCR [Office of Civil Rights at HHS] could do in regulations.”

At the same event where Stannard shared that her eye doctor asked her to acknowledge a privacy notice she never got, I asked her, “Would updating the privacy rule to require a live link when patients make a choice to opt out or into sharing their information be empowering to Americans as individual patients?” She’d just spoken about U.S. Health Secretary Robert F. Kennedy Jr.’ s agenda “to empower individuals with their own health information.”

“That’s an interesting idea,” Stannard responded. “I don’t remember if we’ve considered it before. It’s certainly something that we could consider going forward.” 

One registration form, but a cocktail of technology companies

Navigating the dark patterns in the check-in process was difficult. What I’ve learned however, is that it’s hard to know who picked that interface to use with patients. Did it come from the clinic or the sprawl of vendors that health facilities have come to rely on? 

Private clinics often partner with multiple outside companies (vendors covered by HIPAA) to get technology and administrative support. My appointment involved three different companies: 

  • The mobile link I received to check-in for my appointment comes from a company named Phreesia, which handles patient-facing software, like consents, medical screening surveys and payment. When a patient clicks through those consent forms in the U.S., it goes through Phreesia every 1 in 6 patient visits
  • The clinic had joined Privia Health, which handles management services for nearly 5,000 providers across 15 states, which affect 5.2 millions patients, according to a 2025 press release. The privacy notice I struggled with sent me to Privia’s medical records office to opt out. Phreesia’s logo was also on the copy of my forms that the clinic emailed me. 
  • Finally, for my second telehealth appointment six months later, the clinic sent me a link with the name of another vendor, “athenahealth,” in it. The clinic had replaced Phreesia with athenahealth entirely.

“Unless you’re a really giant system,” said Savage, “you don’t have internal expertise on how to do this. So you buy it. You buy what’s plug-and-play and what’s affordable.” 

The Markup and CalMatters asked all three companies who was responsible for the design of the patient registration interface, and no company gave us a clear answer.

Privia: “Privia is committed to the privacy and security rights of our patients’ information and to ensuring we comply with all regulatory requirements regarding our use of that information,” said Robert Borchert, senior vice president of investor and corporate communications at Privia Health.

athenahealth: “athenahealth provides technology that healthcare providers use to manage patient registration and clinical workflows … configured according to each provider’s requirements and applicable law,” read a statement from athenahealth, provided by Nikki D’Addario, senior public relations manager.

Phreesia: “It is the provider’s form and they determine the content and interface options,” said Dori Zweig Young, Phreesia spokesperson.

None of the companies responded to detailed written questions about how much control clinics have over the interface.

A blindspot for regulators and how it can be fixed

Outside of healthcare, regulators, like the Federal Trade Commission (FTC), the Consumer Financial Protection Bureau (CFPB) and multiple state attorneys general and agencies, have called dark patterns manipulative or abusive tactics that confuse consumers about their privacy choices or lock consumers into paying for services (like the famous Amazon Prime case). Researchers consistently find that people want more control over the context of how their data is shared, and that patients are least comfortable handing over blanket access with broad, open consents, even if they are largely willing to share it for specific uses.

Strahilevitz explained, however, that agencies like the FTC and CFPB, which have been the most active on regulating dark patterns, regulate privacy within their zones, and only occasionally take on boundary cases.

“Health privacy, for the most part, is going to be primarily addressed by HIPAA and Health and Human Services rather than the FTC Act and the Federal Trade Commission,” he said. “There are limits on [the Commission’s] ability to protect patient privacy because that’s basically another entity’s job.”

Greene and Savage both agreed that the Federal Trade Commission has jurisdiction to enforce against dark patterns as unfair or deceptive practices in for-profit healthcare entities. The clinic I went to, like hundreds of thousands across the country, is for-profit. 

But HHS has a broader mandate to regulate healthcare organizations, including non-profit hospitals. 

For example, Strahilevitz said, in consumer finance, regulators at the Consumer Financial Protection Bureau treat a practice as unfair or deceptive when a consumer cannot reasonably avoid the resulting injury. Just as hard-to-cancel online subscriptions force people to pay more, maze-like opt-out structures force patients to pay with their data by default.

Strahilevitz said this provides a framework for thinking about privacy injuries in healthcare. An information exchange could serve as a clearing house for information about a patient’s abortion, which has a clear potential for injury if that information becomes known in a state where abortion treatments are criminalized.

“In other privacy contexts, the courts have said where it’s literally possible to opt out of something but, practically quite difficult, unduly onerous, then we’re not going to treat that as creating an opt-out right,” he said. 

Savage sees more opportunities in carrots than sticks to get to best practices. She argued that the government could invest in good interface design that’s open source and available for anyone to use, and the federal health IT office, where she used to work, could create competitions focused on improving the technical tools that providers buy and use.

If the big technology vendors that independent clinics are already using make these changes, it could affect millions of patients.

State regulation is another possible solution. Strahilevitz said that scrutiny of dark patterns is spreading as states, like California, and regulatory agencies, like the FTC, seek to reign in unfair or deceptive practices through the simple intervention that it should be as easy to cancel as it is to subscribe, with one click.

“I hope that at some point, we’ll get to a point where symmetry of choice is the law of the land, not only with respect to consumer privacy in some states, but to these kinds of medical privacy or financial privacy or other contexts,” he said.

It’s easier for Californians to escape data brokers following a Markup investigation

22 May 2026 at 12:00

The Markup and CalMatters showed how website code could make it harder for Californians to exercise their right to remove personal data. Now much of that code has disappeared.

A woman wearing glasses speaks into a microphone during a congressional hearing while holding a blue pen in one hand. A nameplate reading “MS. HASSAN” sits in front of her as other attendees appear out of focus in the background.

Sen. Maggie Hassan pressed data brokers to make it easier to opt out of their systems, citing an investigation by The Markup and CalMatters, published in partnership with WIRED. U.S. Sen. Maggie Hassan speaks during a Senate Finance Committee on Capitol Hill in Washington, D.C. on March 14, 2025. Photo by Ben Curtis, AP Photo

More data brokers have changed their practices in response to reporting from The Markup and CalMatters as well as a subsequent Senate investigation.

Data brokers — companies that collect and sell access to often-sensitive information on consumers — are required to register in the state of California and provide a way for consumers to request their data be deleted. 

Last year, an investigation by The Markup and CalMatters, published in collaboration with WIRED, showed that many of those companies placed code on the web pages for making those requests that prevented them from appearing in search results. The “no-index” code tells search engines like Google not to catalog those pages, making it less likely that anyone would see them. Experts said that’s a hurdle for Californians looking to exercise their legal rights. 

Last year’s investigation found 35 data brokers were using the code, 12 of whom soon removed it and allowed their pages to appear in search results.

Today, only eight of those 35 brokers are still hiding their deletion pages, according to another review done by The Markup and CalMatters this week. That includes five major data brokers who came under Senate investigation.

After The Markup and CalMatters published their report, the top Democrat on the Senate Joint Economic Committee minority, New Hampshire Democratic Sen. Maggie Hassan, sent letters to five data brokers questioning them about their practices.

Four of the companies — IQVIA Digital, Comscore, Telesign Corporation and 6sense Insights — engaged with the Senate committee about their practices and agreed to make their pages visible in search, according to a report the committee later released. The report also estimated that consumers have lost more than $20 billion from fraud and identity theft related to broker data breaches. 

In an addendum to their initial findings released last week, the committee said that the fifth company facing questioning, Findem, also belatedly removed its “no-index” code, making its deletion pages visible in search engines. 

One of the data brokers no longer hiding its opt-out page, BrightCheck, has a broken opt-out page and no longer appears on California’s broker registry.

Data brokers that hid opt-out pages from search engines

Of 499 brokers registered with the state of California, The Markup and CalMatters in August 2025 found 35 instructing search engines to ignore pages with instructions on how consumers can remove their data. As of May 2026, only eight had such instructions. 
Chart: Tomas Apodaca · Source: California Privacy Protection Agency 2025 Data Broker Registry

Of the eight brokers still hiding their deletion pages, only one, a company called Fideo, responded to a request for comment about whether they would continue using the code on their pages.

Jason Soni, a spokesperson for Fideo, which uses data for crime and fraud prevention purposes, said the company intentionally “chose not to display the application page itself in Google search results for technical and consumer experience reasons.” Consumers, he said, can make requests starting “from our homepage and public privacy resources, which provide the right context, routing, and instructions for privacy requests,” instead of starting at the application page. 

“Americans deserve a choice over whether their personal data is collected, used, and sold for profit or not,” Hassan said in a statement released alongside the amended report. “Data brokers like Findem have a responsibility to provide that choice with clear, user-friendly opt-out functions and straightforward privacy policies.

Websites break California privacy law at ‘industrial scale,’ survey finds

21 April 2026 at 12:00

Tech companies like Google, Facebook and Microsoft are ignoring data controls mandated under California law, researchers say.

The reflection of people walking along a sidewalk is seen on a glass window of a storefront with the Microsoft logo on it. Yellow taxis, trucks and cars can also be seen in the reflection.
Photo by Zamek, VIEWpress via Getty Images

A new audit has found that websites across the internet may be failing to abide by California privacy law, ignoring a requirement to not track visitors who set a privacy control. 

The report, from researchers at webXray, a firm headed by a former Google privacy engineer, said the findings suggest major companies may be simply ignoring the law, and could point to “industrial-scale noncompliance with California requirements.”

The stakes are potentially high. WebXray estimates that if the California Privacy Protection Agency fined all of the websites it found failing to comply with the law, it could result in billions of dollars in penalties. 

“While we don’t have comment on the finding of this specific report,” Tom Kemp, executive director of the privacy protection agency, said in a statement, “we do appreciate that the report brings visibility to the importance of opt out rights.” 

Under California law, businesses are required to respect a signal called the Global Privacy Control. If users navigate the web with the control turned on — either through a setting in the browser or a third-party tool — it tells websites not to sell or share their personal information.

The California Consumer Privacy Act requires businesses to acknowledge the control and to not track people who use it. The state privacy agency has fined companies millions for failing to honor the control, among other violations. 

To understand whether the law is truly being respected, the researchers visited more than 7,000 popular websites from a California internet address. According to the report, major tech companies continued to track users, even with the signal turned on.

Google continued to track users in 86% of cases despite receiving the signal, according to the report. When visitors traveled to the websites while using the signal, the sites still frequently set a cookie from Google to follow those visitors.

Similarly, according to the report, Microsoft failed to honor the signal in 50% of instances. 

The report found that trackers from Facebook parent company Meta don’t just ignore the signal — they fail to check for it at all, leading to tracking 69% of the time despite the signal. 

All of those failures could be remedied with slight changes to the tracking code to respect the signal, the engineers said in the report. 

“They don’t make any substantive effort to comply,” said Tim Libert, founder and chief executive of webXray. 

The report also found that third-party tools that purport to help businesses place advertisements that comply with the law still frequently failed to honor the anti-tracking signal. In one case, a product did not honor those requests more than 90% of the time, the report found. 

The tech companies dispute the idea that they are failing to abide by the law. 

“As outlined in our Privacy Statement, when we receive a GPC signal, we opt the user out of sharing personal data with third parties for personalized advertising, and our advertising systems are designed to reflect that choice,” Courtney Ramirez, a Microsoft spokesperson, said in a statement. “Certain Microsoft cookies are necessary for operational purposes, and may therefore be placed and read even when a GPC signal is detected.” 

Jackie Berté, a spokesperson for Google, said the company complies with the law and that the audit was “based on a fundamental misunderstanding of how our products work.”

A spokesperson for Meta didn’t immediately respond to a request for comment. 

“The idea that I misunderstand anything is a demonstrable falsehood,” Libert said, pointing out his work on cookie policy at Google. 

“I would assert that, when I was there, I knew more about it than anybody else,” he added. 

Background checks to curb dating app violence advance in California legislature

By: Lynn La
17 April 2026 at 18:00

Bill addresses an issue investigated by The Markup last year.

A close-up view of a person holding a white cell phone with both their hands. A ray of light softly illuminates the person's left hand.
Lauren Justice for CalMatters

A California bill to protect people on online dating apps from violence has critics arguing that the measure would put a “scarlet letter” on certain users.

But that’s a feature, not a bug in the proposal. 

The state Senate’s public safety committee this week passed a bill that would require online dating services to run criminal background checks on California users. If the user is a registered sex offender or has been convicted of a violent felony, domestic violence, an assault or a hate crime, the dating service must “place a flag” on the user’s profile to let others know.

Bill author, state Sen. Caroline Menjivar, said that “dating apps have not provided an adequate level of safety for their users.” At the hearing she cited a 2019 Columbia Journalism Investigations survey that found that more than a third of women polled said they were sexually assaulted or raped by someone they met on a dating app.

The Markup last year published an investigation that showed people accused of sexual violence managed to stay on the apps even after victims reported them.

Menjivar, a Van Nuys Democrat, added: “If women, mostly women, continue to be raped or murdered — like another woman (who) was murdered and her body was set on fire last year after a man met her on a dating app — those are the incidents we’re looking to prevent.”

But besides labeling users with a “scarlet letter,” implementing the policy would require dating platforms to collect a significant amount of personal data to avoid misidentifying users, argued Jose Torres, a deputy executive director for the industry group TechNet.

In a rare break with his Democratic colleagues, Sen. Scott Wiener of San Francisco voted against the bill, saying it might have “significant unintended consequences in terms of people’s privacy.” But Wiener’s opposition, along with Republican Sen. Kelly Seyarto of Murrieta, was not enough to stop the bill from advancing out of the six-member committee, according to the Digital Democracy database from CalMatters, of which The Markup is a part. 

With four Democratic lawmakers giving the green light, Menjivar said she plans to amend the measure in response to criticism related to the categories of crime and operational challenges — and that legislators are “going to see a dramatically different bill” when it’s presented to the privacy committee on April 20.

The Markup wins SABEW Award for Best in Business Journalism

30 March 2026 at 12:00

The 18-month-long investigation about how Tinder, Hinge, and their corporate owner kept rape under wraps won in the technology reporting category.

Graphic of a screenshot of The Markup's story "Dating App Cover-Up: How Tinder, Hinge, and Their Corporate Owner Keep Rape Under Wraps" next to the text "WINNER," the headline of the story, and the Society for Advancing Business Editing and Writing’s Logo
The Markup

The Markup’s collaborative investigation “Dating App Cover-Up: How Tinder, Hinge, and Their Corporate Owner Keep Rape Under Wraps” has won in the Society for Advancing Business Editing and Writing’s 2025 Best in Business Awards. The story was produced in partnership with the Pulitzer Center’s AI Accountability Network and was copublished with The Guardian and The 19th.

The 18-month-long investigation about how Tinder, Hinge, and their corporate owner kept rape under wraps won in the technology category. The award recognizes excellence in digital journalism covering all aspects of technology, including culture, policy, and economic impact.

Judges said that the collaborative investigation “draws readers into the dark hole of dating apps’ safety practices, along with how the industry’s dominant player turned a blind eye to the predators roaming its products. With urgency and moral clarity, reporters Emily Elena Dugdale and Hanisha Harjani shine a light on how an investor-pressured Match Group concealed accusations of sexual violence on its dating platforms.”

The Markup previously won four SABEW awards in the 2022 Best in Business Awards.

The most recent investigation is based on a review of hundreds of pages of internal company documents, thousands of pages of court records and securities filings, and dozens of interviews with company insiders and sexual violence survivors. In it, reporters Emily Elena Dugdale and Hanisha Harjani reveal that the Match Group, the world’s largest dating app company, had known about violence on its apps for years and failed to disclose that information with the public.

The investigation centers on a Denver cardiologist, who was sentenced to 158 years in prison after being convicted of drugging and/or sexually assaulting 11 women. We found Match Group was aware of his behavior for years — and yet he remained on its apps, swiping and assaulting.

Innovative product testing, led by statistical journalist Natasha Uzcátegui-Liggett, found banned Tinder users, including those reported for sexual assault, can easily rejoin or move to another Match Group dating app, all while keeping most key personal information the same.

Ten months after the investigation, Uzcátegui-Liggett checked if the accounts created by The Markup in February, which had the same name, birthday, and profile photos of banned accounts, had been eventually banned by Match Group or its moderation systems. Every account checked was still in good standing.

The reporting team overcame many obstacles. Survivors were reluctant to speak, potential whistleblowers cited NDAs. In Colorado, a district court judge sought to prevent us from accessing critical records—including testimony from police officers and Tinder and Hinge messages read in open court.

In December, six women who were attacked by the cardiologist filed a lawsuit, accusing Match Group of “accommodating rapists across its products” through “negligence” and a “defective” product. The 54-page complaint extensively cites our investigation. 

In California, state lawmakers said they are preparing legislation to reform the industry. On Feb. 20, 2026, Democratic state senator Caroline Menjivar introduced a bill that would require dating apps to conduct criminal background checks for California users.

Congratulations to all of this year’s SABEW Awards honorees.

It was John Wayne’s political club. Now it’s spending millions on online influence

9 March 2026 at 12:30

The Lincoln Media Foundation has spent big to push ‘local’ conservative messaging

A close view shows a person using a laptop displaying a news website with a headline and photo on the screen. Another laptop sits nearby on the desk, and the scene is set in a modern office environment with glass walls and overhead lighting.
Photo via iStock

A conservative organization with decades of influence in California has quietly turned attention, and millions of dollars, to a national initiative of right-leaning news operations, records show. 

The Lincoln Club was established in the early 1960s by a group of California business leaders. Since then, it’s been a quiet but formidable force in state and local politics, pushing right-leaning causes and candidates. 

But in the past few years, an affiliated organization, the Lincoln Media Foundation, has massively increased its incoming revenue as it pushes online content with a conservative slant under the guise of local news in markets around the country. 

According to Internal Revenue Service disclosures, the foundation had a little more than $400,000 in net revenue for the fiscal year ending in 2021, all of it from contributions. 

By the fiscal year ending in 2024, the most recent disclosure available, that revenue had ballooned almost 10 times, to nearly $4 million. 

Lincoln Media Foundation grew rapidly

The foundation's annual revenue in dollars.
Source: Lincoln Media Foundation IRS filings via ProPublica

In the same period, the Lincoln Club itself grew more modestly, not quite doubling its revenue to just over $3 million, according to records.

According to independent research and promotional material produced by the club’s media foundation, its money has gone toward creating a network of websites across the country, with the hopes of influencing the public and swaying voters in key states.  

Many of the sites, first flagged by the researcher Max Read of the Institute for Strategic Dialogue, say they are locally organized, with names like The Angeleno and The Keystone Courier.  CalMatters and The Markup recently explored another site linked to the organization, called the California Courier, using the same name as an unrelated Armenian newspaper. The Courier produces a steady stream of often unattributed articles about political controversies throughout the state and pays Facebook to promote those posts and videos on similar topics. 

Critics say the group is attempting to influence the public with the veneer of local news that fails to offer clear disclosures about the messenger. 

Kevin DeLuca, an assistant professor of political science at Yale University who has studied similar news sites, sometimes called “pink slime” news, told The Markup and CalMatters earlier this year that such sites may not be outright lying. Still, the sites often fall short of traditional journalistic standards, failing to properly attribute stories and funding, or heavily pulling and slanting press releases.

Jim Miller, a labor activist and co-author of a progressive history of San Diego, called the tactic “a menacing example of the use of stealth.” 

“If you don’t think you can win an argument in a transparent debate publicly,” he said, “you try to disguise the messenger as much as you can.”

Neither the club nor the foundation responded to requests for comment or interviews with executives about its work.  

The Lincoln Club

The Lincoln Club of Orange County was established in the 1960s by wealthy local businessmen eager to spread pro-business Republican ideas locally and nationally. Those businessmen donated handsomely to sympathetic candidates and causes. 

The club became a power player in Southern California politics when Republicans had more leverage in the Golden State. The group still boasts online of having counted among its ranks famous California political figures like Richard Nixon and John Wayne. 

A 1972 article in The New York Times described it as a group “made up largely of millionaires” who “boast that, without their efforts and generosity, [Nixon] would not be occupying the White House today.” The Times article described the group as an organization with “many secrets” that shunned publicity but successfully influenced the political scene. 

“I think they were very influential back in the ‘60s and ‘70s,” said Steve Earie, professor emeritus of political science at the University of California, San Diego.

By 1996, as the Los Angeles Times reported at the time, the group’s financial power had waned in the face of internal battles, but the club continued to wield influence. 

The group, according to legal documents, partly funded the 2008 anti-Hillary Clinton documentary that became the subject of the landmark Citizens United Supreme Court decision that opened the door to unlimited spending by corporations and unions on elections. 

In 2012, the group was described as the key architect of Proposition 32, a ballot measure that would have severely curtailed the power of unions in the state by limiting their ability to collect and spend funds for political purposes. The ballot measure ultimately failed. 

Although its light may have dimmed from 50 years ago, the Lincoln Club still exerts influence in California politics.

“If you look on their website, they don’t start it talking about helping businesses, the quality of life,” Earie pointed out. “They talk about ‘preserving the American way of life.’ And that’s as much cultural as it is economic.”

A new strategy

Despite its old Republican roots, the group appears to have moved into a 21st-century online influence strategy with the Lincoln Media Foundation. 

According to a promotional video, the foundation uses targeted web ads to broadcast its message where it can reach key voters in battleground states. 

In one recent LinkedIn post accompanying a video explanation of its work, the group says it acts as a corrective to “material omissions, alternative sets of facts, and outright lies” by the media.

“Our country can’t stay free if we’re not informed with the truth,” the video reads, describing the group as a “megaphone” for “unbiased truth.” The video says it delivers that information through 27 publications in seven states, reaching millions through online advertising.  

In reality, even the video is far from unbiased — a stream of germ-like images of “DEI” and “Russiagate” float by in front of the voiceover.

The launch of the foundation, and the disclosures showing it’s well-funded, suggest a new turn for the decades-old group, from one trying to influence politics through candidates to one willing to broadcast its message directly through online influence.

“Unfortunately, it’s a pretty good strategy,” Miller said. 

Recently, headlines published by websites linked to the group have slammed everyone from Democratic school board officials in Orange County to Pennsylvania Gov. Josh Shapiro, while approving of President Trump’s foreign policy. 

The accompanying stories are then pushed on social media platforms to what the video describes as the most influential two percent of voters in the country and as a key part of the group’s strategy. 

Meta, Facebook’s parent company, has rules against “inauthentic activity” on its platforms, although a spokesperson for the company told The Markup and CalMatters that sites linked to the organization weren’t breaking those rules. 

Lincoln Media Foundation isn’t alone in using the strategy to spread its views. Most famously, a right-leaning group called Metric Media has produced sites across the country pushing a right-wing message. As sites with murky attribution and sourcing practices proliferate, experts worry that artificial intelligence tools like ChatGPT could supercharge their tactics. 

“It’s going to make these pink slime sites even harder for people to know that what they’re reading is not from a human source and not really local investigative journalism,” DeLuca says. 

Even with its rapid growth, the Lincoln Media Foundation is only a slice of the hundreds of millions of dollars spent yearly on similar causes, according to a tally by some observers. Not all of those groups use the language of local news to spread their message.

The strategy works, the foundation’s video promises. 

“It’s ad-delivered truth, inoculating lies, and preserving freedom from the inside out,” the video says.

California colleges spend millions on faulty AI systems: 'The chatbot is outdated’

7 March 2026 at 13:00

Community colleges are spending millions on AI-powered chatbots that students say often give inaccurate answers. Many might see upgrades this year.

An illustration in green, red, blue and yellow tones that shows a desktop computer screen with an open window tab that resembles a Pokemon battle scene. At one end of the screen is a pixelated student and at the other is a wolf that represents a chatbot. The illustration includes a bubble text that reads "where can students get free food on campus?" alongside other bubbles of text with red exclamation points.
Illustration by Adriana Heldiz; iStock

California community college districts are spending millions of dollars on artificial intelligence-powered chatbots intended to help students navigate admissions, financial aid and campus services. 

However, they struggle to consistently provide clear and accurate answers, leaving students frustrated and seeking help from others on unofficial social media channels.

In testing by The Markup and CalMatters, they often answered general questions correctly but struggled with more specific ones. East Los Angeles College’s bot couldn’t even correctly name its own president.

Contracts for these chatbots can be pricey and last for years. Three community college districts that responded to a Markup and CalMatters survey reported annual costs ranging from about $151,000 to nearly half a million dollars. At the Los Angeles Community College District, the state’s largest community college system, contracts and amendments approved since 2021 total about $3.8 million through 2029, according to district board documents.

Community college districts that responded to The Markup and CalMatters have contracted with chatbot platforms such as Gravyty and Gecko, which district officials say handle thousands of conversations each month, many outside regular office hours, helping to reduce calls and save students unnecessary trips to campus.

Some of these chatbot platforms rely on manually maintained libraries of frequently asked questions and campus websites to answer questions, which can lead to errors when information is outdated or questions fall outside the system’s database. 

However, officials are working to improve them. Districts like the Santa Monica Community College District have moved to ChatGPT-integrated AI systems that scrape the college’s website to generate answers, which officials say seem more reliable. In the Los Angeles district, officials say they plan to transition to a new AI chatbot platform as early as late spring.

Looking for answers

Improvements to the chatbot couldn’t come soon enough for students like Pablo Aguirre, a computer science major at East Los Angeles College and an information technology intern at the Los Angeles college district office.

Aguirre mostly avoids the chatbot himself because, he said, it might provide unreliable or outdated information. He recalled using the bot to find financial aid information, but said he gave up after it kept asking him questions instead of giving him a clear answer.

“I just didn’t find it as useful,” Aguirre said. He usually turns to Google, social media platforms like Reddit and the college’s website when looking for answers.

“Online, some pages don’t work,” Aguirre said, recalling a 404 error message on the college’s website. Even when pages load, he said, it can be difficult to find the right one, such as when he was trying to figure out where to sign up for Extended Opportunity Programs and Services, a state-funded program that supports disadvantaged students. “That’s where I just jump on Reddit,” he said.

Students walking onto campus at Fresno City College on Oct. 3, 2022. Photo by Larry Valenzuela, CalMatters/CatchLight Local
Students walking onto campus at Fresno City College on Oct. 3, 2022.
Larry Valenzuela, CalMatters/CatchLight Local

Aguirre’s experience isn’t unique. Reanna Carlson, a commercial music major at Fresno City College and student government vice president, said her college’s chatbot, dubbed Sam the Ram after its mascot, repeatedly gave her unclear or incorrect answers to basic questions about campus services. Her district, the State Center Community College District, has a nearly $870,000, three-year contract for Gravyty, formerly Ocelot, through June 20, 2026, according to district board documents. Officials pointed out that the contract comes with other services, including tools that let staff engage in live chats or send text messages to students.

“I think the chatbot is outdated and can’t navigate the services we provide on campus effectively,” Carlson said. “I don’t think it’s the most beneficial option when it comes to asking questions.”

Oddly, Carlson got accurate information on the availability of free food at her campus’ Ram Pantry only when accidentally adding a typo to her query. Repeated Markup and CalMatters testing confirmed the same outcome, though the bot sometimes lists links that include the food pantry after clicking an adjacent “sources” button.

“If it weren’t for the amazing staff on campus that constantly remind students of our services, I’d be lost,” Carlson said.

A screenshot of a conversation with a college chatbot.
Screenshots via Fresno City College website

Testing chatbots

When The Markup and CalMatters tested community college chatbots, they generally returned quick, accurate responses to common questions but were less consistent with more specific ones.

For example, when asked, “Who is the current president of ELAC?” East Los Angeles College’s chatbot incorrectly named Alberto Román, who left the position last year to become the district’s chancellor. In another test, when asked, “What is the financial aid office’s current schedule?” the bot provided incorrect hours and dates.

East Los Angeles College campus in Monterey Park on March 14, 2024.
Jules Hotz for CalMatters

East Los Angeles College’s chatbot claims to support several languages, including English, Spanish, Chinese and Vietnamese. But The Markup and CalMatters found inconsistencies when asking it in Spanish, “Do I need a Social Security number to enroll?” Instead of answering the question, the system directed users to visit the registrar’s office to update their Social Security number. When asked the same question in English, the bot pivoted to discussing financial aid.

Fresno City College’s chatbot, powered by the same AI provider as East Los Angeles College’s system, Gravyty, showed similar problems when asked whether a Social Security number is required to enroll. It also often failed to direct students to the correct offices and, in some cases, listed incorrect locations and hours.

Concerns with chatbots have surfaced elsewhere. In New York City, reporting by The Markup and THE CITY found that a city-run AI chatbot provided guidance that could lead to illegal behavior, prompting Mayor Zohran Mamdani to terminate it in February.

'Good answers with fewer errors'

Santa Monica College’s chatbot, powered by Gecko, was more successful in answering most questions. The single-college district uses a ChatGPT-integrated chatbot that scans the college’s website, which staff regularly update and monitor. The district has contracted with Gecko since 2019 and renewed its annual contract for the tool late last year for $57,000, according to district board documents. It initially showed a major hiccup: when asked about mental health counseling, the bot did not mention the campus’ Center for Wellness and Wellbeing. It does now.

A screenshot of a conversation with a college chatbot.
Screenshots via Santa Monica College website

District officials say chatbots’ problems stem from how the tools are configured and the information they draw from, rather than the technology itself.

The Los Angeles district originally adopted its chatbot through Ocelot, which later merged with Gravyty The same chatbot platform is also used on the California Student Aid Commission website.

Betsy Regalado, one of the district’s associate vice chancellors, said the current system relies on a manually maintained library of frequently asked questions that staff at each of the district’s nine colleges help maintain and review at least once or twice a year for accuracy. She added that chatbots are primarily geared for the public rather than enrolled students, who can access more detailed personal information through their campus portal.

“The current chatbot that we have uses a library of questions. If you don’t have that question in that library, then those poor people don’t get an answer or they won’t get an accurate answer,” Regalado said.

She said the district plans to transition all nine colleges to Gravyty’s platform as early as late spring at no additional cost under its existing contract, which runs through 2029. The new system will use AI to scrape college and external websites to generate responses.

“We’re ready for the modernization of (the chatbot) and the change to generative AI. That is the new world out there,” Regalado said.

A Santa Monica College sign is viewed just over bushes, with a row of palm trees behind it, in front of a building on a college campus.
Santa Monica College in Santa Monica on April 16, 2025.
Alisha Jucevic for CalMatters

Santa Monica College’s chatbot similarly initially relied on a manually loaded library of common questions and answers before transitioning to its fully AI system, according to Esau Tovar, the college’s dean of enrollment services. In an email, he said the bot “was never designed to address all aspects of the student journey,” but to answer general questions from students.

Tovar said the bot draws responses from the college’s website, meaning accuracy depends on how current and complete that information is. As a result, the college prioritizes keeping its website up to date so the bot provides “good answers with fewer errors” rather than “great answers with potentially more errors.”

Widely used, cautiously trusted

Acknowledging limitations, community college districts justify the costs by pointing to heavy student use, which would cost significantly more if performed by call center staff around the clock.

Regalado said the Los Angeles district colleges average 5,000 to 7,000 interactions per month. Other districts reported similar monthly use, including 5,000 interactions at the State Center Community College District, which includes campuses in Fresno and nearby counties, and 4,000 conversations at Santa Monica College. Regalado said that as long as the chatbot remains heavily used, her district would continue to support it.

Tovar said the chatbot provides 24-hour support regardless of time zone or location, which he said is helpful for international students when they are out of the country. He said that answering the tens of thousands of questions the chatbots receive around the clock would cost significantly more if handled by staff.

“Every technology has a cost. We would simply not be able to assist all students if they could only reach us using traditional methods,” Tovar said.

But high usage and expanded access do not always translate into trust, especially when students need precise answers to delicate topics.

Bryan Hartanto, a civil engineering major at Santa Monica College from Indonesia, said the college’s newer chatbot system is smoother and can be a useful starting point, especially for students more comfortable communicating in languages other than English. But as an international student he worries that following inaccurate guidance could jeopardize his visa status.

“Maintaining status as an international student right now is very, very sensitive,” Hartanto said. “I would still rely on human or email communication.”

Martin Romero is a contributor with the College Journalism Network, a collaboration between CalMatters and student journalists from across California. CalMatters higher education coverage is supported by a grant from the College Futures Foundation.

He saw an abandoned trailer. Then, he uncovered a surveillance network on California's border

Southern California residents are noticing new license plate readers that appear to be operated by the Border Patrol. Some have had confusing encounters with agents.

A roadside device mounted on a small trailer sits on the shoulder beside a two-lane road as a blurred van drives past, with utility poles, trees, and rocky hills in the background under a clear sky.
An automated license plate reader sits along Old Highway 80 near Boulevard in the Jacumba Hot Springs area of San Diego on Feb. 7, 2026. Zoë Meyers for CalMatters

On a cracked two-lane road on the eastern edge of San Diego County, James Cordero eased his Jeep onto the shoulder after something caught his eye. It looked like an abandoned trailer. Inside he found a hidden camera feeding a vast surveillance network that logs the license plate of every driver passing through this stretch of remote backcountry between San Diego and the Arizona state line. 

Cordero, 44, has found dozens of these cameras hidden in trailers and construction barrels on border roads around San Diego and Imperial counties: one on Old Highway 80 near Jacumba Hot Springs; another outside the Golden Acorn Casino in Campo; another along Interstate 8 toward In-Ko-Pah Gorge. 

They started showing up after California granted permits to the Border Patrol and other federal agencies to place license plate readers on state highways in the last months of the Biden administration. Now as many as 40 are feeding information into Trump administration databases as the Democratic-led state chafes over the federal government’s massive deportation program.

The cameras are raising concerns with privacy experts, civil liberties advocates and humanitarian aid workers who say California should not be supporting the surveillance and data-collection program, which they view as an unwarranted government intrusion into the lives of Americans who’ve committed no crime. Moreover, they say the program conflicts with state law. 

Supporters say the devices allow law enforcement to quickly identify and locate people they suspect of serious crimes. They also argue the cameras help agencies spot patterns in drug and human trafficking, and could be used to help locate missing persons, such as children or other vulnerable people. 

 “If you’re not doing anything illegal, why worry about it?” said long-time Jacumba resident Allen Stanks, 70.   

“Everyone is talking about privacy, OK. Stop putting everything on Facebook. ‘Here’s a picture of my food.’ Who cares?” said Stanks.  

Some locals, however, suspect the cameras are behind some unusual encounters they’ve had in recent months with officers from Border Patrol and its parent agency, Customs and Border Protection. In one case agents questioned a grandmother – a lawful permanent resident  – about why she went to a casino, according to her grandson. 

Cordero has a different concern. On his days off, he leads volunteers into the far reaches of the county, leaving water, food and clothing for migrants. He fears his colleagues could be detained by agents.

“I’m not so much worried about myself, but I’m worried about a lot of our volunteers that come out,” said Cordero. “I don’t want them to have to deal with any of the nonsense of being tracked or being pulled over and questioned.” 

A person wearing a baseball cap and plaid shirt stands with arms crossed beside a rusted metal post outdoors, with shrubs and a clear blue sky in the background.
James Cordero, water drop coordinator for Al Otro Lado, in the Jacumba Hot Springs area of San Diego on Feb. 7, 2026. Cordero is concerned about the use of new automated license plate readers along the U.S.-Mexico border in California.
Zoë Meyers for CalMatters

He has good reason to be nervous. During the first Trump administration, federal officials prosecuted volunteers from the humanitarian group “No More Deaths” for leaving water and supplies for migrants in the Arizona desert. The volunteers faced charges, including “abandonment of property” and felony harboring, though the convictions for some were later overturned.

Border Patrol provides little information about its use of license plate readers on its website. In 2020, the Department of Homeland Security issued a report that describes the technology in general, but doesn’t specify where it’s being used. The Markup and CalMatters reached out to Border Patrol and Homeland Security officials for comment, but did not receive a response. 

“There’s no transparency, that’s the worst part,” Cordero said. 

The Homeland Security report says some readers are capturing license plate numbers, as well as the make and model of the vehicle, the state the vehicle is registered in, the camera owner and type, the GPS coordinates for where the image was taken, and the date and time of the capture. 

The “technology may also capture (within the image) the environment surrounding a vehicle, which may include drivers and passengers,” the report states. It also says feds can access license plate readers operated by commercial vendors. 

Mapping hidden cameras

Earlier this month, the Electronic Frontier Foundation and a coalition of 30 organizations sent a letter to Gov. Gavin Newsom and the California Department of Transportation urging them to revoke state permits and remove the covert readers operated by federal agencies like Customs and Border Protection and the Drug Enforcement Agency along California border highways.

The San Francisco-based privacy and civil rights advocacy organization, also known as EFF, mapped out more than 40 hidden license plate readers in Southern California, most of them along border roadways. It contends the devices bypass a 2016 state law that spells out how law enforcement agencies can use automated license plate readers, which are often referred to as ALPRs.

“By allowing Border Patrol and the DEA to put license plate readers along the border, they’re essentially bypassing the protections under (California law),” said Dave Maass, the director of investigations for EFF. “That is a backdoor around it.”

Maass said he believes Cordero’s concerns about the agency surveilling humanitarian volunteers may be valid. 

“They claim they might be looking for smugglers or they might be looking for cartel members, but that’s not who they’re collecting data on,” said Maass. “(The program) is primarily collecting data on people who live in the region. 

Maass said there’s no way to be certain which agency is installing each camera, but his organization checked with all other agencies operating in the area, such as the San Diego and Imperial sheriff’s departments, the California Highway Patrol, and Cal Fire, among others.

Close-up of a camera unit mounted inside a recessed compartment on a white roadside trailer, with rocky hills and vegetation blurred in the background.
A portable roadside camera trailer sits on the shoulder beside a highway stretching through low, brush-covered hills, with a traffic cone placed near its hitch and trucks visible in the distance.
First: An automated license plate reader sits along Old Highway 80 outside the Jacumba Hot Springs area of San Diego on Feb. 7, 2026. Last: An automated license plate reader sits along Interstate 8 in the southeastern area of San Diego County on Feb. 7, 2026. Photos by Zoë Meyers for CalMatters
A two-lane road curves through a tree-lined valley toward sunlit mountains, with long evening shadows stretching across the landscape.
Automated license plate readers have been placed along Old Highway 80 in the Campo community of San Diego County, on Feb. 7, 2026.
Zoë Meyers for CalMatters

The camera models currently installed on state highways in the border region are the same as ones the Border Patrol purchased in large amounts, according to Maass. Records obtained from Caltrans by EFF from 2016 appear to show Drug and Enforcement Administration and Border Patrol requesting permits to install the same devices in other parts of San Diego County, according to Maass. 

Customs and Border Protection did not respond to a request for comment. The governor’s office did not comment. The Drug Enforcement Agency also did not respond to a request for comment. 

Caltrans approves ALPR requests

By day, Cordero works in water-damage restoration, the crews residents call after floods and burst pipes. Comfortable with emergencies, he’s the type of guy you’d hope to run into if your car broke down in the middle of nowhere. 

“People are literally dying out here,” Cordero says of his volunteer work, done through the nonprofit Al Otro Lado, a legal services organization that also provides humanitarian support to refugees, migrants and deportees on both sides of the U.S.-Mexico border. “All we’re trying to do is prevent people from dying.” 

In response to questions from The Markup and CalMatters, a spokesperson for Caltrans provided a written statement that the state agency has approved eight permits for license plate readers from federal agencies, like Customs and Border Protection and the Drug Enforcement Administration, to be stationed in state highway rights-of-way.

“Caltrans does not operate, manage, or determine the specific use of technology or equipment installed by permit holders, nor does it have access to any of the collected data,” the statement read in part. 

Caltrans said federal immigration agencies haven’t requested permits for the cameras since June 2024. They did not say how long a permit lasts. Between 2015 and 2024, their records indicate Customs and Border Protection and the Drug Enforcement Administration requested 14 permit applications for “law enforcement surveillance devices.” Of the 14, eight were approved, four were cancelled by the applicants and two did not result in projects in state right-of-way, the agency said.

In California, license plates are tracked not only by the federal government and law enforcement, but also by schools and businesses, including some Home Depots and malls. While schools and businesses may not agree to pass that information on to the federal government, local police with access to those cameras may do so.

California law prevents state and local agencies from sharing license plate data with out-of-state entities, including federal agencies involved in immigration enforcement. A Markup and CalMatters investigation in June 2025 revealed that southern California law enforcement agencies, including sheriff’s departments in San Diego and Orange counties, haveshared automated license plate reader data with federal agencies in violation of state law.

A person wearing a cap, sunglasses, and a plaid shirt crouches beside a roadside trailer device, holding a phone up to photograph or inspect its rear panel, with brush and dirt terrain in the background.
James Cordero, a water drop coordinator for Al Otro Lado, photographs the camera on an automated license plate reader outside the Jacumba Hot Springs area of San Diego on Feb. 7, 2026.
Zoë Meyers for CalMatters

Newsom vetoed a bill to strengthen California license plate reader law last fall. Two days later, Attorney General Rob Bonta filed a lawsuit against the city of El Cajon for multiple violations ofthe license plate sharing prohibition. Since 2024, the attorney general’s office has sent letters to 18 law enforcement agencies, including the Imperial County Sheriff’s Office, the San Diego Police Department, and the El Centro Police Department.

Local agencies continue to share license plate data with federal immigration authorities, and not just along the border. The San Pablo Police Department in Northern California, one of the law enforcement agencies that received letters from the attorney general’s office, shared license plate data with the  Border Patrol as recently as last month, according to records obtained by Oakland Privacy head of research Mike Katz-Lacabe. Some cameras are easy to spot, but Katz-Lacabe said that local police have concealed cameras that scan license plates for more than a decade, sometimes behind the grill of police cruisers or inside speed limit trailers or in a fake saguaro cactus.

“This has been the practice for years,” he said.

On a recent Saturday, Cordero was dressed for the remote border terrain – flannel, hiking boots, a San Diego Padres cap pulled low against the sun. His dirt-caked Jeep is built for places roads don’t go. On this particular weekend, supplies at one of the drop sites had already been used, indicating people may be crossing in the area. 

Cordero has gotten good at finding stuff out here. In the remote Ocotillo washes, where the scrubs claw at people’s shins, he recently found what he believes to be the remains of a human finger.

A year earlier, Cordero found a phone contact list next to human remains. He and his wife, Jacqueline Arellano, were able to use the phone list to notify the person’s family in Arizona about where their missing loved one fell.

That’s why when, months ago, he first saw the abandoned trailer along the side of the road on Old Highway 80, he had to stop to take a closer look. 

“It took me passing by a few times before I realized what it was,” said Cordero. 

Pulling over grandma

An Associated Press investigation published in November revealed that Border Patrol had hidden license plate readers in ordinary traffic safety equipment. The data collected by the agency’s plate readers was fed into a predictive intelligence program monitoring millions of American drivers nationwide to identify and detain people whose travel patterns the algorithm deemed suspicious, according to the AP’s investigation.

Sergio Ojeda, a community organizer with the mutual aid group Imperial Valley Equity and Justice said CBP apparently believed his grandmother’s driving patterns were suspicious because they interrogated her about the amount of time she spends at local casinos in the area. 

“She was outraged about it,” said Ojeda. His grandmother, a resident of Imperial Valley with legal status, was crossing the border when agents asked her about her trips to casinos. 

“She asked them back, ‘Is something wrong with that? Am I not supposed to be doing that or why are you questioning me about this?’ and they were like “Oh, no, it just seems suspicious,” Ojeda recounted. 

Ojeda said he was equally concerned, and he doesn’t enjoy the feeling of being watched just because he lives near the border. “It’s how I feel every day,” he said. “Driving around, I joke with my co-workers: ‘Which chapter of 1984 is this?’” 

Following Markup investigation, Congress finds data brokers cost consumers tens of billions of dollars

27 February 2026 at 18:15

A congressional investigation estimates broker breaches have cost consumers $20 billion in identity theft. Major brokers now promise to make it easier to opt out of their databases.

Sen. Maggie Hassan kicked off an investigation into data brokers in response to CalMatters reporting. Hassan speaks during a Senate Finance Committee on Capitol Hill, March 14, 2025. Ben Curtis, AP Photo

Breaches at data brokers have cost American consumers more than $20 billion, Congress’s Joint Economic Committee revealed Friday as part of an investigation triggered by The Markup and CalMatters. 

The estimated losses stem from identity theft linked to just four recent data breaches involving major brokers, the committee said in a report. 

Released by the committee’s Democratic minority, the document repeatedly cited reporting into data brokers from The Markup and CalMatters, done in collaboration with WIRED. 

The committee followed up directly on the Markup and CalMatters’ reporting, which in August showed how data brokers were hiding from search engines legally-mandated pages where Californians can request that the brokers delete or stop selling their data. 

Shortly after that story was published, New Hampshire Democratic Sen. Maggie Hassan, ranking member of the committee, sent a letter pressing some brokers to explain their practices. In response, the report revealed, four major data brokers engaged with congressional staff and changed their practices to make it easier for consumers to control the use of their data. 

Data brokers and the ‘no-index’ tag

Data brokers, as defined in the California law that requires brokers to provide consumers the so-called “opt out” pages, are companies that gather data on consumers, then sell that data to other companies who do not have a direct relationship with the consumers. Typically, companies buy such information from data brokers for marketing purposes.

Brokers can gather the data from information like public records, or more invasive methods like tracking online activity. Though brokers hold potentially sensitive information on consumers, many Americans are unaware they exist. 

Under the California law, data brokers that reach a certain size are required to register and provide a clear way for consumers to request that their information be removed, that it not be sold or that they get access to it. But The Markup and CalMatters’ August story examined how several data brokers used code called the “no-index” tag on pages where consumers could exercise their right to opt out. 

The tag is used to tell search engines not to index the page, meaning the information may not be returned in search results. The story noted that this created a barrier for consumers looking to block brokers from using their data. Many of the data brokers quickly removed the tag as the story was published. 

In response to that initial reporting, Hassan independently contacted five major brokers, asking for more information about their practices. Only one registered broker, called Findem, declined to engage with staff or change its practices, the report said. 

“Following Ranking Member Hassan’s requests, most companies took action to make their opt out and other privacy pages more visible for individuals, including by removing ‘no index’ code, adding opt-out links in more prominent locations, and publishing blog content that explains how consumers can exercise their privacy rights,” the report reads. “Ranking Member Hassan welcomes these actions as supporting greater protection for consumers against scams and other harms.”

Billions in losses

The report goes on to estimate the potential losses incurred by consumers because of recent data broker breaches, pegging the number at $20.8 billion. 

Congressional staff found that hundreds of millions of people were exposed by just four major data broker breaches in the last 10 years. The breaches counted were a 2017 Equifax incident, impacting 147 million people, as well as others involving Exactis in 2018, 230 million people, National Public in 2023, 270 million people and TransUnion in 2025, 4 million people. 

Using estimates of the number of people who experience identity theft after breaches, as well as an assumed median loss of $200 from thefts, the report arrived at the nearly $21 billion figure. 

The report calls for action to prevent such losses in the future, including by filling gaps exposed by The Markup and CalMatters’ reporting on brokers. 

“The Committee’s findings underscore the need for clear, easy access to opt-out options and more rigorous oversight within the data broker industry. Especially given the Committee’s calculation that U.S. residents have lost more than $20 billion in recent data breaches, additional action is needed to protect Americans from scams connected to data brokers,” the report reads. “At a minimum, opt-out options should be easy to locate and use.” 

A new state website allows Californians to remove their personal information from hundreds of brokers at once. The Markup and CalMatters have a guide to using the website here.

California tried to protect students’ data. Tech companies found loopholes

21 February 2026 at 13:00

A legislative battle is under way over gaps that allow companies to collect and sell students’ personal information.

A young student sits at a table, headphones on, looking at a computer screen in a classroom. The students head peals over the top of the screen as their attention is focused on the computer.
Students in a classroom in Sacramento on May 11, 2022. Miguel Gutierrez Jr., CalMatters

For every aspect of a student’s life, there’s a tech company trying to digitize it. Inside the classroom, online tools proctor exams, create flashcards and submit assignments. Outside, technology coordinates school sports, helps bus drivers find the right route and maintains students’ health records. 

California has a number of laws aimed at protecting children’s data privacy, but those laws have exceptions that allow many tech companies to continue packaging and selling students’ personal information.

This year, Assemblymember Dawn Addis, a San Luis Obispo Democrat, is carrying a high-profile state bill that would add new protections for students. She says it’s important, especially as the Trump admin is trying to collect data about California residents’ immigration status, gender identity, and their use of certain public benefits.

Historically, California has been a leader in data privacy. In 2014, California passed a landmark student privacy law that prohibited technology companies from selling students’ data, targeting students in advertising, or disclosing their personal information. Then in 2018, the state passed another unprecedented bill that required all companies give California users certain privacy rights, such as a chance to opt out of data collection and delete some of their information. 

But as technology evolved and proliferated, privacy laws repeatedly fell short in protecting California’s students — at the same time that the federal government has tried to collect increasing amounts of personal information, Addis said.   

Her bill would restrict how AI companies use student data and create new data protections for college students. Some of Sacramento’s most powerful players are paying close attention to the measure, including the California Labor Federation, which supports the bill, and the California Chamber of Commerce, which opposes it. Combined, these two groups spent nearly $8 million on campaign donations to state legislators or other political activities in 2024, according to the CalMatters Digital Democracy database. TechNet, a trade association that represents many of the most powerful tech companies, also opposes the bill. 

The proposal, Assembly Bill 1159, would close certain loopholes in the state’s 2014 education privacy law, but experts say it may not be enough to prevent companies from selling students’ data. 

A privacy expert struggles to keep her information private

Jen King is a privacy and data policy fellow at Stanford’s institute for AI, where she studies the tricks that companies use to gather users’ data and prevent them from opting out, sometimes known as “dark patterns.” In her personal life, she’s vigilant about avoiding online data tracking and maintains a landline in her Bay Area home to avoid giving out her cell phone number. 

King doesn’t want her children’s information available online or for any company to sell, though sometimes it happens before she can stop it. 

In the fall, King got an email about a platform called TeamSnap, which her 12-year-old son’s cross country coaches were using to manage the team’s roster. The company wanted her information, including her name, date of birth, gender, email address, and phone number. Once she logged in to the platform, she could see some of her son’s information, such as his name, email, and date of birth, were already listed. Photos and personal information from all of her son’s teammates were also available for her to see. 

“I was super irritated,” she said. “You don’t need my birth date — I’m a freaking parent.” She acknowledged some personal information could be useful for a coach but said that other questions seem designed to help the platform sell information to data brokers and ultimately, to advertisers. 

Her 17-year-old son’s data is also on TeamSnap, she later learned, because his robotics team uses it. This month, when King tried to show The Markup and CalMatters her TeamSnap account, a pop-up appeared, asking her if the company could track her activity across other apps and websites.

Federal law requires companies to get parental consent before knowingly collecting or selling data from children 12 and under, but once a child turns 13, their data is generally treated much like an adult’s information, especially when that child is interacting with tech platforms outside of school. TeamSnap’s privacy policy says it doesn’t knowingly collect personal information about users under 13 “without express parental consent,” though it says in some cases a team or organization may provide information on behalf of the child. 

The policy also says that TeamSnap has “not sold the personal information of any consumer for monetary consideration” in the last 12 months, but that its “use of cookies and other tracking technologies may be considered a sale of personal information under the CCPA (California privacy law).” Information sold to advertisers and marketers included users’ names, contact information, purchase history and geolocation, the policy says.

California privacy law specifically requires certain large for-profit companies to get consent to collect data from anyone under 16. Often, consent happens when a user first opens a website and a pop-up appears, asking if the website can sell your data or track your cookies. 

If a teacher, coach, or other authority figure tells a student that they have to use a website or an app, then the student cannot realistically opt out, King said. They may be too young to understand how to opt out, she added. “Most 15-, 16-year-olds don’t have any idea what this is about.” 

Even older college students may have little agency in the technology they use, especially if it’s required for class or residential life. At Stanford, for example, King said her undergraduate students are often required to create Facebook accounts for student groups. 

The same is true for parents. King said she reluctantly gave TeamSnap her personal information, including her name, email, date of birth, and the landline number for her home, because it was the only way to get updates about her son’s team.

How companies get around California’s education privacy laws

In 2014, California became the first state in the country to regulate education technology companies directly, but being first comes with its drawbacks. “We didn’t have examples of what best practice was,” said Amelia Vance, the president of the Public Interest Privacy Center, a nonprofit organization. The law only applies to products that “primarily” serve K-12 schools and that are designed and marketed for students. 

Many tech companies argue that their products aren’t primarily intended for students or at least that they were not designed or marketed that way. The language-learning app DuoLingo, for example, has a version for schools, but the app is also popular for adults. Apps or technologies serving extracurricular programs or sports teams can claim they weren’t designed and marketed for the classroom, or that their use isn’t mandatory, said Vance. “You have this sort of black hole where there haven’t been protections.” 

Addis’ bill expands the number of education technology companies that fall under the state’s student privacy laws, but the language is murky when it comes to apps or online services used outside of class. 

In the case of TeamSnap, Addis’ communications director Alexis Garcia-Arrazola said the company would “most likely” fall under the scope of the bill if its technology is marketed to schools, if schools direct students to use it, and if the sports team is sponsored by the school.  

Public records show that Piedmont Unified School District in Alameda County, Tamalpais Union High School District in Marin County, and Santa Monica Malibu Unified School District all purchased versions of TeamSnap, but only the Santa Monica Malibu district responded to questions about any privacy restriction imposed on the company. Brandyi Phillips, the chief communications officer for the Santa Monica Malibu schools, said the district has an annual subscription with TeamSnap, which is only available to sports staff and parents. She said there’s an agreement with the company “to protect District information and to prevent unauthorized access” but did not clarify if that agreement prevents the district from selling students’ information. 

Berkeley Unified School District, where King’s children attend school, did not respond to questions about any contracts, purchase orders or agreements with TeamSnap. 

Locally, school districts and colleges have the power to negotiate the privacy terms of any contract they make with a technology company, but many websites and apps offer free versions that a teacher or coach might recommend without getting formal approval from their district. 

Last year, the California State University system signed a nearly $17 million contract with Open AI, the company that operates ChatGPT, including an agreement that the company will not train its models on student data. Advocates for Addis’ bill say the same privacy restrictions should apply to any AI company with access to California student data, regardless of whether the company has an agreement with the student’s school district or college.

Are privacy laws getting stricter or looser?

Addis’ bill comes as privacy laws in California and across the country are in flux. In 2020, California voters approved a proposition to create a new state agency to enforce data privacy rules and regulate the businesses that collect data. Advocates for the proposition contributed over $6.7 million to the campaign, compared to just over $50,000 contributed by the opposition, according to state data. The state agency that the proposition formed, now known as CalPrivacy, released new rules this year, restricting the use of automated decision-making technology, such as the use of AI to make admissions or hiring decisions. Those rules were originally stricter but businesses, lawmakers and Gov. Gavin Newsom pressured the CalPrivacy board to water them down.

In Washington D.C., Congress is considering changing federal law to limit how companies interact with children under 17. Separately, Congress is considering a bill that would require social media companies to prevent and mitigate children’s sexual exploitation, bullying, and self-harm. California Attorney General Rob Bonta is concerned that one version of the social media bill contains language that could erode existing protections in California law.

Bonta’s office is responsible for enforcing many of the state’s existing privacy laws. In November, he said the state worked with Connecticut and New York to reach $5.1 million in settlements against Illuminate, an education technology company that uses data to track and evaluate students’ progress, such as their testing scores and developmental milestones. The company had a data breach, exposing “sensitive information” from over 434,000 California students, the state attorney general’s office said in a statement.

It was the first time California successfully went after a company for violating the state’s landmark 2014 education privacy law.

To increase enforcement, Addis’ bill contains a new provision — the right for students and parents to sue tech companies in certain cases for privacy violations. Business and technology groups have opposed the bill, arguing that the new regulations and the right to sue would stifle investment in AI-powered learning tools.

King said that giving consumers the right to sue is often the only way to increase enforcement. Otherwise, the onus is on individual consumers to find concerning practices and try to opt out. 

Despite being an expert in data privacy, King said that she struggled at first to figure out how to delete her TeamSnap account, only later to discover that she needed to send an email to the company. She laughed at the irony, since it’s these kinds of dark patterns in user design that fuel part of her research. 

In academia, the strategy of trapping customers is sometimes called the “roach motel,” she explained, a reference to a popular television ad from the late 1970s for a cockroach trap. 

“You can check in,” she said, “but you can never check out.” 

Blacklight, our privacy inspector tool, now tracks X and TikTok pixels

9 February 2026 at 16:44

We’ve updated Blacklight, our popular privacy tool, to check for TikTok and X trackers.

Illustration of the Blacklight logo, with a purple swish behind it. On the bottom right hand corner is a star-shaped sticker with the words "UPDATE" and a wrench icon.
Gabriel Hongsdusit

Since 2020, readers have used Blacklight, our pioneering website privacy inspector tool, to run more than 18 million scans. Previously, Blacklight detected tracking pixels from Google and Meta. Today, we’re announcing that it can scan for two more digital trackers: TikTok and X pixels.

Scan a website

A tracking pixel is a small piece of code added to a website that sends information about the site’s users to the platform that operates the pixel. That can include details of a user’s activities, such as their browsing activity, purchases and searches. A website that embeds a pixel often does so to inform its advertising campaigns on the platform that create the pixel. When its pixel is embedded across many websites, the platform can compile a user’s data to build a detailed profile of their interests, behavior and other personal information. These profiles allow other businesses to buy ads from the platform to target categories of users — though this data can also be used for other purposes.

When you look up a website in Blacklight, it will now report if it finds the TikTok pixel or X pixel. More detailed information about the specific data being passed through pixels is also available by clicking on “Learn more” in the top right of the results, then clicking the link to “download an archive.”

To develop these new features, we partnered with a group of computer science students in Brandeis University’s Capstone in Software Engineering course. These students – Yiyou “Felix” Fan, Jiawen “Zena” Hu, Hengye Li, Hongchen “Steven” Yang and Yiquan “Frank” Zhang – researched and developed the features with the support of our product team.

Blacklight’s pixel detection features have already powered our Pixel Hunt investigations, which revealed that sensitive personal user information was being shared from government websites with Meta and Google, leading to lawsuits, removal of pixels from sites and increased government scrutiny. These new features give a fuller picture of the digital privacy landscape by exposing tracking pixels from two more companies.

We hope these new features will help you better understand what happens to your data as you navigate the internet. While Blacklight can’t say exactly what companies like TikTok and X do with our data, it can provide a starting point for deeper investigation into how that data is stored, shared and used across the web.

Do you have questions, suggestions or need help understanding your Blacklight results? You can always reach us at blacklight@themarkup.org

❌
❌