Regulation explainerBrain-Computer Interfaces (BCI)
Neural data privacy law: what it asks of BCI and EEG products
Several US states now list neural data as sensitive personal data, the GDPR reaches it through its health and biometric categories, the EU AI Act bans emotion inference at work and school, and Chile has written brain activity into its constitution. For a BCI or EEG product, that means opt-in consent, narrow purposes, short retention and controls on the inferences drawn from recordings, designed in before the first user puts on a headset.
On this page
- Why recordings of brain activity get a stricter rulebook
- Statutes and instruments that already reach neural data
- Definitions and consent models side by side
- Turning neural-data obligations into product requirements
- Where privacy law stops and device regulation starts
- Hypothetical: a meditation headband app moves from Colorado to the EU
- Questions and answers
- Sources
Why recordings of brain activity get a stricter rulebook
A password can be changed and a card cancelled. Neural signals cannot, and the same recording can be reanalyzed later with better models to reveal things nobody agreed to share: fatigue, attention, signs of a neurological condition. That mix of permanence and open-ended inference is why legislators now treat neural data as its own category.
The UK Information Commissioner's Office makes a useful distinction in its neurotechnology report: neurodata used for medical purposes is likely to be special category health data, neurodata used to identify someone is special category biometric data, and other neurodata may fall below that threshold while still carrying serious risk, especially when it is used to classify people by emotion or behavior6. The practical consequence for product teams is that the legal category depends on purpose, so purpose has to be fixed and recorded at design time.
Statutes and instruments that already reach neural data
Colorado Privacy Act, as amended by HB 24-1058 (Protect Privacy of Biological Data)
Colorado, USApplies whenA controller within the Act's scope processes biological data, including neural data from the central or peripheral nervous system, that is used or intended to be used to identify a person1.
- Treat neural data as sensitive data, which the Act allows to be processed only with consent.
- Complete a data protection assessment before processing it.
California Consumer Privacy Act, as amended by SB 1223
California, USApplies whenA covered business collects information generated by measuring central or peripheral nervous system activity that is not inferred from nonneural information23.
- Disclose neural data as sensitive personal information at or before collection.
- Offer the right to limit where it is used to infer characteristics about the consumer.
Montana Genetic Information Privacy Act, as amended by SB 163
Montana, USApplies whenA covered entity handles neurotechnology data, a broader category that also captures information associated with neural activity; the amendment took effect on October 1, 20253.
- Apply the Act's consent and notice duties to neurotechnology data if your business is a covered entity.
- Check that definition first: it is drawn narrowly around genetic data businesses3.
Connecticut Data Privacy Act, as amended by SB 1295
Connecticut, USApplies whenA controller within scope processes information generated by measuring central nervous system activity; the amended definitions, enacted as Public Act 25-113, are effective July 1, 20264.
- Treat neural data as sensitive data under the Act.
- Note that peripheral nervous system signals fall outside this definition, unlike Colorado and California.
General Data Protection Regulation (EU) 2016/679
EU and EEAApplies whenNeural recordings relate to an identifiable person; Article 9 applies where they are data concerning health or biometric data processed to uniquely identify someone5.
- Establish a lawful basis and, for special category data, an Article 9 condition such as explicit consent.
- Carry out an Article 35 impact assessment where processing is likely to be high risk.
Artificial Intelligence Act, Regulation (EU) 2024/1689
EUApplies whenAn AI system infers the emotions of people in a workplace or an education institution7.
- Article 5 prohibits placing such systems on the market or using them, except for medical or safety reasons.
- Assess whether an attention or stress feature drawn from EEG amounts to emotion inference before selling it to employers or schools.
Constitution of Chile, Article 19 as amended by constitutional reform
ChileApplies whenTechnologies are used on people in ways that affect brain activity or information derived from it; the amendment was made by Law 21.3838.
- The constitution now requires the law to protect brain activity and the information that comes from it.
- Expect strict readings of consent and data handling for neurodevices.
Definitions and consent models side by side
The four state laws use different definitions, so the same headband can be covered in one state and not another.
| Question | Colorado | California | Connecticut | GDPR |
|---|---|---|---|---|
| Nervous systems covered | Central and peripheral | Central and peripheral | Central only | Not defined; depends on whether data is personal |
| Identification test | Only when used or intended to identify | None | None | Biometric category only when used for unique identification |
| Default posture | Opt-in consent for sensitive data | Notice plus a right to limit | Consent for sensitive data | Lawful basis plus an Article 9 condition when special |
| Inferred data | No explicit exclusion | Excludes data inferred from nonneural information | No explicit exclusion | Inferences about a person are personal data |
Summarized from the statutory texts and the Future of Privacy Forum's comparison of state definitions3. Montana is omitted because its law amends a genetic privacy statute with a different scope.
Turning neural-data obligations into product requirements
Fix the purposes before collecting anything
List each purpose separately: running the feature, improving the model, research, sharing with a clinical partner. Each gets its own consent toggle, retention period and access group, so a recording made for a focus timer cannot silently become training data.
Design consent for recordings and for inferences
Explain what the device measures and what the software infers from it, in plain words, before the first session. Make withdrawal one tap away inside the app and make it trigger deletion of stored recordings and derived features, not only a stop to future collection.
Process on the device where the feature allows
Compute band power, classifier outputs or session summaries on the headset or phone and send only those upstream. Raw signal leaves the device only for a purpose the user has opted into, such as contributing to a research dataset.
Separate identity from signal
Store recordings under a pseudonymous key, keep the key table in a separate store with tighter access, and log every read of raw signal. Pseudonymized neural data is still personal data.
Gate every onward disclosure
Block transfers to third parties, including analytics and advertising SDKs, without a specific consent. Processor contracts should forbid reuse of neural data and require deletion on termination.
Assess, then reassess when features change
Run the Colorado data protection assessment or the GDPR impact assessment before launch, and repeat it when a new inference, market or partner is added. That review is where a new stress score or employer offering gets caught.
Where privacy law stops and device regulation starts
Privacy statutes apply whatever the product claims to do. Device regulation depends on the claim. A headband sold for relaxation or focus may fall under the US Food and Drug Administration's general wellness policy for low-risk products12, while software that claims to diagnose or treat a condition is on a medical device pathway. Research recordings in US federally funded studies also fall under the Common Rule's informed consent requirements13.
Non-binding international instruments point the same way. The OECD Recommendation on Responsible Innovation in Neurotechnology includes safeguarding personal brain data among its principles11, and UNESCO's General Conference adopted a Recommendation on the Ethics of Neurotechnology in November 202510. At federal level in the US, the proposed MIND Act would ask the Federal Trade Commission to study how neural data should be governed9. The brain-computer interface hub sets out how ColdAI treats the regulated device route: led by qualified clinical partners, with no clinical claims from us14.
Hypothetical: a meditation headband app moves from Colorado to the EU
Questions and answers
Are inferred mental states covered by neural data laws?
Often, yes. California's right to limit applies specifically when sensitive information is used to infer characteristics about a consumer, and under the GDPR an inference about an identifiable person is itself personal data. Colorado and Connecticut do not exclude inferences from their definitions. Design consent and retention around the inferences your software produces, not only the raw recordings.
Can EEG data be anonymized so privacy law no longer applies?
Treat that as unlikely. Removing names and device identifiers leaves the signal itself, which can carry characteristics that distinguish one person from another. The ICO notes that neurodata which could identify someone is still personal data even when it is not used for identification6. Safer patterns are aggregation, storing derived features instead of raw signal, and short retention.
Do research exemptions apply to BCI studies?
Partly, depending on the law. State privacy acts carve out some regulated research and the GDPR allows research derogations with safeguards, but ethics approval and informed consent still apply. A commercial product that reuses study recordings for model training generally needs a fresh legal basis or consent that clearly covered that reuse.
Does neural data privacy law apply to employers using EEG wearables for safety?
Yes, the privacy laws apply to the data whatever the motive, and the ICO cautions that consent is often unsuitable in employment because of the power imbalance. In the EU, the AI Act prohibits emotion inference in workplaces except for medical or safety reasons, so a fatigue-detection use needs a documented safety rationale, a narrow output and no secondary use for performance management.
Sources
- HB24-1058 Protect Privacy of Biological Data — Colorado General Assembly · checked 10 October 2026
- SB-1223 Consumer privacy: sensitive personal information: neural data — California Legislative Information · checked 10 October 2026
- The Neural Data Goldilocks Problem: Defining Neural Data in U.S. State Privacy Laws — Future of Privacy Forum · checked 10 October 2026
- Public Act No. 25-113 (Substitute Senate Bill No. 1295) — Connecticut General Assembly · checked 10 October 2026
- Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex · checked 10 October 2026
- ICO tech futures: neurotechnology, regulatory issues — Information Commissioner's Office · checked 10 October 2026
- Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex · checked 10 October 2026
- Ley 21.383: modifica la Carta Fundamental para establecer el desarrollo científico y tecnológico al servicio de las personas — Biblioteca del Congreso Nacional de Chile · checked 10 October 2026
- S.2925 MIND Act of 2025 — Congress.gov · checked 10 October 2026
- Recommendation on the Ethics of Neurotechnology — UNESCO · checked 10 October 2026
- Recommendation of the Council on Responsible Innovation in Neurotechnology (OECD/LEGAL/0457) — OECD · checked 10 October 2026
- General Wellness: Policy for Low Risk Devices — US Food and Drug Administration · checked 10 October 2026
- 45 CFR Part 46: Protection of Human Subjects — eCFR · checked 10 October 2026
- Brain-Computer Interfaces (BCI) — ColdAI