Skip to content

California AB 2624: What It Tries to Solve, Where It Goes Wrong, and How It Should Have Been Fixed

What AB 2624 Tries to Solve

California Assembly Bill 2624, authored by Mia Bonta, extends California’s Safe at Home address confidentiality program — originally created in 1998 for survivors of domestic violence, stalking, sexual assault, and human trafficking — to a new category of covered persons: workers, volunteers, and certain affiliates of organizations providing immigration support services.

In practice, this includes people connected to immigration legal aid, nonprofit support services, humanitarian assistance, translation, case management, advocacy, accredited representative offices, and related facilities — the broad ecosystem of staff and volunteers who provide direct services to immigrants and asylum seekers.

The threat environment the bill responds to is real. Workers at immigration-support organizations across California have faced doxxing, online harassment, courthouse targeting, vigilante threats, and in some cases people showing up at their homes or the homes of their family members. Testimony before the Assembly Privacy Committee included accounts of staff being followed leaving lunch, people arriving at family members’ residences looking for named workers, and coordinated threat campaigns against named organizations and individuals. Whatever one’s politics on immigration enforcement itself, the personal targeting of frontline civic-support workers for doing lawful work is a real failure mode in the system.

Address confidentiality programs exist precisely to address that failure mode. The original 1998 program allowed domestic-violence survivors to use a substitute address for public records, preventing abusers from locating them through government databases. Subsequent expansions added reproductive health workers and gender-affirming care providers as new covered categories. AB 2624 follows this same pattern for immigration-support workers.

The bill’s core address-confidentiality function — a structured application process, documentation requirements, substitute-address issuance through the Secretary of State, misdemeanor penalties for false certification — is the part most clearly continuous with existing law and most directly protective.

What the Bill Does Beyond Address Confidentiality

The address-confidentiality core is not the controversial part. The controversial part is Section 6218.19(b), which extends beyond confidentiality of address into a broader online-disclosure restriction.

The bill defines “personal information” expansively: information that identifies, relates to, describes, or can be associated with a covered person — including name, physical description, address, telephone number, education, employment, employment history, and financial information.

It then prohibits a person, business, or association from posting, displaying, disclosing, or distributing that information on the internet after receiving a written demand. The demand lasts four years. A successful plaintiff recovers attorney’s fees.

This is the structural break with the original Safe at Home logic. Address confidentiality protects safety information from public records. The demand-letter mechanism creates a private cause of action that operates against general internet speech about covered persons, with a broad definition of what counts as protected information.

Where the Bill Goes Wrong

Three structural defects.

Person/institution conflation. The bill’s protections are anchored to individuals (workers, volunteers, employees) but operate by reference to organizational affiliation (designated immigration support services facilities). The result is that information about an organization’s activities — staff names, job titles, employment history, operational details — can become protected under “personal information” of covered individuals. The legitimate safety interest is in protecting people’s homes and families. The practical effect can extend into protecting organizational operations from scrutiny.

Threat overbreadth. The criminal-threat portions of the bill are narrowly tied to specific intent to incite imminent harm or create objectively reasonable fear of violence. Those provisions are defensible and continuous with existing anti-doxxing logic. But the civil demand-letter mechanism operates on a much broader threshold: a written demand alone triggers a four-year restriction, without requiring a showing of credible safety risk. That breadth creates a private suppression tool independent of actual threat circumstances.

Coalition-coded design. Safe at Home began with categories — domestic violence survivors, stalking victims, trafficking victims — that command cross-cutting political legitimacy. Each subsequent expansion (reproductive health workers, gender-affirming care providers, immigration-support workers) has added a category that maps to one side of an active political conflict. Individually, each expansion is defensible on safety grounds. Cumulatively, the framework is being recoded from a generally protective institution into infrastructure that protects the civic intermediaries of one political coalition. That recoding has consequences: it invites symmetric expansions for the opposing coalition’s protected classes in other jurisdictions, and it undermines the cross-cutting legitimacy that made the original program effective.

How It Should Have Been Fixed

A stronger version of AB 2624 would have followed three design principles.

Principle 1 — Protect the person, not the institution

The bill should have protected home addresses, family-member information, private contact details, school or childcare locations, private vehicle data, and other genuinely safety-sensitive disclosures. It should not have created legal uncertainty around organizational accountability — investigation, reporting, criticism, public-records analysis, or financial scrutiny of immigration-support facilities, public-grant recipients, contractors, or nonprofits.

Specifically: the “personal information” definition should have been narrowed to safety-sensitive items only, excluding name, job title, public role, and organizational affiliation. The bill should have included explicit language stating that nothing in it prohibits public-interest scrutiny of organizations or programs.

Annual aggregate reporting requirements should have been added — applications, approvals, denials, demand letters invoked, lawsuits filed — without exposing individual participants, so abuse of the framework would be detectable.

Principle 2 — Protect from threats, not from scrutiny

The bill should have drawn a clear line between doxxing, harassment, and stalking on one side, and lawful public observation or criticism on the other.

A public-interest carveout should have covered journalists, independent journalists, citizen journalists, researchers, watchdog groups, and people documenting matters of public concern — defined by the function of the speech rather than the institutional affiliation of the speaker.

Filming, photographing, identifying, or criticizing people in public places — public meetings, courts, government offices, hearings, protests — should have been explicitly protected, unless the conduct was tied to stalking, targeted harassment, true threats, intimidation, or disclosure of private safety information.

The demand-letter mechanism should have been tightened: specific identification of the safety-sensitive information at issue, a sworn statement of reasonable safety risk, a shorter default duration (perhaps one year), and renewal only with continuing threat evidence.

Principle 3 — Make protection function-defined, not coalition-defined

The bill should have used role-function language rather than coalition-coded category language. A stronger draft would have read something like:

Any person providing lawful services in a politically targeted civil-society, legal, humanitarian, public-health, election, or enforcement-adjacent public-facing role may qualify for address confidentiality when they face documented threats, harassment, stalking, or violence because of that role.

That formulation would have preserved the practical protection for immigration-support workers while resisting the broader pattern of class-by-class coalition coding. It would also have reduced the political precedent created for future symmetric expansions in other jurisdictions.

Cross-cutting safeguards

Three further structural fixes that do not fit cleanly under any single principle.

Anti-SLAPP integration and reciprocal fee-shifting. California’s existing anti-SLAPP statute should explicitly apply to demand-letter actions, and a prevailing defendant should be able to recover fees. Otherwise, the cost of defending against a weak suit becomes the punishment, independent of legal merit. A law does not need to win in court to chill speech. It only needs to make lawful scrutiny expensive enough that ordinary people back off.

Sunset clause. The expansion should sunset in four or five years, requiring reauthorization based on actual usage data. Class-based privacy protections tend to ratchet — easy to add, hard to remove. A sunset converts the ratchet into a periodic review.

Severability. If a court strikes down the speech-sensitive disclosure provisions, the core address-confidentiality protection should explicitly survive intact. This is defensive drafting that protects the legitimate function from the constitutionally risky function.

Bottom Line

AB 2624 is a legitimate response to a real intimidation problem and simultaneously a partisan-coded measure that risks converting a protective framework into coalition infrastructure. Both characterizations are true at the same time, and in a polarized political environment, that overdetermination is the diagnostic signal — not a contradiction to be resolved.

The right response was boundary repair, not rejection. The bill should have protected home addresses, family information, private contact details, and other genuinely dangerous disclosures. It should not have created legal uncertainty around filming in public places, naming public-facing actors, investigating publicly funded organizations, or criticizing immigration-support nonprofits.

Done correctly, the bill could have been a defensible expansion of an existing protective framework. Done as drafted, it carries structural defects that produce predictable systemic responses — constitutional challenge, chilling effects, counter-mobilization, and eventual symmetric counter-expansion in opposing-coalition jurisdictions — that may ultimately weaken rather than strengthen protection for the workers the bill was meant to serve.

Leave a Reply

Your email address will not be published. Required fields are marked *