Netchoice, LLC v. BontaNetchoice, LLC v. Bonta
FOR PUBLICATION
OPINION
SUMMARY*
First Amendment
The panel affirmed in part and vacated in part the district court‘s preliminary injunction in an action brought by NetChoice, a national trade association of online businesses that promotes free speech on the Internet, challenging the California Age-Appropriate Design Code Act (CAADCA), which the California State Legislature enacted with the aims of promoting robust online privacy protections for children under the age of eighteen and ensuring that online products that are likely to be accessed by children are designed in a manner that recognizes the distinct needs of children.
The panel held that NetChoice was likely to succeed in showing that the CAADCA‘s requirement that covered businesses opine on and mitigate the risk that children may be exposed to harmful or potentially harmful materials online facially violates the First Amendment. The panel therefore affirmed the district court‘s decision to enjoin the enforcement of that requirement, and the other provisions that were not grammatically severable from it.
The panel vacаted the remainder of the district court‘s preliminary injunction because it is unclear from the record whether the other challenged provisions of the CAADCA facially violate the First Amendment, and it is too early to determine whether the unconstitutional provisions of the CAADCA were likely severable from its valid remainder. The panel remanded to the district court for further proceedings.
* This summary constitutes
COUNSEL
Robert Corn-Revere (argued), Foundation for Individual Rights and Expression, Washington, D.C.; David M. Gossett and Meenakshi Krishnan, Davis Wright Tremaine LLP; Washington, D.C.; Ambika Kumar, Davis Wright Tremaine LLP; Seattle, Washington; Adam Sieff, Davis Wright Tremaine LLP; Los Angeles, California; for Plaintiff-Appellee.
Kristin Liska (argued), Deputy Attorney General; Elizabeth Watson, Attorney; Anya Binsacca, Supervising Deputy Attorney General; Thomas S. Patterson, Senior Assistant Attorney General; Rob Bonta, Attorney General of California; Office of the California Attorney General, San Francisco, California; Nicole J. Kau, Deputy Assistant Attorney General, Office of the California Attorney General, Los Angeles, California; for Defendant-Appellant.
John P. Schnapper-Casteras and Rachael Yocum, Schnapper-Casteras PLLC, Washington D.C.; for Amicus Curiae The Institue for Law Innovation and Technology.
Juyoun Han, Patrick K. Lin, and Eric Baum, Eisenberg & Baum LLP, New York, New York; for Amici Curiae Fairplay et al..
Russell C. Bogue, Assistant Attorney General; Ashwin P. Phatak, Principal Deputy Solicitor General; Caroline S. Van Zile, Solicitor General; Brian L. Schwalb, Attorney General for the District of Columbia; Office of the Attorney General for the District of Columbia, Washington, D.C.; Kiel B. Ireland, Deputy Solicitor General; Heidi P. Stern, Solicitor General; Aaron D. Ford, Attorney General for the State of Nevada; Office of the Attorney General for the State of Nevada; for Amici Curiae Nevada, The District of Columbia, Arizona, Arkansas, Colorado, Connecticut, Delaware, Florida, Illinois, Maryland, Michigan, Minnesota, Mississippi, New Jersey, New Mexico, New York, North Carolina,
Gautam S. Hans, Cornell Law School, Ithaca, New York; for Amici Curiae Privacy and First Amendment Law Professors.
Anne M. Murphy, Joseph W. Cotchett, Karin B. Swope, and Blair Kittle, Cotchett Pitre & McCarthy LLP, Burligame, California; for Amicus Curiae The American Academy of Pediatrics, The American Psychological Association, and the California Academy of Child and Adolescent Psychiatry.
Marc P. Epstein, Jon Greenbaum, and David Brody, Lawyers’ Committee for Civil Rights Under Law, Washington, D.C.; for Amicus Curiae The Lawyers’ Committee for Civil Rights Under Law.
Glenn E. Chappell and Hassan A. Zavareei, Tycko & Zavareei LLP, Washington, D.C.; for Amici Curiae Design Scholars.
Jason S. Harrow, Gerstein Harrow LLP, Los Angeles, California; for Amicus Curiae Princeton University Center for Information Technology Policy, Tech Policy Clinic.
Alison S. Gaffney and Dean Kawamoto, Keller Rohrback LLP, Seattle, Washington; for Amici Curiae The American Federation of Teachers and the California Federation of Teachers.
Alvaro M. Bedoya, Commissioner, Federal Trade Commission, Washington, D.C.; for Amicus Curiae Federal Trade Commissioner Alvaro M. Bedoya.
Linda Singer and David I. Ackerman, Motley Rice LLC, Washington, D.C.; for Amici Curiae Elizabeth Denham CBE and Stephan Wood.
Megan Iorio, Tom McBrien, and Suzanne Bernstein, Electronic Privacy Information Center, Washington, D.C.; for Amicus Curiae Electronic Privacy Information Center.
Matthew P. Bergman and Patrick Strekert, Social Media Victims Law Center PLLC, Seattle, Washington; for Amicus Curiae The Center for Humane Technology.
Stephanie A. Joyce, Potomac Law Group PLLC, Washington, D.C.; Computer and Communication Industry Association.
Corbin K. Barthold, TechFreedom, Washington, D.C; for Amicus Curiae TechFreedom.
Megan L. Brown, Kathleen E. Scott, and Boyd Garriott, Wiley Rein LLP, Washington, D.C.; Jonathan D. Urick and Maria C. Monaghan, United States Chamber Litigation Center; Washington, D.C.; for Amicus Curiae Chamber of Commerce of the United States of America.
Brian R. Hardy, Marquis Aurbach Coffing, Las Vegas, Nevada; Ben Sperry аnd Geoffrey A. Manne; International Center for Law and Economics; Portland, Oregon; for Amicus Curiae International Center for Law and Economics.
Aaron D. Mackey, Adam Schwartz, David Greene, and F. Mario Trujillo, Electronic Frontier Foundation, San Francisco, California; Samir Jain, Eric Null, and Kate Ruane, Center for Democracy and Technology, Washington, D.C.; for Amici Curiae Electronic Frontier Foundation and Center for Democracy and Technology.
Vera Eidelman and Elizabeth Gyori, American Civil Liberties Union Foundation, New York, New York; Jacob A. Snow, Nicolas A. Hidalgo, Chessie Thacher, Nicole A. Ozer, and Matthew T. Cagle, American Civil Liberties Union Foundation of Northern California, San Francisco, California; for Amici Curiae American Civil Liberties Union.
Jessica R. Amunson, Lindsay C. Harrison, and Andrew C. DeGuglielmo, Jenner & Block LLP, Washington, D.C.; for Amicus Curiae Professor Eric Goldman.
Mark W. Brennan, J. Ryan Thompson, and Thomas B. Vietch, Hogan Lovells US LLP, Washington, D.C.; Jess Miers, Chamber of Progress, McLean, Virginia; Suzanna Kang, Consumer Technology Association, Arlington, Virginia; Carlos Gutierrez, LGBT Tech, Staunton, Virginia; David Loy, First Amendment Coalition, San Rafael, California; Lawrence Walters, Walters Law Group, Longwood, Florida; for Amici Curiae Chamber of Progress, Consumer Technology Association, First Amendment Coalition, Information Technology and Innovation Foundation, IP Justice, LGBT Tech, The Trevor Project, and Woodhull Freedom Foundation.
Bruce D. Brown, Katie Townsend, Gabe Rottman, Grayson Clary, Emily Hockett, Reporters Committee for Freedom of the Press, Washington, D.C.; for Amici Curiae Reporters Committee for Freedom of the Press and 14 Media Organizations.
OPINION
M. SMITH, Circuit Judge:
In 2022, the California State Legislature enacted the California Age-Appropriate Design Code Act (CAADCA or Act),
We agree with NetChoice that it is likely to succeed in showing that the CAADCA‘s requirement that covered businesses opine on and mitigate the risk that children may be exposed to harmful or potentially harmful materials online,
However, we vacate the remainder of the district court‘s preliminary injunction order, which not only failed to properly consider the facial nature of NetChoice‘s First Amendment challenges to other provisions of the CAADCA,
LEGAL BACKGROUND
In 2018, the California State Legislature enacted the California Consumer Privacy
Two years later, in 2020, California voters approved a ballot measure that amended the CCPA to clarify and expand its protections. See 2020 Cal. Legis. Serv. Prop. 24. The CCPA, as amended, instructs the California Attorney General to promulgate “regulations requiring businesses whose processing of consumers’ personal information presents significant risk to consumers’ privacy or security, to . . . [s]ubmit to the California Privacy Protection Agency on a regular basis a risk assessment with respect to their processing of personal information.”
In 2022, the California State Legislature enacted the CAADCA,
provision requiring online businesses to create a Data Protection Impact Assessment (DPIA) report identifying, for each offered online service, product, or feature likely to be accessed by children, any risk of “material detriment to children that arise from the data management practices of the business.”
(i) Whether the design of the online product . . . could harm children, including by exposing children to harmful, or potentially harmful, content . . . .
(ii) Whether the design . . . could lead to children experiencing or being targeted by harmful, or potentially harmful, contacts . . . .
(iii) Whether the design . . . could permit childrеn to witness, participate in, or be subject to harmful, or potentially harmful, conduct . . . . (iv) Whether the design . . . could allow children to be party to or exploited by a harmful, or potentially harmful, contact . . . .
(v) Whether the algorithms used by the online product . . . could harm children.
(vi) Whether targeted advertising systems used by the online product . . . could harm children.
(vii) Whether and how the online product . . . uses system design features to increase, sustain, or extend use of the online product . . . .
(viii) Whether, how, and for what purpose the online product . . . collects or processes sensitive personal information of children.
Apart from the required DPIA reports, the CAADCA also compels online providers to:
(5) Estimate the age of child users with a reasonable level of certainty appropriate to the risks that arise from the data management practices of the business or apply the privaсy and data protections afforded to children to all consumers.
(6) Configure all default privacy settings provided to children by the online service . . . to settings that offer a high level of privacy, unless the business can demonstrate a compelling reason that a different setting is in the best interests of children.
(7) Provide any privacy information, terms of service, policies, and community standards concisely, prominently, and using clear language suited to the age of children likely to access that online service . . . .
(8) If the online service, product, or feature allows the child‘s parent, guardian, or any other consumer to monitor the child‘s online activity or track the child‘s location, provide an obvious signal to the child when the child is being monitored or tracked.
(9) Enforce published terms, policies, and community standards established by the business, including, but not limited to, privacy policies and those concerning children.
(10) Provide prominent, accessible, and responsive tools to help children, or if applicable their parents or guardians, exercise their privacy rights and report concerns.
The CAADCA also forbids “business[es] that provide[] an online service, product, or feature likely to be accessed by children,”
(1) Use the personal information of any child in а way that the business knows, or has reason to know, is materially detrimental to the physical health, mental health, or well-being of a child.
(2) Profile a child by default unless . . . (A) [t]he business can demonstrate it has appropriate safeguards in place to protect children[] [and] (B) [e]ither of the following is true:
(i) Profiling is necessary to provide the online service . . . with which the child is actively and knowingly engaged.
(ii) The business can demonstrate a compelling reason that profiling is in the best interests of children.2 (3) Collect, sell, share, or retain any personal information that is not necessary to provide [the] online service . . . unless the business can demonstrate a compelling reason that [doing so] is in the best interests of children likely to access the online service . . . .
(4) If the end user is a child, use personal information for any reason other than a reason for which that personal information was collected, unless the business can demonstrate a compelling reason that use of the personal information is in the best interests of children.
(5) Collect, sell, or share any precise geolocation information of children by default unless the collection . . . is strictly necessary for the business to provide the service . . . requested . . . .
(6) Collect any precise geoloсation information of a child without providing an obvious sign to the child for the duration of that collection that precise geolocation information is being collected.
(7) Use dark patterns to lead or encourage children to provide personal information beyond what is reasonably expected to provide that online service . . . to forego privacy protections, or to take any action that the business knows, or has reason to know, is materially detrimental to the child‘s physical health, mental health, or well-being.
(8) Use any personal information collected to estimate age or age range for any other purpose or retain that personal information longer than necessary to estimate age. . . .
The CAADCA exclusively authorizes the California Attorney General to bring a civil enforcement action against any business that fails to comply with the Act‘s requirements or violates its prohibitions. See
The CAADCA also authorizes the creation of a “Children‘s Data Protection Working Group,” comprised of experts in children‘s data privacy, physical health, mental health and well-being, computer science, and children‘s rights, and appointed by various members of state government, including the Governor and the Attorney General.
PROCEDURAL HISTORY
NetChoice‘s members include Amazon, Google, Meta, Netflix, and X. See About Us, NetChoice, https://netchoice.org/about/. NetChoice filed this lawsuit against Rob Bonta, the Attorney General of the State of California (the State), on December 14, 2022, challenging the CAADCA as facially unconstitutional and preempted by federal statute. Spеcifically, the complaint asserts the following claims: (1) violation of the First and Fourteenth Amendments to the U.S. Constitution and Article I, § 2(a) of the California Constitution; (2) violation of the Fourth Amendment to the U.S. Constitution; (3) void for vagueness under the First Amendment and Due Process Clause of the U.S. Constitution and Article I, § 7(a) of the California Constitution; (4) violation of the Commerce Clause of the U.S. Constitution; (5) preemption by the Children‘s Online Privacy Protection Act,
On February 17, 2023, NetChoice moved for a preliminary injunction to enjoin enforcement of the CAADCA, which the district court granted on September 18, 2023. In its order supporting the injunction, the district court began its analysis by observing that “both parties appear to have accepted the relaxed standard for standing in a First Amendment facial challenge,” and because of that, the court would consider “arguments about the CAADCA‘s alleged impact on the expressive activities of individuals and entities who are not NetChoice members.” NetChoice, LLC v. Bonta, 692 F. Supp. 3d 924, 939 (N.D. Cal. 2023). The district court also stated that it did not need to reach any of NetChoice‘s First Amendment arguments “based on prior restraint, overbreadth, and vagueness,” because NetChoice‘s arguments about the CAADCA‘s facial infirmities were “dispositive.” Id. at 939–40.
The district court then proceeded to analyze whether the CAADCA‘s provisions implicated protected speech, sufficient to trigger First Amendment scrutiny. In undertaking this threshold inquiry, the district court grouped the CAADCA‘s provisions into two major categories: its prohibitions, see
As for the CAADCA‘s affirmative commands, the district court noted that they “are more varied than the [CAADCA‘s]
The district court then analyzed the CAADCA‘s command that businesses enforce their “published terms, policies, and community standards.”
requiring businesses to estimate the age оf child users and provide them with a high default privacy setting or forego age estimation and provide a high default privacy setting to all users,
Next, to determine the appropriate level of judicial scrutiny, the district court examined what types of speech are implicated by the CAADCA—i.e., commercial or non-commercial speech. Id. The district court ultimately found that it was “difficult to determine whether the [CAADCA] regulates only commercial speech.” Id. at 947. Accordingly, the court assumed for the purposes of the motion for a preliminary injunction “that only the lesser standard of intermediate scrutiny for commercial speech applies” because the outcome of the analysis would be the same under both intermediate scrutiny and strict sсrutiny. Id. at 948.
The district court then examined whether it could sever the unconstitutional provisions from the remainder of the statute and concluded that it could not, primarily because of the unconstitutional DPIA report requirement. Id. at 960. Specifically, if a business is in substantial compliance with
its obligation to create, disclose, and mitigate the risks identified in its regular DPIA reports, the Attorney General must give it written notice of possible violations and an opportunity to cure them before bringing suit. SeeThe court declined to issue preliminary rulings on the merits of NetChoice‘s remaining claims, since it was clear to the court that NetChoice was likely to succeed on its facial claim brought under the First Amendment. Id. at 961-64. Upon concluding that NetChoice met the remaining preliminary injunction factors under Winter v. Natural Resources Defense Council, Inc., 555 U.S. 7 (2008), on that claim, the court enjoined enforcement of the CAADCA in its entirety. NetChoice, 692 F. Supp. 3d at 964-65. The State timely appealed.
JURISDICTION AND STANDARD OF REVIEW
We have jurisdiction pursuant to
ANALYSIS
“A plaintiff seeking a preliminary injunction must establish that he is likely to succеed on the merits, that he is likely to suffer irreparable harm in the absence of preliminary relief, that the balance of equities tips in his favor, and that an injunction is in the public interest.” Winter, 555 U.S. at 20. On appeal, the State does not meaningfully contest the district court‘s determinations regarding the balance of equities, irreparable injury, and public interest factors, but does insist that NetChoice is not likely to succeed on the merits of its First Amendment challenge to the CAADCA. Accordingly, our analysis focuses on whether NetChoice is likely to succeed on the merits of its First Amendment challenge.
I. NetChoice Is Likely to Succeed in Showing That the DPIA Report Requirement Facially Violates the First Amendment.
“For a host of good reasons, courts usually handle constitutional claims case by case, not en masse.” Moody, 144 S. Ct. at 2397. The Supreme Court “has therefore made facial challenges hard to win.” Id. In a typical facial challenge, “a plaintiff cannot succeed unless he ‘establish[es] that no set of circumstances exists under which the [law] would be valid,’ or he shows that the law lacks a ‘plainly legitimate sweep.‘” Id. (alterations in original) (first quoting United States v. Salerno, 481 U.S. 739, 745 (1987); and then quoting Wash. State Grange v. Wash. State Republican Party, 552 U.S. 442, 449 (2008)).
However, in First Amendment cases, the Supreme Court “has lowered that very high bar.” Id. “To provide breathing room for free expression,” the Supreme Court has “substituted a less demanding though still rigorous standard.” Id. (cleaned up); see also Tucson v. City of Seattle, 91 F.4th 1318, 1327 (9th Cir. 2024).6 “[I]f thе law‘s unconstitutional applications substantially outweigh its constitutional ones,” then a court may sustain a facial challenge to the law and strike it down. Moody, 144 S. Ct. at 2397. As Moody clarified, a First Amendment facial challenge has two parts: first, the courts must “assess the state laws’ scope“; and second, the courts must “decide which of the laws’ applications violate the First Amendment,
Just like the parties and lower courts in Moody, “no one has paid much attention to” the requirements for a facial challenge so far in this case. Id. Nevertheless, for the reasons set forth immediately below, we conclude that this oversight did not cause any error in the district court‘s analysis of the CAADCA‘s DPIA report requirement. See
Specifically, every business covered by the CAADCA must create DPIA reports identifying, for each offered online service, product, or feature likely to be accessed by children, any risk of “material detriment to children that arise from the data management practices of the business.”
Whether it be NetChoice‘s members or other covered businesses providing online services likely to be accessed by children, all of them are under the same statutory obligation to opine on and mitigate the risk that children may be exposed to harmful or potentially harmful content, contact, or conduct online. While it is certainly possible that in some applications, a covered business will ultimately conclude that it need not address certain risks in its DPIA report because its new service to be offered does not create such risks, see
Accordingly, unlike the record in the Moody case, the record here is sufficiently developed to consider the scope of the DPIA provision and whether its unconstitutional applications substantially outweigh its constitutional ones. We therefore proceed to consider whether the requirement is likely to survive NetChoice‘s First Amendment facial challenge.
A. The DPIA Report Requirement Undoubtedly Regulates Protected Speech, Thereby Implicating the First Amendment.
The State argues that the DPIA report requirement is “incidental to [the
In response, NetChoice argues that the DPIA report requirement “constructs a censorship regime,” and “compels services to speak,” and therefore, invites First Amendment scrutiny. According to NetChoice, the DPIA report requirement has little to do with privacy and instead “force[s] covered businesses to identify and disclose to the government potential risks that minors might be exposed to potentially harmful content [online] and [to] develop a timed plan to mitigate or eliminate the identified risks before publication” (cleaned up).
We agree with NetChoice that the DPIA report requirement, codified at
The State makes much of the fact that the DPIA reports are not public documents and retain their confidential and privileged status even aftеr being disclosed to the State, but the State provides no authority to explain why that fact would render the First Amendment wholly inapplicable to the requirement that businesses create them in the first place. On the contrary, the Supreme Court has recognized the First Amendment may apply
Second, the DPIA report requirement invites First Amendment scrutiny because it deputizes covered businesses into serving as censors for the State. The Supreme Court has previously applied First Amendment scrutiny to laws that deputize private actors into determining whether material is suitable for kids. See Interstate Cir., Inc. v. City of Dallas, 390 U.S. 676, 678, 684 (1968) (recognizing that a film exhibitor‘s First Amendment rights were implicated by a law requiring it to inform the government whether films were “suitable” for children). Moreover, the Supreme Court recently affirmed “that laws curtailing [] editorial choices [by online platforms] must meet the First Amendment‘s requirements.” Moody, 144 S. Ct. at 2393.
The State resists NetChoice‘s characterization of the DPIA report requirement as constructing a censorship scheme by arguing that “the mitigation requirement contains no referenсe to content whatsoever; it solely requires a company to mitigate risks from its data management practices.” But that argument ignores that
At oral argument, the State suggested companies could analyze the risk that children would be exposed to harmful or potentially harmful material without opining on what material is potentially harmful to children. However, a business cannot assess the likelihood that a child will be exposed to harmful or potentially harmful materials on its platform without first determining what constitutes harmful or potentially harmful material. To take the State‘s own example, data profiling may cause a student who conducts research for a school project about eating disorders to see additional content about eating disorders. Unless the business assesses whether that additional content is “harmful or potentially harmful” to children (and thus opines on what sort of eating disorder content is harmful), it cannot determine whether that additional content poses a “risk of material detriment to children” under the CAADCA. Nor can a business take steps to “mitigate” the risk that children will view harmful or potentially harmful content if it has not identified what content should be blocked.
Accordingly, the district court was correct to conclude that the CAADCA‘s DPIA report requirement regulates the speech of covered businesses and thus triggers review under the First Amendment.
B. Strict Scrutiny Applies to the DPIA Report Requirement.
Given that the DPIA report requirement triggers review under the First Amendment, the district court then needed to determine the appropriate level of scrutiny in assessing whether NetChoice was likely to succeed in showing that the requirement violates the First Amendment. In its preliminary injunction order, the district court found that it was “difficult to determine whether the [CAADCA] regulates оnly commercial speech.” NetChoice, 692 F. Supp. 3d at 947. Accordingly, the court assumed for the purposes of the preliminary injunction “that only the lesser standard of intermediate scrutiny for commercial speech applies” because the outcome of the analysis would be the same under both intermediate commercial speech scrutiny and strict scrutiny. Id. at 947-48. While we understand the district court‘s caution against prejudicing the merits of the case at the preliminary injunction stage, there is no question that strict scrutiny, as opposed to mere commercial speech scrutiny, governs our review of the DPIA report requirement.
Laws regulating commercial speech are generally subject to a lesser standard than strict scrutiny. See Cent. Hudson, 447 U.S. at 563-66. Speech is commercial when it “does ‘no more than propose a commercial transaction.‘” Bolger v. Youngs Drug Prods. Corp., 463 U.S. 60, 66 (1983) (quoting Va. State Bd. of Pharmacy v. Va. Citizens Consumer Council, Inc., 425 U.S. 748, 762 (1976)). We have recognized that the “commercial speech ‘analysis is fact-driven, due to the inherent “difficulty of drawing bright lines that will clearly cabin commercial speech in a distinct category.“‘” First Resort, Inc. v. Herrera, 860 F.3d 1263, 1272 (9th Cir. 2017) (quoting Greater Balt. Ctr. for Pregnancy Concerns, Inc. v. Mayor & City Council of Balt., 721 F.3d 264, 284 (4th Cir. 2013)). Therefore, in close cases, we consider the three factors identified by the Supreme Court in Bolger v. Youngs Drug Products Corporation, to determine if speech is commercial. Id. (“[S]trong support’ that the speech should be characterized as commercial speech is found where the speech is an advertisement, the speech refers to a particular product, and the speaker has an economic motivation.” (quoting Hunt v. City of Los Angeles, 638 F.3d 703, 715 (9th Cir. 2011))). If commercial speech is misleading or related to illegal activity, it is not entitled to protection. Cent. Hudson, 447 U.S. at 563-64. As for laws that compel the disclosure of “purely factual and uncontroversial” commercial speech, such laws are subject to a form of rational basis review. Zauderer, 471 U.S. at 651. For all other commercial speech, courts must apply a form of intermediate scrutiny by asking “whether the asserted governmental interest is substantial,” “whether the regulation directly advances the governmental interest asserted,” and “whether [the law] is not more extensive than is necessary to serve that interest.” Cent. Hudson, 447 U.S. at 566.
The DPIA report requirement — in requiring covered businesses to opine on and mitigate the risk that children are exposed to harmful content online — regulates far more than mere commercial speech. In the DPIA report, a covered business must do far “more than propose a commercial transaction.” Va. State Bd. of Pharmacy, 425 U.S. at 762. Instead, businesses covered by the CAADCA must opine on potential speech-based harms to children, including harms resulting from the speech of third parties, disconneсted from any economic transaction. Cf. Riley v. Nat‘l Fed‘n of the Blind of N.C., Inc., 487 U.S. 781, 796 (1988) (“Our lodestars in deciding what level of scrutiny to apply to a compelled statement must be the nature of the speech taken as a whole and the effect of the compelled statement thereon.“); Wheat Growers, 85 F.4th at 1266, 1275 (assuming that a warning to customers about a carcinogen is purely commercial speech). The mere fact that a business may earn revenue from its services is “insufficient by itself” to render its opinions about those services “commercial.” Bolger, 463 U.S. at 67. And the DPIA requirement goes further, because it not only requires businesses to identify harmful or potentially harmful content but also requires businesses to take steps to protect children from such content. Therefore, the DPIA report requirement appears to meet none of the three Bolger factors: (1) the reports are not advertisements, (2) they require businesses to go beyond opining about their products or services to opine on highly controversial issues of public concern and then take steps to censor material that the company has deemed sufficiently harmful, and (3) businesses do not have a clear economic motivation to provide these opinions or perform this state-required censorship. The same can be said for the speеch that businesses are deputized into self-censoring by operation of the CAADCA‘s mitigation provision. There should be no doubt that the speech children might encounter online while using covered businesses’ services is not mere commercial speech. Further, a business‘s opinion about how its services might expose children to harmful content online is not “purely factual and uncontroversial.” Zauderer, 471 U.S. at 651. We therefore conclude that the subjective opinions compelled by the CAADCA are best classified as non-commercial speech. See Riley, 487 U.S. at 796 (“[W]e do not believe that the speech retains its commercial character when it is inextricably intertwined with otherwise fully protected speech.“).
Amicus Institute for Law, Innovation & Technology (iLIT) contends that the district court “fundamentally misunderst[oo]d what DPIAs entail, how they are used, where they originated, when they are necessary — and the central fact that they are widespread and commonly used.” Tellingly, iLIT compares the CAADCA‘s DPIA report requirement with a supposedly “similar DPIA requirement” found in the CCPA, and proceeds to argue that the district court‘s striking down of the DPIA report requirement in the CAADCA necessarily threatens the same requirement in the CCPA. But a plain reading of the relevant provisions of both laws reveals that they are not the same; indeed, they are vаstly different in kind.
Under the CCPA, businesses that buy, receive, sell, or share the personal information of 10,000,000 or more consumers in a calendar year are required to disclose various metrics, including but not limited to the number of requests to delete, to correct, and to know consumers’ personal information, as well as the number of requests from consumers to opt out of the sale and sharing of their information.
Considering the above, the district court in its preliminary injunction analysis should have subjected the DPIA report requirement to strict scrutiny, as opposed to mere intermediate commercial scrutiny. Strict scrutiny is warranted because the DPIA report requirement (1) compels speech with a particular message about controversial issues, see Nat‘l Inst. of Fam. & Life Advocs. v. Becerra, 585 U.S. 755, 766 (2018); and (2) deputizes private actors into censoring speech based on its content, see United States v. Playboy Ent. Grp., Inc., 529 U.S. 803, 806, 813 (2000). While it is true that “a State possesses legitimate power to protect children from harm, [] that does not include a free-floating power to restrict the ideas to which children may be exposed.” Brown v. Ent. Merchants Ass‘n, 564 U.S. 786, 794 (2011) (citations omitted).
C. The DPIA Report Requirement Likely Fails Strict Scrutiny.
Although the district court stopped short of concluding that strict scrutiny governed its review of the DPIA report requirement, the court‘s ultimate conclusion that the DPIA report requirement is likely to fail First Amendment scrutiny was correct.
Assuming arguendo that the State has a compelling interest in protecting children from “being pushed ... unwanted material, such as videos promoting self-harm,” as the State itself contends, the State is unlikely to show that the DPIA report requirement is “the least restrictive means” available for advancing that interest. Playboy Ent. Grp., 529 U.S. at 813. As Amici American Civil Liberties Union and American Civil Liberties Union of Northern California (together, the ACLU) note in their amicus brief, the CAADCA‘s broad requirement that companies identify the risk of children being exposed to potentially harmful content necessarily compels companies to “assess the potential for [online] material to instigate grief, sorrow, pain, hurt, distress, or affliction in a minor.” Such material
includes online mental health resources and communities that many children turn to for support. It touches reporting about school shootings, war, climate change, and teen suicide. And it reaches minors’ own political or religious speech, as well as their personal updates about deaths in the family, rejection from a college, or a breakup.
The State could have easily employed less restrictive means to accomplish its protective goals, such as by (1) incentivizing companies to offer voluntary content filters or application blockers, (2) educating children and parents on the importance of using such tools, and (3) relying on existing criminal laws that prohibit related unlawful conduct.
The State also asserts that the DPIA report requirement protects children‘s safety by encouraging companies to proactively assess “hоw their products use children‘s data and whether their data management practices or product designs pose risks to children,” so that “fewer children will be subject to preventable harms.” Again, assuming this interest is compelling, the DPIA report requirement is still likely to fail on the tailoring-end of the analysis. See Playboy, 529 U.S. at 813.
In addition, a disclosure regime that requires the forced creation and disclosure of highly subjective opinions about content-related harms to children is unnecessary for fostering а proactive environment in which companies, the State, and the general public work to protect children‘s safety online. For instance, the State could have developed a disclosure regime that defined data management practices and product designs without reference to whether children would be exposed to harmful or potentially harmful content or proxies for content. Instead, the State attempts to indirectly censor the material available to children online, by delegating the controversial question of what content may “harm to children” to the companies themselves, thereby raising further questions about the onerous DPIA report requirement‘s efficacy in achieving its goals. And while the State may be correct the DPIA reports’ confidentiality reflect a degree of narrow tailoring by minimizing the burden of forcing businesses to speak on controversial issues, that feature may also cut against the DPIA report requirement‘s effectiveness at informing the greater public about how covered businesses use and exploit children‘s data.
Ultimately, the DPIA report requirement falls well short of satisfying strict First Amendment scrutiny. The district court was therefore correct to conclude that NetChoice is likely to succeed in showing that the DPIA report requirement facially violates the First Amendment.
II. It Is Unclear From the Record Below Whether Other Challenged Provisions of the CAADCA Facially Violate the First Amendment.
In every application of the DPIA report requirement to a covered business, the DPIA report requirement raises the same First Amendment issues. Accordingly, the current record allows us to analyze whether the DPIA report requirement is likely to violate the First Amendment was through a facial challenge. Whether NetChoice is likely to succeed on its facial challenge as to the remaining provisions it challenges is less certain. For instance, most of those provisions, by their plain language, do not necessarily impact protected speech in all or even most applications. See
Consider, for instance, the CAADCA‘s prohibition agаinst using
dark patterns to lead or encourage children to provide personal information beyond what is reasonably expected to provide that online service ... to forego privacy protections, or to take any action that the business knows, or has reason to know, is materially detrimental to the child‘s physical health, mental health, or well-being.
The district court also sustained facial attacks on several other provisions that, on their face, do not necessarily impact protected speech in all or even most applications. See
The only remaining provision challenged by NetChoice that clearly triggers First Amendment scrutiny in all its applications is
In light of the above, we conclude that the district court‘s failure to properly consider the facial nature of NetChoice‘s challenges to
III. It Is Too Early to Determine Whether the Unconstitutional Provisions of the CAADCA Are Likely Severable from Its Valid Remainder.
Because it is unclear to us whether NetChoice is likely to succeed in its facial challenges to
“Severability is ... a matter of state law.” Sam Francis Found. v. Christies, Inc., 784 F.3d 1320, 1325 (9th Cir. 2015) (alteration in original) (quoting Leavitt v. Jane L., 518 U.S. 137, 139 (1996)). “In California, the presence of a severability clause in a statutory scheme that contains an invalid provision ‘normally calls for sustaining the valid part of the enаctment.‘” Garcia v. City of Los Angeles, 11 F.4th 1113, 1120 (9th Cir. 2021) (quoting Cal. Redevelopment Ass‘n v. Matosantos, 267 P.3d 580, 607 (Cal. 2011)). No such severability clause exists in the CAADCA.
Regardless of whether there is a severability clause, courts must also examine whether the invalid portion of a statute is “grammatically, functionally, and volitionally” severable from the valid remainder of the statute. Calfarm Ins. Co., 771 P.2d at 1256; Legislature v. Eu, 816 P.2d 1309, 1335 (Cal. 1991) (“[I]t is
Here,
However, we vacate the district court‘s determination that the DPIA report requirement is unlikely to be functionally severable from the remainder of the law. For instance, NetChoice has failed to show why the CAADCA‘s “Children‘s Data Protection Working Group,” which is tasked with making recommendations to the California State Legislature on “best practices” concerning the data privacy of children, cannot function without the DPIA report requirement. See
We also think it is a much closer question than the district court assumed whether the elimination of the 90-day cure period, which cannot operate without the DPIA report requirement, see
CONCLUSION
For the foregoing reasons, we AFFIRM the district court‘s preliminary injunction insofar as it enjoined enforcement of