As of July 1, 2026, Connecticut residents became some of the most legally protected brain-wave owners in the world. Under the state’s amended data privacy law, neural data — information generated by measuring the activity of the nervous system — is now classified as “sensitive data,” triggering the same heightened protections as biometric identifiers, precise location data, and medical records.
This isn’t a law about neuroscience research in hospital settings. It’s a law directly responding to consumer technology: the meditation headbands, EEG sleep trackers, focus-enhancement apps, and brain-computer interface devices that have quietly moved from research labs onto bestseller pages and into millions of bedrooms, offices, and gyms.
The category exists. The devices are real. The data they collect is among the most intimate any consumer technology has ever produced. And in most of the United States, it has no specific legal protection at all.
What Neural Data Actually Is
Neural data is any information derived from measuring the electrical activity of the brain or peripheral nervous system. The term covers several things that consumer devices currently collect:
Electroencephalography (EEG) signals. Raw brainwave patterns, collected via scalp electrodes. Consumer EEG devices like the Muse headband measure these signals and use them to infer mental states: focus level, stress, relaxation, sleep depth. The raw signals themselves are rarely what users see — they’re processed by algorithms that produce readable outputs like a “calm score” or “focus index.”
Derived cognitive states. Machine learning models trained on EEG data can classify what a person is experiencing — concentration, distraction, anxiety, drowsiness — from raw signals. Some consumer apps report these derived states as data about you. That classification layer is its own form of personal data, distinct from the raw signal that produced it.
Sleep architecture data. EEG-based sleep trackers distinguish between light sleep, deep sleep, and REM sleep at a level of granularity far beyond what standard wrist-worn accelerometers can achieve. Devices like certain sleep headbands use neural or neural-adjacent signals to map sleep architecture in detail. This is qualitatively different from knowing you slept seven hours — it’s a clinical-grade characterization of your brain’s activity through the night.
Longitudinal cognitive profiles. Some devices train users to consciously alter their neural states — lowering anxiety or improving focus through biofeedback — and collect data on how those patterns change over weeks and months. A company that has years of your cognitive-state data has something that looks less like wellness metrics and more like a detailed record of your mental life over time.
What makes neural data distinctive is not just its sensitivity in the privacy-violation sense. It’s that neural patterns can potentially reveal things a person doesn’t consciously know about themselves: early signs of neurological conditions, mental health states, cognitive performance trends, and emotional responses to specific stimuli. Unlike step count or sleep duration, this data operates at a level that isn’t fully transparent even to the person generating it.
Where the Laws Stand Now
Colorado was the first state to explicitly classify neural data as sensitive personal information, adding it to the state’s comprehensive privacy law in 2024. California followed with amendments that brought neural data under the California Consumer Privacy Act’s heightened protections. Montana and Connecticut have since added similar classifications.
Connecticut’s July 1, 2026 effective date is the most recent and among the most robust. Under the amended Connecticut Data Privacy Act, any company that processes neural data from a Connecticut resident must:
- Obtain explicit opt-in consent before processing it for any purpose
- Obtain separate, additional consent before selling or sharing it with third parties
- Provide clear disclosure of what neural data will be collected and how it will be used
- Conduct and document a data protection assessment before initiating processing
These requirements apply to consumer neurotechnology companies regardless of where they’re incorporated. A meditation app based in California that has users in Connecticut must comply with Connecticut’s standards for those users.
At the federal level, the picture is less encouraging. The MIND Act (Management of Individuals’ Neural Data Act) — which would direct the FTC to study neural data governance and potentially establish enforceable standards — has not passed as of mid-2026. Without federal legislation, the primary federal backstop is Section 5 of the FTC Act, which prohibits “unfair or deceptive acts or practices.” That standard requires showing a company did something demonstrably harmful, not merely that it collected sensitive data without a clear disclosure or meaningful consent mechanism.
For the majority of US states, neural data collected by a consumer EEG headband has fewer legal protections than a medical record, a bank statement, or a driver’s license number. That’s the current state of the law.
What Consumer Devices Are Collecting
The market for consumer neurotechnology has grown faster than most people realize. A few of the major products and what they collect:
Muse by Interaxon. The Muse headband uses EEG sensors to provide biofeedback during meditation sessions, rating the user’s mental calm in real time and guiding them toward quieter brain states. Data is processed in the Muse app and synced to the cloud. Interaxon’s privacy policy states it collects “brain activity data” and may share aggregate data with research partners, while retaining user data for the duration of the account relationship and a period after deletion.
Emotiv EPOC X and Insight. Emotiv’s devices are more research-oriented but marketed to consumers for productivity and focus monitoring. Emotiv collects EEG data and has built a proprietary dataset from user recordings for its AI model development. Users have the option to opt out of this program, but the default is opt-in, meaning users who don’t read the terms carefully are contributing their neural data to model training without realizing it.
Focus-enhancement apps paired with consumer EEG hardware. Numerous apps designed to improve concentration, reduce anxiety, or train specific mental states work in conjunction with consumer EEG headbands. Some of these apps are built by small developers with minimal legal infrastructure and vague privacy policies that don’t specifically address neural data, what happens to it upon account deletion, or who they share it with.
Neuro-wellness apps without hardware. A growing category of apps uses heart rate variability, breathing patterns, and other physiological signals that can serve as proxies for neural states. These apps occupy a gray zone: they may not collect data the law specifically classifies as “neural,” but the derived inferences they produce — stress levels, emotional regulation capacity, sleep quality assessments — are functionally similar.
The Risk Isn’t Just Hacking
Most privacy coverage focuses on external breaches: unauthorized access to data by people outside the company. For neural data, the internal and secondary risks may be equally significant.
Insurance and employment discrimination. Neural data patterns can potentially reveal risk markers for neurological conditions — early signs of attention difficulties, anxiety patterns, disrupted sleep architecture associated with mental health conditions. If this data leaves a wellness app and reaches an insurer or employer, it could affect underwriting or hiring decisions in ways that are difficult to detect or challenge. The legal protections against this kind of discrimination are currently weaker than the technical feasibility of the discrimination itself.
Targeted advertising for mental states. Knowing that a person experiences elevated stress during certain hours, or shows engagement patterns suggesting anxiety, is potentially valuable to advertisers in ways that go beyond standard demographic targeting. Derived cognitive state data — your stress score by hour of day, your focus trend across a week — is a detailed behavioral profile that could be used to time, target, and calibrate advertising.
Future re-identification. Neural patterns may be biometrically unique, similar to fingerprints. Aggregate neural data collected today, even if labeled “anonymized,” may become re-identifiable as technical capabilities improve. Data collected for wellness purposes and retained indefinitely is data that exists in whatever technical and legal environment the future brings.
Acquisition risk. Small neurotechnology startups are acquisition targets. Many consumer neurotech products have changed hands — sometimes with disruptions to the privacy commitments the original company made. A product’s privacy policy at the time of purchase is not necessarily its policy two years later. Acquisition clauses in privacy policies that allow data transfer to a “successor company” mean your neural data follows the company through corporate transactions, not just the product through its lifecycle.
What to Look For When Evaluating a Neural Wearable
Not all consumer neurotechnology has equivalent data practices. Before buying or continuing to use an EEG-based device, a few things are worth checking:
Where data is processed. Does the device process EEG signals entirely on your device, or does raw EEG data get sent to the cloud? On-device processing means the neural signal never leaves your phone or the headband itself. Cloud processing means it’s stored on the company’s servers, subject to their retention policies, security practices, and any government demands directed at those servers.
What the company does with derived data. Even if raw EEG is processed on-device, the derived outputs — your calm score, your focus trend, your sleep stage breakdown — may be synced to the cloud for app functionality. Check whether these derived metrics are also used for model training, shared with research partners, or shared with advertising partners.
Opt-out from data sharing. Look for an explicit option to decline research participation and third-party data sharing. If the app doesn’t offer a clear opt-out from these uses, the default is that your neural data may be used for purposes beyond your wellness session.
Data deletion. If you stop using a device, what happens to the neural data already collected? Look for a concrete deletion option — not just account deactivation — that removes both raw signals and derived data from the company’s systems, and specifies a timeframe for completion.
What jurisdiction applies. Colorado, California, Montana, and Connecticut residents have specific legal rights over neural data that residents of other states don’t. Some privacy-conscious companies have made universal commitments — applying the strongest available state standard to all users — which you can verify in their privacy policy’s state-specific disclosures section.
The European Context
Users in Europe likely have stronger baseline protections than US users do under current law. Under the GDPR’s Article 9, neural data almost certainly qualifies as “biometric data processed for the purpose of uniquely identifying a natural person” or as health data, both of which are “special categories” requiring explicit consent and a specific legal basis for processing. “Legitimate interest” alone cannot justify processing special category data.
This means European users of consumer EEG devices theoretically have stronger rights — to withdraw consent, to request deletion, to object to specific processing — than the law currently provides in most US states. The practical enforceability of those rights against small consumer tech companies operating across borders is a separate question, but the framework is meaningfully stronger.
How the Regulatory Gap Could Close
The trend across state-level privacy law has been consistent: a category gains explicit protection in one state, then spreads. Biometric data went from an Illinois law in 2008 to being classified as sensitive in nearly every comprehensive state privacy law enacted since. Genetic data followed a similar path.
Neural data appears to be on the same trajectory. Colorado, California, Montana, and Connecticut made the first legislative moves. Several other states with active privacy legislation are expected to add neural data to their sensitive categories in the next legislative cycle. The category is unusual in legislative terms because it crosses obvious partisan lines — concerns about government access to brain activity data, about corporate exploitation of cognitive profiles, and about the potential for neural data to be used in employment decisions are not arguments that cluster neatly on one side of the political spectrum.
At the federal level, the most likely path to broader protection runs through FTC enforcement authority. The agency has shown increasing willingness to act against companies that collect sensitive data categories without adequate consent or security measures. A significant neural data breach, or a documented case of an insurance company using wellness app data to adjust rates, would likely accelerate both FTC enforcement and federal legislative interest.
For the time being, the practical advice is the same as it is for any sensitive category of personal data that hasn’t yet achieved universal legal protection: understand what you’re sharing, verify what the company does with it, and choose providers with clear data practices rather than relying on the law to protect you by default.
The law will catch up. It always does. In the meantime, your brain waves are yours. Act accordingly.