Neural data · Grey Matter

Neural data is information generated by measuring the activity of a person's nervous system, and it is the legal object that the first laws on neurotechnology protect, because the mind itself cannot be regulated while the recordings can.


Neural data. Neural data is information generated by measuring the activity of a person's nervous system, and it is the legal object that the first laws on neurotechnology protect, because the mind itself cannot be regulated while the recordings can.

The laws define it by origin rather than content. Colorado's 2024 amendment calls it information generated by measuring the activity of a person's central or peripheral nervous system that can be processed by or with a device; California's, the same year, adds that it must not be inferred from non-neural information. Under both it counts as sensitive personal data, so a company needs stronger justification and, in Colorado, consent to collect and use it.

It is being collected already. Consumer EEG headbands, earbuds and headsets for meditation, sleep, focus and gaming record it; a 2024 review of thirty such companies found that 29 appeared to have access to users' neural data and that their policies gave users few clear rights over it.

It leaks more than its owner intends. A 2012 study showed that software with access to a cheap EEG headset could narrow down a user's bank, PIN digits or home area from the brain's responses to images flashed on screen.

It identifies and diagnoses. Raw recordings carry signatures specific to a person and signs of conditions such as epilepsy or sleep disorders, so even data collected for a game is health and identity data.

Medical and research data sit under other rules. Recordings made by doctors and in clinical trials are governed by health privacy and research ethics, and consumer privacy laws mostly exempt them.

Neural data is protected by where it comes from.

The laws do not wait to see what can be decoded from a recording; they treat any measurement of the nervous system as sensitive from the start.

Questions: Do neural data laws protect a raw recording, or only what is decoded from it? The raw recording, at whatever rate it was sampled. Colorado and California define neural data as information generated by measuring the activity of the nervous system, so the protection attaches to the measurement itself, before any decoding. That choice matters because what can be extracted from a recording depends on how it was sampled and on decoders that will keep improving, so a stored recording can reveal more in a few years than it did when it was collected. How do Colorado and California define neural data, and what changes for a company that collects it? Colorado's law, signed in April 2024, defines neural data as information generated by measuring the activity of a person's central or peripheral nervous system that can be processed by or with a device; California's, signed in September 2024, uses nearly the same words and excludes data inferred from non-neural information. In Colorado neural data became sensitive data under the Colorado Privacy Act, so a company needs the person's consent to process it; in California it became sensitive personal information, which consumers can require a business to use only as needed for the service they asked for. Both laws attach the protection to the measurement itself, before anything is decoded from it. Is a headband that measures blood oxygen in the cortex collecting neural data under the law? The answer is not settled. fNIRS measures haemoglobin in the blood vessels of the cortex, a signal that follows neural activity without being it, while both state laws define neural data as information generated by measuring the activity of the nervous system. California adds that neural data must not be inferred from non-neural information, a clause that a company could read as excluding vascular signals and a regulator could read the other way, since the blood response is used precisely as a measure of neural activity. Colorado's broader category of biological data, which includes physiological properties used for identification, may cover such signals anyway. What did Chile's Supreme Court order in the first case brought under the neurorights amendment? In August 2023 the court ruled against Emotiv, a maker of consumer EEG headsets, in a case brought by a user of its Insight device, and ordered the company to delete the brain data it had collected from him. It found the company's practices incompatible with the new constitutional protection of brain activity, questioned whether accepting terms of service to use a purchased device is free consent, and held that using data for research requires specific consent naming that research. The ruling showed the amendment applying to an ordinary consumer product, years before any device could read thoughts. If consumer EEG is so noisy, how much can it reveal about its user? Enough to matter, because noise is beaten by repetition. In a 2012 study, software connected to a cheap EEG headset flashed images of banks, digits and places and read the brain's recognition response to each, narrowing down which bank a user had, digits of a PIN and where they lived better than chance. A single noisy trial says little, but many trials averaged by an app that runs for hours say more, which is why privacy advocates treat even low-quality consumer recordings as sensitive neural data. What happens to the brain recordings that an implanted stimulator stores? Closed-loop devices such as the responsive neurostimulator record activity at the seizure focus continuously and store stretches of it, which are uploaded for the clinicians who adjust the settings. Those years of intracranial recordings are also research data: pooled from 37 people, they revealed that seizure risk follows cycles of weeks. Such data are health data covered by medical privacy rules, and the questions of who may reuse them, for what, and with what consent are the same ones that neural data laws raise for consumer devices, answered here by research ethics instead. Would a record of activity written inside brain cells count as neural data? Under the definitions written so far it plausibly would, since Colorado and California cover information generated by measuring the activity of the nervous system, and reading a molecular record is such a measurement made after the fact. The question is hypothetical, because molecular recorders work only in cells and animals and are read from fixed tissue. It shows a design choice in those laws: by attaching protection to the origin of the data, they also cover recording methods that do not exist yet. Why is neural data treated as more sensitive than other personal data? A recording of the brain can reveal things its owner has not chosen to express and may not know, such as recognition, attention, mood or signs of a neurological condition, and it is produced without a deliberate act the way speech or typing is. What it reveals also grows after collection, because a stored recording can be analysed again with better decoders years later. For these reasons ethicists proposed treating it like organs, protected by default and shared only by explicit choice, and Colorado and California classed it as sensitive data in 2024.