When privacy and accountability collide, the line that matters is intent. California’s AB 2624 draws that line where threats and targeted intimidation begin—expanding long‑standing address‑confidentiality tools to immigrant‑service workers while limiting new online liability to postings meant to provoke violence or fear. The core program is familiar; the controversy is whether anti‑doxxing rules can be drafted narrowly enough to protect safety without chilling scrutiny.
At a Glance
- AB 2624 adds designated immigration support workers and volunteers to California’s Safe at Home address‑confidentiality program.
- The law also creates targeted remedies against publishing personal data or images with intent to facilitate violence or cause reasonable fear.
- Supporters frame it as a continuation of a 25‑year administrative model protecting people at risk of harassment or assault.
- Critics warn vague anti‑doxxing provisions can chill lawful reporting and spawn costly litigation; First Amendment scholars have flagged risks in similar laws.
What the law actually does: program mechanics and scope
AB 2624, authored by Assemblymember Mia Bonta, builds atop California’s Safe at Home program—the Secretary of State’s substitute‑address and mail‑forwarding regime created in 1999 for victims of domestic violence and later extended to other at‑risk groups. The bill brings “designated immigration support services” providers, their employees, and volunteers—people who have experienced threats or harm because of that work—under the same address‑confidentiality umbrella. That means qualified participants can use a state‑provided address with government entities and shield residential details that otherwise circulate through routine records and data brokers.
The statute also establishes a civil, intent‑based online privacy protection: posting a participant’s personal identifiers or images with the purpose of causing imminent physical harm—or conduct that would cause a reasonable person to fear for their safety—can trigger court‑ordered removal, statutory damages, and attorneys’ fees. The law becomes operative October 1, 2027, aligning implementation with rulemaking and agency readiness windows documented in legislative analyses and bill tracking.
How we got here: Safe at Home’s evolution and the anti‑doxxing turn
Safe at Home is not experimental. For a quarter‑century, California has administered substitute addresses to reduce the risk that home information becomes a vector for stalking, retaliation, or worse. Over time, legislators added cohorts exposed to credible threats—reproductive‑health workers, certain public officials, and others—reflecting a policy judgment: when targeted harassment escalates to safety risks, address shielding is a proportionate mitigation, with carve‑outs for law enforcement needs and agency compliance. AB 2624 continues that administrative pattern by adding a workforce that, sponsors argue, now faces similar risks tied to polarizing public rhetoric around immigration.
What is newer is the codified response to doxxing—the publication of identifying details to expose targets to offline harassment. States have begun grafting anti‑doxxing provisions onto privacy programs, but the First Amendment implications are real. Constitutional doctrine protects publication of truthful information on matters of public concern absent narrow exceptions; scholars reviewing the first wave of anti‑doxxing laws conclude many were drafted overbroadly and risk facial invalidation if they punish truthful speech without a tight mens rea and harm nexus. AB 2624’s drafters, aware of this, hinge civil liability on intent to facilitate violence or induce reasonable fear—an approach closer to constitutionally durable threats/harassment doctrines than to content‑based speech bans.
The contested ground: safety versus scrutiny
Supporters say the bill is precisely targeted. Legislative analyses describe covered persons as those who have faced threats, harassment, or violence because of their work; remedies focus on postings weaponized to intimidate or endanger, not on ordinary reporting. On the address‑confidentiality side, agencies have two decades of protocols for honoring substitute addresses without breaking public‑records systems. On the online side, the law requires a court to find intent and harm before penalties attach, a due‑process chokepoint that filters hard cases from heated rhetoric.
Opponents, led prominently by Assemblymember Carl DeMaio and YouTuber Nick Shirley, contend the statute’s language—especially where “images” and “harassment” appear alongside personal identifiers—can be stretched to target citizen watchdogs. Their fear is not far‑fetched in structure: even if they ultimately prevail in court, the threat of injunctions, minimum statutory damages, and fee‑shifting can chill investigations of nonprofits receiving public funds. That is the classic “process as punishment” concern. They also argue that any private enforcement tool keyed to “reasonable fear” can be pleaded opportunistically by organizations seeking to bury unflattering footage.
Where the text is likely durable—and where it is legally exposed
Courts separate three categories cleanly. First, address‑confidentiality programs are well‑established administrative measures; they regulate government handling of personal data and have survived for decades because they do not restrict speech by private parties. AB 2624’s extension to immigration‑service workers comfortably sits here. Second, targeted bans on publishing data with intent to facilitate violence or true threats track established unprotected speech categories; properly cabined mens rea and harm elements make these provisions more defensible. If AB 2624’s record shows it aims at doxxing to incite violence, not to suppress criticism, courts generally uphold such narrow tools.
The gray area is any clause that converts subjective “unwelcome” recording or broad “harassment” into liability absent intent to threaten or facilitate harm. Legal scholars warn that anti‑doxxing statutes fail when they criminalize or civilly punish publication of truthful information about matters of public concern based on amorphous distress standards. If AB 2624’s operative sections are applied to suppress nonviolent documentation of alleged fraud, expect prompt First Amendment challenges, and some provisions could be enjoined if they cannot be read narrowly to avoid punishing protected speech.
The “Stop Nick Shirley Act.”
AB 2624 does not stop Nick Shirley or criminalize investigative journalism. Could the law be abused, though? Let's see.
AB 2624 expands California’s existing Safe at Home address-confidentiality program to eligible employees and volunteers of… pic.twitter.com/JWcKP5BDlO
— Wíñchéstër Cölt (@scorpio8675309) August 23, 2026
Practical implications: how watchdogs, agencies, and covered workers should proceed
For immigrant‑service providers and their staff, the address‑confidentiality pathway is straightforward: qualify through the Secretary of State, incorporate the substitute address in government interactions, and coordinate with counsel and local law enforcement where threats persist. Safe at Home does not erase the internet, change federal records, or replace police protection; it reduces passive exposure by diverting mail and masking home locations in routine filings.
For journalists and investigators—established outlets and independent creators alike—the operative guardrail is intent. Filming in public, publishing truthful information about the operations of publicly funded entities, and naming organizations or officials remain protected activities. The legal risk concentrates where content is coupled with doxxing tactics—exposing residential addresses, phone numbers, or images in a manner calculated to unleash harassment or physical harm. If AB 2624 is administered and adjudicated the way supporters describe, that line will be policed by courts applying an intent‑to‑harm test; if it is not, litigation will clarify and, if necessary, prune overbroad applications.
Bottom line: a familiar tool with a modern stress test
AB 2624 is best understood as two linked but distinct moves: a routine expansion of a 1999 address‑confidentiality program to a workforce facing documented threats, and a contemporary attempt to deter doxxing that escalates into violence. The first is settled administrative practice. The second is where constitutional doctrine does, and should, bite. The statute’s survivability turns on whether its civil‑liability provisions operate only against postings intended to facilitate physical harm or instill reasonable fear tied to that harm—not against the publication of uncomfortable truths about how public money is spent. Done right, it protects people, not institutions, from violence. Done poorly, it will not survive contact with the First Amendment—and courts, as ever, will enforce that limit.
Sources:
pjmedia.com, yahoo.com, spsf.senate.ca.gov, calmatters.digitaldemocracy.org, apcp.assembly.ca.gov, fastdemocracy.com, thegatewaypundit.com, politracks.com, hindustantimes.com, gov.ca.gov, youtube.com