The Newsom Administration’s Oversight Scandal: $201.7 Million in Taxpayer-Funded Fees, Unanswered Warnings
The Newsom Administration paid Lendistry more than $200 million to run taxpayer-funded grant programs. A filed lawsuit alleges missing oversight, continuing data harvesting, and failures to enforce California’s privacy law.
The Newsom Administration’s Oversight Scandal$201.7 Million in Taxpayer-Funded Fees, Unanswered Warnings
The Gavin Newsom Administration put a single private contractor in charge of grant programs authorized at more than $4.5 billion and paid it more than $200 million in administrative fees. A filed lawsuit alleges that the Administration failed to enforce California’s privacy law across the system it purchased, exposing applicants’ financial records, communications, and continuing bank activity to outside collection and commercial use. Written warnings described ongoing harm and demanded an investigation. The Newsom Administration did not answer or follow up.
When the COVID-19 pandemic disrupted California’s economy, the Gavin Newsom Administration launched a grant program to help small businesses and nonprofits survive. The program grew into a multibillion-dollar undertaking. Its final award figures record approximately $3.79 billion distributed through 330,023 awards. Other programs supported independent live-event venues and nonprofit performing-arts organizations, reimbursed employers for COVID-related sick leave, and funded new small businesses.
Authorized across six agreements
Latest reviewed ceilings total $4.5955 billion.
Paid out in the flagship relief program
330,023 awards; awards are not a count of unique people.
Sources
Reported administrative fees
The Administration’s figure at the April 23, 2024 hearing.
Sources
To the November 2025 warnings
No answer or follow-up through September 28, 2026.
The Newsom Administration hired B.S.D. Capital, Inc., doing business as Lendistry, to operate the application systems, collect supporting records, verify eligibility, and distribute the money. Businesses seeking these grants went through the contractor’s portals and processes. The relationship expanded to agricultural disaster relief and other business programs. Across the six agreements examined in this report, the latest authorized program ceilings total $4.5955 billion. All six placed administration of those programs with Lendistry.
The problem alleged in a lawsuit against the Newsom Administration is what happened to the information businesses had to surrender to get help. The complaint describes repeated access to bank accounts after the initial verification, outside processing of tax and payroll records, analysis of applicants’ conversations, and commercial use of information gathered through the grant system. It accuses the Administration of paying for that operation without enforcing the privacy protections and oversight California law required.
The taxpayer money. The Newsom Administration’s own budget officer told the Legislature that Lendistry’s administrative fees across the grant programs totaled approximately $201.7 million. The Administration chose the contractor, defined its work, and retained contractual powers to inspect and enforce performance. Taxpayers funded an operation whose budgets included technology, security, and compliance work.
The Administration’s own alleged failures. The lawsuit accuses the Newsom Administration of leaving California’s Information Practices Act unenforced across the outsourced system: excessive collection, unaccounted-for disclosures, missing safeguards, uncontrolled vendor access, and no usable procedures for people to inspect or correct their files.
The unanswered warnings. In November 2025, written warnings told the Newsom Administration that bank-account access and other collection were continuing. They described AI processing of sensitive records and communications, tracking, and commercialization. They requested an investigation and concrete reforms. The Newsom Administration did not answer or follow up.
The records demanded from applicants could reach far beyond a business balance sheet: tax returns identifying spouses and dependents, payroll showing employees’ wages and COVID-related absences, and access to bank accounts. The people exposed to collection therefore included employees and family members who had never applied for a grant themselves. The complaint alleges that the Newsom Administration commissioned and funded this system without applying the state law that limited collection, required accountability for disclosures, and gave individuals rights over their records.
California’s Information Practices Act expressly addresses outsourced government records. Section 1798.19 requires an agency, consistent with its authority, to cause the Act’s requirements to apply when it contracts for a personal-information records system to perform an agency function. Hiring a private company to run the applications did not relieve the Newsom Administration of that duty.
The Administration had contractual tools to demand compliance. Its agreements specified application workflows, security representations, reports, invoicing, and inspection. The original relief agreement required Lendistry to provide its annual controls report. An amendment repeated that requirement. Yet when the Newsom Administration responded to a request for audits and findings, the ten reports in the identified production supplied the contractor’s descriptions of security practices without the underlying assessments.
The November 2025 warnings made the stakes explicit. “These instances of improper access to grant applicant accounts are still happening,” a November 5 letter said. “None of the affected businesses have been notified.” One letter was addressed to Van T. Nguyen, an Administration official whose position the contracting agency’s published policy designated as Privacy Officer. The letters requested an investigation of compliance with privacy law. The Newsom Administration did not answer or follow up.
The action was filed in Los Angeles Superior Court on August 5, 2026. Its allegations have not been adjudicated. This report examines the complete complaint alongside the contracts, official payment statements, program reports, agency policies, statutes, and warning letters. The documents establish the Administration’s spending, contractual powers, and the specific demands directed to its officials; the complaint supplies the allegations about how the systems operated and how the Administration failed to perform its duties.
The accountability question runs through every stage of the programs. What did the Newsom Administration require people to surrender to seek assistance? What did its contracts permit private companies to do with the records? What did officials demand in return for taxpayer-funded administration? And after warnings identified continuing harm, what did the Administration do to investigate and stop it?
The Administration’s decisions, in sequence
The contracts and payment records establish the scale. The letters establish the warnings. The filed complaint alleges the failures.
- The grant program begins
The flagship California Small Business COVID-19 Relief Grant Program launches. Lendistry administers the application system.
[L01, PDF p. 27, ¶¶101–102] [F11, PDF p. 24] - $4.225 billion received by Lendistry
A later signed acknowledgment records $4,050,123,000 for grants and $174,877,000 for administration received from December 2020 through December 2021.
[F02, PDF pp. 1, 7] - $201.7 million in reported administrative fees
Administration budget officer Philip Chen reports this aggregate administrative-cost figure to the Legislature. It overlaps the earlier administrative receipts.
[F01, 01:35:57–01:36:38] - Written warnings seek an investigation
Letters to Administration officials describe allegedly continuing collection and commercial use, identify the agreements, and request concrete reforms.
[L07, PDF pp. 1–5] [L08, PDF pp. 1–5] - The complaint is filed
The action is filed in Los Angeles Superior Court. The allegations have not been adjudicated.
[L01, PDF p. 1] - No answer or follow-up through this date
The report’s response-status cutoff: the Administration had not answered the warnings or followed up.
[N01]
The money and the mandate
Billions in public funding. The rules the Administration was required to apply.
California Had a Privacy Law. The Newsom Administration Had to Follow It.
California had protected privacy long before the Newsom Administration directed emergency-grant applicants into Lendistry’s systems. Voters added privacy to the State Constitution in 1972 in response to government and business using computers to accumulate personal information and reuse it for unrelated purposes. The complaint invokes that history because it alleges that applying for a public benefit became an enduring source of information for private companies.
The Information Practices Act of 1977 gave that protection statutory force. The Legislature identified indiscriminate collection, maintenance, and dissemination of personal information as threats amplified by computers and called for strict limits. It directed that the Act be interpreted liberally to protect privacy under the statute and the state and federal constitutions. The Newsom Administration inherited an existing duty to control the information its programs collected.
The lawsuit accuses the Newsom Administration of failing to carry those protections into a system it commissioned and paid to operate. California had enacted limits on government recordkeeping. The complaint says the Administration built a taxpayer-funded application process without establishing the control over the resulting records that those limits required.
The contractor is B.S.D. Capital, Inc., doing business as Lendistry. The six-agreement relationship examined here is the Newsom Administration’s relationship with that contracting company.
The Newsom Administration acted through two agencies named as defendants: the Governor’s Office of Business and Economic Development, formally abbreviated GO-Biz, and its California Office of the Small Business Advocate, CalOSBA. Government Code section 12096.2 places the former within the Governor’s office, makes its director responsible to the Governor, and authorizes the Governor-appointed director to contract for professional and consultant services. The latter administered the grant programs. The complaint also names their directors in their official capacities: Dee Dee Myers and Elmy Bermejo, respectively. The requested orders would bind those Administration agencies and officials to perform their statutory duties.
The Newsom Administration could set the rules before the first applicant uploaded a tax return. Across six agreements and at least eight amendments, the Administration specified application systems, fraud prevention, languages, and reporting. The lawsuit alleges that officials repeatedly exercised that authority while leaving applicants’ statutory privacy rights unimplemented.
What Did Taxpayers Get for $201.7 Million?
The $201.7 million figure came from the Administration itself. At an April 23, 2024 Assembly budget hearing, a legislator asked about the administrative fees paid to Lendistry. Administration budget officer Philip Chen answered that approximately $201.7 million had been used for administrative costs, roughly 4.3 percent of approximately $4.7 billion across programs. The official captions preserve the exchange.
Six agreements. $4.5955 billion authorized.
Latest program ceilings in the agreements reviewed.
- Pandemic relief and venues20GOB039 [F03, PDF pp. 1–2]$4.148 billion
- Supplemental paid sick leave22GOB031 [F08, PDF p. 1]$250 million
- Agricultural drought and flood relief23GOB014 [F04, PDF p. 1]$95 million
- Nonprofit performing arts21GOB025 [F07, PDF p. 1]$49.5 million
- Dream Fund21GOB024 [F06, PDF p. 1]$35 million
- CA:RISE23GOB033 [F05, PDF p. 1]$18 million
The Newsom Administration had already signed an acknowledgment of $174,877,000 in administrative payments. Amendment 3 to the flagship agreement records Lendistry’s receipt of $4.225 billion from December 2020 through December 2021: $4,050,123,000 for grants and $174,877,000 for administration. The Administration and Lendistry signed it in May 2022. Those earlier receipts overlap the later total reported by the Administration.
The Newsom Administration’s Amendment 3 records $174,877,000 in administrative payments received by Lendistry through December 2021. Budget excerpt, Agreement 20GOB039, PDF p. 7 (Exhibit A, p. 6 of 10).
Open the complete document ↗The six agreements examined here span pandemic business relief, venues, the Dream Fund, nonprofit performing arts, supplemental paid sick leave, agricultural drought and flood relief, and CA:RISE. Venues is included within the flagship agreement. The latest program ceilings in the agreements reviewed across the six agreements total $4.5955 billion. These ceilings describe authorized program scale; the payment evidence comes from the separate acknowledgment and hearing statement.
| State agreement and program | Latest ceiling in the agreements reviewed | Separately stated administrative allowance |
|---|---|---|
| 20GOB039 relief and venues | $4.148 billion | Earlier administrative receipts are recorded in Amendment 3. |
| 23GOB014 agricultural drought and flood relief | $95 million | $4.75 million |
| 23GOB033 CA:RISE | $18 million | $900,000 |
| 21GOB024 Dream Fund | $35 million | $1.75 million |
| 21GOB025 nonprofit performing arts | $49.5 million | $2.475 million |
| 22GOB031 supplemental paid sick leave | $250 million | $12.5 million |
The five separately stated allowances total $22.375 million. They are not additional receipts to add to the $201.7 million figure. The agricultural agreement also reserves a separate outreach amount. Redacted budgets and differing accounting measures limit how precisely the public record can allocate the fees among functions.
The visible budgets show the kinds of work taxpayers were being asked to fund. CA:RISE estimated $167,701 for technology expenses described as hosting the application portal, including document storage and audits. It estimated $147,832 for call-center support. The performing-arts budget included $74,255 for outside legal and compliance work. Other categories included bank verification, software licensing, data analytics, and technical support.
The sick-leave budget put $286,488 against a lead backend developer, $190,992 against a lead frontend developer, $183,726 against technical support, and $91,863 against AWS and development operations. Five program budgets allocated another $54,615 to CEO salary and benefits. These budget lines identify the technical and executive work the Administration agreed to fund. They record planned costs rather than distributions of personal profit.
CA:RISE’s outside-legal-cost explanation expressly anticipated applicant escalations, subpoenas, and “any applicant litigation that may arise out of the program.” The amount is redacted. The Newsom Administration accepted a budget contemplating legal disputes over the program. The lawsuit alleges it failed to provide the lawful information handling and usable records procedures applicants needed in the first place.
The spending gives the oversight failure alleged in this case its scale. The public paid for administration that included technical systems, security representations, and compliance work. The Administration could specify privacy duties, demand supporting records, and inspect performance. The complaint accuses it of paying the contractor while failing to make California’s privacy statute govern the records. It is that alleged failure to obtain and enforce the protections attached to the work that calls the Administration’s stewardship of taxpayer money into question.
Billions in Taxpayer-Funded Assistance, One Private Gatekeeper
Each taxpayer-funded program had a defined job. Pandemic grants helped businesses remain open. Paid-sick-leave grants reimbursed qualifying employers. Other programs supported live venues, nonprofit performing arts, new businesses, and agricultural businesses affected by drought or flooding. CA:RISE, the California Regional Initiative for Social Enterprises, supported organizations employing people with barriers to employment. Those purposes limited what the Administration needed to collect and what it could authorize others to do with the information.
The flagship California Small Business COVID-19 Relief Grant Program began in 2020. In February 2021, Governor Newsom signed Senate Bill 87, adding $2.075 billion to the original $500 million program. Another $1.5 billion expansion in July 2021 used American Rescue Plan Act funding. The complaint cites the program's final award records for $3,792,105,434 disbursed across 330,023 awards. The Administration's subsequent annual report independently reports the same award count and amount.
That federal contribution helped finance a system the Newsom Administration commissioned Lendistry to operate: portals, record collection, eligibility verification, applicant communications, and disbursements. The record identifies the federal contribution to the grant program without allocating Lendistry’s aggregate administrative payments between federal and state sources.
The six agreements covered this broader set of functions and programs:
| State agreement | Public purpose and scale reflected in the record |
|---|---|
| 20GOB039: small-business pandemic relief, including the later venues program | The main relief program ran in 2020–2023 and reported $3.792 billion across 330,023 awards. The separate venues program offered eligible independent live-event venues grants up to $250,000; the Administration reports $152.892 million across 1,083 awards in 2021–2023. [L01, PDF pp. 27–28, ¶¶101–106] [F11, PDF p. 24] |
| 21GOB024: California Dream Fund | The program was created in 2021 to seed entrepreneurship and new small businesses. Its one-time appropriation was $35 million. The Administration's later annual report records $30.77 million across 4,669 awards, covering 2021–2023. [L01, PDF pp. 28–29, ¶107] [F06] [F11, PDF p. 24] |
| 21GOB025: nonprofit performing arts | Grants up to $75,000 supported eligible nonprofit performing-arts organizations. The Administration reports $38.875 million across 881 awards in 2022–2023. [L01, PDF p. 28, ¶105] [F07] [F11, PDF p. 23] |
| 22GOB031: supplemental paid sick leave | Created by Assembly Bill 152 in September 2022, the program offered grants of $5,000 to $50,000 to eligible small businesses and nonprofits that provided qualifying COVID-19 sick leave. The program received a one-time $250 million appropriation; the agreement separately budgeted its administration. [L01, PDF p. 28, ¶104] [F08] [F11, PDF p. 24] |
| 23GOB014: agricultural drought and flood relief | The program, created through 2022 legislation, addressed qualifying declines in gross receipts or profits caused by drought or storm flooding. The Administration reports $71.09 million across 1,032 awards in 2023–2024. [L01, PDF p. 29, ¶108] [F04] [F11, PDF p. 23] |
| 23GOB033: CA:RISE | The agreement commissioned Lendistry to run application intake, customer support, grant management, fraud prevention, disbursement, and reporting for qualifying employment social enterprises. The contract set grant tiers from $150,000 to $500,000, linked to the enterprise's revenue and eligibility. [F05, PDF pp. 3–7] |
The award figures document public assistance delivered. They also show the reach of a system whose records extended beyond successful recipients. Award counts measure transactions, not unique people whose information entered the system. Rejected applicants submitted records too. Employees and family members appeared in supporting documents despite never applying themselves. The awards, appropriations, and contractual grant tiers in the table are distinct from the contractor’s administrative compensation.
The Files Reached Into the Lives of Employees, Spouses, and Children
The Newsom Administration required evidence of eligibility for taxpayer-funded assistance. The complaint identifies filed tax returns, payroll, government-issued identification, and bank records among the materials applicants had to supply. CA:RISE’s agreement independently documents the same approach: owner or signatory demographic information, identification, organizational records, filed federal tax returns, financial validation, and eligibility checks.
Those files can reveal far more than whether a business crossed an eligibility threshold. A personal tax return can identify a spouse and dependents, show identifying numbers, and disclose income sources, investments, retirement income, and claimed deductions. Depending on its contents, it can reveal charitable giving, medical expenses, mortgage interest, and the finances of a closely held business. Payroll records can identify employees and disclose pay, hours, and absences. The privacy interest therefore extends to people whose only connection to the program was appearing in someone else's supporting documents.
By requiring these records, the Administration assumed responsibilities lasting beyond an eligibility decision. It had to establish why the information was needed, preserve its sources, control access and disclosures, maintain accuracy, and provide the rights required by law. Those duties reached the people named in the records. The Administration’s decision to collect through a contractor made enforceable rules for that contractor and its vendors essential.
The Newsom Administration Commissioned the System. It Set the Terms.
The Newsom Administration purchased an operation reaching far beyond grant disbursement. It assigned Lendistry outreach, application intake, eligibility review, document validation, fraud prevention, customer support, and disbursement. CA:RISE’s agreement also placed its website, contact center, communications, and instructional materials within that purchased service. These were parts of the public program that officials commissioned.
The required records identified human beings. The contract called for information about the business owner or authorized signatory, demographic information, government-issued photo identification, payroll, and federal tax returns. The complaint’s inventory also includes home and business addresses, birth dates, Social Security or taxpayer numbers, profit-and-loss information, and bank details. An application could combine identifying information with documents describing a person’s income, transactions, employment, and communications.
The Newsom Administration’s contracts anticipated contact with people who would receive no grant. The agreement required Lendistry to direct every applicant to additional support resources regardless of selection. The complaint alleges that rejected applicants, ineligible applicants, and people who abandoned an application after linking a bank account nevertheless entered the same collection system.
The lawsuit accuses the Newsom Administration of commissioning this entire operation without applying the IPA to records held by Lendistry and its component vendors. The alleged collection extended beyond documents deliberately uploaded: information extracted from those documents, inferences drawn from conversations, repeated bank-account retrievals, and records of online activity.
The Administration’s application process allegedly produced a file that kept growing: transcripts, voiceprints, device profiles, transaction classifications, and predictions about behavior. The complaint says the Administration failed to apply the required protections to that expanding record. Its alleged failure therefore concerns the operation it funded as a whole, including information generated after the applicant supplied the original documents.
The Law Made the Newsom Administration Responsible for Outsourced Records.
The duties. The alleged failures.
The lawsuit ties the Newsom Administration’s conduct to specific requirements.
Limit collection and explain its purpose
Maintain only information relevant and necessary to an authorized agency purpose. Collect directly from the individual to the greatest extent practicable and provide the required collection notice.
The complaint alleges unnecessary bank access and broader collection, together with notices that failed to identify the vendor disclosures.
Make privacy protections follow outsourced records
When contracting for personal records to perform an agency function, cause the IPA’s requirements to apply to those records, consistent with the agency’s authority.
The complaint alleges that GO-Biz and CalOSBA failed to apply those protections through the six grant agreements and left the records in private systems under the same arrangements.
Establish safeguards and assign responsibility
Establish appropriate safeguards, set handling rules, instruct the people handling the records, and designate an employee responsible for IPA compliance.
The complaint alleges that the agencies failed to implement these protections for applicant data held by Lendistry and its vendors, despite general privacy and security commitments.
Authorize disclosures and keep the required accounting
Disclose identifiable personal information only as authorized by the Act. Keep and retain the accounting required for specified disclosures, including their date, nature, purpose, and recipient.
The complaint alleges unauthorized disclosures to distinct vendors and the absence of the required disclosure accounting.
Preserve sources and maintain accurate decision records
Preserve accessible source information, subject to statutory exceptions. Maintain records used for decisions with accuracy, relevance, timeliness, and completeness to the maximum extent possible.
The complaint alleges missing source records and unassessed automated decisions based on material applicants could neither inspect nor correct.
Provide a working route to inspect and correct records
Adopt regulations or publish guidelines implementing individual records rights, including inquiry, access, amendment, and review.
The complaint alleges that neither GO-Biz nor CalOSBA supplied these procedures for the grant records, during the programs or afterward.
California assigned agencies concrete responsibilities for their records. The IPA defines maintaining information to include collecting, acquiring, using, and disclosing it. Its protections therefore govern how a system operates and how information moves among companies, not merely whether a hacker breaks in.
Collect only what the public program actually needs. Section 1798.14 limits maintained personal information to what is relevant and necessary to a legally required or authorized agency purpose. Section 1798.15 calls for collection directly from the individual to the greatest extent practicable. Those provisions ask whether a grant administrator needed a particular category of information and why it obtained information elsewhere when the applicant could supply it. They give legal significance to the difference between verifying eligibility and building a broader profile.
Keep track of where personal information came from. Section 1798.16 generally requires agencies to retain the source or sources of personal information. For electronic collection, it also addresses retention of sources or intermediate forms created or possessed by the agency. The source information must remain readily accessible for the individual to inspect, subject to the statutory exceptions. A record assembled through several services should not become an unexplained conclusion with its origins lost. Source traceability is how a person or an agency can begin to identify where inaccurate or unauthorized information entered the process.
Tell people what is being collected and why. Section 1798.17 prescribes a notice covering the collecting agency, the responsible official, the legal authority, whether submission is mandatory or voluntary, the consequences of withholding information, principal uses, foreseeable disclosures, and access rights. A form that tells applicants which documents to upload does a different job from a notice explaining the government's authority and the uses to which those documents will be put.
Keep the records accurate—especially when decisions depend on them. Section 1798.18 requires records used to make determinations about individuals to be maintained, to the maximum extent possible, with accuracy, relevance, timeliness, and completeness. When transferring a record outside state government, the agency must correct, update, withhold, or delete portions it knows or has reason to believe are inaccurate or untimely. The obligation matters when a system extracts fields from documents, combines information from different sources, or produces an eligibility decision. It connects the quality of the data to the fairness of what the government does with it.
Make the contractor follow the privacy law. Section 1798.19 addresses contracts for operating or maintaining a records system to accomplish an agency function. It directs the agency to cause the Act's requirements to be applied to the system. The complaint alleges that the Newsom Administration failed to do this in the six agreements. Its theory places the breach at the Administration’s own decision to commission and maintain the system without the required protections.
The Newsom Administration had to perform that duty when arranging for the records system. The complaint contends that an applicant’s later click on a private vendor’s terms could not perform it for the Administration. Officials were responsible for the contracts, instructions, and controls needed to make the law operate.
Put someone in charge and make the safeguards work. Sections 1798.20–1798.22 require rules of conduct; instruction concerning those rules, the Act, and its remedies and penalties; appropriate administrative, technical, and physical safeguards; and a designated agency employee responsible for compliance. These provisions concern people, procedures, and management as well as technology. A security product, standing alone, cannot publish an access procedure, decide whether a disclosure is permitted, or make an agency answer a correction request.
Establish authority for disclosures and keep the required accounting. Section 1798.24 restricts disclosure of information in a form identifying an individual, subject to enumerated exceptions. Section 1798.25 requires an accounting for specified disclosures, including their date, nature, purpose, and recipient. Section 1798.27 generally requires that accounting to be retained for at least three years, or until the underlying record is destroyed, whichever is shorter. These requirements provide a means to reconstruct what happened to information after its initial collection.
Give people a working way to inspect and correct their files. Sections 1798.30 and 1798.32 require published procedures and an inquiry process through which an individual can learn whether an agency maintains a record about them. The access provisions address records indexed under other identifiers when the agency knows or should know that they relate to the individual. Sections 1798.35 and 1798.36 provide a process to seek amendment, obtain a response, request review of a refusal, and place a statement of disagreement in the record. These are practical controls over a system capable of making or preserving mistakes.
Section 1798.60 separately restricts agencies’ commercial distribution, sale, or rental of an individual’s name and address unless specifically authorized by law. Its scope is limited to that information. The Act’s broader rules govern the collection, use, and disclosure of other personal records. Together, these provisions required the Administration to control the purposes for which information entered and left its grant systems.
California’s Security Rules Applied to the Contracts, Too
California's mandatory information-security framework supplied additional instructions for the Administration. Government Code section 11549.3(b) requires covered executive entities to implement the policies and procedures of the Office of Information Security. The Governor’s direct authority over the contracting office places it within that executive reporting framework. Government Code section 11019.9 separately requires each state agency to maintain a permanent privacy policy adhering to the Information Practices Act and conspicuously post it.
The State Administrative Manual translates those duties into operating and procurement requirements. Section 5300.5 adopts NIST Special Publication 800-53 as California's minimum information-security controls and directs state entities to use NIST and Federal Information Processing Standards in planning, developing, implementing, and maintaining their security programs. Section 5305 assigns each entity responsibility for an information-security program, including planning, oversight, and coordination. Section 5315 expressly requires security requirements to be integrated into contracts for outsourced products and services.
The State's published rules were specific about outside providers. The version of SAM section 5305.8 reproduced in a state-hosted 2024 document required written agreements addressing appropriate security, transmission, and storage standards, compliance with statewide law and policy, confidentiality, incident notification, and the State's right to participate in or conduct its own investigation. It also required provisions addressing specified costs of contractor-caused security incidents and the handling and disposition of records. These were concrete subjects the Administration could put into a contract and enforce.
SAM section 5310.3 likewise required third parties handling personal information for a state function, and their personnel or agents with access, to formally agree to the entity's privacy policies and practices. The rule directly addresses the vendor chain: transferring a function to one contractor does not make the contractor's downstream providers irrelevant to the State's privacy obligations.
The NIST controls cited in the complaint sharpen the same point. SA-4 calls for security and privacy requirements in the acquisition contract, explicitly or by reference, along with allocation of responsibility and acceptance criteria. SA-9 addresses external system services, requiring compliance with the organization's security and privacy requirements, documented oversight roles, and ongoing monitoring of provider compliance. Its explanation leaves responsibility for managing the risks with the authorizing officials. PS-7 concerns external personnel, including contractors, and requires documented personnel-security requirements and monitoring of provider compliance.
The Newsom Administration’s procurement and oversight responsibilities were explicit. Officials had to integrate applicable requirements into outsourced services and monitor compliance. The complaint alleges that their contracts and supervision failed to apply those protections to applicant records and the outside services handling them. A general security assurance did not perform the required work of tracing information sources, accounting for disclosures, controlling private uses, or providing access and correction rights.
The Newsom Administration Protected Its Audit Rights. The Lawsuit Asks Why Privacy Rights Were Left Behind.
The complaint identifies a specific difference in the standard contract package. The standard terms the Administration used required audit rights and nondiscrimination obligations to follow the work into subcontracts. According to the pleading, the same terms contained no corresponding requirement carrying privacy, security, or IPA obligations downstream. The companion certification clauses supplied none either.
The Newsom Administration knew how to make obligations follow public work into another company’s hands. It used that method to preserve audit and nondiscrimination duties. The lawsuit alleges that it omitted the corresponding protections for the personal records applicants were required to surrender.
The pleading also examines the alternative information-technology template. It alleges that the template’s generic confidentiality provision depended on information being designated confidential by the State and supplied no IPA disclosure-accounting requirement. It identifies an optional non-IT confidentiality exhibit adopted in January 2026, after these programs were contracted. Its charge is that the standard procurement package did not provide the information-practices system these records required.
Section 1798.19 placed the duty on the agency itself: it had to cause the IPA’s requirements to apply to outsourced agency recordkeeping, consistent with its authority. The section also treats covered contractors and their employees as agency employees for the Act’s penalty article. Calling the operator an independent contractor did not extinguish that rule. The question is what the Newsom Administration did to make the protections work.
The complaint traces the alleged omission through the actual agreements and amendments. It says the Administration did not apply the IPA, require disclosure accounting, or bind recipients handling banking data, AI processing, and tracking to the Act. In their place, the contracts repeated general statements about privacy laws “as applicable” and a security program designed to protect the contractor’s own assets.
A Sick-Leave Grant Was No License to Build a Personal Dossier
The Newsom Administration’s authority to collect personal information had a limit: relevance and necessity to the program’s authorized purpose. For supplemental paid sick leave, that purpose was to verify payroll showing an eligible employer had paid qualifying COVID-19 leave and match the proof to the requested reimbursement. The complaint quotes that statutory task from Government Code section 12100.975.
The complaint asks why administering that reimbursement required a history of where an applicant shopped, what the applicant bought, or whom the applicant paid. It makes the same challenge to voiceprints, behavioral models, device graphics signatures, and information about browsing elsewhere on the Internet. Each alleged category presents the Administration with the same question: what authorized program need justified collecting it?
Employees formed another affected population. Payroll records identified workers by name and disclosed wages, hours, absence dates, and COVID-related leave. Those workers had not applied for anything. The complaint alleges that they received no notice that their information had entered an Administration program, been routed to a private administrator, and been held in outside systems.
The Newsom Administration could require evidence of qualifying leave and still had to protect the workers identified in it. The complaint alleges that the Administration demanded the records while failing to implement those protections. Employees’ information reached private systems because the Administration made payroll part of the application.
The information collected
The complaint traces six paths through the system.
One application process. Six alleged paths.
The complaint traces different information through different services. The Administration’s responsibilities extended across the records system it commissioned.
GO-Biz and CalOSBA commissioned the grant system and retained tools to govern its operation.
- Apply the privacy lawCause IPA requirements to apply to covered outsourced recordkeeping, consistent with agency authority.[L13, §1798.19]
- Obtain controls reportsThe flagship agreement and an amendment required the contractor’s annual controls report.[F12, PDF p. 6] [F13, PDF p. 12]
- Inspect and enforce performanceContracts reserved inspection and compliance powers.[F04, PDF pp. 18–19]
- Control disclosures and accessThe IPA limits disclosures, requires specified accounting, and provides individual records rights.[L16] [L15] [L14] [L17]
Supplies records, connects a bank account, seeks help, and uses the application website.
Application intake, verification, communications, review, and disbursement.
- DocumentsTax, payroll, and identity files → outside processing
The complaint alleges that licensed AI components processed submitted records, retained their contents, and used them to develop or improve commercial products.
[L01, PDF pp. 30–32, ¶¶115–122] - Bank accountsBank connection → recurring retrieval and further uses
The complaint alleges reusable access to balances and transactions, machine-learning analysis, sales of banking data, and onward disclosure to AI and anti-money-laundering providers.
[L01, PDF pp. 39–42, ¶¶152–165] - ChatsHelp conversation → outside analysis and profiling
The complaint alleges that transcripts, identifiers, and behavioral information went to an outside platform and were used to model applicants and support other commercial purposes.
[L01, PDF pp. 42–44, ¶¶166–176] - CallsRecorded voice → analytics and biometric uses
The complaint alleges live outside analysis, retained recordings and transcripts, extracted voice characteristics, system training, and monetization through other datasets.
[L01, PDF pp. 44–45, ¶¶177–182] - EmailMessage contents and attachments → outside companies
The complaint alleges that replies were duplicated beyond the understood recipient and that readable messages and attachments underwent AI and machine-learning analysis.
[L01, PDF pp. 45–46, ¶¶183–188] - Browsing and advertisingPortal activity and identifiers → analytics and advertising
The complaint alleges form and device collection, persistent recognition, remarketing audiences, and distribution of applicant-linked information through advertising auctions.
[L01, PDF pp. 46–52, ¶¶189–214]
“We Don’t Want People Reviewing Tax Returns”
The Newsom Administration paid for a workflow that put automated review first. The accepted proposal described a decisioning engine evaluating applications with underwriting and processing teams available as another level of review. The complaint alleges that the Newsom Administration did not examine the applications or read an applicant’s tax return. It entrusted that work to the contractor’s system.
That system allegedly sent sensitive documents through components licensed from other companies. According to the complaint, third-party AI and machine-learning services processed tax returns, payroll, and identity documents inside the contractor’s platform. To the applicant, there was one grant portal. Behind it, the pleading describes several outside companies processing the applicant’s records. The Administration’s obligation to govern the records had to reach that chain.
The complaint cites Lendistry’s own public descriptions of the operation: AI gathered information from the Internet, rated risk, predicted outcomes from industry history, extracted and summarized data, and connected similarities among businesses and applications. It also cites the company’s participation in a House Financial Services AI working-group roundtable. The described process could combine a person’s submitted documents with outside information and judgments generated by software.
“We don’t want people reviewing tax returns,” the CEO says in the recorded explanation quoted in the complaint. Later in the same passage: “We don’t need people to review tax returns and documents anymore. Let’s let the technology do it.” The Administration’s accepted proposal put that preference into the purchased workflow: automated review came first.
We don’t need people to review tax returns and documents anymore. Let’s let the technology do it.
The lawsuit charges that the use did not stop when the grant-processing task was done. It alleges that outside companies retained tax and payroll contents and used them to develop or improve products sold to other customers. Documents required for taxpayer-funded assistance thus became, on the complaint’s account, raw material for another company’s business.
Applicants allegedly received no explanation of which automated systems would read their documents, which companies operated them, what those companies would keep, or whether the records would improve commercial products. The complaint says applicants could not refuse that processing and still apply. It also alleges that the Administration’s agreements imposed no limits on what a component vendor could retain or derive. The claimed failure therefore begins with the Administration’s purchase of a system that required sensitive records without governing the uses that followed.
The Complaint Describes Bank Accounts Harvested Again and Again
A verification step with an alleged afterlife
The guide disclosed a bank connection. The complaint challenges the reusable authority and subsequent uses that allegedly followed.
Disclosed verification
The March 2021 guide described verifying bank statements and facilitating transfers. It promised privacy, no sharing without permission, and no sale or rental.
[V01, PDF pp. 49, 56]Alleged retained access
The complaint alleges that the vendor and portal operator retained reusable authority to enter the account without another login, including authority to renew access.
[L01, PDF pp. 39–40, ¶¶152–156]Alleged repeated retrieval
Balances and itemized transactions allegedly continued to be collected. Completing or abandoning an application did not itself terminate the connection.
[L01, PDF pp. 40–41, ¶¶157–160]Alleged subsequent uses
The complaint describes machine-learning analysis, commercial outputs, sales of banking data, and further disclosure to AI and anti-money-laundering providers.
[L01, PDF p. 41, ¶¶161–163]
The unresolved endpoint: the complaint alleges that applicants had no expiration date or disconnect control and were never told the standing access had ended.
[L01, PDF pp. 40–42, ¶¶157–158, 164–165]The central bank allegation is repeated access after verification. The complaint says the Newsom Administration’s grant process created reusable authority to enter applicants’ accounts without another login. Some applicants typed bank usernames and passwords into the interface; others authorized the connection on a bank-hosted page. The allegation rests on the portal’s code, published technical documentation, and the absence of expiration or disconnection controls.
The pleading describes how a brief encounter with the application could leave behind a lasting connection. A short-lived credential, accompanied by metadata identifying the connection, went to a server the applicant could not see. There, it was exchanged for a longer-lived credential retained by the vendor and portal operator. Separate renewal authority allowed expiring access to be renewed without any further action by the applicant. Another credential supported standing reports on the account and its transactions.
Under that alleged arrangement, completing or abandoning an application did not end access to the bank account. The operator had to remove the connection or the bank had to revoke authorization. A program’s closure did neither automatically. The complaint says applicants had no credential identifier, expiration date, or disconnect control. They could not discover where the authority was held, what it reached, or how to terminate it. The Administration’s application process had allegedly created an ongoing exposure that the applicant could neither see nor manage.
The complaint also challenges what the bank was told. It alleges that the request represented the continuing access as applicant-authorized even though the applicant had agreed only to verification. The bank’s automated system then issued the credential sustaining the connection. The alleged misrepresentation concerned the scope of access, not whether the applicant had participated in a visible bank-verification step.
The Administration’s own contract contains conflicting signals about when the connection belonged in the process. The complaint quotes scope-of-work provisions tying bank connectivity to funding selected awardees and bank checks to approved applications. It alleges that the deployed portal instead demanded connection before submission. The accepted proposal elsewhere in the agreement did place bank connectivity in that earlier workflow. Both provisions matter: the agreement contemplated the earlier sequence even as its funding provisions described a narrower population. The complaint alleges that the result swept in people who never received a grant.
Applicants were offered a much narrower explanation. The portal presented the connection as a quick substitute for uploading documents and a route to a faster decision. It called the process secure and private. Program materials described account verification and transfers, promised no sharing without permission and no sale or rental, and said Lendistry could not access applicants’ login credentials. The complaint challenges the reusable authority created behind that login and what the recipients did with the information it continued to yield.
According to the complaint, sharing permission was enabled by default. Applicants had no affirmative choice and could not refuse collateral use while seeking assistance. They were never told that standing authority had been created or that it had ended. The pleading alleges that the access remained active when the lawsuit was filed.
The Newsom Administration’s March 31, 2021 guide documents what selected applicants were told: the connection would verify bank statements and facilitate transfers; their information was private; it would not be shared without permission, sold, or rented. The guide named and illustrated the provider and offered another verification method when an applicant’s bank was unavailable through the preferred service. Disclosure of the bank connection is therefore part of the record. The lawsuit’s charge is that the Administration failed to control the undisclosed continuing collection and collateral uses that followed.
The Alleged Second Business: Turning Applicants’ Bank Histories Into a Commercial Product
The recurring access described in the complaint harvested a moving record of applicants’ financial lives: account and routing identifiers, current and historical balances, account types, and itemized transactions spanning months or years. A transaction could disclose its date, amount, description, and counterparty. That history revealed considerably more than whether an account existed or could receive a grant.
The complaint alleges that the bank-verification platform fed those records through machine-learning systems, classified them, and generated outputs and metadata for business customers. It cites the vendor’s engineering materials for that description. The resulting information included both what the bank recorded and what another company’s system inferred. The Newsom Administration’s alleged failure to govern the outsourced records system thus extended to the new information created from the bank data.
The pleading charges that end-user banking data was routinely sold despite the program’s no-sale assurance. It further alleges that readable information went onward to AI and anti-money-laundering providers. According to the complaint, the Newsom Administration had not identified or accounted for those recipients, their permitted uses, or their retention of the records. That is the commercial-use allegation at the center of this part of the case: a system introduced for public assistance allegedly continued supplying information to outside businesses.
Encryption in transit could not perform the missing oversight. A company authorized to receive the information could read it at the endpoint. The Newsom Administration had to address who could receive the records, the purpose of each disclosure, and the obligations that followed the information. Secure transmission and lawful use are separate questions.
Applicants Asked for Help. The Lawsuit Says Their Chats Became AI Profiles.
An applicant seeking help through the grant portal appeared to be speaking with the administrator about eligibility, documents, or application status. The complaint says the portal’s code routed that conversation to an outside platform that analyzed the exchange both live and afterward. The public program’s help channel allegedly became another source of records about the person seeking assistance.
The information allegedly collected went well beyond a transcript. It included the start time, IP address, browser and device, words that triggered transfer to a representative, and behavioral analysis drawn from the exchange. According to the complaint, the vendor combined transcripts with identifying and behavioral information and used the results for itself and other parties. The conversation had allegedly acquired a commercial life beyond resolving the application question.
The pleading quotes the vendor’s own account of the commercial problem its product addressed: people avoid forms, withhold their identities, or give false information because they want to remain anonymous. The advertised solution derived buyer intent and used AI and automation to turn website interactions into a sales pipeline. The lawsuit charges that the Newsom Administration paid for a grant workflow incorporating this technology without applying the IPA to the personal records it created.
The alleged output was a model of the applicant. The complaint describes keystroke patterns and other behavioral characteristics combined with personal, voice, and biometric information to predict how a particular person would behave. It alleges that generative systems used the material for those purposes.
Applicants allegedly received no notice identifying the outside recipient or explaining the automated analysis, retained transcripts, derived characteristics, or uses beyond answering their questions. The Newsom Administration’s alleged omission therefore covered both the conversation it required a contractor to handle and the new information produced from that conversation.
The Voice on the Phone Became Part of the Alleged Data Harvest
Calling for help could expose payroll figures, wages, account details, identifying information, and portal login information or passwords. According to the complaint, the contractor’s telephone system connected an outside analytics service that reviewed calls live. The pleading grounds that account in the call-system configuration and published descriptions of the products involved.
The complaint describes far more than a recording kept for quality review. It alleges that the service examined callers’ intent, modeled and sought to influence their behavior, retained recordings and transcripts, and extracted voice characteristics including patterns and voiceprints. It used that material to train and develop its systems. People calling about taxpayer-funded assistance were allegedly supplying both personal information and training material for a private system.
The pleading further charges that recordings and derived voice data entered a biometric dataset with economic value and were monetized through inclusion in other datasets. Applicants allegedly were never told their voices would be used to supply that product.
A voice print is expressly included among the IPA’s examples of an identifying particular. An encrypted call also remains audible to an outside company authorized to listen. The Newsom Administration’s responsibility therefore required controls over the recipient and its uses of the caller’s information. Protecting the transmission alone would leave the alleged extraction, retention, and commercial use untouched.
Every Email Could Carry More Private Records to Outside Companies
The alleged disclosures also followed applicants into their inboxes. The contractor requested tax and payroll documents by email, and applicants sent them while trying to complete their applications. The complaint identifies code embedded in messages sent to applicants as the basis for alleging transmissions when those messages were opened or answered.
According to the pleading, replies were duplicated to destinations beyond the mailbox applicants understood they were addressing. Outside companies obtained readable message contents and attachments and applied AI and machine-learning analysis. The alleged access occurred in transmission, storage, and receipt, producing insights similar to those derived from chats and calls. Records requested for a program administered by the Newsom Administration allegedly reached recipients the applicant had not been told were part of the exchange.
Each further document request allegedly repeated the process. The complaint describes multiple exchanges of sensitive tax and business information routed and analyzed in the same way. Completing the application meant continuing to send the requested records. The lawsuit charges that the Newsom Administration failed to govern the disclosures generated by that recurring, contractor-directed exchange.
The Tracking Allegedly Started Before the First Click
The complaint alleges that the Newsom Administration’s application process led people into a broader collection network before they made a meaningful choice about their information. Required steps moved applicants among the portal, its subdomains, and the contractor’s public marketing site. They could not complete the application without encountering that marketing site.
The pleading says scripts, tags, pixels, and other components began transmitting as soon as a page loaded—before a person typed, clicked, or submitted anything. It cites the code delivered to applicants’ browsers and the destinations receiving those transmissions. There was allegedly no consent banner, toggle, preference control, or recipient disclosure through which an applicant could refuse or limit collection. Entering the Administration’s application route was enough to start it.
The alleged record tracked pages visited and their order, selected links, viewed media, downloaded files, scroll depth, time on a page, and interactions with application forms. It also captured what applicants typed and the contents of pages they viewed. In this setting, those fields could contain Social Security numbers, taxpayer identifiers, addresses, birth dates, and payroll amounts. The exposure alleged in the complaint reached the information applicants entered to obtain assistance as well as the way they moved through the process.
The code allegedly interrogated the device too. It requested the browser’s configuration and caused the browser to perform tests. The complaint identifies IP-derived location, information from the browser’s geolocation interface, browser and operating-system details, language, processor and touch capabilities, screen properties, fonts, plugins, storage availability, and input-device information among the collected fields.
One alleged test was invisible to the applicant. The browser rendered text and images, then returned pixel data and information about graphics hardware and drivers. Small variations in those results could produce a stable signature of the machine. The complaint describes a way to recognize the device even when the applicant had not deliberately supplied an identifier.
According to the pleading, that signature became part of a device-level profile written into the applicant’s browser storage. Fingerprint-derived fields accompanied identification messages that joined a user identifier to associated traits. The grant portal allegedly left a durable identifying record on the applicant’s computer without notice or consent. The Newsom Administration’s alleged collection failure thus reached information extracted from the device and records placed on it, not only documents uploaded to the contractor.
Seeking Taxpayer-Funded Assistance Became a Marketing Signal, the Complaint Says
The complaint alleges that the grant portal operated with a customer-data platform built into it. The portal’s content-security configuration permitted communication with the platform’s collection endpoint, while a persistent identifier linked applicants’ activity across sessions and over time. The system allegedly queued events, transmitted them in batches, and routed information onward to analytics, marketing, and data-warehouse recipients.
The transmitted record included more than the contents of a form or page. The pleading identifies page paths, requested and referring addresses, endpoints, timestamps, session identifiers, and user or device identifiers. Taken together, those fields could reconstruct who did what, when, and where inside the application process. The alleged record was a continuing account of a person’s pursuit of government assistance.
According to the complaint, the configuration also collected address parameters and search terms, monitored video activity, and enabled automatic collection of email addresses, with first-name fields present. Advertising features and personalization signals were turned on. Events connected to applying for relief were marked as marketing conversions.
The practical charge is that seeking emergency assistance supplied an advertising operation. The complaint says advertising identifiers traveled onward and audiences built from applicants’ activity were exported to advertising accounts for remarketing. The allegation concerns a limit the Newsom Administration was responsible for enforcing: information collected for a public program had to serve that program’s authorized purpose.
Following the Newsom Administration’s instructions allegedly supplied more data. The contract required instructional videos, and the complaint says the tracking configuration transmitted applicants’ selections of program videos together with identifying information. Even learning how to complete the application could become an identifiable event sent outside the program.
Closing the browser allegedly did not stop recognition. The pleading describes identifiers that persisted after browser closure and cookie deletion, worked in private browsing, and supported recognition across devices. It also alleges continued tracking after applicants left both the program and contractor sites.
That alleged behavior directly conflicts with an assurance given to applicants. They were told that incognito mode permitted private entry and prevented information from being remembered or cached. The complaint says device-derived recognition defeated that assurance even when ordinary cookies were suppressed. Applicants following the stated privacy advice allegedly remained identifiable to the system.
Who Got the Data? The Advertising Disclosures the Newsom Administration Allegedly Failed to Account For
The lawsuit alleges a further loss of control when applicant identifiers and associated information entered real-time advertising auctions. It cites a July 2020 Senate letter explaining how those auctions work generally: information about a potential recipient can reach hundreds of participants even though only one will display the ad. Participants can obtain information without winning or placing an advertisement, including participants that join solely to collect data.
The complaint applies that mechanism to the grant system by alleging that the distributed information could identify an applicant through user and device identifiers, IP addresses, and matching services that join one recipient’s data to another’s. It also identifies browser and device information, the visited site and page address, and sensitive interest categories among the distributed information. The Senate letter describes the mechanism; the complaint supplies the allegation about these applicants.
A visit to an emergency-relief portal can itself disclose something valuable to a commercial recipient: possible financial distress. The pleading describes that inference being combined with categories involving debt collection, short-term lending, bankruptcy, medical conditions, religion, racial or ethnic identity, sexual orientation, and other personal circumstances. Its theory is that the act of seeking taxpayer-funded help generated another marketable judgment about the applicant.
The alleged distribution also undermined the ability to account for disclosures. According to the complaint, broadcasting information to unknown simultaneous recipients made it impossible to identify everyone who received it or secure its removal. The charge is that the Newsom Administration commissioned a system whose distribution practices defeated the accountability the IPA required it to maintain.
Across these channels, the complaint alleges the same failure of public control. Applicants were told about verification, grant processing, and recorded-call quality or training. The described practices extended to recurring access, outside analysis, commercial product development, and wider distribution. The pleading alleges that the Newsom Administration maintained neither the required disclosure accounting nor a published way to request it. Without that accounting, applicants lacked the route the law provided to discover where their information had gone.
Oversight and unanswered warnings
Contractual powers, records requests, and a direct demand to investigate.
The Privacy Promises and the Practices the Lawsuit Says Broke Them
Lendistry publishes a different account of its information practices. Its privacy policy effective May 6, 2026 states that it did not sell personal information during the preceding twelve months. It describes confidentiality and use restrictions for business-purpose disclosures, affiliate sharing, and opt-out rights. The complaint challenges how the grant systems actually operated, what recipients did with the information, and whether the Newsom Administration performed its own duties. The current policy cannot establish what terms each applicant received in earlier years. Resolving that conflict requires examining the systems and their records—the oversight at issue in this case.
Earlier litigation over Plaid’s data practices ended in a $58 million settlement with business-practice changes approved in July 2022. Plaid denied liability, and that settlement did not decide whether the California grant implementation violated the law. The public history nevertheless supplied a potential avenue of inquiry after warnings of continuing bank access were sent to the Newsom Administration. Its responsibility extended further: the letters called for scrutiny of the collection and disclosure practices affecting applicants to its programs, and the Administration’s duties covered the whole outsourced records system.
Asked for Audits, the Newsom Administration Produced Contractor Program Reports.
10 program reports. 94 pages.
No underlying controls assessments in that production.
The Newsom Administration’s original relief agreement requires Lendistry’s most recent annual controls report. The next bullet separately requires narrative program reports. Agreement 20GOB039 excerpt, PDF p. 6 (Exhibit A, p. 5 of 8).
Open the complete document ↗The Newsom Administration wrote a specific oversight requirement into the original flagship agreement: Lendistry had to provide its most recent annual System and Organization Controls II report, described as covering security, processing integrity, confidentiality, and privacy. The contract separately required narrative progress and final program reports. Those narrative reports did not fulfill the controls-report requirement.
Amendment 2 repeated the obligation in direct language: “Lendistry will provide to CalOSBA its annual SOC II report.” Later agreements similarly referred to controls reporting and security practices. The Newsom Administration had therefore written a specific means of examining controls into its relationship with the contractor from the outset.
Asked for internal and external audits, evaluations, and reviews of Lendistry’s performance, including findings and corrective actions, the Newsom Administration identified a set of records responsive to that category of a December 2024 request. That production consists of ten contractor program reports totaling 94 pages.
Six of those reports describe annual SOC reporting. The Dream Fund materials discuss penetration testing. None supplies the underlying assessment or a State privacy-compliance audit. What the Administration produced shows the contractor describing its controls; it does not provide the assessments the flagship contract expressly required Lendistry to deliver.
That production is the basis for the complaint’s allegation that the Newsom Administration never demanded, obtained, or reviewed the promised reports for these programs. The documented oversight gap is specific: a request expressly seeking audits and findings produced program narratives without the underlying assessments. The production does not establish the contents of records outside those ten files.
An assessment also required officials to act on what it covered and what it found. They needed to determine whether the programs, vendors, data flows, and periods were within its scope and whether deficiencies called for correction. The IPA separately required lawful collection and disclosure. Possessing a controls report would not itself authorize harvesting unrelated information or using it for another company’s business.
The November 2025 warnings made the demand for oversight explicit. They identified the agreements, described conduct allegedly still occurring, and asked the Newsom Administration to investigate. The Administration did not answer or follow up. It provided no explanation of any action taken.
The Contracts Included Compliance Work. The Lawsuit Alleges the Newsom Administration Left the Law Unenforced.
The Newsom Administration accepted privacy and security commitments as part of the work taxpayers funded. The sick-leave agreement and accepted proposal promised protection of collected information, security procedures, and compliance with applicable privacy laws. They described controls reporting and compliance with federal and State privacy requirements. Those commitments gave officials subjects to inspect and performance to demand.
One sentence stated whose assets the promised security program would safeguard: “The vision of the information security program is to safeguard the confidentiality, integrity, and availability of Lendistry assets.” The Newsom Administration’s IPA duty concerned the people whose records its programs collected. The lawsuit alleges that officials accepted general security promises without making the required limits, individual rights, and accountability operate across those records.
The Newsom Administration retained practical tools to enforce the work it purchased. The agricultural agreement required weekly accountability meetings, status reporting, expenditure monitoring, and verification of final work. Invoices required supporting documentation. Part of the administrative compensation was withheld until completion and approval of final reports. State inspection and audit rights reached program records.
That agreement separately identified a platform fee and other technology, vendor, and subcontractor costs billed at cost with documentation. It required advance approval for a specified category of program vendors while excepting ordinary business vendors. An existing commercial relationship did not remove covered personal records from the IPA. To oversee the system it purchased, the Administration needed to understand which existing vendors received those records and how they handled them.
A Newsom Administration official publicly appeared alongside the contractor. Lendistry’s retrospective of its February 2023 Tustin office opening lists Tara Lynn Gray, who led the Administration’s California Office of the Small Business Advocate, and State Treasurer Fiona Ma among the speakers. This documented relationship gives context to the oversight question: what did the Administration require and enforce when Lendistry handled the records entrusted to it through taxpayer-funded programs?
Warnings of Continuing Data Harvesting Were Sent to a Newsom Administration Privacy Officer. They Went Unanswered.
The same official appears in three critical parts of the record. Van Nguyen signed the Newsom Administration’s response to the records request about Lendistry. The published privacy policy of the Governor’s Office of Business and Economic Development assigned implementation to its Deputy Director of Legal Affairs, the position Nguyen held, and designated that position as Privacy Officer. The November 5 warning was addressed to Nguyen in that same position and referred to the earlier records correspondence.
The privacy responsibility and the warning met at the same office
- 01 · Published policy
The designated position
GO-Biz assigned implementation of its privacy policy to the Deputy Director of Legal Affairs and designated that position as Privacy Officer.
[L10, PDF p. 2] - 02 · Signed response
The records correspondence
Nguyen signed the Administration’s response to the records request concerning Lendistry.
[V03, PDF p. 1] - 03 · Addressed warning
The November 5 letter
The warning was addressed to Nguyen in that position. It referred to the earlier correspondence and requested investigation and reforms.
[L08, PDF pp. 1, 4–5]
The Administration provided no responsive explanation of an investigation or corrective action by the report’s cutoff date.
[N01]The Newsom Administration’s GO-Biz privacy policy assigns implementation and adherence to the Deputy Director of Legal Affairs, then names that position as Privacy Officer. Policy excerpt, PDF p. 2.
Open the complete document ↗The Newsom Administration’s response identifies records responsive to the audits-and-evaluations category and bears Van T. Nguyen’s signature as Deputy Director of Legal Affairs. Letter excerpt, PDF p. 1.
Open the complete document ↗The November 5, 2025, warning addresses the Newsom Administration’s Deputy Director of Legal Affairs, Van T. Nguyen, and refers to earlier public-records correspondence. Letter excerpt, PDF p. 1.
Open the complete document ↗The warning identified ongoing conduct and the Newsom Administration’s agreements under which it allegedly occurred. It described repeated bank-account downloads, continued collection and commercialization, AI processing of sensitive documents and voices, and browser and device tracking. It named six agreements and alleged that the Administration had failed to comply with the IPA.
The November 5, 2025, letter tells the Newsom Administration that third-party access to applicant bank accounts was continuing and that affected businesses had not been notified. These are the letter’s allegations. Excerpt, PDF p. 2.
Open the complete document ↗Its requested remedies included changes to procurement terms, contractor oversight, reporting, and compliance. It specifically demanded “Investigation by the Governor’s Office of Contractor’s compliance with contract terms pertaining to adherence to applicable privacy laws.” The letter also sought a negotiated resolution.
A separate letter sent the same substantive warnings to Sara Curtis, Chief of Staff of the California Office of the Small Business Advocate, which administered the programs for the Newsom Administration. Both letters described an August 2025 government claim as unanswered. The lawsuit later alleged that the November letters also received no response.
Through September 28, 2026, the Newsom Administration had not answered or followed up. Its designated privacy official and the chief of staff responsible for the grant programs had been sent specific allegations of continuing harm and a direct request to investigate. The Administration provided no responsive explanation of an investigation or corrective action. The unanswered demand is central to the report’s account of administrative neglect.
The Newsom Administration had means to investigate: contractual inspection powers, access to program records, and a designated privacy official. An inquiry could have demanded access and retention records, examined controls assessments, tested the claimed purposes, or identified corrective steps. Neither recipient answered or followed up.
The letters followed an earlier government claim. The complaint alleges that a claim presented to the Department of General Services in August 2025 identified the responsible Administration offices, contracts, privacy failures, and injuries and produced no written rejection or untimeliness notice within the period pleaded. The November letters again asked the Newsom Administration to engage, investigate, and correct the system. The administrative claim and the correspondence are separate steps in the record of notice.
The Programs Ended. The Personal Records Stayed in Private Hands.
Closing a grant program did not resolve what would happen to the information collected from its applicants. The complaint alleges that the agreements expired without requiring the application files to be returned or destroyed, or requiring certification that either had occurred. One provision expressly left applications and supporting material with the contractor throughout the agreement and for two years afterward, subject to the Newsom Administration’s inspection and audit.
The information allegedly left behind extended well beyond uploaded files. The pleading identifies behavioral profiles, device fingerprints, transaction histories, recorded voices, and identifiers sent into advertising systems. Returning a tax return would leave a separate question unanswered: what happened to the information extracted from it, combined with other records, or incorporated into a private company’s systems?
The bank connections raised another unresolved question. The complaint alleges that the Newsom Administration never determined whether the standing authority to access applicants’ accounts had been revoked. It grounds that allegation in two absences: the public-records production contained no revocation or termination records, and applicants received no notice confirming that access had ended.
Records-retention and audit duties can require the State and its contractors to keep material after a program closes. Keeping it carries continuing responsibilities: a lawful purpose, a defined duration, safeguards, and usable rights for the person described in the record. The complaint alleges that the Newsom Administration left both the original files and the information derived from them in private systems without implementing the statutory framework governing their continued handling.
The Newsom Administration Left Applicants Without a Way to Exercise Their Records Rights, the Lawsuit Alleges
California’s records rights require an agency procedure people can actually use. Section 1798.30 requires agencies to adopt regulations or publish guidelines implementing the individual rights in Article 8. The complaint alleges that the Newsom Administration did neither for the records collected through these programs, during their operation or afterward. The published policies of the Administration offices running the programs, it says, offered no functioning route to ask about a record, inspect it, request a correction, or obtain the required information about disclosures.
The pleading examines what the Newsom Administration had published for the government functions it oversaw. It identifies the conflict-of-interest code of the Governor’s Office of Business and Economic Development and its regulations for California Competes, Made in California, EB-5, and iHub. It alleges that none implements the relevant IPA rights. The omission it identifies is specific: the Administration had regulations and policies for other purposes, but no required system through which people could exercise their rights over these personal records.
Other California agencies show what implementation looks like. The complaint identifies the California Housing Finance Agency’s longstanding policy, Department of Motor Vehicles guidelines specifying procedures and recipients, and Department of Corrections and Rehabilitation regulations. It also identifies the Franchise Tax Board’s explanation of a statutory exception where particular amendment and review procedures do not apply. For the records collected through these grant programs, the Newsom Administration allegedly supplied neither the procedures nor an identified exemption.
The November letters directly asked the Newsom Administration to identify those procedures and comply with the Act, while seeking a resolution without litigation. The complaint alleges that no response followed and no missing procedures were adopted in the interim. Its account describes people still unable to use an agency process to find their records, inspect them, correct them, or learn about covered disclosures.
The Contracts Could Close the Help Lines While Leaving the Records in Private Hands
The Newsom Administration’s contracts sent applicants to Lendistry for help. The sick-leave agreement required applicant communications to pass through the contractor “and thus not be directed to or channeled through GO-Biz.” Similar terms appear in the agricultural and CA:RISE agreements. The Administration kept the power to administer and inspect the contracts while directing the people whose information filled the system to the company.
That public-facing route could end before the records disappeared. The agricultural and CA:RISE agreements contemplated closing websites and service telephone numbers within 30 days of the specified closeout point. The contractor would still retain records, and the Administration would still hold inspection rights after the agreements ended. These provisions establish the agreed terms; they do not establish when every channel actually shut down. They make the need for the Administration to provide a lasting procedure concrete: a person’s ability to obtain a file should not expire with a temporary grant website or telephone number.
and thus not be directed to or channeled through GO-Biz
Could close within 30 days of the specified closeout point.
Could remain with the contractor, subject to inspection.
The agricultural and CA:RISE agreements set these terms. They do not establish when each channel actually closed. [F04, PDF pp. 17–18] [F05, PDF pp. 11–12, 14]
The California Housing Finance Agency offers a close comparison. Its policy expressly addresses personal information held by outside loan servicers under section 1798.19. Borrowers may ask the agency’s Public Records Coordinator to obtain their records from the servicer on their behalf. CalHFA thus tells people which public official can reach into the contractor’s system and retrieve their information.
DMV likewise publishes Article 8 guidelines. CDCR has implementing regulations. The Franchise Tax Board identifies particular tax-related exceptions where certain amendment procedures do not apply. These agencies give people procedures or explain the statutory limits on them. The complaint compares those concrete measures with the procedures the lawsuit alleges the Newsom Administration failed to provide.
Other agencies show what a working records process looks like.
The records identify concrete procedures—and the omissions alleged in these grant programs.
California Housing Finance Agency (CalHFA)
Its IPA policy expressly covers outside loan servicers. A borrower may ask the agency’s Public Records Coordinator to obtain servicing records from the contractor on the borrower’s behalf.
A direct example of an agency providing access to personal records held by a contractor performing an agency function.
Department of Motor Vehicles (DMV)
Published Article 8 guidelines explain record inquiries, inspection, amendment, and review. They identify the Chief Privacy Officer as the recipient for the initial requests and explain where a review request goes.
Turns statutory rights into instructions a person can use, including a recipient, identification requirements, and a review route.
Department of Corrections and Rehabilitation (CDCR)
Section 3450 provides procedures to inspect personal records and seek amendments. Requests go to the Warden, Regional Parole Administrator, or Secretary, depending on the person’s circumstances.
Implements records rights through regulations and identifies the responsible official for each request.
Franchise Tax Board (FTB)
Publishes records-request instructions and explains that specified IPA amendment and remedy provisions do not apply to tax-liability determinations under Revenue and Taxation Code section 19570.
Explains a defined statutory exception; it is not an example of unrestricted IPA amendment rights for tax determinations.
Newsom Administration: GO-Biz and CalOSBA
GO-Biz’s November 2025 privacy policy designates its Deputy Director of Legal Affairs as Privacy Officer. That policy does not provide Article 8 inquiry, inspection, amendment, or review procedures. The complaint alleges that neither GO-Biz nor CalOSBA adopted or published those procedures.
The alleged omission concerns a usable process for applicants’ records. The complaint also alleges that neither office identified a statutory exemption.
Six Contracts. At Least Eight Amendments. The Same Alleged Privacy Gap.
The Newsom Administration had already required secured storage and reports on the contractor’s controls. The complaint alleges that the Administration failed to demand, obtain, or review the promised assurance reports and failed to assess whether applicant documents were actually stored in a secured system. It identifies the absence of those assessments from the audit-related public-records production as the basis for that allegation.
The Administration also had repeated opportunities to address the contract terms. The complaint identifies at least eight amendments that added funds, programs, reporting requirements, or subcontractor provisions while leaving the alleged privacy omission uncorrected. Its authority continued after the immediate emergency: inspection and audit rights survived expiration, allowing the Administration to examine records the contractor still held.
The Administration could also act directly. Adopting regulations or publishing procedures for individual rights did not require renegotiating a private contract. The complaint alleges that the Administration continued to leave that authority unused. Its charge reaches the Administration’s ongoing conduct, including the years after the emergency decisions of 2020.
The same question applies to the next program. The pleading alleges that future outsourced systems will inherit the same procurement and procedural omissions unless the Administration changes its practices. The asserted duty extends to every individual whose protected personal information the Administration maintains through these programs, a group that grows as the Administration undertakes new programs.
Together, these allegations describe a failure of public administration across the life of the records. The Newsom Administration required people to enter a system operated by multiple companies. It allegedly failed to limit or account for the original and derived information, failed to provide functioning access and correction procedures, and failed to use its continuing powers to repair those omissions. The requested reforms address both the information already collected and the next system the Administration commissions.
The cost to applicants
The complaint describes how the process and its alleged harms unfolded.
More Records. More Calls. Then Lendistry Withdrew the Application.
The application, step by step.
The accounting firm’s attempt to obtain a supplemental paid sick leave grant brought its principals back through the same information systems.
The application required records and a bank connection
The firm says it supplied tax returns, payroll records, and identity documents. It connected its bank account before the portal would permit submission.
A denial led to a call and reinstatement
Lendistry declined the application based on payroll records. After one of its principals called to discuss the denial, the application was reinstated and its documents reviewed again.
More payroll records. Another recorded call.
Lendistry requested additional payroll data. The firm uploaded more records, and a principal placed another call after hearing the recorded-line message.
Another denial led to chat and a written complaint
Lendistry insisted on a particular payroll document. The firm disputed the issue through chat and submitted a written complaint. Two months later, Lendistry reaffirmed the denial.
Promised approval required still more calls
Representatives later said the application would be approved. Authentication codes failed to arrive for approximately a week, and further calls followed before the firm could reach its approval documents.
The firm disputed the offer. Lendistry withdrew the application.
Lendistry identified $5,246.86 in eligible payroll expenses but offered $5,000. When the firm questioned the calculation, a representative gave it a deadline to accept. Lendistry subsequently withdrew the application.
The complaint traces these alleged failures through one accounting firm’s attempt to obtain a supplemental paid sick leave grant. The application carried personal information about three of the firm’s principals because the Newsom Administration required demographic information and government-issued photo identification from owners or authorized signatories. A business was seeking reimbursement, but individuals were surrendering personal records. The rights they assert under the IPA belong to those individuals.
The principals say they read the Administration’s program materials before applying, consulted them while preparing the application, and relied on the descriptions of how their information would be handled. They connected the firm’s bank account after the portal described the connection as secure and private and said Lendistry could not access their credentials. They spoke on recorded calls after hearing that recordings were for training and quality purposes. They used chat without being told, they allege, that another company was receiving and analyzing the exchange.
They also uploaded tax returns, payroll records, and identity documents, and exchanged emails containing those files. They say no one told them that other companies’ automated systems would read the contents. They used the website believing its private-browsing instruction meant information would not be remembered. Had they known what the systems would do, they say, they would have acted differently. Their account challenges both the understanding on which they supplied the information and what happened to it afterward.
The firm says it supplied the required documents and connected its bank account before the portal would allow it to submit the application. Lendistry initially declined the request based on payroll records. After a telephone discussion, it reinstated the application and reviewed the documents again. It then asked for more payroll information. The firm uploaded more records and made another recorded call.
The next denial insisted on a particular payroll document, according to the complaint, although some employers did not receive that form from their payroll providers. The firm disputed the issue through chat and submitted a written complaint. Two months later, Lendistry reaffirmed the denial. Representatives subsequently contacted the firm again and said the application would be approved.
Even obtaining the approval documents required more calls. The portal demanded an authentication code, but the complaint describes roughly a week in which codes failed to arrive—a technical problem said to affect other applicants too. When the firm finally reached the documents, Lendistry said it had identified $5,246.86 in eligible payroll expenses but offered $5,000. The firm questioned the calculation. A representative gave it a deadline to accept the offer or “your application will be withdrawn.” Lendistry subsequently withdrew the application.
The complaint identifies two separate failures at that point. Lendistry allegedly offered no appeal from a denied application or disputed award amount. The Newsom Administration separately provided no Article 8 procedure through which the individuals could inspect and request correction of the personal records underlying the process. IPA records rights do not decide entitlement to a business grant. They give people rights over the personal information held about them, and the complaint alleges that the Administration left those rights without a usable procedure.
The lawsuit presents the sequence as an example of the system the Newsom Administration commissioned. The contracts, portal, bank verification, telephone and chat services, email, and tracking were allegedly ordinary parts of seeking assistance. Each additional upload, call, or request for help could send more information through those systems. The complaint alleges that the same missing protections governed the records of other applicants.
The Application Ended. The Plaintiffs Say the Harm Kept Going.
The complaint describes harm that outlasted the application. One principal says his information entered the file and the firm’s bank account remained exposed to standing third-party access that he cannot confirm has ended. Another identifies a call he personally made: he heard the recording announcement and spoke, after which an outside company allegedly analyzed his recorded voice for its own purposes. The third says her personal information remains in program records without the required protections or accounting of disclosures. Their claims concern their different encounters with the same system; each person need not have personally used every channel for those allegations to arise.
Trying to discover what happened carried costs of its own. The principals say they spent hours reviewing connected accounts, looking for information about what had been retrieved and where it went, trying to identify and revoke continuing access, and monitoring accounts and identifying information for misuse. They also allege expenses beyond their own time: payments for services and personnel to investigate the data handling, assess changes to computers and systems, and increase security.
The alleged intrusion also reached their devices. The complaint says code wrote persistent identifying profiles into applicants’ computers and continued to operate after they left the portal. It alleges costs already incurred, and costs that continue, to remove that condition and restore the systems. The injury asserted here is the work and expense of removing an allegedly persistent identifier from a computer.
The principals also allege ongoing anxiety and distress about what they cannot trace or control: voices allegedly converted into identifying characteristics, words captured as typed, financial accounts left accessible, and models potentially built from personal conduct. They say they cannot identify everyone holding the information, retrieve it, or prevent further use. On their account, finishing or withdrawing an application did not tell them where their information had gone or end its exposure.
A further allegation concerns the commercial value of that information. The complaint says transaction data, communications, voices, and behavioral profiles improved private companies’ commercial systems or reached further recipients, increasing the value of their products. Applicants supplied the material as a condition of seeking public assistance and received no compensation for its commercial use. The pleading assigns no dollar valuation to that use and does not claim that the administrative fees paid to Lendistry were proceeds of data sales.
The complaint connects these injuries to particular protections the Newsom Administration allegedly omitted. Contractual restrictions would have constrained recipients’ uses. Disclosure records would have identified where information went. Access procedures would have let individuals obtain that accounting and request corrections. Safeguards would have addressed unauthorized handling. The lawsuit argues that these were the measures designed to prevent the claimed injuries—and that their continued absence obstructs the effort to regain control.
Lendistry’s Own Reports Gave the Newsom Administration Reasons to Ask Questions
Applicants’ difficulties also appeared in the contractor’s own reports. Its Round 4 report describes museum applicants struggling to supply owner information and expressing concern about surrendering personal Social Security numbers. In some cases, the person available to apply was a volunteer uncomfortable providing a personal SSN. The program was demanding identifying information from people acting for organizations, even where those individuals’ finances were not the object of the grant.
Other reports describe automatic declines caused by incorrect entries, navigation problems, and applicants leaving after unclear guidance. They also describe training, assistance, and changes made in response. The reports show that the Administration and contractor had an operating relationship through which applicant problems could be reported and addressed. The complaint asks why that relationship did not produce the legally required controls and individual rights over the personal files the programs generated.
Concerns about administration and oversight reached a public hearing. In April 2024, a Community Alliance with Family Farmers representative described serious agricultural-program problems and said the organization had stopped contracting with Lendistry as a technical-assistance provider. Separately, the Legislative Analyst’s Office found that the original relief agreement had not required the business-level demographic information needed to evaluate the program. It recommended stronger reporting.
The record also documents substantial assistance delivered. The Newsom Administration reported approximately $3.79 billion across 330,023 awards in the flagship program, and the Legislative Analyst’s Office found that nearly all appropriated assistance had been distributed. The Administration undertook two concurrent obligations: deliver assistance and protect the people whose information it collected to do so. The lawsuit concerns the protections the Administration allegedly failed to provide while distributing that money.
Two Proposed Classes: Force Reform and Seek Compensation
The lawsuit proposes two classes with the same members but different remedies. Both would cover natural persons who are California citizens and who, on or after January 1, 2020, applied to an identified grant program or had their personal information submitted in an application, with that information contained in records maintained for the program. Someone need not have submitted the application personally: the proposed definition also reaches people such as employees whose information appeared in payroll records.
The proposed injunctive class would pursue the first three claims, seeking government action and judicial declarations. The proposed liability-only class would pursue the two monetary-liability claims, leaving each member’s damages for later individual determination. The complaint asks the court to certify these classes and appoint representatives and counsel. That request does not establish certification or an automatic payment to every applicant.
The common evidence proposed is the Newsom Administration’s own framework: its agreements, published procedures, required disclosure records, and standards for the programs. The complaint argues that this evidence can establish shared failures without requiring separate lawsuits to make the Administration create the same compliance system. It says application and award records can identify members, alleges that the applicants’ experiences and interests are representative, and asserts that experienced counsel can adequately represent the proposed classes. The cost of an individual suit to compel those procedures, it argues, would exceed one person’s stake.
To describe the scale, the complaint cites more than 330,000 grants and a portal figure of 344,000 submitted applications. Awards and applications are the measures cited; neither independently establishes the number of unique individuals exposed. The proposed classes would also include qualifying people whose records entered through someone else’s application. The definitions exclude the State, officials involved in administering the programs, the assigned judicial officers and their staffs, and anyone who timely opts out of the liability class if it is certified.
The lawsuit and the accounting
Five claims ask the court to enforce the duties, trace the records, and remedy the harm.
Five claims. A demand for an accounting.
Apply the IPA to outsourced records and implement its safeguards, handling rules, and individual rights.
A writ requiring GO-Biz, CalOSBA, and their directors to perform the specified duties.
The agencies’ disputed IPA obligations governing outsourced records, safeguards, and individual rights.
Judicial declarations settling the disputed obligations and the agreements’ compliance.
Observe the Act’s limits on collection, maintenance, and disclosure while providing required protections.
An injunction, an accounting of information held by vendors, an end to continuing access, and notice to class members.
Comply with the IPA; its monetary remedy addresses violations that adversely affect an individual.
A determination of liability, with each class member’s actual damages decided individually.
Perform mandatory statutory duties designed to protect against the kinds of injury alleged.
Public-entity liability under Government Code section 815.6, with individual damages determined later.
Claim One: Make the Newsom Administration Follow the Law
The first claim asks a court to require the Newsom Administration to perform duties the complaint says it left undone. California’s mandamus provisions authorize orders compelling official duties and address petitions by people with a beneficial interest who lack an adequate ordinary remedy. The applicants identify a current interest: their personal information remains in the program records while the protections and access procedures they claim are required remain unavailable.
The requested work is specific. Apply the IPA to outsourced records. Adopt regulations or publish procedures for individual rights. Establish safeguards. Write handling rules and instruct the people using the records. Assign responsibility for compliance. Keep the required disclosure and source records. The complaint treats those steps as obligations to build and operate a lawful information system.
Two additional statutes reinforce the claim. Government Code section 11019.9 requires a permanent privacy policy that adheres to the IPA. Government Code section 11549.3 requires implementation of the State’s governing information-security policies and standards. The complaint alleges that these duties went unimplemented for the grant data. A general privacy statement or a position named “privacy officer,” it argues, does not establish that protections actually operated throughout the contractor’s systems.
The writ is directed to the Governor’s Office of Business and Economic Development, the California Office of the Small Business Advocate, and their directors in their official capacities. The complaint ties the first director’s responsibility to contracting authority and the second director’s responsibility to administration of the programs and their records. It identifies those officials as the members of the Newsom Administration with the power to correct the omissions. Their institutional responsibilities do not depend on a finding that the Governor personally handled an application or directed a vendor’s processing.
Some requested measures would serve people beyond these grant programs. The complaint says published rights procedures, handling rules, and assigned compliance responsibility must cover every individual whose personal information the two named defendants maintain. It also seeks application of the IPA to future contracts that outsource personal-record operations. A damages payment would not itself create an access procedure, produce an accounting of disclosures, or reveal what happened to a file. The writ seeks the government action needed to do that work.
Claim Two: Declare the Privacy Duties Governing These Contracts and the Next Ones
The second claim asks the court to settle what the Newsom Administration owes the people whose information it collects. Declaratory relief determines rights and obligations in an actual controversy. The complaint alleges that the challenged arrangements and missing procedures continued after written notice. It infers the Administration’s contrary position from that conduct; it does not cite a substantive response rejecting the applicants’ interpretation of the law.
The requested declarations cover the Administration’s responsibilities, the records, and the contracts. They would establish that the IPA applies, determine the duty governing outsourced records, decide whether the agreements comply, and address access procedures, disclosure accounting, safeguards, and collection notices. One declaration would address the statute’s treatment of contractors and their personnel as agency employees for Article 10 purposes. That statutory treatment is limited to those purposes; it does not make them State employees for everything.
The complaint seeks an answer that carries into future programs. It alleges that the Administration continues using standard terms that fail to apply the Act to personal records, creating a recurring omission unless the governing duty is resolved. It also argues that later adoption of procedures or contract amendments would not by itself settle the dispute over past and continuing obligations. That is why it seeks declarations of the law as well as orders to perform particular acts.
Claim Three: Stop Unlawful Collection and Account for the Data
The third claim seeks an injunction against the continuing practices. The IPA separately authorizes injunctions against unlawful agency practices, and the complaint invokes that authority for records the Newsom Administration allegedly caused to be created and continues to control through the grant arrangements. It asks the court to restrain the challenged conduct and require the Administration to exercise its authority over the system.
This claim reaches the full handling of personal information. It alleges failures to identify collection authority, purposes, relevant disclosures, and access rights; preserve source information; maintain accurate records used to make determinations; keep the required disclosure accounting; instruct personnel; and assign working responsibility for the grant data. It also challenges collection through banks, browsers, and employers under the statute’s preference for collecting information directly to the greatest extent practicable.
Each recipient presents a separate question of authorization. The complaint identifies services for bank verification, chat, call analysis, document processing, monitoring, customer data, and analytics and advertising, along with further recipients. It alleges that each disclosure needed its own legal basis. Authority to process information for a grant does not by itself authorize a company to use that information to develop a private product or distribute it further.
The claim also invokes section 1798.60, which restricts commercial distribution, sale, or rental of an individual’s name and address without specific authorization by law. The complaint alleges prohibited distribution through the commercial uses described in the pleading and through advertising identifiers capable of being linked to names and addresses. This theory depends on proving the distribution alleged; it does not treat every instance of private processing as forbidden.
The requested injunction would prohibit maintaining applicant records under contracts that fail to apply the IPA, retaining information unnecessary to an authorized purpose, and allowing prohibited commercial distribution. It would require the Administration to obtain an accounting from Lendistry and its vendors of the applicant information they received and retained, secure an end to continuing access, and notify class members about the records held about them and the procedures created for their rights. That requested inventory of vendor-held information extends beyond the disclosures ordinarily covered by section 1798.25.
Claim Four: Compensate the People Harmed
The fourth claim asks the Newsom Administration to answer financially for harm allegedly caused by noncompliance. It invokes the IPA’s monetary remedy for a violation that adversely affects an individual. The claimed effects arise from the information collected, its alleged exposure and use, and the resulting inability to trace or correct records. This claim incorporates the allegations of individual harm and government-claim presentation that the first three claims do not.
The IPA’s damages provision expressly includes mental suffering within actual damages. The complaint identifies distress and expenditures separately: anxiety about information allegedly placed beyond the individuals’ control, and time and money spent investigating, monitoring accounts, attempting to revoke access, and improving security. It seeks a determination of liability for the proposed class, followed by individual determinations of each member’s damages.
The issue under this claim is whether the alleged statutory failures caused adverse effects and actual compensable harm. Filing the complaint establishes neither liability nor a quantified loss for each proposed class member. Those are matters the claim asks the court to determine.
Claim Five: Hold the Newsom Administration Liable for Failures to Perform Mandatory Duties
The fifth claim ties the Newsom Administration’s alleged omissions to mandatory public duties. Government Code section 815.6 addresses a public entity’s failure to perform a mandatory duty imposed by an enactment designed to protect against a particular kind of injury, where the failure proximately causes an injury of that kind. It also provides a defense when the entity establishes reasonable diligence in performing the duty. The complaint alleges that the Administration’s failures satisfy the requirements for liability.
The claim identifies the duties one by one: protections for outsourced records; procedures for individual rights; disclosure accounting and retention; security standards; compliant privacy policies; handling rules and instruction; assigned responsibility; direct collection; source records; restrictions on commercial distribution; collection limits; and record accuracy. Its argument is that authority to decide how to implement a duty did not permit the Administration to omit it.
The complaint locates the purpose of those duties in California’s privacy protections. The State Constitution recognizes privacy as an inalienable right, and the IPA’s findings identify indiscriminate collection and dissemination as threats magnified by information technology. The pleading argues that exposure, uncontrolled private use, and the inability to discover or correct the handling of government-collected information are the injuries those laws were designed to prevent. That constitutional background supports the statutory claims; the five-count complaint does not bring a separate constitutional cause of action.
The Administration’s use of outside companies does not, the complaint argues, break the causal connection. Those companies obtained access through the programs and contracts the Administration commissioned. Its own missing records and procedures then prevented people from discovering what had happened. It controlled contract terms and funding and had already required a secured system and assurance reports—powers the complaint identifies as evidence that protections were within its reach.
The fifth claim seeks class-wide liability for the alleged injuries, including mental suffering and expenditures, with damages determined person by person. It reserves the ability to identify additional mandatory enactments through discovery. Together with the other claims, it seeks both changes in the Administration’s conduct and monetary responsibility for injuries allegedly caused by that conduct.
The Requested Judgment: Trace the Data, Stop Unlawful Uses, and Remedy the Harm
The requested judgment brings the five claims together. It would require performance of neglected duties, declare the governing rights, restrain continuing unlawful practices, identify information retained across the contractor’s system, notify affected people, and determine liability for harm. The complaint also seeks attorneys’ fees and litigation costs under the IPA and California’s public-interest enforcement provision, and demands a jury on issues eligible for jury trial. Its requested relief does not include an automatic grant award for every applicant.
The action was filed in Los Angeles Superior Court on August 5, 2026. The filed complaint includes three signed verifications limited to the writ petition and the allegations it incorporates. Statements made on information and belief are verified as beliefs, and the verifications expressly do not extend to the other counts. Those verifications conclude the 99-page pleading. The contracts, letters, and other records linked in this report are separately presented evidence, rather than an exhibit packet appended to the filed document.
Billions in Taxpayer Funds, Unanswered Warnings: The Newsom Administration Owes California an Accounting
The scale reaches hundreds of thousands of California businesses. In March 2021, the Newsom Administration itself reported that more than 350,000 small businesses and nonprofits had applied in the first two funding rounds alone. The complaint alleges that the Administration’s application requirements drew the personal records of owners, employees, and family members into a system the Administration failed to bring under California’s Information Practices Act.
The Newsom Administration put Lendistry in charge of programs authorizing more than $4.5 billion in taxpayer funding. A signed agreement acknowledges $4.225 billion already transferred by the Administration to Lendistry by December 2021. The Administration’s budget officer later told the Legislature that approximately $201.7 million had been used for administrative costs across the programs. These were public dollars committed to public work, with security and compliance obligations attached.
The lawsuit accuses the Administration of funding that system without putting the legally required privacy oversight in place: failing to control continuing collection and commercial use, failing to account for disclosures, and leaving people without a working route to inspect or correct their records. When asked for audits and findings, the Administration produced contractor program reports without the underlying controls assessments. The Administration had required those assessments and retained powers to inspect the work. The complaint alleges that it failed to use those powers to protect the people whose information the programs demanded.
The November 2025 letters warned that the collection was continuing and asked the Newsom Administration to investigate and enforce the law. The Administration did not answer or follow up through September 28, 2026. Hundreds of thousands of applicants and billions of taxpayer dollars demand an accounting. The Administration that authorized the spending owes California an explanation for the unanswered warnings—and evidence that it required the protections the law promised.
Read the records. Follow the sources.
Explore the filed complaint, original agreements, official statements, policies, and warning letters.