As privacy professionals, we’ve watched US state privacy expand to an extraordinary 23 comprehensive privacy laws across the country. But what a lot of companies haven’t necessarily clocked yet is that there’s an entire patchwork of laws sitting underneath that number, built just for kids and teens. It’s not always visible from the outside either, because a lot of these obligations only surface once you dig into a specific law’s children’s provisions, or once an age signal tells you something about your users that you didn’t know before. Getting on top of this complicated area of privacy compliance starts with understanding where the different laws sit and requires a clear plan to turn that understanding into something operational.
We were recently joined by Shelby Dolen, an Associate at Troutman Pepper Locke’s Privacy, Cyber, and AI group, for a webinar talking through exactly where things stand with children’s and teens’ privacy. You can catch up and watch the full webinar replay here.
Table of Contents
The Regulatory Landscape, Briefly
A lot of companies have historically assumed children’s privacy laws don’t apply to them because they had no way of knowing if children were using their app or product. Part of the difficulty is that the traditional understanding of what constitutes a child in law has changed. Previously, organizations could rely on a child being defined as anyone under 13. Now, many state-level consumer privacy laws extend that definition to age 16, or, in some cases, 18. What this means in practice for organizations is that a whole demographic of teenagers is now covered, depending on which state you’re operating in.
Of the 23 comprehensive state privacy laws currently signed, more than half include children’s data requirements layered on top, typically around consent, restrictions, and purpose limitations. And the requirements are far from consistent. Some states, including Maryland, Vermont, and New York, prohibit the sale of children’s personal data outright. Others don’t address it directly, and some states, like Maryland, Nebraska, and South Carolina, prohibit targeted advertising to minors entirely, while New York allows it on an opt-in basis. This inconsistency is exactly why so many companies are struggling with how to design a single approach that works across every state they operate in.
We’re not going to go deep into the weeds on every law and update here, but this is an overview of the current shape of the patchworked privacy landscape, broken down into four distinct categories to help build an understanding and context around the complexity of the task at hand when tackling children’s privacy.
COPPA
The FTC finalized its most recent updates to COPPA in early 2025, the first changes to the law since 2013. The amendments went into effect this past April, and if your company has customers or users under 13, there are several changes worth your attention.
- Companies now need separate verifiable parental consent for different types of disclosures, rather than relying on one blanket consent method
- The definition of personal information has expanded to specifically include biometric identifiers and government-issued identifiers
- Data retention limits are stricter; a written information security program is now mandatory
- Privacy notices have to identify specific categories of third-party recipients
That last point raises a question that lies beneath a lot of this patchwork: how do these laws tie together? Listing a third-party recipient in your privacy policy could be read as admitting you’re selling children’s data. This can trigger requirements under an entirely different law. That kind of knock-on effect comes up again and again across this particular landscape, and it’s worth bearing in mind as you operationalize the different elements of your privacy program.
Age-Appropriate Design Codes (AADCs)
AADCs set a broad standard across California, Nebraska, Vermont, and South Carolina. Each state currently has its own version, and while the details vary, the common threads include age estimation, default privacy settings set to the highest level of privacy for that user group, disclosures written for children rather than adults, restrictions on collecting, selling, or sharing precise geolocation data, and prohibitions on profiling minors.
South Carolina’s law goes further than most, requiring public independent third-party audits starting July 1st of this year. What is particularly notable about this audit requirement is that it introduces external accountability into your compliance process, meaning a company can no longer simply self-certify that it’s meeting its obligations.
Children’s Data Privacy Laws
When it comes to specific children’s privacy laws, this is a separate category entirely, and laws of this nature are currently only found in Arkansas and New York. However, the approach they take is distinctly different from AADCs. AADCs are built around the notion of a product or service being ‘reasonably likely to be accessed by minors’, essentially asking whether your service is the kind of thing minors would plausibly use, based on its design, content, and audience. If it is, you’re in scope, regardless of what you actually know about any individual user.
Children’s privacy laws have a primary trigger of applicability when an organization has actual knowledge that a specific user is a minor. That means a product that was never designed for kids and wouldn’t be covered by an AADC can still fall under these laws the moment your organization knows a user is a minor. In New York, this trigger is taken a step further, stating that knowledge isn’t limited to what you learn directly. I.e., a device or browser signal indicating a user is a minor can itself create legal knowledge, even on a product aimed at a general audience with no account or login involved. Once that signal is received, the operator has to treat the user as a covered minor from that point on.
App store accountability laws
App store accountability laws are the newest and arguably the most consequential category, with laws currently active in Alabama, Louisiana, Texas, and Utah, plus a related version in California. Typically, these laws require app stores and operating system providers to verify age and secure parental consent, as well as communicate an age-range signal to the app developer. The developer then has obligations of its own, including age verification, limiting use of that age data, and configuring defaults accordingly.
One key part of this to be aware of is that once an app store or operating system communicates a signal that minors are using your app, your organization has actual knowledge of an individual’s age. And actual knowledge of a user’s age, as we just discussed, is something that can pull you into scope of several other laws in this patchwork, even if your app was never built or marketed for kids in the first place.
What Regulators Care About When It Comes to Children’s Privacy
Enforcement around children’s privacy is starting to shift. Regulators are increasingly moving away from narrow, COPPA-only enforcement toward a broader, multi-theory approach, layering COPPA violations on top of unfair and deceptive trade practices claims, state privacy law violations, and security-related theories.
The ‘actual knowledge’ standard is also being interpreted more aggressively. Regulators are increasingly taking the position that companies should have known, based on the nature of their services, that children were using them, drawing on evidence like site content and internal communications to establish that awareness. In practice, this moves the standard closer to ‘constructive knowledge’ than ‘actual knowledge’.
Rather than waiting for complaints or breach notifications, regulators are creating task forces and running investigative sweeps, and state Attorneys General offices are expected to be a major source of enforcement activity going forward, including bringing alleged COPPA violations under their own state authority.
How Do You Operationalize Children’s Privacy?
The real question organizations are asking is how to turn all of this into something operational. The instinct is often to manage this state by state, but with 23 comprehensive privacy laws and a children’s law patchwork sitting beneath them, that approach is difficult to manage. A more straightforward approach is to build toward one central playbook, comply with the strictest standard across the board, and treat each law’s requirements as a control to map against what you’re already doing, whether that’s disclosures, consent mechanisms, or data inventories, with a named, responsible owner so accountability is built in. Here’s eight steps we’d recommend:
1 – Scope First
Before anything else, figure out the scope of the laws as they apply to what you’re doing, including what age an individual is legally considered a child under each law. This calls for a full scoping analysis, and it matters more than it might sound like on paper. One example that illustrates this well involves a B2B company that assumed it had no children’s data at all until a data inventory revealed that its customer base actually includes children. Its obligations as a B2B service provider therefore looked quite different from what was expected. Don’t assume you’re out of scope until you’ve actually checked.
2 – Identify Your Gray Zones
Once you understand your scope, look closely at which products and services you’re actually providing and to whom, and ask whether you really need to provide them to children at all. If there is an area that you’re not fully sure about, it’s often possible to change what that offering looks like so you’re less exposed, rather than trying to argue your way through the ambiguity.
This step gets skipped a lot, but it’s often the most practical one. If a particular feature or data collection point puts you in ambiguous territory, sometimes the simplest fix isn’t a legal interpretation but a change to your product that moves you out of the gray zone entirely.
3 – Know When Consent Is Needed, And From Whom
You don’t necessarily need to build separate consent infrastructure for kids and adults, but the same tool has to run different logic depending on who the consent has to come from and what age they are. Under the CCPA, for example, 13- to 16- year-olds can give their own consent for the sale of their data or targeted ads, while under-13s require parental consent instead; other states have similar age-tiered distinctions. The tool can be the same, but the strategy behind it can’t be, and it needs to be built to recognize which age group a user falls into so it can route consent accordingly.
Under the app store accountability laws, that burden starts upstream with app store providers, who are required to implement a parental account system, obtain verifiable parental consent before a minor under 18 can download an app or make a purchase, and give parents a way to withdraw that consent later. The provider then passes an age signal down to you as the developer.
Once your organization receives that signal, you have to limit how you use that age data to appropriate purposes only, obtain consent yourself where the law requires it, and configure your features and defaults accordingly. The moment you know a user is a minor, that knowledge comes with rules attached, and you need a process ready to receive it, identify who gave consent (e.g., the minor or a parent), and stop personal information from being used for anything beyond what the original consent was given for.
4 – Check Your Exemptions, State by State
Many of these laws still include exemptions you can rely on, and when children’s requirements sit inside a broader consumer privacy law, the broader law’s exemptions typically still apply too. This is part of the scoping exercise, but it deserves its own dedicated check, because exemptions are not uniform across states.
5 – Know Your Data
None of this is possible without a real understanding of your business practices, mapped by process and by data type. You cannot make good decisions about consent, disclosures, or minimization without first understanding, in detail, what data you collect, how it moves through your business, and which processes touch it.
6 – Treat Disclosure Requirements as Ongoing
As your products and services evolve, your disclosures need to evolve with them. This isn’t a project you complete once and file away. It needs an owner, and it needs to be revisited every time something changes on the product or data side.
7 – Minimize your data
Reducing the amount of data you collect from children and teens is often required outright by many privacy laws, and it’s one of the most effective ways to reduce your own compliance burden. The least amount of data collected is always going to help you, and in some situations, it will be required rather than optional.
8 – Build Privacy by Design Into Your Operations
Embedding privacy into products, services, and operations is the mindset that ties everything else together, and it allows you to reach a sustainable, defensible position. This takes real effort up front, but the goal is a privacy-forward approach that holds up as laws and products keep changing, because there is simply no wiggle room when it comes to protecting kids.
What’s Next For Children’s Privacy Laws in the US?
Unfortunately, this patchwork isn’t close to being finished. Legislative sessions keep producing new laws and amendments to existing ones, and states that don’t yet have a comprehensive privacy law, or a children’s-specific one, are watching what’s happening elsewhere and building their own versions. Age signals are likely to become more common too. Meaning more organizations that never thought of themselves as being in scope for children’s privacy will find themselves there anyway, simply because they now have ‘actual knowledge’ they didn’t have before.
Waiting for the picture to settle before you act is a precarious position to put yourself in, especially with a heightened enforcement focus in this area. But building a compliance program flexible enough to absorb the next law without a full rebuild, and one that treats children’s privacy as a permanent part of how your business operates… that’s not a bad way to be positioned.
To learn more about the children’s privacy patchwork, how it interacts with state law, and how it can impact your organization, tune in to the on-demand version of our recent webinar with Shelby Dolen of Troutman Pepper Locke’s Privacy, Cyber, and AI group. Watch it here: https://youtu.be/oOXTcS3bZKE
Data Inventory Roadmap: Business Guide
Check out our Data Inventory guide and start simplifying compliance!