Children’s privacy laws in the United States start with the Children’s Online Privacy Protection Act, known as COPPA, which since 2000 has controlled how websites and apps collect personal information from children under 13. That federal baseline now sits inside a much larger structure: the Federal Trade Commission finalized major amendments to the COPPA Rule in January 2025, states have passed their own design codes and social-media laws at speed, and regulators in the UK, EU, and Australia have imposed rules that reach any global platform. The result is a layered set of obligations that vary by the child’s age, the type of service, and where the user lives.
What COPPA Requires
COPPA applies to two kinds of operators: those running websites or online services directed at children under 13, and those running general-audience services that have actual knowledge they are collecting personal information from a child under 13.1FTC. Children’s Online Privacy Protection Rule (COPPA) Covered operators must post a clear privacy policy, give parents direct notice of what they collect, and obtain verifiable parental consent before collecting personal information from a child. Parents can review the data on file about their child, ask that it be deleted, and refuse to allow further collection.
The FTC enforces COPPA and can impose civil penalties for violations. The statute also allows industry groups to run self-regulatory “safe harbor” programs approved by the FTC; participants in an approved program are generally handled through that program’s review and discipline rather than direct agency enforcement, so long as the program’s protections meet or exceed the Rule.2FTC. FTC Approves kidSAFE Safe Harbor Program Falsely claiming membership in a safe harbor program is itself a violation of the FTC Act.3FTC. Do Your COPPA Safe Harbor Claims Hold Water
COPPA does not extend to teenagers. Its protections stop at 13, and unless a state law or a platform’s own rules apply, users aged 13 through 17 are treated like any other user under federal privacy law.
What Changed in the 2025 COPPA Rule
On January 16, 2025, the FTC finalized the most substantial changes to the COPPA Rule since 2013, approving them 5-0.4FTC. FTC Finalizes Changes to Children’s Privacy Rule The core changes:
- Operators must obtain a separate verifiable parental consent before disclosing a child’s personal information to third parties for targeted advertising. Bundling this into a general consent is no longer enough.
- Operators can no longer keep children’s personal information indefinitely. Data may be retained only as long as reasonably necessary for the specific purpose it was collected.
- The definition of “personal information” now includes biometric identifiers and government-issued identifiers.
- FTC-approved safe harbor programs have to publicly disclose their membership lists and report additional information to the agency.
The FTC declined to adopt proposed requirements for push notifications aimed at children and chose not to write COPPA-specific rules for education technology in school settings, citing the Department of Education’s stated plan to propose updates to the Family Educational Rights and Privacy Act (FERPA) that could have conflicted with new edtech provisions.5K-12 Dive. FTC Finalizes COPPA Rule Children Data Privacy Covered entities have one year from Federal Register publication to reach full compliance.
The FTC has also moved separately on age verification. On February 25, 2026, the Commission issued a policy statement saying it will not bring COPPA enforcement actions against operators of general-audience sites that collect personal information solely to determine a user’s age, provided the data is used only for that purpose, not retained longer than necessary, protected by reasonable security, and paired with clear notice to parents.6FTC. FTC Issues COPPA Policy Statement to Incentivize Use of Age Verification Technologies The Commission also indicated it would begin a formal review of the COPPA Rule to address age verification more permanently.
State Laws Filling the Gap
Because COPPA stops at 13 and federal legislation to extend it has stalled, states have written their own rules. The result is a patchwork that covers older minors, restricts specific business practices, and in some cases imposes design obligations that reach every service likely to be used by kids.
Age-Appropriate Design Codes
Several states have adopted laws modeled on the UK’s Age Appropriate Design Code. California went first with the California Age-Appropriate Design Code Act (CAADCA), enacted in 2022 and applicable to services likely to be accessed by users under 18.7IAPP. Nebraska, Vermont’s Age-Appropriate Design Codes Look to Bolster Children’s Online Safety The industry group NetChoice sued on First Amendment grounds, and on March 12, 2026, the Ninth Circuit issued a split ruling: it vacated the lower court’s blanket injunction and lifted the block on the law’s age-estimation requirement, but affirmed injunctions against provisions it found unconstitutionally vague, including “materially detrimental” and “best interests.”8Holland & Knight. Ninth Circuit Issues Mixed Ruling on California Age-Appropriate Design Code
Maryland’s Kids Code took effect in October 2024 and is also facing a NetChoice challenge. A federal judge denied the state’s motion to dismiss on November 24, 2025, letting the case proceed to discovery.9Law360. Maryland Judge Keeps Kids Privacy Law Challenge Vermont’s version was signed in June 2025 with an effective date of January 2027, and among its requirements covered businesses must set default privacy settings to their highest level, disable push notifications for minors by default, and give users a way to delete accounts within 15 days of a request.10Hunton Andrews Kurth. Vermont Enacts Age-Appropriate Design Code Nebraska enacted its version in May 2025, effective July 2026. South Carolina signed its law on February 5, 2026, and NetChoice sued days later, arguing content-based speech restrictions, vagueness, and preemption by both COPPA and Section 230.11Hunton Andrews Kurth. NetChoice Files Suit Challenging South Carolina Age-Appropriate Code Design
Targeted-Advertising and Data-Sale Restrictions
Connecticut, Georgia, and Louisiana enacted laws restricting targeted advertising to children effective July 2025. Oregon’s Consumer Privacy Act, effective January 2026, prohibits the sale of the personal information of known minors under 16 and bars using their data for targeted advertising at all. New York’s Child Data Protection Act, effective June 2025, covers the collection and processing of personal data for users under 18.
Social Media Age and Design Rules
Florida passed a law banning social media accounts for children under 14 and requiring parental consent for 14- and 15-year-olds; an Eleventh Circuit panel stayed an earlier preliminary injunction against the law in November 2025. New York’s SAFE for Kids Act prohibits social media platforms from using addictive algorithms for users under 18. California and Minnesota now require health warning labels on social media about mental health risks. Several states, including California, New York, and Utah, have passed laws requiring disclosure that AI companion chatbots are not human and mandating suicide-prevention protocols when chatbots detect suicidal ideation.
State Attorney General Enforcement
The Texas Attorney General has been particularly active, filing suits against TikTok and Snapchat for alleged violations of the Texas SCOPE Act, which prohibits sharing a minor’s personal identifying information without parental consent, and opening investigations into Character.AI, Reddit, Instagram, and Discord over how they handle minors’ data.12Mayer Brown. Protecting the Next Generation
Children’s Privacy in Schools
School-issued devices and cloud-based learning platforms collect substantial amounts of student data; roughly one-third of elementary through high school students use school-issued devices.13Electronic Frontier Foundation. Student Privacy Under COPPA, the FTC allows schools to provide consent on behalf of parents for the collection of student personal information, but only when the data is used exclusively for school-authorized educational purposes and not for commercial activities.14Honigman. Privacy Tips for Ed Tech Companies and Schools Edtech companies relying on school-based consent must still provide the school with the COPPA notice describing their data practices.
The 2025 COPPA Rule update did not create a special exemption for edtech, leaving those companies subject to standard enforcement.5K-12 Dive. FTC Finalizes COPPA Rule Children Data Privacy Class actions have been filed against edtech companies including IXL Learning and PowerSchool, alleging unauthorized monetization of student data. FERPA permits schools to share education records with service providers under a “school official” exception, but the scope of that exception and how it aligns with COPPA’s consent requirements continue to generate compliance uncertainty.
How the Rules Are Enforced
Enforcement is where children’s privacy law has bite. The FTC’s recent actions show what triggers penalties and what remedies the agency seeks.
Epic Games — $520 Million (2022)
The largest COPPA-related settlement to date involved Epic Games, the maker of Fortnite. In December 2022, Epic agreed to pay $275 million for collecting personal information from players under 13 without parental consent, plus $245 million to refund consumers harmed by deceptive billing practices and dark patterns.15FTC. Fortnite Video Game Maker Epic Games to Pay More Than Half a Billion Dollars The FTC alleged that Epic enabled real-time voice and text chat by default for children and teens and created “extraordinary hoops” for parents trying to get accounts deleted.16Loeb & Loeb. Fortnite Video Game Maker Settles FTC Privacy Deception Claims for Record $520 Million Under the consent order, Epic must turn off voice and text communications by default for children and teens, delete previously collected data from players under 13 unless consent is obtained, and submit to regular independent privacy audits.
TikTok and ByteDance (Pending)
In August 2024, the Department of Justice, acting for the FTC, sued TikTok, ByteDance, and several affiliates in the Central District of California.17U.S. Department of Justice. Justice Department Sues TikTok and Parent Company ByteDance The complaint calls TikTok a “repeat offender,” pointing to a 2019 consent order over COPPA violations involving its predecessor Musical.ly. The government alleges TikTok knowingly allowed millions of children under 13 to create accounts and interact with adults on the standard platform without parental consent, that human reviewers spent only five to seven seconds verifying flagged accounts, and that the company built workarounds allowing account creation through third-party services like Google and Instagram to bypass age gates.18FTC. FTC Investigation Leads to Lawsuit Against TikTok and ByteDance The complaint seeks civil penalties and a permanent injunction, and the case remains pending.19FTC. United States of America v. ByteDance Ltd., et al.
Disney — $10 Million (2025)
In late 2025, a federal court approved a consent order requiring Disney to pay $10 million for enabling the unlawful collection of children’s personal data through YouTube.20U.S. Department of Justice. Disney Agrees to $10M Civil Penalty and Injunction The FTC alleged Disney applied “Made for Kids” or “Not Made for Kids” labels at the channel level rather than reviewing individual videos, causing child-directed content featuring properties like Frozen, Toy Story, and Mickey Mouse to be labeled as not for kids. That mislabeling allowed targeted advertising and the collection of children’s personal information without parental consent across more than 1,250 YouTube channels.21FTC. Disney to Pay $10 Million to Settle FTC Allegations YouTube had notified Disney as early as mid-2020 that it had manually corrected more than 300 misclassified videos, but Disney continued its channel-level labeling policy. The consent order requires Disney to establish a program to review individual videos for proper audience designation.
Other Recent Actions
In January 2025, Genshin Impact developer Cognosphere agreed to pay a $20 million fine and was banned from selling loot boxes to teens under 16 without parental consent.22FTC. Kids Privacy and COPPA In 2025, robot-toy maker Apitor Technology settled allegations that its mobile app allowed a third-party software development kit to collect children’s geolocation data without parental consent; the $500,000 penalty was suspended for inability to pay.23Corporate Compliance Insights. What Recent FTC Enforcement Actions Reveal About COPPA Risks The FTC also sued the operators of the Sendit app, alleging actual knowledge of more than 116,000 users who reported being under 13 whose data was collected without parental consent.
The Age Verification Problem
Nearly every children’s privacy law runs into the same question: how do you determine a user’s age without creating new privacy problems? The available methods each have significant drawbacks.24IAPP. Are New Global Age Verification Requirements Creating a Children’s Online Safety Legal Patchwork Self-declaration through a birthdate box is trivially easy to bypass and, in the UK, has been declared legally insufficient. Document-based verification with a government ID requires users to hand sensitive personal data to third-party verification companies, creating breach and surveillance risks; the Electronic Frontier Foundation has pointed to high-profile breaches at verification companies and platforms as evidence of the danger.25Electronic Frontier Foundation. 10 Not-So-Hidden Dangers of Age Verification An estimated 15 million U.S. adults lack a driver’s license, and 2.6 million lack any government photo ID, so document-based systems exclude substantial populations.
AI-based facial age estimation avoids the ID problem but introduces its own. Studies have shown higher error rates for Black, Asian, Indigenous, and Southeast Asian individuals, and the technology often fails on faces with physical differences and misclassifies transgender and non-binary users. In U.S. courts, age verification requirements have repeatedly been challenged on First Amendment grounds, with judges grappling over whether systems that are both over-inclusive (blocking adults) and under-inclusive (failing to stop all minors) can survive constitutional scrutiny. The FTC’s February 2026 policy statement is one attempt to reduce the disincentive: by promising not to enforce COPPA against companies that collect data solely for age determination and promptly delete it, the agency is trying to make it easier for platforms to build age gates without being punished for the data they collect while doing so.26FTC. Enforcement Policy Statement Promoting the Adoption of Age-Verification Technology
Rules That Reach Global Services
A U.S.-based service that reaches users abroad is subject to those countries’ children’s rules as well.
European Union
Under Article 8 of the General Data Protection Regulation (GDPR), processing a child’s personal data based on consent requires the explicit consent of a parent or guardian if the child is under 16.27European Commission. Are There Any Specific Safeguards for Data About Children Member states can lower the threshold, but not below 13, creating variation across the bloc.28GDPR-info.eu. Art. 8 GDPR Data controllers must make “reasonable efforts” to verify that parental consent is valid, and any communications directed at children must use language a child can easily understand. Meta alone has paid nearly $1 billion in total GDPR fines, and TikTok was fined £12.7 million by the UK’s Information Commissioner’s Office for data privacy failures involving children.
United Kingdom
The UK’s Age Appropriate Design Code, enforced by the Information Commissioner’s Office (ICO), sets 15 standards that services likely to be accessed by children must follow, including setting privacy to “high” by default, minimizing data collection, keeping geolocation off by default, and refraining from nudge techniques that push children to weaken privacy settings.29ICO. Age Appropriate Design: A Code of Practice for Online Services In February 2026, the ICO fined Reddit £14.47 million for unlawful processing of children’s personal information, finding the platform had no age-verification mechanisms beyond self-declaration until July 2025 and failed to conduct a required data protection impact assessment.30Osborne Clarke. UK ICO Fines Online Platform £14.47M The ICO also fined Imgur’s parent MediaLab.AI £247,590 for similar failures.31DLA Piper. UK Protecting Children Online: A Changing Regulatory Landscape Information Commissioner John Edwards said “relying on users to declare their age themselves is not enough when children may be at risk,” and the ICO is now prioritizing enforcement against platforms that rely primarily on self-declaration.
Australia
Australia’s social media minimum age law took effect on December 10, 2025, barring children under 16 from maintaining social media accounts.32eSafety Commissioner. Social Media Age Restrictions The law applies to 10 platforms: Facebook, Instagram, Snapchat, Threads, TikTok, Twitch, X, YouTube, Kick, and Reddit. By January 2026, platforms had removed access to 4.7 million accounts held by users under 16. Platforms face fines of up to $49.5 million AUD for failing to take reasonable steps, though enforcement has proven difficult: an eSafety Commission report found that seven out of ten children with pre-ban accounts still had “some access” to social media, and the eSafety Commissioner opened formal investigations into the compliance of Facebook, Instagram, Snapchat, TikTok, and YouTube.33BBC. Australia Social Media Ban Enforcement The government announced it would double the maximum penalty to $99 million AUD. Platforms may not compel users to provide government-issued ID for age verification, though they may offer it as one option alongside alternatives such as facial age estimation.34Office of the Australian Information Commissioner. Social Media Minimum Age
Federal Bills That Have Not Become Law
Two federal bills often come up in coverage of children’s privacy, and neither is currently law. The Children and Teens’ Online Privacy Protection Act, commonly called COPPA 2.0, would extend privacy protections to users under 17, ban targeted advertising to children and teens, create an “eraser button” for personal information, and establish a Youth Marketing and Privacy Division at the FTC.35U.S. Senate Committee on Commerce. Senate Overwhelmingly Passes Children’s Online Privacy Legislation The Senate passed it on July 30, 2024, and it was reintroduced as S.836 in the 119th Congress, but it has not been signed into law.36Congress.gov. S.836 – Children and Teens’ Online Privacy Protection Act
The Kids Online Safety Act (KOSA) would create a legal “duty of care” requiring covered platforms to prevent and mitigate specific harms to minors, including suicide, eating disorders, substance use disorders, child sexual exploitation, and addictive design features, and would require the strongest privacy settings by default for minors and tools letting minors opt out of personalized algorithmic recommendations.37Senator Richard Blumenthal. Kids Online Safety Act The Senate passed it 91-3 in 2024, but it has stalled in the House. As of February 2026, the bill has more than 75 Senate co-sponsors but remains held in the Senate Commerce Committee, where Chair Ted Cruz has not scheduled a markup; House leadership has raised First Amendment concerns.38Children and Screens. Policy Update February 2026 Until either bill is enacted, the federal floor remains COPPA and its 2025 Rule, with the rest supplied by state law and, for global services, foreign regulators.