Children’s Online Privacy Protection Act

Portions of this blog were also co-authored by Taft Summer Associate Ashley Patriquin.

Businesses that provide a website or online services that collect data from or about minors or children should be aware of expanding legal requirements from U.S. states. These laws impose a range of obligations on businesses, including age estimation requirements, heightened privacy disclosures, limitations on data collection and profiling, and duties to act in the best interests of minors.

State legislatures have also recently begun directly regulating the privacy practices of companies that provide social media solutions to consumers, often with an eye to protecting underage users. Common amongst these new laws are age verification requirements and parental control and consent requirements. Some laws go further, such as requiring ‘deplatforming’ in certain circumstances and restricting ‘shadow banning’ practices. Many of these statutes define “social media” to broadly include any technologies that facilitate interactions among end users and can carry significant penalties for noncompliance.

Below is a summary of certain recent state laws regulating these topics.

Continue Reading Children’s Data & Social Media Privacy Laws

We have another one! We wrote last week about Oklahoma’s new consumer protection law. Now, Alabama has passed its own comprehensive privacy law. The Alabama Personal Data Protection Act, House Bill 351, (the  Law) will go into effect on May 1, 2027.

Here is a general summary of what to expect:

Continue Reading “Sweet Home, Data Privacy” – Alabama’s New Privacy Law is Coming Online in 2027

On April 22, 2026, the Federal Trade Commission will begin enforcing compliance with its most recent amendments to the Children’s Online Privacy Protection Rule (the COPPA Rule). As discussed in more detail below, the FTC published amendments in a 2025 final rule that, among other updates, expands the scope of the COPPA Rule, expands notice requirements, and requires specific data retention and information security policies and procedures.

Continue Reading Enforcement Begins Soon for Significant COPPA Rule Amendments

As previously reported, states such as California, Louisiana, Texas and Utah have adopted App Store Accountability (ASA) Laws. These new laws require app store operators (e.g., Apple and Google) along with app developers (i.e., the business that owns the app) to implement safeguards for age verification. While these laws are framed as child-protection measures, their impact is universal. Every app must comply, regardless of its audience. For businesses, meeting the requirements outlined in ASA Laws is mandatory for apps to remain available for download.

Louisiana, Texas and Utah’s laws are similar and take effect at various points in 2026, while California’s Digital Age Assurance Act (CA ASA Law) is unique and takes effect January 1, 2027. This is what businesses should know about the unique features of the CA ASA Law.

Continue Reading A Deeper Dive Into California’s App Store Accountability Law

From California to Texas to Ohio, lawmakers are increasingly turning to age-verification requirements to protect children online. These laws target a range of concerns, with a growing body of research suggesting that certain online activities may pose risks to children’s mental health and well-being.

At the same time, privacy laws continue to proliferate across the United States, many of which emphasize data minimization and limitations on the use of sensitive personal information. This creates a growing tension. Protecting children online may require companies to collect more personal data than they otherwise would, and potentially subject themselves to additional privacy requirements and consumer concerns.

Continue Reading Collection for Protection: The Age-Verification Paradox

Under newly implemented regulations of the California Consumer Privacy Act (CCPA), California now requires a formal risk assessment “before initiating any processing activity” of certain (sensitive) sorts. The regulation explicitly contemplates that businesses will complete risk assessments now, in 2026.

Eventually, such risk assessments – including those completed this year – must be signed by an executive and submitted to the California regulator under penalty of perjury.

Continue Reading New CCPA Risk Assessment Requirements Now In Effect

State regulators are increasingly prioritizing children’s data privacy. These efforts follow several changes to protect children’s online privacy at the federal level. One of the latest sweep of changes involve several states (e.g., California, Louisiana, Texas and Utah) imposing app store accountability laws (ASA Laws).

These new laws require app store operators (e.g., Apple and Google) along with app developers to implement safeguards for age verification, age rating, parental consent and data minimization. While the aim of these laws is to protect children, the obligations imposed on businesses apply broadly, regardless of the age of an app’s users. For businesses with mobile apps, these safeguards are not optional. They are mandatory to keep  apps available for download.

While the ASA Laws slightly vary in their respective requirements, a general overview of what businesses should know is below.

Continue Reading New App Store Accountability Laws in 2026: If Your Business Has an App, Read On

Early on July 1, the U.S. Senate voted to halt an effort to impose a 10-year moratorium on state regulation of artificial intelligence. The vote, 99-1, removed the AI provision from President Trump’s “Big, Beautiful Bill” that had evolved from a full moratorium on state AI regulation for the next decade, to its most recent iteration that required states to adopt the ban in order to receive federal broadband funding over the next five years.

Yesterday, Sen. Marsha Blackburn of Tennessee and Sen. Ted Cruz of Texas attempted to revise the AI ban to address current regulations. According to media reporting, efforts toward banning state AI regulation broke down amidst concerns that the language was overly broad and could adversely impact existing laws concerning privacy, consumer protection, and child safety.

Continue Reading US States Can (And Will) Continue To Regulate Artificial Intelligence … for Now

As we reported early last year, the Federal Trade Commission (FTC) issued a notice of proposed rulemaking to the Children’s Online Privacy Protection Act rule (COPPA). On April 22, 2025, over a year after the notice of proposed rulemaking was issued, the FTC has finalized its amendments to the COPPA rule and are set to go into effect on June 23, 2025.

To note, while the amendments will be effective on June 23, 2025, regulated entities under COPPA have until April 22, 2026 to comply.

Continue Reading Children’s Online Privacy Protection Act Amendments Effective June 23, 2025

As we discussed last year, the Federal Trade Commission (FTC) has increased its focus and its enforcement related to the Children’s Online Privacy Protection Act (COPPA), especially in the educational context. Now the FTC is taking further steps to secure and protect children’s information as online tools and technologies continue to quickly advance.

In December 2023, the FTC issued a notice of proposed rulemaking to the COPPA rule that focuses on targeted advertising, push notifications, surveillance in the educational context, and providing more clarity on the exceptions under COPPA. According to the FTC Chair Linda M. Kah, “[t]he proposed changes to COPPA are much-needed, especially in an era where online tools are essential for navigating daily life—and where firms are deploying increasingly sophisticated digital tools to surveil children.” Moreover, the FTC issued a lengthy statement from Commissioner Alvaro M. Bedoy that attempts to dispel the critiques around COPPA and other regulations around children’s data collection, such as the critique that many violations of such data privacy statutes regulate conduct that does not involve a great deal of harm. Looking at all of the above, it is clear that the FTC believes new tools and technologies utilized by companies online are a major risk to children and that this new rulemaking is necessary to keep up with such new tools and technologies.

Continue Reading Children’s Online Privacy Protection Act Update: Part Deux! New FTC Rulemaking Proposal