State Kids' Online Safety Laws in 2026: What Consumer App Founders Must Do Beyond COPPA
Most founders assume COPPA is the only kids' privacy law that matters. But California's AADC, Texas's SCOPE Act, and Utah's social media laws now impose design-code obligations, age-assessment duties, and data-minimization requirements on any platform likely to be accessed by minors—not just EdTech.
Most founders we talk to assume that if they comply with COPPA—the federal Children's Online Privacy Protection Act—they've checked the kids' privacy box. That was a reasonable assumption three years ago. It's not anymore.
A growing patchwork of state laws now imposes design-code obligations, age-assessment duties, data-minimization requirements, and mandated default settings on any platform "likely to be accessed by minors"—not just apps directed at children under 13, and not just EdTech companies. If your consumer app, social platform, streaming service, gaming product, or health tool is used by teenagers, these laws likely apply to you. We've written about COPPA compliance broadly and the 2025 COPPA amendments in other posts; this article focuses on the state laws that reach beyond COPPA's under-13 threshold and into the 13-to-17 age range—and into product design decisions that COPPA never touches.
Why COPPA Is Not Enough
COPPA applies to operators of websites or online services directed to children under 13, or operators with actual knowledge they are collecting personal information from children under 13. It requires verifiable parental consent before collecting personal data from young children, but it does not regulate how you design your product, what default settings you ship with, or how you handle data for teenagers aged 13–17. For a deeper dive on the federal baseline, see our COPPA compliance guide for startups.
The state laws we cover here fill—or attempt to fill—that gap. They apply to users up to age 18, they regulate product architecture (not just data collection), and they create enforcement risk through state attorneys general who are actively litigating against major platforms. Even where parts of these laws have been enjoined, other provisions remain in effect and carry real penalties.
California's Age-Appropriate Design Code (AB 2273)
What It Covers
The California Age-Appropriate Design Code Act (CAADCA), signed into law in September 2022, applies to businesses that provide an online service, product, or feature "likely to be accessed by children" under 18. According to the Tech Policy Press tracker, the law was modeled after the UK's Age-Appropriate Design Code and was originally set to take effect July 1, 2024.
The coverage standard is broad. A service is considered "likely to be accessed by children" when it is reasonable to expect children will access it, based on indicators such as whether the service is directed to children under COPPA, whether evidence shows it is routinely accessed by a significant number of children, whether it includes advertisements marketed to children, or whether it contains design elements known to appeal to children—such as games, cartoons, music, or celebrities popular with children. As the Ninth Circuit noted in its March 2026 opinion, children can access a wide variety of services, including ride-sharing platforms, ticketing services, fitness applications, and health tools—not just "kids' apps."
What's Enforceable Now
The CAADCA's path to enforcement has been anything but smooth. NetChoice, a tech industry trade group, sued to block the law in December 2022, and a district court issued a preliminary injunction in September 2023. The Ninth Circuit issued a mixed ruling in August 2024, and on March 12, 2026, the court issued an opinion that narrowed the injunction further, lifting it for several key provisions while keeping others blocked.
According to a March 2026 analysis from Kilpatrick Townsend, the provisions now enforceable include:
- Coverage definition: The "likely to be accessed by children" standard is in effect, meaning the law's scope applies to a wide range of consumer services—not just children's apps.
- Age estimation: Covered businesses must estimate the age of child users with a reasonable level of certainty appropriate to the risks of their data practices, or apply child-level privacy protections to all users. This "opt-out" approach means you can avoid age estimation entirely if you treat every user as a minor for privacy purposes.
- Default privacy settings: Privacy settings for children must default to the highest level, unless the business can demonstrate a compelling reason that a different setting is in the child's best interest.
- Clear privacy information: Privacy information, terms of service, and community standards must be presented concisely and in language suited to the age of children likely to access the service.
- Monitoring signals: If your service allows parents, guardians, or others to monitor a child's activity or track location, you must provide an obvious signal to the child when monitoring is occurring.
- Enforcement of published terms: Businesses must actually enforce the terms, policies, and community standards they publish.
What's Still Blocked
The Ninth Circuit kept the injunction in place for the CAADCA's data use restrictions and dark patterns provision. These include prohibitions on using children's personal information in ways materially detrimental to their well-being, profiling children by default, collecting or retaining data not necessary to provide the service, and using dark patterns to encourage children to give up privacy protections. These provisions are not currently enforceable, but they could come back into play depending on further court proceedings.
Penalties
Violations can result in civil penalties of up to $2,500 per child for negligent violations and $7,500 per child for intentional violations, enforceable by the California Attorney General.
Texas SCOPE Act (HB 18)
What It Covers
The Texas Securing Children Online Through Parental Empowerment (SCOPE) Act took effect September 1, 2024. According to a detailed analysis by Kelley Drye, the law applies to "digital service providers" (DSPs) that host platforms allowing users to create public profiles, post public content, and interact with other users. Importantly, the law exempts small businesses as defined by the U.S. Small Business Administration, financial institutions subject to the Gramm-Leach-Bliley Act, and higher education institutions.
What's Enforceable Now
As of the law's effective date, the following requirements remain in effect:
- Age registration: DSPs must register the age of users who sign up and prevent them from later altering their age.
- Data collection limits: DSPs must limit collection and use of minors' personally identifiable information (PII). They are prohibited from collecting minors' precise geolocation data, and from selling or sharing minors' PII, unless a parent or guardian has permitted it through parental controls.
- Purchase restrictions: Minors cannot make purchases or engage in financial transactions through the platform unless a parent or guardian has provided consent—and even then, the service provider must restrict the minor's ability to effectuate purchases.
- Algorithm disclosures: DSPs must clearly disclose in their terms of service or privacy policy how algorithms show content to minors, how algorithms rank or filter content, and what PII algorithms take into account.
- Parental tools: DSPs must create and publish parental tools allowing verified parents or guardians to control the minor's privacy and account settings, monitor time spent on the platform, and review, download, or delete the minor's PII.
What's Been Blocked
The SCOPE Act has faced two rounds of preliminary injunctions. In August 2024, Judge Robert Pitman of the Western District of Texas blocked the law's "harm prevention" requirements—provisions that would have required DSPs to filter content deemed harmful (promoting suicide, self-harm, eating disorders, and other categories the court found "unconstitutionally vague").
In February 2025, the same court issued a second injunction blocking three additional provisions: two restricting targeted advertising to minors and one requiring age verification. The court found these sections "unconstitutionally vague" as well. The Texas Attorney General has appealed to the Fifth Circuit.
Despite these blocks, the Texas AG has already used the law to sue TikTok (in October 2024) for allegedly failing to protect minors' data and allowing minors to bypass restrictions—a signal that enforcement is active even as the legal landscape shifts.
Penalties
The Texas Attorney General can seek civil penalties of up to $10,000 per violation. There is no private right of action, and the statute expressly forbids class action certification.
Utah's Social Media Regulation Laws
What Happened
Utah's original Social Media Regulation Act (S.B. 152 and H.B. 311) was signed into law in March 2023. It would have required age verification for all users, parental consent for minors' accounts, a 10:30 p.m. to 6:30 a.m. curfew on minor access without parental consent, and restrictions on targeted advertising and algorithmic recommendations to minors. According to Wikipedia's summary of the law, NetChoice challenged it, and in September 2024, Chief Judge Robert J. Shelby granted a preliminary injunction blocking enforcement.
Utah's legislature responded by repealing the original law and passing the Utah Minor Protection in Social Media Act (S.B. 194 and H.B. 464), signed by Governor Cox in March 2024. According to the Tech Policy Press tracker, this replacement law shifted from "age verification" to "age assurance" methods, required privacy settings to be set to maximum by default for minors, restricted minor accounts' visibility, and offered supervisory tools for parents. H.B. 464 created a private right of action allowing parents to sue platforms for mental health harms caused by algorithmic curation, with damages of at least $10,000 per adverse outcome.
However, on September 10, 2024, Judge Shelby again granted a preliminary injunction against the replacement law. The state appealed to the Tenth Circuit, and as of early 2026, the appeal is pending.
What Founders Should Know
Utah's law is currently enjoined, meaning no provisions are enforceable while the appeal is pending. But the legal trajectory is instructive: Utah lawmakers have shown they will iterate and replace legislation to address constitutional concerns, and the Tenth Circuit's eventual ruling could reactivate enforcement. If you operate a social media platform or consumer app with significant Utah users, you should be tracking this case closely and building compliance-ready product features now rather than waiting for the injunction to lift.
How These Laws Differ from COPPA
The critical distinction is scope and depth. COPPA regulates data collection from children under 13 with actual knowledge. The state laws we've described reach users up to 18, regulate product design and default settings, and in some cases create private rights of action. Here's a quick comparison:
| Obligation | COPPA | CA AADC (enforceable provisions) | TX SCOPE Act (enforceable provisions) | UT (enjoined, pending appeal) |
|---|---|---|---|---|
| Age threshold | Under 13 | Under 18 | Under 18 | Under 18 |
| Age assessment | Actual knowledge | Age estimation or universal child-level protections | Age registration (verification provision blocked) | Age assurance (enjoined) |
| Default privacy settings | Not required | Highest level by default | Not specifically required | Maximum by default (enjoined) |
| Data minimization | Limited to what's necessary | Data use restrictions (enjoined) | Collection limits and geolocation ban in effect | Activity-based data collection ban (enjoined) |
| Design-code obligations | None | Clear terms, monitoring signals, enforce published policies | Algorithm disclosures, parental tools | Remove addictive features, chronological content (enjoined) |
| Enforcement | FTC | California AG ($2,500–$7,500 per child) | Texas AG ($10,000 per violation) | Utah AG + private right of action (enjoined) |
Actionable Next Steps for Consumer App Founders
If your app, platform, or service could be accessed by users under 18—and most consumer apps can—you should take these steps now:
- Conduct a coverage assessment. Determine whether your service is "likely to be accessed by children" under the California standard. Look at your user demographics, advertising, design elements, and whether similar services are commonly used by minors. Document your analysis.
- Implement age estimation or universal protections. Under the CAADCA, you can either estimate user age with reasonable certainty or apply child-level privacy protections to all users. If your user base skews young, the universal-protection approach may be simpler and lower-risk.
- Audit your default settings. Privacy defaults should be set to the highest level for users identified as minors. If you operate a social or interactive platform subject to Texas SCOPE, ensure age registration is functional and cannot be bypassed.
- Build parental tools now. Both California and Texas require features that let parents monitor, control, and delete their children's data. Design these as first-class product features, not afterthoughts. Under Texas law, you must also disclose algorithmic content ranking in your terms of service.
- Stop collecting precise geolocation from minors. Texas SCOPE prohibits it outright. California's (currently enjoined) data restrictions would limit it. Build location features with granular age-based controls.
- Review your advertising practices. Texas's targeted advertising restrictions are currently enjoined, but California's broader coverage definition is in effect. If your ads target minors, document your compliance rationale and be prepared for enforcement to shift.
- Monitor the litigation pipeline. The California case is back at the district court on remand. The Texas case is at the Fifth Circuit. The Utah case is at the Tenth Circuit. Set up alerts for these dockets—enforcement can change quickly when injunctions are lifted or narrowed.
- Get a state-by-state compliance map. These three states are the leading edge, but others—including Arkansas, Mississippi, Ohio, and Nevada—are actively pursuing similar legislation. A compliance map that tracks which laws are in effect, which are enjoined, and which are pending will help you prioritize engineering and legal resources.
State children's online safety law compliance is not a one-time checkbox. It's an ongoing product engineering and legal discipline that requires monitoring a shifting enforcement landscape, building age-aware features, and being ready to pivot when courts act. The founders who treat this as a core compliance function—not a COPPA afterthought—will be the ones who avoid enforcement actions and build trust with the families who use their products.
Building a consumer app that minors might access? We help founders navigate the state-by-state children's online safety law patchwork—coverage assessments, age-assessment strategy, default settings, and compliance roadmaps.