There is no single compliance model for handling minors’ data, but companies can take several steps now to mitigate the risks, attorneys Greg Szewczyk and Madison Etherington of Ballard Spahr explain. For years, many companies treated youth privacy on their apps as a narrow compliance question: Is the app directed to users under 13 years old, or does the company have actual knowledge a user is younger than 13? This seemingly straightforward approach is rapidly becoming obsolete as a confluence of federal regulations, state-level legislation, and app store policies creates a far more intricate and demanding environment for businesses handling the personal information of young individuals.

The federal Children’s Online Privacy Protection Act (COPPA) has long served as the bedrock of children’s online privacy. Enacted in 1998 and taking effect in 2000, COPPA has governed how websites and online services that are directed to children under 13, or that have actual knowledge of collecting personal information from children under 13, must obtain verifiable parental consent before collecting, using, or disclosing such data. The Federal Trade Commission (FTC) is the primary enforcer of COPPA. While the core tenets of COPPA remain, the regulatory landscape has significantly evolved, necessitating a more proactive and comprehensive approach from businesses.

A Shifting Federal Framework: COPPA’s Evolution

COPPA’s influence, while foundational, is no longer the sole determinant of compliance. The FTC has actively updated its regulations to address emerging technologies and evolving data practices. A pivotal development occurred in 2025 when the FTC finalized significant amendments to the COPPA Rule. These changes introduced new requirements, notably mandating separate parental opt-in consent before certain disclosures of youths’ personal information to third parties, particularly for the purpose of targeted advertising. This amendment underscores a growing concern among regulators about the monetization of children’s data and the potential for its misuse.

In general, businesses are advised to continue treating COPPA as a minimum standard for compliance. This means clearly disclosing that products or services are not directed at children and, importantly, refraining from collecting information from children without first securing verifiable parental consent. In instances where a company becomes aware of the inadvertent collection of children’s information, immediate remediation is crucial. This typically involves promptly deleting the collected data and ceasing all related processing activities to prevent further non-compliance. The FTC has consistently signaled its intent to vigorously enforce COPPA, with enforcement actions often resulting in substantial fines and reputational damage for non-compliant entities. For example, in recent years, the FTC has brought numerous cases against companies for COPPA violations, highlighting the agency’s commitment to protecting children’s online privacy.

The Rise of State-Level Regulations: Teen Data Takes Center Stage

While COPPA has historically focused on children under 13, a significant and accelerating trend is the emergence of state-level privacy laws that specifically address the data of teenagers, generally defined as individuals between the ages of 13 and 18. This growing body of legislation signifies a recognition that older minors, while potentially more digitally savvy, still require enhanced protections regarding their personal information. These state laws are not merely an extension of COPPA; they often introduce distinct requirements, consent mechanisms, and restrictions that businesses must navigate.

The implications of this bifurcated regulatory approach are profound. Companies are now confronted with highly granular questions regarding their data handling practices. For instance, when does it become mandatory or advisable to disable targeted advertising for users within a certain age bracket? What limitations should be placed on third-party data sharing for this demographic? Should social features be restricted? In some cases, creating dedicated, simplified interfaces specifically designed for minors might emerge as the most straightforward and legally compliant path forward. This nuanced approach acknowledges that a one-size-fits-all strategy is no longer tenable.

The legislative momentum at the state level is considerable. States like California, with its California Age-Appropriate Design Code Act (CA AD Act), have taken a proactive stance. While the CA AD Act is still subject to ongoing legal challenges and implementation details are being refined, its intent is to impose a higher standard of care on businesses that provide online services likely to be accessed by children. This includes requirements for conducting data protection impact assessments and designing services with the best interests of children in mind. Other states are also exploring or enacting similar legislation, creating a complex patchwork of rules that vary in scope and stringency.

International Perspectives: Canada’s Evolving Stance

Beyond the United States, other jurisdictions are also actively developing their frameworks for protecting minors’ data. In Canada, for example, the Office of the Privacy Commissioner of Canada (OPC) released updated guidance in May 2026 concerning age assurance. This guidance emphasizes the importance of organizations assessing the necessity of age verification measures, employing methods that are proportionate to the identified risks, and seriously considering alternatives such as limiting certain data practices or opting for default privacy-protective settings.

Canada’s primary federal privacy legislation, the Personal Information Protection and Electronic Documents Act (PIPEDA), mandates meaningful consent before organizations can collect, use, or disclose an individual’s personal information. The OPC’s guidance clarifies that while parental or guardian permission is typically required for individuals under 13, the maturity level of older minors becomes a more significant factor than a simple age cutoff. This approach acknowledges the varying capacities of individuals within the adolescent age range. Quebec, a province with its own distinct privacy legislation, goes even further. Under Quebec’s privacy law, businesses are generally barred from collecting personal information directly from minors under 14 years old without the permission of a parent or tutor, unless the collection is demonstrably for the minor’s benefit. This highlights a trend towards stricter consent requirements for younger individuals, even within the broader definition of "minor."

The overarching lesson from these international developments is that companies cannot assume a single national policy will adequately address every regional age threshold, consent standard, or advertising restriction. Each jurisdiction’s specific definitions, age limits, consent requirements, and limitations on marketing, profiling, and data transfers deserve careful and individual review.

App-Store Accountability: A New Layer of Responsibility

Adding another significant layer to the compliance puzzle are app-store accountability measures. These regulations are shifting some of the responsibility for age verification and parental consent away from app developers and towards the app stores themselves and operating-system providers. This shared responsibility model aims to create a more robust ecosystem for protecting minors online.

The implementation of these laws is likely to result in a complex and potentially confusing "patchwork" of requirements. Some laws may place the primary obligations for age verification and parental consent squarely on app stores, while simultaneously requiring developers to provide accurate age ratings and relevant notifications. Other legislative approaches may be more directly focused on app developers, imposing direct compliance duties. Further complicating matters, ongoing legal challenges are expected to impact the precise timing and scope of these emerging laws.

A concrete example of this evolving regulatory landscape can be seen in Texas’s S.B. 2420. Following a legal battle that saw a preliminary injunction against the law being stayed by the Fifth Circuit, this legislation has come into effect. S.B. 2420 mandates that covered app stores verify users’ age categories, link minor accounts with parent accounts, and secure parental consent under specific circumstances. Crucially, app stores are required to make this age-category and consent information accessible to app developers. In turn, developers must assign appropriate age ratings to their applications, promptly respond to significant changes in age-related information, and ensure their data handling practices are consistent with the law’s restrictions. This interwoven structure demonstrates the collaborative, yet complex, approach being adopted.

The intricate relationship between app stores and developers means that even with app-store-level compliance, developers may still face additional, platform-specific requirements imposed by the app stores themselves. Navigating these dual layers of regulation necessitates careful attention to both legislative mandates and the terms of service and technical requirements of major app distribution platforms.

Mitigating Risk: A Proactive Compliance Strategy

In light of this evolving regulatory environment, companies handling minors’ data must adopt a proactive and comprehensive risk mitigation strategy. This process begins with a thorough internal assessment to determine if the company is collecting any data that falls within the scope of any of these emerging laws. This inquiry may extend beyond simply identifying age data; it requires a deep understanding of the types of information collected and how it is used.

Following the identification of relevant data, companies must assess the value of that data, the specific compliance obligations that may be triggered, and the operational changes necessary to achieve compliance. This includes a critical review of vendor contracts, particularly those involving third-party analytics tools and advertising technologies. It is imperative to ensure that minors’ information is not transmitted or processed in ways that conflict with the company’s internal policies or applicable laws. Such a review might necessitate renegotiating terms, implementing new data handling protocols, or even discontinuing the use of certain technologies if they pose an unacceptable compliance risk.

The complexity of these issues underscores the need for ongoing legal counsel and a commitment to staying abreast of regulatory developments. The landscape of minors’ data privacy is not static; it is a dynamic and continuously evolving field. Businesses that fail to adapt and implement robust compliance programs do so at their own peril, facing significant financial penalties, reputational damage, and the potential for loss of user trust. The future of digital engagement with young people hinges on a commitment to responsible data stewardship and a proactive approach to navigating these increasingly intricate legal requirements.

Ballard Spahr summer associate T’Phani Perley-Schiele contributed to this report.

By