US State Law California, USA

California Age-Appropriate Design Code: Status and Duties

The CAADCA after NetChoice v. Bonta: what is enjoined, what survives in practice, and how to build age-appropriate design compliance that outlasts the litigation.

Regulation

California Age-Appropriate Design Code Act (AB 2273, 2022), Civ. Code 1798.99.28 et seq.

Max Penalty

Up to $2,500 per affected child (negligent) or $7,500 per affected child (intentional), if enforcement resumes

Enforcing Authority

California Attorney General (enforcement currently enjoined by federal courts)

Official Source

oag.ca.gov

Executive Summary

  • The CAADCA (AB 2273, 2022) imported the UK's Children's Code: businesses providing online services likely to be accessed by under-18s must default to high privacy, assess and mitigate harms, and avoid dark patterns and detrimental profiling.
  • Its enforcement is currently blocked: NetChoice's First Amendment challenge produced a preliminary injunction, the Ninth Circuit affirmed it as to the DPIA provisions in 2024, and the district court enjoined the remainder in 2025; appeals continue.
  • The legal status is therefore: enacted but unenforceable while the injunction stands, with the state defending the act and legislatures elsewhere passing narrower successors.
  • The design expectations survive commercially and globally: the UK Children's Code is enforced by the ICO, COPPA governs under-13 data federally, and Maryland and other states have passed design-code laws drafted to dodge the CAADCA's constitutional defects.
  • Rational strategy: build the age-appropriate design substance (defaults, no minor profiling, DPIAs) to the UK/COPPA baseline, and track the litigation rather than betting against the trend.

The CAADCA is US privacy law’s most consequential stalled statute: a British import that would have rewritten product design for every service teenagers touch, frozen by the First Amendment before its first enforcement day. Its afterlife matters more than its text, courts are drawing the constitutional boundary for a dozen copycat laws, and the design norms it codified keep spreading through the UK’s enforced original and narrower US successors.

LawCAADCA (AB 2273, 2022)
StatusEnjoined (NetChoice v. Bonta); appeals ongoing
Would-be penalty$2,500-$7,500 per affected child
Enforcer (if revived)California AG
ModelUK Age Appropriate Design Code (ICO)

What to build regardless of the injunction

Age-aware defaults. High-privacy settings for minors by default: no behavioral ads, no precise geolocation, restricted visibility, no data-maximizing nudges. The ICO enforces exactly this against services reaching UK children, and COPPA requires parental consent below 13 in the US with the FTC’s largest privacy penalties behind it.

Age assurance with judgment. The CAADCA’s dilemma, verify age or over-protect everyone, remains real under other laws. Risk-proportionate estimation (self-declaration plus signals for low-risk services, stronger assurance for high-risk features) is the emerging standard; document why your method fits your risk. See age-gating approaches.

A children’s DPIA. Even with California’s version enjoined, the same artifact is mandatory under the UK Code and prudent under COPPA and the state children’s laws: what data, what risks to minors, what mitigations, reviewed when features change.

No dark patterns for minors. Consent flows, streak mechanics, and settings friction aimed at teenagers draw scrutiny under the FTC Act and state UDAP laws independent of the CAADCA, the legal theories survive even where the design code does not.

Watching the law settle

Three tracks to monitor: the NetChoice appellate timeline (whether any CAADCA core survives), Maryland-model statutes (data-practices-only design codes now in force), and the CCPA’s own minor provisions (under-16 opt-in for sale/sharing remains fully enforceable, as do the CPPA’s minors-related priorities). Build once to the strictest enforceable standard, the UK Code, and US compliance becomes configuration.

Check what your service actually collects from young users, and which third parties receive it, with a free scan.

Frequently Asked Questions

Is the CAADCA in effect right now?

It is enacted law but under a federal preliminary injunction: the Northern District of California blocked enforcement on First Amendment grounds (NetChoice v. Bonta, 2023), the Ninth Circuit in August 2024 affirmed the injunction as to the DPIA requirements while remanding the rest, and in 2025 the district court again enjoined the remaining provisions. Unless the injunction is lifted on appeal, the AG cannot enforce it. Do not confuse enjoined with repealed: the statute remains on the books.

What would the act require if it survives?

For online services likely to be accessed by children (under 18): data protection impact assessments identifying risks to children before launch; high-privacy default settings; age estimation proportionate to risk or applying child protections to all users; no use of minors' data materially detrimental to them; no profiling by default; no dark patterns steering children to weaken protections; and plain-language policies. Penalties would run per affected child, which scales catastrophically for consumer platforms.

What was the constitutional problem?

The courts held the DPIA provisions compel speech and press editorial judgments: requiring businesses to assess and mitigate exposure to 'harmful or potentially harmful' content regulates protected expression, not just data practices. The Ninth Circuit found those provisions likely unconstitutional and not severable in application. Later state design codes (Maryland's, notably) dropped content-harm assessments and focus on data practices to survive the same challenge.

So can we ignore age-appropriate design?

No, for three reasons: COPPA still federally regulates under-13 collection with real FTC enforcement (Epic Games paid $275M); the UK Children's Code applies to services reaching UK children and drives global product defaults; and the state legislative wave continues with laws engineered around the First Amendment issues. Product decisions outlast injunctions, and firms that built high-privacy defaults for the UK are already most of the way to whatever survives in the US.

What should our compliance posture be while the litigation runs?

Maintain a children's-data DPIA internally (the UK version is enforceable anyway if you have UK users), set under-18 accounts to high-privacy defaults, disable behavioral advertising and precise-location collection for known minors, avoid manipulative consent flows, and document age-assurance reasoning. Track the NetChoice appeals and Maryland-style statutes; our state children's privacy overview maps the live obligations.

Regulatory Crosswalk

UK Children's CodeCOPPAState children's privacy laws

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.