The CAADCA is US privacy law’s most consequential stalled statute: a British import that would have rewritten product design for every service teenagers touch, frozen by the First Amendment before its first enforcement day. Its afterlife matters more than its text, courts are drawing the constitutional boundary for a dozen copycat laws, and the design norms it codified keep spreading through the UK’s enforced original and narrower US successors.
| Law | CAADCA (AB 2273, 2022) |
|---|---|
| Status | Enjoined (NetChoice v. Bonta); appeals ongoing |
| Would-be penalty | $2,500-$7,500 per affected child |
| Enforcer (if revived) | California AG |
| Model | UK Age Appropriate Design Code (ICO) |
What to build regardless of the injunction
Age-aware defaults. High-privacy settings for minors by default: no behavioral ads, no precise geolocation, restricted visibility, no data-maximizing nudges. The ICO enforces exactly this against services reaching UK children, and COPPA requires parental consent below 13 in the US with the FTC’s largest privacy penalties behind it.
Age assurance with judgment. The CAADCA’s dilemma, verify age or over-protect everyone, remains real under other laws. Risk-proportionate estimation (self-declaration plus signals for low-risk services, stronger assurance for high-risk features) is the emerging standard; document why your method fits your risk. See age-gating approaches.
A children’s DPIA. Even with California’s version enjoined, the same artifact is mandatory under the UK Code and prudent under COPPA and the state children’s laws: what data, what risks to minors, what mitigations, reviewed when features change.
No dark patterns for minors. Consent flows, streak mechanics, and settings friction aimed at teenagers draw scrutiny under the FTC Act and state UDAP laws independent of the CAADCA, the legal theories survive even where the design code does not.
Watching the law settle
Three tracks to monitor: the NetChoice appellate timeline (whether any CAADCA core survives), Maryland-model statutes (data-practices-only design codes now in force), and the CCPA’s own minor provisions (under-16 opt-in for sale/sharing remains fully enforceable, as do the CPPA’s minors-related priorities). Build once to the strictest enforceable standard, the UK Code, and US compliance becomes configuration.
Check what your service actually collects from young users, and which third parties receive it, with a free scan.