How does COPPA actually work, and what changed in the 2025 amendments?
COPPA (15 U.S.C. 6501-6506 and the FTC's rule at 16 CFR Part 312) applies to operators of websites and online services directed to children under 13, and to any operator with actual knowledge it is collecting personal information from under-13 users, with 'directed to children' judged on subject matter, visuals, music, child celebrities, ads, and audience evidence, and the YouTube settlement (2019, $170 million with the NY AG) establishing that a general-audience platform has actual knowledge of child-directed channels when their content and metadata say so. The core mechanics: direct notice to parents and verifiable parental consent (VPC) before collecting personal information (which includes persistent identifiers, so behavioral advertising to children without VPC is a violation on identifiers alone, the theory of the YouTube and Musical.ly cases); approved VPC methods include signed consent forms, payment-card verification, government-ID matching, knowledge-based authentication, face-match-to-ID, and the support-for-internal-operations exception permits contextual functions (frequency capping, security) without consent; parents get review and deletion rights; data minimization and retention limits apply; and safe-harbor programs offer self-regulatory cover. The 2025 amendments, the first major update since 2013 (effective June 2025, compliance phased): separate VPC required for disclosing children's data to third parties, including for targeted advertising, an opt-in gate on the adtech flow itself; written information-security programs mandated; retention limited to purpose-necessary duration with a published policy and no indefinite holding; the personal-information definition extended to biometric identifiers; and safe-harbor programs face stronger transparency duties. The penalty math: civil penalties adjusted to $53,088 per violation, and 'per violation' counts per child, which is how Epic Games' Fortnite matter reached $275 million in COPPA penalties inside its $520 million total (2022) and why the per-violation exposure is functionally uncapped at scale.
What do the GDPR and its family require for children?
Four features distributed through the regulation rather than one chapter. The consent age (Article 8): where information-society services rely on consent, a child below the member-state threshold cannot give it alone, parental authorization is required, and the threshold varies by state within the 13-16 band Article 8 permits (16 in Germany and the Netherlands, 15 in France, 13 in the UK before and after Brexit, Ireland at 16), so a pan-EU consumer service runs a per-country age table, and 'reasonable efforts' to verify parental authority scale with risk. Enhanced protection doctrine: recital 38's premise that children merit specific protection flows into the legitimate-interests balancing (children's interests weigh heavier, making LI harder to sustain for minors' profiling), transparency (child-comprehensible notices where children are the audience), and the DPIA triggers (children's data is a WP248 criterion making assessments quasi-mandatory). The enforcement record, which made children's defaults the most expensive UX decisions in Europe: the Irish DPC's Instagram decision (September 2022, 405 million EUR) over business accounts publishing minors' contact details and public-by-default settings for child users, and its TikTok decision (September 2023, 345 million EUR) over public-by-default child accounts, the family-pairing weakness, and dark patterns steering children toward public settings, both decisions turning on Article 25 defaults rather than consent paperwork, the doctrinal point being that design is where children's compliance lives. The family resemblances: LGPD Article 14 requires processing in the child's best interest with parental consent for under-12s' data (the ANPD's guidance framing best-interest analysis for adolescents); PIPL classifies all personal information of children under 14 as sensitive, importing separate-consent, necessity, and dedicated-rules duties, with the minor-mode conventions Chinese platforms run reflecting CAC pressure; Quebec's Law 25 requires consent from a parental authority holder for under-14s; and the DSA layers on: platforms accessible to minors must ensure a high level of privacy, safety, and security, and Article 28 bans ads targeted at minors based on profiling, an EU-wide adtech line independent of consent.
What did the age-appropriate design codes change, and where does the California version stand?
The UK Children's Code (the ICO's Age Appropriate Design Code, in force with enforcement from September 2021, a statutory code under the Data Protection Act 2018): applies to information-society services likely to be accessed by under-18s, a deliberately broad net catching mainstream platforms, not just children's apps, and sets fifteen standards including the best interests of the child as a primary consideration; high-privacy settings by default; geolocation off by default with visible indicators; profiling off by default; no nudge techniques steering children toward weaker privacy; data minimization; age-appropriate transparency; and detrimental-use prohibitions; its regulatory theory is that consent architecture fails children, so the duty shifts to the service's design, and its practical effect was visible within months, platforms turned off targeted ads for teens, defaulted minors' accounts private, and disabled location features, changes rolled out globally because per-jurisdiction UX forking costs more than compliance. The California AADC (AB 2273, 2022), closely modeled on the UK code with DPIA obligations and enforcement by the AG, has been the test case for whether design codes survive US speech doctrine: NetChoice's First Amendment challenge produced a preliminary injunction (2023), a Ninth Circuit ruling (August 2024) affirming the injunction against the DPIA-and-mitigation provisions as likely compelled speech while vacating and remanding on the remainder, and continued district-court proceedings enjoining enforcement, so the statute stands mostly inoperative while the litigation runs, but its progeny multiplied: Maryland's Kids Code (effective October 2024) enacted a design-duty regime drafted around the litigation, Vermont and Nebraska followed in 2025, and Connecticut's CTDPA amendments added minors' design duties, alongside the separate wave of social-media minor laws (parental-consent-for-accounts statutes in Utah, Texas, Florida, and others, themselves under constitutional challenge with the Supreme Court's 2025 free-speech jurisprudence reshaping the field). The composite planning reality: design-code duties (defaults, no profiling of minors, age assurance) are the direction of travel on both continents, whatever any single statute's litigation fate, and the engineering investments they demand overlap heavily with the GDPR-enforcement lessons above.
How should services handle age assurance without over-collecting?
The regulatory ask has sharpened into a paradox: know which users are children (to apply protections) without identifying everyone (which minimization forbids), and the emerging doctrine resolves it through proportionality and layering. The method spectrum: self-declaration (age gates), trivially circumvented and adequate only for low-risk contexts, though even regulators accept it as a first layer where stakes are low; age estimation, facial-age analysis (with the FTC approving a facial-estimation VPC mechanism in 2024-2025 rulemaking contexts), behavioral and account-signal inference, and email/phone-based heuristics, offering privacy-preserving approximation with error bands that must be honestly engineered around (buffer ages, step-up on doubt); age verification, document checks, payment-card methods, credit-bureau matching, mobile-operator confirmation, reserved for high-risk contexts (the UK Online Safety Act's duties for pornography, the social-media minor statutes) because the privacy cost of verifying everyone is itself a harm regulators weigh; and parent-mediated models (family accounts, platform parental controls, the app stores' emerging age-signal APIs) that shift assurance to a device or account layer. The doctrinal anchors: the ICO's Children's Code standard requires age assurance proportionate to the risks of the processing, with its accompanying opinion endorsing layered approaches; the EDPB's 2025 age-assurance statement sets principles (proportionality, minimization, no new tracking built from assurance data, accuracy appropriate to risk); the euCONSENT project and the EU's age-verification blueprint push interoperable, token-based proof-of-age that discloses only the age attribute; and COPPA's actual-knowledge standard means platforms cannot design themselves into ignorance, willful blindness to child-signaling data is the YouTube theory. Engineering disciplines that survive audits: assurance data minimized and purpose-bound (estimate, decide, discard the biometric); the child-flag propagated to every downstream system that varies behavior (ads off, defaults locked, DSAR handling adjusted); error handling that fails protective (uncertain age gets the child experience); and the assurance method itself documented in the DPIA, because 'how do you know who is a child' is now a standard regulator question in every jurisdiction above.
What does a coherent global children's program look like for a mixed-audience service?
Six decisions, made once and enforced in design. Audience determination, honestly: apply the COPPA directed-to-children factors, the Children's Code's likely-to-be-accessed test, and your own analytics to classify each product surface (child-directed, mixed, adult), documenting the analysis, because the classification drives everything and regulators (the FTC on YouTube, the ICO in code audits) treat implausible adult-only claims as the first violation. The age architecture: a jurisdiction table of thresholds (under-13 COPPA, the member-state Article 8 band, under-14 PIPL/Quebec, under-16 and under-18 duties from the design codes and DSA), an assurance method per surface proportionate to its risk, and the child/teen flag as a first-class attribute propagated through ads, defaults, messaging, recommendations, and data retention. Consent plumbing where consent is the mechanism: VPC flows meeting the FTC's approved methods (with the 2025 separate-consent gate for third-party disclosure built in), parental-authorization capture for the GDPR band, and PIPL's separate consent for under-14 data, each producing records. Design duties where design is the mechanism: high-privacy defaults for minors, geolocation and profiling off, no dark patterns in children's flows (the TikTok decision's nudging findings), no profiling-based ads to minors (DSA Article 28 as the bright line, matching the platforms' post-Code practice), and age-appropriate notice surfaces. The adtech kill-switch: child-directed contexts send no behavioral-advertising identifiers at all (contextual only), mixed surfaces gate on the age flag, and the SDK inventory is audited for what child surfaces actually transmit, the recurring FTC and state-AG finding being an SDK the app team forgot. And governance with teeth: children's DPIAs for every relevant launch (quasi-mandatory under GDPR, explicit in the codes and the 2025 COPPA amendments' spirit), retention schedules honoring the new COPPA limits, incident playbooks that treat children's data as high-severity by default, and a standing watch on the moving statutes, the COPPA amendment compliance dates, the state design codes and social-media laws in litigation, the Online Safety Act's phased duties, and the EU's age-verification workstream, because no privacy domain is moving faster.