COPPA drew its line at 13 in 1998, and for a quarter century American law had almost nothing to say about the online lives of everyone between 13 and 18. The states noticed. The result is a layered, litigious map: stable teen ad-consent rules inside comprehensive privacy laws, ambitious design codes borrowing from the UK, and social-media age laws colliding with the First Amendment in real time. Preemption will not save anyone, COPPA blocks only inconsistent under-13 regulation, and the strategic error is building fifty compliance postures for fifty statutes when one strict program, no targeted ads to known minors, high-privacy defaults, proportionate age assurance, documented assessments, satisfies nearly all of them at once and survives whichever injunctions lift.
| COPPA scope | Under 13, actual knowledge or child-directed |
|---|---|
| Preemption | Inconsistent state law only; teens and design untouched |
| Stable state tier | Teen opt-ins for ads/sale (CCPA under-16 and analogs) |
| Contested tier | Design codes, social-media age laws (NetChoice litigation) |
| Strategy | One strictest-common-denominator minors’ program |
Building the unified minors’ program
Anchor on the stable rules. COPPA’s 2025 requirements plus teen ad-consent provisions in CCPA and its analogs are enforceable today; build there first.
Design age assurance once. Proportionate, privacy-preserving screening that serves every regime is the hard engineering problem; the age-gating guide covers the methods and their failure modes.
Write the impact assessment. AADC-style documented assessments are the artifact design codes converge on, and they double as litigation-readiness evidence; safe harbor programs can audit the under-13 slice.
Track the dockets, not the headlines. Injunction postures shift quarterly; assign an owner and re-map obligations per state each quarter, including school contexts under FERPA/CIPA.
Minors’ compliance starts with knowing what your pages collect before any age gate appears: check with a free scan.