US Federal Law United States

COPPA vs State Minors' Privacy Laws: Mapping the Overlap

How COPPA interacts with state children's and teens' privacy laws: preemption limits, age-appropriate design codes, social media age laws, and building one program for all of them.

Regulation

COPPA (15 USC 6501-6506) with limited preemption; state regimes including California AADC and SB 976, Texas SCOPE Act and HB 18, Florida HB 3, Utah minors' acts, Maryland Kids Code, plus teen provisions in comprehensive state privacy laws

Max Penalty

COPPA penalties per violation per child; state laws add their own, e.g. civil penalties per affected minor, with several regimes enjoined in whole or part pending First Amendment litigation

Enforcing Authority

FTC (COPPA); state attorneys general and state privacy agencies (state laws)

Official Source

www.ftc.gov

Executive Summary

  • COPPA preempts only inconsistent state law; states may regulate above the federal floor and outside COPPA's scope, and they have: design codes, teen data rules, social-media age verification, and addictive-feed restrictions.
  • COPPA stops at 13; the state wave regulates minors to 18, with knowledge standards broader than COPPA's actual-knowledge test, so COPPA compliance alone no longer covers the minors' privacy problem.
  • California's Age-Appropriate Design Code and several social-media laws (Texas HB 18, Florida HB 3, Utah, Arkansas) face First Amendment challenges, with injunctions in various postures, obligations differ by state and by month.
  • Comprehensive state privacy laws add teen-specific consent rules: most prohibit targeted advertising and sale for known 13-to-15-year-olds without opt-in consent.
  • The workable strategy is one minors' program built to the strictest common denominator: age assurance proportionate to risk, no targeted ads to known minors, high-privacy defaults, and documented impact assessments.

COPPA drew its line at 13 in 1998, and for a quarter century American law had almost nothing to say about the online lives of everyone between 13 and 18. The states noticed. The result is a layered, litigious map: stable teen ad-consent rules inside comprehensive privacy laws, ambitious design codes borrowing from the UK, and social-media age laws colliding with the First Amendment in real time. Preemption will not save anyone, COPPA blocks only inconsistent under-13 regulation, and the strategic error is building fifty compliance postures for fifty statutes when one strict program, no targeted ads to known minors, high-privacy defaults, proportionate age assurance, documented assessments, satisfies nearly all of them at once and survives whichever injunctions lift.

COPPA scopeUnder 13, actual knowledge or child-directed
PreemptionInconsistent state law only; teens and design untouched
Stable state tierTeen opt-ins for ads/sale (CCPA under-16 and analogs)
Contested tierDesign codes, social-media age laws (NetChoice litigation)
StrategyOne strictest-common-denominator minors’ program

Building the unified minors’ program

Anchor on the stable rules. COPPA’s 2025 requirements plus teen ad-consent provisions in CCPA and its analogs are enforceable today; build there first.

Design age assurance once. Proportionate, privacy-preserving screening that serves every regime is the hard engineering problem; the age-gating guide covers the methods and their failure modes.

Write the impact assessment. AADC-style documented assessments are the artifact design codes converge on, and they double as litigation-readiness evidence; safe harbor programs can audit the under-13 slice.

Track the dockets, not the headlines. Injunction postures shift quarterly; assign an owner and re-map obligations per state each quarter, including school contexts under FERPA/CIPA.

Minors’ compliance starts with knowing what your pages collect before any age gate appears: check with a free scan.

Frequently Asked Questions

Does COPPA preempt state children's privacy laws?

Only narrowly. 15 USC 6502(d) preempts state law 'inconsistent with' COPPA's treatment of the activities it covers, meaning states cannot relax COPPA or contradict its scheme for under-13 online data collection. States remain free to regulate what COPPA does not touch: teens 13 to 17, offline data, platform design duties, addictive features, and age verification for account access. Courts examining the design codes have generally analyzed them under the First Amendment rather than COPPA preemption, and where preemption arguments have been raised (NetChoice litigation against various state acts) they have not broadly nullified state minors' regimes. Planning assumption: preemption defends you against a state trying to re-run COPPA differently for under-13 collection, and against nothing else.

What are the main categories of state minors' laws?

Four families. Design codes: California's AADC (impact assessments, high-privacy defaults, no dark patterns for under-18s, enforcement enjoined in significant part through NetChoice litigation) and Maryland's Kids Code (similar duties, drafted to dodge California's constitutional problems). Social-media minor-access laws: Utah, Arkansas, Texas HB 18, Florida HB 3, requiring parental consent or banning under-14 accounts, most tangled in injunctions. Addictive-design laws: California SB 976 and New York's SAFE for Kids Act, restricting algorithmic feeds and night-time notifications to minors without parental consent. Teen data provisions inside comprehensive privacy laws: CCPA's opt-in for sale/sharing for consumers known to be under 16; Connecticut, Colorado, and most newer state laws banning targeted advertising and sale for known under-16s or under-18s. The first three families are litigation-volatile; the fourth is stable and enforceable now.

How do the age and knowledge standards differ?

COPPA: under 13, triggered by child-directed content or actual knowledge. CCPA: under-16 opt-in for sale/sharing, with 'willful disregard' of age counting as knowledge, broader than COPPA's actual-knowledge test. Connecticut and several newer laws: obligations for consumers a controller 'knows or wilfully disregards' are minors, with targeted-ad and sale bans to 18 in some. Design codes: under 18, keyed to services 'likely to be accessed' by minors, an audience-probability test far wider than child-directed. Social-media laws: various cutoffs (14 in Florida, 16, 18) with verification duties. The compounding effect: a general-audience service that could ignore teens under COPPA may owe them opt-ins under state privacy laws and design duties under design codes, and 'we did not know ages' fails wherever wilful disregard or likely-access standards govern.

What is actually enforceable today given the injunctions?

Treat three tiers differently. Stable and enforced: COPPA (especially post-2025 amendments); teen targeted-ad and sale restrictions in comprehensive state privacy laws (CCPA under-16 opt-in and its analogs), enforced by state AGs and the CPPA through ordinary privacy enforcement. Partially operative: design-code duties, California's AADC injunction (affirmed in relevant part by the Ninth Circuit as to impact-assessment provisions) left pieces contested while Maryland's code proceeds; New York's SAFE Act and California SB 976 have survived early challenges in whole or part. Enjoined or unsettled: several social-media age-verification and parental-consent statutes (Arkansas, Utah's original act, portions of Texas and Florida laws) pending NetChoice/CCIA litigation, with the Supreme Court's 2025 decision in Free Speech Coalition v. Paxton (upholding Texas's adult-content age verification) recalibrating the doctrine. Compliance posture: build to the stable tier now, design for the contested tier, and track the dockets quarterly rather than assuming any injunction is permanent.

How do we build one program covering all of it?

Six elements to the strictest common denominator. Age assurance proportionate to risk: neutral age screens at minimum, stronger assurance where content or state law demands it (the age-gating tradeoffs are their own discipline). Segmented treatment: under-13 users get full COPPA handling (verifiable parental consent, 2025 unbundled ad-consent); known 13-to-17s get no targeted advertising, no sale, no profiling defaults, satisfying CCPA, Connecticut, and design codes at once. High-privacy defaults for minors: geolocation off, private accounts, no message solicitation from unknown adults. Design review: dark-pattern audit and, for services likely accessed by minors, a documented impact assessment, the AADC-style artifact several states now expect. Retention discipline per the 2025 COPPA amendments. Governance: a single minors' data policy owner tracking litigation shifts. The unified build costs less than fifty state-specific ones and reads as good faith to every regulator watching.

Regulatory Crosswalk

UK Age Appropriate Design CodeEU DSA minors provisionsCOPPA safe harbor programs

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.