Children’s privacy law in the US is now a three-layer stack: COPPA for under-13 (federal, stable, newly amended), teen provisions in the comprehensive state laws (spreading, ratcheting toward 18), and design codes plus social-media laws (ambitious, litigated, partially surviving). The litigation noise obscures the signal: every layer converges on the same operational rule, know your minor audience, and stop monetizing it through targeted advertising and profiling.
The operational stack
Layer 1: COPPA under 13. Verifiable parental consent, the 2025 amendments’ unbundled ad-disclosure opt-in, retention limits, and security programs, covered in the COPPA guide. This layer preempts and anchors everything.
Layer 2: teen provisions, 13-17. Consent gates for targeted advertising, sale, and profiling at rising ages: Connecticut’s model, New Jersey to 16, Delaware to 18, Maryland’s outright ban, Montana’s 2025 adoption. The engineering answer is one flag: under-18 users exit the ad-monetization path.
Layer 3: design codes and access laws. Where surviving (Maryland’s code, portions of the social-media laws), they add DPIAs, high-privacy defaults, and feature restrictions; Florida’s FDBR adds penalty trebling. Track the dockets, but build to the floor that survives regardless.
Cross-cutting duties. Known-child data is sensitive data in every comprehensive law (consent rules); minors’ processing triggers assessments; and age-verification vendors introduce their own biometric exposure when face-estimation is used.
Ad pixels and trackers running on minor-likely surfaces are the most common violation and the most visible: check yours with a free scan.