
Rules
California Age-Appropriate Design Code vs COPPA for Social Apps
California Age Appropriate Design Code rules meet COPPA in this side-by-side look at who is covered, what each law demands, and where compliance overlaps.
What to take away
- The California Age Appropriate Design Code (AADC, AB 2273) covers services likely to be accessed by users under 18, while COPPA covers services directed to children under 13.
- COPPA is enforced by the Federal Trade Commission and state attorneys general; the AADC is enforced by the California Attorney General.
- COPPA requires verifiable parental consent before collecting personal information from a child under 13. The AADC requires a data protection impact assessment for each feature likely to be accessed by minors.
- A single privacy program can satisfy both laws if you map age ranges, default settings and data retention to the stricter rule in each case.
- Neither law tells you how to verify age without collecting more data than the law allows, which is the shared problem both leave open.
What the two laws actually cover
COPPA, passed in 1998, applies to operators of commercial websites and online services directed to children under 13, and to operators with actual knowledge they are collecting data from that group. The FTC's Children's Online Privacy Protection Rule sets out notice, consent and deletion duties.
AB 2273 was signed in 2022 and applies to businesses that provide an online service, product or feature likely to be accessed by children. California defines a child as a user under 18, which is a wider net than COPPA. The full text sits on the California legislative information site.
One practical difference follows from that age line. A social app aimed at teens aged 13 to 17 falls outside COPPA's consent trigger but inside the AADC's design duties. Teams that treat the two as the same rule usually miss the older group.
The criteria that matter
| Criterion | COPPA | California AADC |
|---|---|---|
| Age covered | Under 13 | Under 18 |
| Trigger | Directed to children or actual knowledge | Likely to be accessed by children |
| Core duty | Notice and verifiable parental consent | Data protection impact assessment before launch |
| Defaults | Limited collection from children | High privacy by default for minors |
| Enforcement | FTC and state AGs | California Attorney General |
| Penalty shape | Civil penalties per violation | Civil penalties per affected child |
Option by option
COPPA first
A developer building a game or learning app for elementary school users should start with COPPA. The consent machinery is the hard part, and the FTC has a long record of consent orders that show what adequate notice looks like. If your audience is under 13, the federal rule sets the floor.
For a longer view of how federal privacy enforcement has shifted over time, see our account of Facebook FTC settlement history in USD, which tracks how penalties grew across cases.
AADC first
A social app with a teen user base should start with the AADC. The impact assessment is a written document, filed internally, that names each risk to minors and the measure taken against it. Defaults must be set high for minors, and nudges that encourage extended use need justification.
Age assurance is the expensive item. The law asks for a reasonable estimate of age, not a document check on every user, and that wording leaves room for estimates drawn from account signals.
Both at once
Most US social products end up in both regimes. The efficient path is one assessment template with two columns, one for under 13 and one for 13 to 17. Consent records cover the younger column; design decisions cover both.
A checklist for the shared template:
- Map every feature that collects personal information and note the youngest likely user.
- Write the retention period for each data type and the deletion trigger.
- Record the default privacy setting for each age band before launch.
- Keep the impact assessment and consent log in one auditable folder.
Where each one wins
COPPA wins on clarity of process. The consent standard, the notice content and the deletion duty are all spelled out, and the FTC publishes business guidance that answers common questions. A small team can follow it without counsel on retainer.
For background on how the federal statute reads, the Children's Online Privacy Protection Act text in the US Code is short and worth reading in full.
The AADC wins on coverage of design choices. It reaches recommendation feeds, notification timing and default visibility, which COPPA largely leaves alone. That is where most teen harm claims now land, so the California rule is the more demanding of the two for a social product.
What none of them solve
Both laws assume a service can tell a child from an adult. Neither specifies an age verification method that works at scale without collecting more personal data, which then creates its own risk. That gap is the same one that shows up in internet communities comparison in plain terms, where different platforms reach different answers on the same question.
Neither law sets a federal standard for teen accounts. A developer serving users in fifty states still watches for new state codes that copy the California model, and each one adds its own filing duty.
Common questions
Does COPPA compliance mean AADC compliance? No. COPPA stops at age 13 and focuses on consent. The AADC reaches 17 and focuses on design. A compliant consent flow can still sit inside a product with defaults the California rule would question.
Who enforces the California AADC? The California Attorney General, through civil penalties. The FTC enforces COPPA separately, and state attorneys general can also bring COPPA actions.
What counts as likely to be accessed by children? California looks at whether the service is directed to children, plus evidence such as user base, marketing and design. A general audience app with a large teen share can fall inside the definition.
Can one impact assessment cover both laws? Often yes, if it records consent for under 13 users and design decisions for all minors. Keep the two columns separate so an auditor can trace each duty to its source.







