Rules
How COPPA and California's design code change social apps for US teens
COPPA sets the federal baseline for kids' data, while California's Age-Appropriate Design Code adds design duties that reshape teen social apps across the US.
What to take away
- COPPA is the federal children's privacy rule enforced by the FTC, requiring verifiable parental consent before collecting personal data from children under 13.
- California's Age-Appropriate Design Code requires social apps to default to high privacy settings for minors and to estimate user age, duties that go beyond federal consent rules.
- COPPA forces data minimisation, parental controls and deletion rights; the AADC forces default privacy, age assurance and impact assessments.
- FTC civil penalties for COPPA violations can reach tens of thousands of dollars per violation, with each affected child counted separately.
- Platforms serving US teens must now reconcile a federal consent regime with state design mandates, raising compliance costs and changing product roadmaps.
What COPPA requires of social apps aimed at US teens
The Children's Online Privacy Protection Act, commonly known as COPPA, is the federal law that governs how online services collect and use personal information from children under 13. The FTC enforces the Children's Online Privacy Protection Rule, which sets out what operators of websites and apps must do.
For social apps, COPPA compliance begins with deciding whether the service is directed to children. The full text sits in the Children's Online Privacy Protection Rule.
A social app is considered directed to children if it targets kids under 13 through its content, characters, music, or marketing. Even if a platform says it is for teens and adults, the FTC may still treat it as directed to children if actual users include young kids and the operator has reason to know.
That is why many social apps set a minimum age of 13 in their terms, though the rule does not require a specific age gate.
Once COPPA applies, the operator must provide notice to parents and obtain verifiable parental consent before collecting personal information from a child. Personal information includes names, email addresses, geolocation data, photos, videos, and persistent identifiers like cookies that can recognise a user over time.
For social apps, that covers profile data, friend lists, messages, and even device IDs used for advertising.
COPPA also gives parents the right to review and delete their child's personal information and to refuse further collection. Operators must keep data only as long as necessary and must secure it. These duties apply to third-party services that collect data through a child-directed app, such as ad networks and analytics providers.
The FTC's complying with COPPA FAQ walks through the social media cases.
The rule has been updated over time, most notably in 2013 to cover persistent identifiers and geolocation. The FTC has brought numerous enforcement actions against social platforms and apps that violated COPPA, resulting in settlements and consent orders. Those orders often require the company to change its data practices and to submit to independent audits.
For social apps aimed at US teens, COPPA creates a compliance floor. It does not regulate design features directly, but it does affect how data can be collected from younger users.
That distinction matters when comparing COPPA to California's design code, which focuses on how platforms are built rather than only on consent. How each cohort uses these apps feeds the wider story of generational digital culture.
How the FTC enforces the Children's Online Privacy Protection Rule
The Federal Trade Commission is the primary enforcer of COPPA. It can bring civil actions against companies that violate the rule, and it can seek civil penalties for each violation. The FTC also works with state attorneys general, who can enforce COPPA in federal court.
This shared enforcement means a social app could face action from both federal and state authorities.
Enforcement typically begins with an investigation, often triggered by a complaint, a breach, or a review of a company's practices. The FTC may issue a civil investigative demand for documents and testimony. If it finds a violation, it can negotiate a consent order or file a lawsuit.
Consent orders often require the company to delete illegally collected data, to change its practices, and to obtain parental consent going forward.
The FTC also uses Notices of Penalty Offenses to put companies on notice that certain conduct can lead to civil penalties. These notices are not rules themselves, but they establish that the agency has warned the industry.
If a company engages in conduct covered by a notice after receiving it, the FTC can seek penalties more easily. The Notices of Penalty Offenses page explains how this tool works.
Civil penalties for COPPA violations can be substantial. The FTC adjusts the maximum penalty for inflation each year, and it can count each violation separately. In cases involving millions of users, the total exposure can reach hundreds of millions of dollars. That is why COPPA compliance is a board-level concern for social platforms.
In addition to penalties, the FTC can require companies to implement comprehensive privacy programs and to obtain biennial independent assessments. These orders can last for 20 years. For social apps, that means a single enforcement action can shape product decisions for a generation.
The FTC also engages in rulemaking to update COPPA. The process is governed by the Magnuson-Moss Warranty Act and the FTC Act, and it includes public comment periods. The FTC rulemaking process sets out how the agency proposes and finalises rules.
Any changes to COPPA could expand the definition of personal information or add new requirements for social media operators.
California's Age-Appropriate Design Code and its design duties
California passed the Age-Appropriate Design Code Act in 2022. The law, often abbreviated as AADC, imposes design duties on online platforms that are likely to be accessed by children under 18. It does not use the same under-13 threshold as COPPA. Instead, it covers all minors and focuses on how platforms are designed, not just on data collection.
The AADC requires covered businesses to consider the best interests of children when designing their products. That includes defaulting to high privacy settings for minors, unless the business can demonstrate a compelling reason to do otherwise. It also requires limiting the collection of personal information to what is necessary to provide the service.
The law mandates age assurance or age estimation for certain features. Platforms must estimate the age of child users with a reasonable level of certainty or use age assurance methods.
This is a significant departure from COPPA, which does not require age verification. The AADC's age assurance requirement has been the subject of litigation and debate over privacy and free speech.
The AADC also requires data protection impact assessments for features that are likely to be accessed by children. These assessments must identify risks and mitigation measures. Platforms must document how they comply and make the assessments available to the California Attorney General upon request.
Other design duties include providing clear privacy information, not using dark patterns to encourage children to give up more data than necessary, and not collecting precise geolocation unless necessary. The law also restricts the use of children's data for advertising unless the platform can show it is not harmful.
The AADC is enforced by the California Attorney General, who can seek civil penalties and injunctive relief. The law was originally set to take effect in 2024, but a federal court enjoined parts of it in 2023, and the case is ongoing.
As of 2026, the status of the AADC remains uncertain, but its requirements are already influencing platform design. For a deeper comparison, see our article on the California Age-Appropriate Design Code.
Feature-by-feature comparison: what each rule forces a platform to change
The table below compares the specific feature changes that COPPA and the AADC force social apps to make. It focuses on the practical product decisions that follow from each law.
| Feature area | COPPA requirement | AADC requirement |
|---|---|---|
| Default privacy settings | No explicit default setting rule, but parental consent required before data collection | Must default to high privacy settings for minors unless a compelling reason exists |
| Data minimisation | Must collect only what is reasonably necessary and retain no longer than needed | Must limit collection to what is necessary to provide the service |
| Age assurance | No age verification required, but knowledge of child status triggers compliance | Must estimate age or use age assurance for child users |
| Parental controls | Must provide notice and obtain verifiable parental consent | Must provide clear privacy information and tools for parents |
| Data deletion | Parents can review and delete child's data | Children can request deletion of their data |
| Advertising | Cannot condition participation on collecting more data than necessary | Cannot use children's data for advertising if harmful |
| Impact assessments | Not required | Required for features likely accessed by children |
Under COPPA, a social app that wants to serve users under 13 must build a parental consent flow. That often means email plus a signed form, a credit card check, or a government ID check. The app must also allow parents to review and delete their child's data. These are operational changes that affect onboarding and account management.
Under the AADC, the same app must set privacy defaults to high for all minors. That could mean making profiles private by default, limiting who can message a teen, and turning off location sharing. The app must also conduct impact assessments for features like recommendation algorithms or direct messaging. These are design changes that affect the core user experience.
Both laws push platforms to collect less data. COPPA does this by requiring consent for collection, which makes data collection costly. The AADC does it by directly limiting collection to what is necessary. The result is similar: less data for advertising and personalisation, especially for younger users.
Age assurance is where the two diverge most. COPPA does not require platforms to verify age, but if a platform knows a user is under 13, it must comply. The AADC requires platforms to estimate age or use age assurance.
That means building age estimation technology or integrating third-party services. It also raises privacy concerns, since age assurance can require collecting more data.
For product managers, the feature changes are concrete. COPPA forces a consent gate and parental controls. The AADC forces default privacy, age estimation, and impact assessments. Both force data minimisation and deletion rights. The table above summarises the differences.
Default settings, data minimisation and age assurance under the AADC
The AADC's default privacy requirement is one of its most far-reaching provisions. It says covered businesses must configure default settings to provide a high level of privacy for children, unless the business can demonstrate a compelling reason that a different setting is in the best interests of children.
For social apps, that means private accounts by default for minors, restricted messaging, and limited discoverability.
Data minimisation under the AADC is also strict. Platforms must not collect, sell, share, or retain personal information of children unless it is necessary to provide the service. That limits the use of teen data for targeted advertising and algorithmic recommendations. It also requires platforms to delete data when it is no longer needed.
Age assurance is the AADC's most controversial requirement. The law says platforms must estimate the age of child users with a reasonable level of certainty or use age assurance. That could mean using facial age estimation, ID verification, or other methods.
The California Attorney General has not issued detailed guidance, and the law's enforcement has been delayed by litigation. Still, platforms are preparing for a future where age assurance is mandatory.
The AADC also requires privacy impact assessments. These must be conducted before launching features likely to be accessed by children. The assessments must identify risks and mitigation measures and must be provided to the Attorney General on request. This is a new compliance burden that does not exist under COPPA.
For social apps, the AADC's requirements mean rethinking core features. A default private setting changes how teens discover content and connect with friends. Data minimisation limits the effectiveness of ad targeting. Age assurance adds friction to sign-up. Impact assessments slow down product launches. These are significant changes that go beyond COPPA's consent model.
The AADC's focus on design reflects a broader shift in privacy regulation. Instead of putting the burden on parents to consent, it puts the burden on platforms to design safely. That shift is also visible in other state laws, such as those in New York and Washington.
For a comparison with another jurisdiction, see our article on Quebec privacy law.
Where COPPA and the California code overlap and where they collide
COPPA and the AADC overlap in their goal of protecting children online. Both require data minimisation and give parents or children rights over data. Both impose penalties for violations.
Both apply to social apps that serve minors, though COPPA focuses on under-13s and the AADC covers all under-18s. Both grew out of years of critiques of social media from researchers and parents.
They collide on age thresholds. COPPA applies to children under 13, while the AADC applies to all minors under 18. That means a platform that complies with COPPA for under-13s may still violate the AADC for 13-to-17-year-olds. The AADC's broader scope forces platforms to change design for teens, not just young children.
They also collide on consent versus design. COPPA is built on parental consent. The AADC is built on design duties that do not depend on parental consent. A platform can comply with COPPA by getting consent, but it cannot comply with the AADC without changing its default settings and conducting impact assessments.
The two approaches can conflict, especially when consent is used to justify data collection that the AADC would prohibit.
Age assurance is another point of collision. COPPA does not require age verification, but the AADC does. A platform that implements age assurance to comply with the AADC may collect more data, which could raise COPPA concerns if it collects data from children under 13 without consent. This creates a tension between the two laws.
Enforcement also differs. COPPA is enforced by the FTC and state attorneys general. The AADC is enforced by the California Attorney General. A platform could face simultaneous enforcement actions under both laws for the same conduct. That increases legal risk and compliance costs.
Despite these differences, the two laws can be harmonised. A platform can build a single compliance program that meets both standards by defaulting to high privacy for all minors, minimising data collection, and implementing age assurance carefully. That approach may be more costly up front, but it lowers the risk of enforcement under either regime.
Compliance costs and penalty exposure for US platforms
Compliance with COPPA and the AADC is expensive. Platforms must build consent flows, age assurance systems, impact assessment processes, and data deletion tools. They must also train staff and audit their practices. These costs are especially high for smaller social apps that lack dedicated privacy teams.
Penalty exposure is also significant. Under COPPA, the FTC can seek civil penalties per violation. The maximum penalty is adjusted for inflation and can exceed $50,000 per violation. If a platform violates the rule for millions of children, the total exposure can be enormous.
Notices of penalty offenses make it easier for the agency to seek penalties for conduct it has already flagged.
Under the AADC, the California Attorney General can seek civil penalties of up to $2,500 per affected child for negligent violations and up to $7,500 per affected child for intentional violations. These penalties can add up quickly. The law also allows for injunctive relief, which can force platforms to change their design.
Beyond fines, platforms face reputational damage and loss of user trust. Parents are increasingly aware of privacy issues, and an enforcement action can lead to negative press. That can affect user growth and advertising revenue. For social apps, the cost of non-compliance can be existential.
Compliance costs also include the cost of age assurance. Third-party age verification services charge per verification, which can be expensive at scale. Platforms must also handle the privacy implications of collecting more data for age assurance. That can create a vicious cycle where compliance leads to more data collection, which then requires more compliance.
A practical compliance checklist for a US social app looks like this:
- Confirm whether the app is directed to children under 13
- Map every personal information field collected from minors
- Set default privacy to high for all users under 18
- Document impact assessments before each launch
- Keep records of consent and deletion requests
For US platforms, the combined effect of COPPA and the AADC is a higher bar for serving minors. That bar is likely to rise as more states pass similar laws. New York, Washington, and Texas have all considered or passed children's privacy laws.
Pew Research Center data on age and generations shows how central social platforms remain for US teens.
What the FTC rulemaking process may change next
The FTC has been reviewing the COPPA rule for possible updates. In 2024, the agency sought public comment on a range of issues, including whether to expand the definition of personal information and whether to add new requirements for social media operators. The process is ongoing, and any changes could significantly affect social apps.
The FTC's rulemaking is governed by the Magnuson-Moss Warranty Act, which requires the agency to publish a notice of proposed rulemaking and take public comment. The process can take years, and it is subject to legal challenges. Those filings build a public record, which is its own lesson in archiving internet culture properly.
Potential changes include requiring platforms to obtain parental consent for teens, not just children under 13. That would be a major shift, and it could conflict with the AADC's design approach. Other possible changes include new limits on targeted advertising to children and new data retention requirements.
The FTC could also clarify how COPPA applies to social media operators. The agency's compliance guidance already addresses some social media issues, such as when a platform is directed to children. But that guidance is not binding, and the FTC could codify its positions in a rule.
For platforms, the rulemaking process is a chance to shape the rules. Companies can submit comments and meet with FTC staff. But they also need to prepare for the possibility of stricter rules. That means building flexible compliance systems that can adapt to new requirements.
State laws will also continue to evolve. California's AADC is a model for other states, and more states are likely to pass similar laws. The result is a patchwork of federal and state requirements that platforms must handle.
The FTC's rulemaking could also address the tension between COPPA and state design codes. If the FTC expands COPPA to cover teens, it could preempt some state laws. But that is uncertain, and the outcome will depend on the courts and Congress. For now, platforms must comply with both.
Common questions
What is COPPA? COPPA is the Children's Online Privacy Protection Act, a federal law that requires websites and apps to obtain parental consent before collecting personal information from children under 13. The FTC enforces it through the COPPA Rule.
How does California's Age-Appropriate Design Code differ from COPPA? The AADC applies to all minors under 18 and focuses on design duties like default privacy settings and age assurance. COPPA applies to children under 13 and focuses on parental consent for data collection.
What are the penalties for violating COPPA? The FTC can seek civil penalties per violation, which can exceed $50,000 per violation after inflation adjustments. It can also require companies to change their practices and submit to audits.
Do social apps need to verify user age? COPPA does not require age verification, but if a platform knows a user is under 13, it must comply. The AADC requires age estimation or age assurance for child users.
What feature changes does the AADC force? The AADC forces default high privacy settings for minors, data minimisation, age assurance, impact assessments, and restrictions on advertising to children.
What is the FTC rulemaking process for COPPA? The FTC reviews the COPPA Rule and can propose changes through a public rulemaking process. That process includes public comment and can take years. Any changes could expand the rule's scope to teens.
