Guides
Sacramento and the California Age-Appropriate Design Code, a guide for social apps
California Age-Appropriate Design Code sets design duties for social apps in Sacramento, covering defaults, data minimisation and age assurance.
What to take away
- The California Age-Appropriate Design Code is a state law that forces social apps to treat children's privacy as a design requirement, not a settings toggle.
- Sacramento is where the California legislature writes these rules, and the state attorney general enforces them.
- Design duties include high-privacy defaults, data minimisation, and age assurance or age estimation before a child's data is collected.
- Penalties run per affected child, and federal COPPA still applies on top of state law.
- Social app operators should start with default settings, data mapping, and an age-assurance method that does not over-collect.
How Sacramento writes the rules social apps must follow
Sacramento is the seat of the California legislature, and that is where the state's design code for social apps was drafted and passed. The Capitol building on 10th Street is the room where the text was negotiated, amended and voted on. For compliance leads, the practical point is that California writes platform rules itself, separate from Congress.
The state has a habit of moving first on tech regulation. California privacy law platforms follow often becomes the national baseline, because a social app that operates in the United States almost always has California users. A rule passed in Sacramento therefore lands on product roadmaps in Menlo Park, Seattle, New York and Austin.
The legislature works through committees, and the Age-Appropriate Design Code moved through the standard process: policy committee, fiscal review, floor votes, and the governor's signature. That path matters because it explains why the final text is narrower than early drafts. Amendments removed some broad language and kept specific duties.
Sacramento social media law also interacts with federal rules. The Federal Trade Commission enforces the Children's Online Privacy Protection Rule, and its rulemaking process is where federal design-code fights now play out. The FTC's rulemaking process is worth watching for anyone tracking where federal and state rules may diverge.
One comparison that helps compliance teams: the California Age-Appropriate Design Code is not a copy of COPPA. It regulates design choices that affect all minors, not just the collection of personal information from children under 13.
The California Age-Appropriate Design Code in plain terms
The California Age-Appropriate Design Code, often shortened to AADC, requires covered businesses to consider the best interests of children when they design, develop and provide online services, products or features likely to be accessed by children.
Covered services include social media apps, games, and any online product a child is likely to use. The law defines a child as a user under 18, which is broader than the federal under-13 line. That single definition changes how much of a social app's user base falls inside the rule.
The code sets out a list of duties rather than a single ban. Businesses must assess whether their design could harm children, and they must document that assessment. They must also configure privacy settings for children differently from adults.
A key idea is that privacy cannot depend on a child finding a settings menu. The law pushes protections into the default state of the product. If a feature shares data or makes a profile public, the child-safe version should be the starting point.
Federal law still runs alongside it. The same federal rule sets the baseline for collecting data from children under 13, and the California code adds state-level design obligations on top of that floor.
The code also borrows from privacy frameworks used elsewhere. Regulators and lawyers sometimes compare it to the Quebec privacy law, which also imposes duties on platforms that serve younger users, though the enforcement routes differ.
Design duties: defaults, data minimisation and age assurance
The design duties are the operational core of the code, and they are where product teams feel the most pressure. Three categories cover most of the work: default settings, data minimisation, and age assurance or age estimation.
Default settings must be set to the highest level of privacy unless the business can justify a different choice for a child. That means no public-by-default profiles for minors, no location sharing switched on at signup, and no contact discovery enabled without a deliberate action by the user.
Data minimisation means collecting only what the service actually needs for the feature being offered. If a social app does not need a precise birth date for a core function, it should not demand one. If it does need an age signal, it should collect the least identifying version that works.
Age assurance or age estimation is the hardest piece. The law does not mandate one technology. Operators can use age estimation, age verification, or another method that is reasonably designed to determine whether a user is a child. The method must not collect more data than necessary for that purpose.
A practical sequence for a compliance team:
- Map every data field collected from users under 18 and label the purpose for each one.
- Review default settings for each feature and flip child-facing defaults to the most private option.
- Choose an age-assurance method that fits the product, then document why it is proportionate.
- Run a data protection impact assessment and keep the record current.
- Re-test defaults and age signals after every release that touches onboarding or sharing.
Pew Research Center tracks how different generations use social platforms, and its age and generations research is useful when sizing the under-18 population inside an app. Those shifting usage patterns are part of the wider generational digital culture, and they affect which features count as likely to be accessed by children.
Who enforces the code and what penalties look like
The California Attorney General is the primary enforcer of the Age-Appropriate Design Code. The office can bring civil actions against covered businesses that violate the design duties. There is no separate state agency created just for the code.
Penalty exposure is calculated per affected child. A violation can draw a civil penalty for each child whose data was affected, and the totals can grow quickly for a large platform. The law also allows injunctive relief, which means a court can order changes to the product itself.
Enforcement usually starts with an investigation and a request for records, including the required impact assessments. Companies that cannot produce a current assessment are in a weak position, even if their product is otherwise compliant.
The Federal Trade Commission remains active in the same space. Its COPPA compliance guidance explains how federal obligations apply to apps that collect data from children under 13. A state action and a federal action can proceed on the same facts.
Section 230 of the Communications Decency Act does not shield a platform from these design and privacy claims. It limits liability for third-party content, not for a company's own product decisions. That distinction is often misunderstood in policy debates.
Other states have passed similar laws, including Maryland and Vermont, and more are considering them. Federal rulemaking activity is one place to watch for movement that could preempt or reinforce state codes.
What social app operators in California must change first
Start with the items that carry the most legal risk and the least engineering cost. Defaults and documentation usually fit that description. Age assurance takes longer because it touches onboarding, identity and vendor selection.
A first-90-days checklist for a social app with California users:
- Confirm whether the app is likely to be accessed by children under 18, and write down the reasoning.
- Inventory every data field collected at signup and in the first session, with a stated purpose for each.
- Set child-facing defaults to the most private option for visibility, messaging, location and contact discovery.
- Select an age-assurance or age-estimation method and document why it collects the minimum data needed.
- Complete a data protection impact assessment and store it where counsel can retrieve it.
- Add a review step to the release process so defaults are re-checked after any onboarding change.
- Train support and trust-and-safety staff on the new escalation path for child-privacy complaints.
Product designers should treat the impact assessment as a design document, not a legal appendix. If a feature cannot be explained in the assessment without collecting extra data, that is a signal to redesign the feature.
Compliance leads should also track the public debate. Much of the critiques of social media literature focuses on harms to younger users, and that research shapes how regulators interpret design duties. Knowing the arguments helps teams anticipate what enforcers will ask about next.
Finally, keep a change log. When the attorney general asks how a default was set six months ago, a dated record is the difference between a clean answer and a costly one.
Common questions
Does the California Age-Appropriate Design Code apply to apps with no California users? The code reaches businesses that provide services likely to be accessed by children in California. If a social app has California users under 18, it should assume coverage.
What is the difference between age assurance and age verification? Age assurance is the broad category, covering any method that estimates or confirms a user's age. Age verification is a narrower approach that confirms age, often with stronger identity signals. The code allows either if it is proportionate.
Can a social app just ask for a birth date? It can, but data minimisation duties mean the app should not collect more than it needs. A full birth date may be more identifying than the feature requires, so many teams use age bands or estimation instead.
Do federal COPPA rules still apply? Yes. COPPA covers children under 13 and continues to apply alongside state law. The FTC publishes compliance guidance for social media operators that explains the federal requirements.
Who can sue under the code? The California Attorney General enforces the law. The code does not create a general private right of action for users, though other consumer protection theories may apply.
What happens if a company misses the impact assessment? The assessment is a core duty. Missing or stale assessments weaken a company's defense and can support a civil penalty calculated per affected child.




