Rules

3 US platform rules that shape what stays online

US platform rules come down to three: Section 230, COPPA and California's AADC. Here is what each one lets a platform keep, restrict or remove.

What to take away

  • Three US platform rules do most of the work: Section 230, COPPA and the California Age-Appropriate Design Code.
  • Section 230 lets a platform keep almost any user post and still moderate it, with federal criminal law and intellectual property as the main exceptions.
  • COPPA forces removal or restriction when a service collects personal data from children under 13 without verifiable parental consent.
  • The California code does not ban content by category. It forces design changes and data protection impact assessments for users under 18.
  • The FTC enforces COPPA and its own Act through warning letters, consent orders and civil penalties, but it does not police most lawful speech.
  • Nothing in the three rules covers lawful but ugly adult content, algorithmic amplification or most state-level speech statutes.

Rule one: Section 230 and what a platform may keep

Section 230 of the Communications Decency Act is the reason a US platform can host a stranger's post and not answer for it in court. The provision sits inside the Telecommunications Act of 1996, which rewrote American communications law around competition and internet access.

Two sentences carry the weight. One says an interactive computer service is not the publisher or speaker of information provided by another information content provider. The other protects a platform's own good-faith moderation, including the removal of material it finds objectionable, whether or not that material is constitutionally protected.

That second sentence is the part people forget. It means a platform may keep almost anything a user posts, and it may also take that same post down, without turning itself into a publisher. The choice is largely the platform's.

The keep verdict under Section 230

Under Section 230, a US platform may keep defamatory posts, harassment, misinformation, conspiracy content and most lawful but awful speech. It faces no federal liability for hosting them. This is the broadest keep rule in American internet law.

There are carve-outs. Federal criminal law applies. So does intellectual property law, which is why the Library of Congress and DMCA takedown records matter to platforms. State criminal law is a murkier area after later amendments and litigation.

The practical result is that a US platform can leave a post up even when a European platform would face a takedown order. Section 230 is a shield for the host, not a rule about the content itself.

The restrict verdict under Section 230

A platform may restrict anything it wants. Section 230's moderation clause protects the decision to label, demote, age-gate or remove. No federal rule requires a platform to carry a particular post.

This is why the same provision is cited by people who want more moderation and by people who want less. It protects both choices. For a deeper look at the original scope, see what Section 230 originally protected for US platforms.

The remove verdict under Section 230

Section 230 does not require removal of anything on its own. Removal becomes mandatory only when another law applies: a federal criminal statute, a copyright claim, a court order or a child privacy rule.

That distinction matters for moderators. Section 230 is the floor under your discretion, not a removal mandate. If a post must come down, some other law is doing the work.

Rule two: COPPA and what a platform must remove or restrict

COPPA is the federal children's privacy rule. It applies to operators of commercial websites and online services directed to children under 13, and to general-audience services that have actual knowledge they are collecting personal information from a child under 13.

The Children's Online Privacy Protection Rule ("COPPA") | Federal Trade Commission sets out the compliance duties: notice, verifiable parental consent, limits on collection, and deletion on request. Social apps that let a child register without consent are the classic target.

The keep verdict under COPPA

A platform may keep content posted by an under-13 user if it never collected personal information from that child, or if it has verifiable parental consent and follows the rule. Content alone is not the trigger. Data collection is.

In practice, most large platforms avoid the question by setting a minimum age of 13 and removing accounts that appear younger. That is a business choice built on top of a legal risk, not a COPPA command.

The restrict verdict under COPPA

COPPA restricts what an operator may collect, not what a child may say. An operator that wants younger users must build consent flows, limit data retention and avoid conditioning participation on unnecessary data.

Age assurance sits here too. A platform that asks for a birth date and then ignores the answer is in worse shape than one that never asked. Knowledge is the hinge.

The remove verdict under COPPA

When a service learns it collected a child's personal information without consent, COPPA requires deletion. That means the account, the profile data and the associated content come down. This is the clearest remove mandate of the three rules.

COPPA does not require a platform to remove a child's post from a service that never collected personal data. It requires the data to go. The post usually goes with the account.

Rule three: the California Age-Appropriate Design Code and design duties

The California Age-Appropriate Design Code Act is a state design law, not a content law. It applies to businesses that provide online services likely to be accessed by children under 18 and are subject to California jurisdiction.

It requires data protection impact assessments before a service launches, default high-privacy settings for minors, and limits on using a child's data in ways that could harm them. It also requires clear privacy information written for the age group.

The California Age-Appropriate Design Code is often compared with COPPA because both target minors. The difference is scope: COPPA covers under-13 data collection, while the California code reaches all minors and regulates design choices.

The keep verdict under the AADC

The code does not require removal of lawful content for users under 18. A platform may keep a teenager's post. What it cannot keep is a design that nudges that teenager toward harmful data exposure by default.

The distinction is the whole point. California regulates the architecture around the content, not the content itself.

The restrict verdict under the AADC

Restriction shows up as default settings, limited notifications, restricted location sharing and tighter profiling for minors. A platform must estimate the age of its users and apply protections accordingly.

A business that cannot determine age with a reasonable level of certainty must treat all users as children. That is a costly default, and it is why age assurance vendors grew quickly after the law passed.

The remove verdict under the AADC

The code does not impose a general removal duty. Removal obligations arrive through other laws: COPPA for under-13 data, or a platform's own terms when a design assessment shows harm.

Enforcement of the California code has also been contested in federal court, so its practical reach is narrower than its text. Platforms should treat it as a live design constraint, not a settled removal rule.

Side-by-side: keep, restrict or remove under each rule

The table below states the verdict for each rule. Use it as a quick reference when a moderation question arrives without a legal answer attached.

Rule Keep Restrict Remove
Section 230 Almost any user post, including lawful but harmful speech Anything, at the platform's discretion Only when another law requires it
COPPA Content from a child if no personal data was collected or consent exists Data collection, retention and features for under-13 users Personal data and accounts collected without verifiable parental consent
California AADC Lawful content for users under 18 Defaults, profiling, notifications and location features for minors No general removal duty; removal comes from other laws

A checklist for moderators

  • Confirm whether the post involves a user under 13 and whether the service collected personal data.
  • Check whether the account was created with a false birth date and whether the platform had actual knowledge.
  • Ask whether a California user under 18 is affected and whether default settings were applied.
  • Identify the specific law that would require removal before promising a takedown.
  • Route copyright and federal criminal issues away from the moderation queue and to counsel.
  • Record the decision and the rule cited, because FTC and state inquiries ask for the basis.
  • Recheck the account if the user later discloses their real age.

How the three rules interact on one US platform

Picture a US social app with a feed, direct messages and a public profile. A 12-year-old signs up with a fake birth year. The platform never asks again. That is the common fact pattern behind most enforcement.

Now a post from that account goes viral. Section 230 lets the platform keep the post. COPPA may require deletion of the account and its data if the platform had actual knowledge of the child's age. The California code may require design changes for the under-18 population regardless.

Three rules, three different questions. Section 230 asks who is liable. COPPA asks what data was collected from a child. California asks how the service was designed for minors.

The interaction also explains why platforms often remove first and argue later. Removal is cheap. Litigating an FTC consent order is not. The Facebook FTC settlement history shows how the dollar amounts escalate once a consent order is in place.

Enforcement: FTC actions, penalties and warning letters

The FTC is the main federal enforcer here. It brings COPPA cases and also uses its authority under Section 5 of the FTC Act against deceptive or unfair practices. The Statutes | Federal Trade Commission page lists the laws the agency enforces, including COPPA and Section 5.

Warning letters are the lightest tool. The agency sends them to companies over claims or practices that may mislead users, including privacy and security promises. The Warning Letters | Federal Trade Commission collection is public and worth reading before writing a privacy policy.

Notices of penalty offenses are heavier. When the FTC issues one, a company that engages in the described conduct with knowledge can face civil penalties. The Notices of Penalty Offenses | Federal Trade Commission page explains the mechanism and lists the notices issued.

Consent orders sit between the two. A platform settles, agrees to compliance terms and accepts reporting duties. Violating the order brings penalties per violation, which is how a modest privacy case becomes an eight-figure number.

What enforcement does not do

The FTC does not police lawful speech. It polices deception, unfairness and specific statutory duties. A platform that hosts ugly but lawful content is not an FTC target on that basis alone.

That is why memes and virality platforms measure the platform and the agency, not the harm itself. Case counts track agency priorities and settlement timing, not the amount of harm online.

State attorneys general also enforce COPPA and their own consumer laws. California, New York, Texas and Washington have been active, and the District of Columbia has sued platforms over design and data practices.

Illinois adds a separate wrinkle through its Biometric Information Privacy Act, which covers facial and voice data. That is a state privacy statute, not a platform speech rule, but it shapes what features ship in the US.

What these three rules still leave unregulated

Lawful but harmful content is the largest gap. Section 230 permits it, COPPA ignores it once a user turns 13, and the California code addresses design rather than the post itself.

Algorithmic amplification is another gap. None of the three rules says how a recommendation system must rank a post. Design assessments touch the question, but they do not set ranking standards.

Adult content for users over 18 is largely untouched at the federal level. State age-verification laws have grown, and they are being litigated, but they sit outside these three rules.

Age assurance remains unsettled. COPPA relies on actual knowledge. California pushes toward estimating age. The two standards create different compliance burdens for the same product.

Preemption questions are unresolved. Federal law, state design codes and state speech statutes overlap, and courts are still sorting out which state rules survive. That uncertainty is itself a compliance cost.

Finally, none of the three rules requires a platform to explain a moderation decision to the user who posted. Transparency duties come from terms of service, European rules or state disclosure laws, not from Section 230, COPPA or the California code.

Readers who follow the wider debate will recognize the pattern from critiques of social media writing: the strongest claims are usually about design and incentives, not about a single illegal post.

One more context point. The Telecommunications Act of 1996 | Federal Communications Commission created the framework that Section 230 sits inside, and the FCC still handles communications policy that touches platforms at the edges, including broadband and universal service questions.

Common questions

Does Section 230 require a platform to remove anything? No. It shields a platform from liability for user content and protects good-faith moderation. Removal duties come from other laws, such as COPPA or copyright.

What does COPPA actually require a platform to delete? Personal information collected from a child under 13 without verifiable parental consent. In practice that usually means the account and its associated data.

Does the California Age-Appropriate Design Code ban content for teens? No. It regulates design, default settings and data protection impact assessments for users under 18. It does not ban content by category.

Can the FTC fine a platform for a first COPPA violation? Yes. The FTC can seek civil penalties for COPPA violations and for conduct covered by a notice of penalty offenses. Warning letters are the softer first step.

Do these three rules cover misinformation? Not directly. Section 230 lets platforms keep it, COPPA does not address it, and the California code addresses design rather than the truth of a post.

Which states are most active beyond California? New York, Washington, Texas and Massachusetts have all pursued platform-related privacy, design or consumer cases, and Illinois adds biometric rules of its own.

More in Rules

Rules

How COPPA and California's design code change social apps for US teens

COPPA sets the federal baseline for kids' data, while California's Age-Appropriate Design Code adds design duties that reshape teen social apps across the US.

Rules

Section 230 and state speech laws, what US platforms must remove

Section 230 shields platforms from liability for user posts, but state speech laws and federal rules like COPPA still force removals and design changes.

Rules

What does the FCC actually regulate on US social platforms?

FCC social platforms sit mostly outside the agency's reach, but robocalls, texts and licensed spectrum bring parts of platform conduct under its rules.

Guides

Sacramento and the California Age-Appropriate Design Code, a guide for social apps

California Age-Appropriate Design Code sets design duties for social apps in Sacramento, covering defaults, data minimisation and age assurance.

Latest from Value Desk