The compliance floor just moved. For years, you could treat COPPA under-13 threshold as your bright line. If your service wasn't directed at children and you didn't have actual knowledge of users under 13, you were clear. That model no longer works.
In 2025, the FTC finalized COPPA Rule amendments requiring separate parental opt-in consent before certain disclosures of youth personal information to third parties for targeted advertising. More significantly, states are carving out a new compliance category: teen data. New York, Maryland, Arkansas, and Colorado now regulate how you handle information from users between 13 and 18, each with different thresholds, consent mechanisms, and processing restrictions.
If you're still treating youth privacy as a binary COPPA question, you're operating with an outdated risk model.
State-by-State Changes
The landscape shifted from a single federal baseline to a fragmented state-by-state framework. Here's what you're now managing:
New York's Child Data Protection Act regulates personal data for covered users under 18. For teens aged 13-17, certain processing must either be strictly necessary for specified activities or supported by informed consent. The law also restricts how you use personal data collected while a user was a minor after they turn 18.
Maryland's Online Data Privacy Act prohibits targeted advertising and the sale of personal data when you knew or should have known the consumer was under 18. That "should have known" standard matters. It shifts the burden from actual knowledge to constructive knowledge based on available signals.
Arkansas' Children and Teens' Online Privacy Protection Act creates separate obligations for children below 13 and teens aged 13-16 when you have actual knowledge of their age.
Colorado's Privacy Act amendments provide additional protections for children under 18 when a controller has actual knowledge or willfully disregards information establishing that a user is a minor. The attorney general's draft rules list factors for determining willful disregard: whether users can provide or edit their age, whether profiles include bio sections, whether there's indicia of age like grade level, and whether you categorize them differently for marketing purposes. The draft rules state this list isn't exhaustive and determinations depend on the totality of circumstances.
Texas S.B. 2420 took effect after the Fifth Circuit stayed a preliminary injunction. It requires covered app stores to verify users' age categories, associate minor accounts with parent accounts, and obtain parental consent in specified circumstances. App stores must make age-category and consent information available to developers, who must assign age ratings and use that information consistently with the law's restrictions.
Key Findings
1. Teen data is now a distinct compliance category
You can't lump 13-year-olds and 17-year-olds into a single "not a child under COPPA" bucket. New York draws the line at 18. Maryland prohibits targeted advertising and sales for under-18s. Arkansas separates 13-16 from under-13. Colorado's draft rules suggest that any age signal you ignore could establish willful disregard.
2. "Should have known" and "willful disregard" standards expand liability
Maryland's "should have known" language and Colorado's "willful disregard" framework mean you can't simply avoid collecting birthdates and claim ignorance. If your product includes grade-level fields, school email domains, or teen-focused content categories, regulators may argue you had constructive knowledge.
3. App stores are becoming compliance intermediaries
Texas S.B. 2420 shifts age verification and parental consent obligations to app stores in specified circumstances, then requires developers to use that information consistently. This creates a new dependency: your compliance now partly relies on accurate age signals from platform providers and your ability to act on them.
4. Processing restrictions vary by state and age band
New York requires strict necessity or informed consent for 13-17 processing. Maryland bans targeted advertising and sales for under-18s. Arkansas applies different rules to under-13 versus 13-16. You're not managing one teen policy; you're managing a matrix of age thresholds, consent types, and prohibited activities.
5. International frameworks are converging on similar principles
Canada's Office of the Privacy Commissioner released guidance in May 2026 advising organizations to assess whether age assurance is necessary and use methods proportionate to risks. Quebec bars collection directly from minors under 14 without parent or tutor permission unless clearly for the minor's benefit. You're facing parallel compliance obligations across jurisdictions with overlapping but non-identical requirements. Quebec personal information collection requirements
What This Means for Your Team
You need to answer three questions before you can build a defensible program:
Do you collect information within scope of these laws? This isn't just birthdate fields. It's any personal data from users you knew or should have known were minors. Review analytics tags, advertising identifiers, behavioral data, and user-generated content.
What's the value of that data versus the compliance cost? Some companies will find it's simpler to disable targeted advertising for all users who might be minors rather than build age-gated processing flows. Others will need that data for core functionality and must implement informed consent mechanisms.
Can you operationalize different rules for different age bands in different states? If you have users in New York, Maryland, Arkansas, and Colorado, you're managing at least four different frameworks with different age thresholds and processing restrictions.
Action Items by Priority
Immediate (next 30 days):
Map your data flows for users under 18. Identify every point where you collect, use, or share information that could fall under state teen privacy laws. Don't limit this to registration data; include analytics, advertising identifiers, and inferred attributes.
Audit your vendor contracts. Confirm that third-party analytics tools, advertising technologies, and data processors aren't transmitting minors' information in ways that conflict with state restrictions. Maryland's prohibition on sales and targeted advertising applies to your processors, not just your direct activities.
Review app store age ratings and developer agreements. If Texas S.B. 2420 applies to your distribution channels, confirm you're meeting age-rating obligations and prepared to use age signals from app stores consistently with the law.
Short-term (next 90 days):
Build a state-by-state compliance matrix. Document each state's age threshold, consent requirements, processing restrictions, and prohibited activities. Identify conflicts where one state requires informed consent while another prohibits the processing entirely.
Assess your age assurance methods. Colorado's draft rules suggest that failing to act on available age signals could establish willful disregard. Determine whether you need active age verification, passive age estimation based on behavioral signals, or age-gated interfaces that limit functionality for likely minors.
Update privacy notices and consent flows. You need separate disclosures for minors in states that require informed consent, and you need to disable certain processing in states that prohibit it outright. A single national privacy policy won't satisfy these requirements.
Ongoing:
Monitor state legislative activity. Several states have proposed app-store accountability laws and teen privacy frameworks. Legal challenges will affect timing and scope, but the trend is clear: more states will regulate teen data separately from adult data.
Test your ability to respond to age signals from app stores. As platforms implement age verification and parental consent mechanisms, you'll need systems to receive, validate, and act on those signals in real time.
Review how you handle data collected while users were minors after they turn 18. New York's Child Data Protection Act restricts this specifically. If you're retaining behavioral data, advertising profiles, or inferred attributes from when users were 16, you need a policy for what happens when they turn 18.





