
If your business operates a website, app, online platform, or connected device that could be accessed by anyone under 18, the regulatory landscape around children's data privacy just changed dramatically — and most businesses aren't ready.
The Children's Online Privacy Protection Act, commonly known as COPPA, was signed into law in 1998. For nearly 25 years, the FTC applied it to children under 13, and enforcement was relatively limited. That era is over. COPPA 2.0, combined with a wave of aggressive state-level legislation, has fundamentally rewritten the rules for how U.S. businesses must handle the personal data of minors. The age threshold has expanded, the penalties have multiplied, and the technical obligations now rival those of HIPAA and PCI-DSS in scope and complexity.
This post is for business leaders, compliance officers, and IT professionals who need to understand what has changed, what it means operationally, and what steps to take now.
What Changed: COPPA 2.0 and the Broader Legislative Wave
The Federal Overhaul
After years of legislative attempts, Congress finally passed a comprehensive update to federal children's online privacy law. The new framework extended COPPA's protections from children under 13 to minors under 17, closed the so-called "actual knowledge" loophole that allowed platforms to claim ignorance about underage users, and introduced a blanket prohibition on targeted advertising to minors — regardless of parental consent.
The FTC's enforcement authority was significantly expanded. Civil penalties per violation were increased, and the commission gained explicit authority to pursue actions against companies that engage in what the law describes as "commercial surveillance" of minors. That term is broad enough to encompass behavioral tracking, personalized content algorithms, and data-driven product recommendations.
Critically, the update also introduced data broker restrictions specifically around children's data. Businesses that buy, sell, or license personal information from minors — even indirectly through third-party data pipelines — are now explicitly within scope.
The State-Level Surge
Alongside the federal update, a significant number of states have enacted or strengthened their own children's data privacy laws. Following in the footsteps of California's Age-Appropriate Design Code Act, states including Texas, Colorado, New York, Florida, and Illinois have enacted legislation that goes beyond COPPA 2.0 in some respects.
Common elements across these state laws include:
- Age estimation requirements: Businesses must implement reasonable technical measures to estimate whether users are minors — even if users don't self-report their age.
- Default privacy settings: Privacy settings for minor users must default to the most protective option. You cannot require a child to opt out of tracking — it must be opt-in.
- Prohibition on dark patterns: Any interface design intended to encourage minors to share more data than necessary, extend session time, or bypass privacy controls is explicitly prohibited.
- Data Protection Impact Assessments (DPIAs): Several states now require formal DPIAs before launching any product or service likely to be accessed by minors.
- Geolocation restrictions: Many state laws prohibit collecting precise geolocation data from minors, or require explicit parental consent to do so.
For businesses operating nationally — which includes virtually every company with a website — the patchwork creates a compliance floor that, in practice, means meeting the most stringent requirements across all applicable jurisdictions.
Who Is Actually Affected?
This is where many businesses make a dangerous mistake. They assume children's privacy laws only apply to platforms obviously targeting kids: education apps, children's gaming sites, YouTube-style video platforms. That assumption is wrong — and costly.
Under the expanded definitions, you may be in scope if your platform:
- Is likely to be accessed by minors, even if not specifically marketed to them
- Offers any service free of charge in exchange for data (social, gaming, entertainment, news)
- Uses behavioral advertising or recommendation engines
- Processes data from users who may include minors based on the nature of your service
- Operates a loyalty program, online community, or user account system
The FTC has made clear that "we didn't know kids were using it" is no longer an acceptable defense. The standard is now what a reasonable business should have known, based on the nature of the platform and its likely user base.
Sectors that are discovering they're newly in scope include retail and e-commerce, online gaming and entertainment, fitness and wellness apps, news and media publishers, and any SaaS platform with consumer-facing components.
The Technical Requirements: What Compliance Actually Looks Like
The gap between understanding that you're in scope and actually achieving compliance is significant. Children's privacy compliance under the 2026 framework is not a policy exercise — it's a technical and operational overhaul.
Age Estimation and Verification
The law does not mandate a specific method for estimating user age, but it does require a "reasonable and proportionate" approach. Common approaches include:
- Self-declaration with corroboration (not compliant on its own for most platforms)
- Credit card or ID verification (high friction, limited to high-risk use cases)
- AI-powered age estimation from behavioral signals (emerging, with its own privacy implications)
- Parental consent workflows with email plus identity verification loops
Each approach has trade-offs between privacy, user experience, and reliability. Your compliance strategy needs to define which method is proportionate to the risk level of your platform — and document that decision.
Data Minimization and Purpose Limitation
Children's data laws apply the strictest version of data minimization principles. You may only collect data that is strictly necessary to deliver the service. Secondary uses — analytics, advertising, product improvement, sale to third parties — require explicit, verifiable parental consent for users identified or estimated to be minors.
This has significant downstream implications for businesses relying on third-party analytics and advertising SDKs. Many of those tools collect data indiscriminately. If they're deployed on pages or in apps where minors may be present, you're potentially in violation regardless of the third party's own compliance posture.
Privacy by Default in Product Design
This is one of the most operationally disruptive requirements for businesses that haven't approached it before. Under several state laws, any product or service likely to be accessed by minors must be designed with privacy-protective defaults from the ground up. That means:
- No behavioral tracking by default
- Geolocation disabled by default
- Social sharing features disabled or restricted by default
- Push notifications requiring explicit opt-in
- Profile visibility set to private by default
If your product was designed with engagement-maximizing defaults — which describes most consumer-facing digital products — you have architectural decisions to revisit, not just settings to toggle.
Data Protection Impact Assessments
Multiple state laws now require documented DPIAs before launching or significantly modifying services that may process children's data. A DPIA must identify the data flows involved, assess the risks to minor users, document mitigation measures, and be reviewed and updated periodically.
This isn't a one-time exercise. Any significant product change that affects data collection or processing triggers a fresh DPIA requirement.
The Penalties: Why This Deserves Urgent Attention
The penalty structure under the new federal and state frameworks is genuinely alarming for businesses that haven't prepared.
At the federal level, the FTC can now pursue penalties of up to $51,744 per violation per day — and "violation" can mean each individual minor user whose data was mishandled. In a class action or large-scale enforcement context, cumulative exposure can run into the hundreds of millions of dollars.
State attorneys general have become increasingly aggressive enforcement actors. California's AG has demonstrated a willingness to pursue tech companies with large penalties and public enforcement actions. Texas, Florida, and New York have made children's privacy enforcement a stated priority.
Beyond regulatory penalties, the private right of action included in several state laws means individual consumers — or more likely, plaintiff's attorneys representing them — can file suit directly. Class actions around children's privacy are already appearing in federal and state courts.
And then there's the reputational dimension. A single enforcement action or data breach involving children's data produces a level of public scrutiny that dwarfs most other privacy incidents. The reputational recovery timeline is long, and the impact on customer trust is severe.
What Your IT and Security Team Needs to Do Now
Understanding the legal landscape is step one. Building the operational capability to comply is where most businesses need to focus their energy.
Conduct a Data Inventory Focused on Minor Users
Before you can remediate, you need visibility. Map every system that collects, processes, stores, or transmits personal data — and identify where minor users may be present. This includes your CRM, analytics platforms, advertising tech stack, third-party integrations, and any mobile applications.
Layer27's Compliance services include data inventory and mapping capabilities designed to give businesses exactly this visibility. We work with your existing systems to identify where sensitive data flows — including data that may be subject to children's privacy obligations — and help you document those flows in formats regulators expect to see.
Audit Your Third-Party Data Ecosystem
This is where many businesses have significant hidden risk. Every third-party SDK, analytics tool, and advertising platform you've integrated may be collecting data from your users — including minors — under their own terms, not yours. That doesn't absolve you of liability.
Review every third-party tool deployed across your web and mobile properties. Evaluate their children's data policies. Determine whether they're being deployed in contexts where minors may be present. If they don't offer compliance-appropriate configurations, you may need to remove or replace them.
Implement Appropriate Access Controls Around Children's Data
Data classified as belonging to minor users requires elevated access controls. Only personnel with a documented business need should have access to it. Access should be logged, audited, and subject to periodic review.
Our Protect Pro and Infrastructure Pro services include the access control and audit logging infrastructure businesses need to meet this standard. And for teams that need ongoing oversight without building an internal security function from scratch, our Co-Managed IT model lets your team retain control while Layer27 provides the governance and monitoring layer on top.
Train Your Team — Including Non-Technical Staff
Children's privacy compliance isn't just an IT problem. Marketing teams need to understand why they can't run retargeting campaigns against certain audience segments. Product managers need to understand why certain features require additional review. Customer service staff need to understand how to handle data deletion and correction requests from parents.
Layer27's Security Awareness Training programs can be customized to include privacy-specific modules — including training on children's data handling obligations — so that compliance isn't siloed in legal or IT but embedded across your organization.
Establish a Parental Rights Request Process
COPPA and its successors give parents meaningful rights over their children's data: the right to access it, correct it, delete it, and restrict its processing. You need a documented, tested process for handling these requests within the legally required timeframes.
This process needs to include identity verification for the parent (to prevent third parties from making fraudulent deletion requests) and backend workflows that can actually execute on a deletion request across all systems — including backups and third-party platforms.
Layer27's Backup-as-a-Service (BaaS) solutions are designed with granular data management capabilities, so when a legitimate deletion request comes in, you can execute on it without creating gaps in your backup integrity.
Prepare an Incident Response Plan Specific to Children's Data
If you experience a breach involving children's data, the notification obligations, regulatory reporting timelines, and public communications requirements are distinct from standard data breach response. Your existing incident response plan — if you have one — likely doesn't address this scenario specifically.
Our Managed Detection & Response (MDR) and 24x7 SOC services give businesses continuous monitoring and rapid response capability so that threats involving sensitive data — including children's records — are detected and contained before they become reportable incidents.
The Intersection with Other Privacy Frameworks
One complexity businesses are discovering is that children's privacy obligations don't exist in isolation. They intersect with:
- General state privacy laws (CCPA, Colorado Privacy Act, Virginia CDPA, and others), which have their own requirements around sensitive data categories
- FERPA, the Family Educational Rights and Privacy Act, which applies to student data in educational contexts and creates an overlapping but distinct set of obligations
- HIPAA, when children's health or mental wellness data is involved
- International regulations like the UK's Children's Code and the EU's GDPR, for businesses with global operations
For businesses in healthcare, education technology, or any sector dealing with children's sensitive personal information, the compliance matrix is genuinely complex. Getting it right requires coordination between legal, IT, security, and product teams — and in most cases, external expertise.
Building a Sustainable Compliance Program
One-time remediation isn't enough. The regulatory environment around children's data privacy is still evolving, and the operational requirements demand ongoing attention.
A sustainable children's data privacy program includes:
- Annual or biannual data mapping reviews to catch new data flows introduced by product changes
- Vendor review cadence to assess third-party tools as they update their own practices
- Regular DPIA reviews when products or services change
- Staff training refresh cycles aligned with regulatory updates
- Incident response tabletop exercises that include children's data breach scenarios
For businesses that don't have the internal bandwidth to run this program independently, Layer27's Compliance services offer an ongoing advisory and monitoring function — keeping you current with regulatory changes, maintaining your documentation, and preparing you for audits before they happen.
The Bottom Line
Children's data privacy has moved from a niche compliance concern for children's app developers to a mainstream legal obligation affecting thousands of U.S. businesses across virtually every sector. The combination of COPPA 2.0, aggressive state-level legislation, and an activated enforcement environment means that ignorance is no longer a viable defense — and delay is an increasingly expensive choice.
The businesses that will navigate this well are those that treat children's privacy not as a legal checkbox but as a genuine operational capability: built into product design, enforced through technical controls, maintained through ongoing governance, and backed by the incident response infrastructure to handle problems when they arise.
If you're not sure where your organization stands — or if you know you have gaps but aren't sure where to start — that's exactly the kind of assessment Layer27 helps businesses work through.
Ready to Assess Your Children's Data Privacy Posture?
Layer27 works with businesses across the United States to build compliance programs that are operationally grounded, technically sound, and built to hold up under regulatory scrutiny. Whether you need a data mapping exercise, a gap assessment against the new legal requirements, or ongoing compliance support, we're here to help.

