The Feds (and States) Up the Heat on Kid Privacy
A New Era for Children’s Online Privacy
This year marked a significant shift in the landscape of children’s online privacy as the Federal Trade Commission (FTC) implemented revised regulations to the Children’s Online Privacy Protection Act (COPPA). These updated rules are all about transparency and heightened data security. Companies must now disclose more about how they handle children’s data and are restricted in how they can share it, which sends a clear message: the days of treating children’s data as merely another resource are over.
State Initiatives to Fill COPPA Gaps
But the federal regulations are just the beginning. States across the U.S. are stepping up to address areas that COPPA does not fully cover, particularly regarding minors aged 13 to 17. New Age-Appropriate Design Code (AADC)-style laws are being adopted, which hold platforms accountable for assessing and minimizing risks to minors. For instance, companies are now required to set high-privacy defaults for younger users, limiting data collection to what is absolutely necessary.
Several states are also enforcing age-verification and parental-consent measures. These laws, which require anyone under 18 seeking social media accounts or online services to have parental approval, mark a significant shift in how kids interact digitally. This multi-tiered approach signals a future where regulations not only focus on data privacy but also encompass safety and consent standards throughout childhood and adolescence.
The Age-Signal Laws: New Obligations for App Developers
Recent changes in legislation from states like California, Louisiana, Texas, and Utah are pulling mobile app developers into this new regulatory environment. These states are introducing age-signal laws that compel app stores and developers to verify the age of users and implement age-based safeguards. For the first time, such laws require app stores to disclose the age of app users to developers. This raises significant implications under COPPA, especially since developers may need to reassess their practices regarding data for users under 18.
While Texas’s age-signal law set to launch in January 2026 faces constitutional challenges, the other states are swiftly moving forward. These regulations mean developers can no longer overlook the implications of the data they collect, as they must now contend with additional obligations derived from their awareness of user age.
California’s New Wave of Privacy Laws and Enforcement
When it comes to child privacy and broader consumer protections, California is a leader. The California Privacy Protection Agency (CPPA), recently rebranded as CalPrivacy, has fine-tuned the California Consumer Privacy Act (CCPA) to introduce comprehensive regulations that will take effect in 2026. These new rules extend far beyond minor adjustments; they introduce extensive risk assessments, stricter cookie and pixel usage rules, and additional obligations for data brokers.
A notable addition is the requirement for cybersecurity audits, which demand a formal evaluation of 18 specific areas within a company’s cybersecurity framework. These audits will be essential for organizations generating over $100 million in revenue and handling sensitive information. With enforcement already at unprecedented levels, companies need to prepare thoroughly for these significant changes.
Cookies and Tracking: A Growing Enforcement Landscape
The last year has seen a surge in litigation and regulatory scrutiny surrounding website tracking technologies like cookies. As businesses navigate this complex landscape, they must ensure compliance while balancing functionality and legal obligations. New enforcement trends suggest that companies could face lawsuits under various legal frameworks, including the California Invasion of Privacy Act and federal wiretapping laws.
Despite chaotic legal challenges, organizations continue to adapt by developing customized compliance strategies through updated cookie management resources. Companies that fail to keep up with these compliance needs risk facing not only financial penalties but also reputational damage.
U.S. Limits on Data Transfers to Sanctioned Countries
Alongside these state-level initiatives, the U.S. government has been busy finalizing rules that restrict personal data transfers to sanctioned nations, including China and Russia. This regulation also took effect in early 2025 and puts the onus on companies to adjust their data-sharing practices. Organizations must establish meticulous data governance protocols to ensure compliance as the enforcement phase evolves.
CIRCIA: The Cyber Incident Reporting Framework
Another critical development is the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), set to introduce new reporting requirements for cyber incidents. The framework will obligate approximately 300,000 entities to report incidents within 72 hours and ransomware payments within 24 hours. Companies in critical infrastructure sectors must use this preemptive period to enhance their incident response mechanisms and prepare for rigorous enforcement starting in 2026.
The AI Threat Landscape Expands
As technology continues to evolve, so too do the risks associated with it. The emergence of AI-driven cyber threats marks a pivot in how organizations must approach security. AI has already been harnessed by malicious actors, leading to faster and more sophisticated attacks. Businesses are bolstering their defenses through AI-enabled technologies, creating a race between attackers and defenders.
Europe: Simplification of Data Privacy Regulations
Across the Atlantic, the European Commission is shifting toward simplification through the proposed Digital Omnibus legislation, designed to streamline existing digital regulations. These changes promise to enhance compliance processes while reducing complexity, allowing companies in the EU to adapt more quickly to evolving standards.
The Evolving Definition of Pseudonymized Data
A recent court case in the EU clarified the status of pseudonymized data, emphasizing how businesses must assess whether they are handling personal data differently based on their interactions with it. This ruling highlights the evolving complexity of data privacy laws, urging organizations to stay vigilant as they navigate these legal waters.
Ongoing Implementation of NIS2 Requirements
Finally, the EU continues its efforts to bolster digital resilience through legislative measures like NIS2. As member states roll out the requirements of this regulation, businesses are expected to enhance their cybersecurity practices significantly. The growing compliance burden calls for active engagement from leadership teams and a culture shift toward prioritizing security across organizations.
By understanding these multifaceted developments, businesses and consumers alike can be better prepared for the changes to come, particularly in the domain of children’s online privacy. The evolving landscape necessitates proactive measures and a nuanced understanding of the implications of federal and state laws as they continue to take shape.

