Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

State and Federal Developments in Minors’ Privacy in 2026

By Lindsey Tonsager, Jenna Zhang & Natalie Maas on July 31, 2026
Email this postTweet this postLike this postShare this post on LinkedIn

Consistent with recent years, 2026 has proved to be a busy year for children and teens’ privacy legislation. This post recaps notable developments and trends thus far in 2026. Our mid-year and end-of-year recaps for 2025 can be found here and here.

App Marketplace Laws

Two distinct approaches to app marketplace regulation are emerging. Some states, including Texas, Utah, Louisiana, and Alabama, have focused on app store providers, while others, such as California and Colorado, have adopted a broader framework that reaches operating system providers.

  • Laws Regulating App Store Providers: Legislation governing app store providers has expanded in 2026 with a new Alabama law effective January 1, 2027, and amendments to laws in Utah (effective May 6, 2027) and Louisiana (effective July 1, 2027). The Fifth Circuit lifted the stay on Texas’s App Store Accountability Act. CCIA subsequently filed an emergency application asking the Supreme Court to block the law. The court denied CCIA’s application on July 6, 2026, allowing the law to remain in effect while the appeal proceeds.
  • Laws Regulating Operating System Providers: Following California’s approach, Colorado’s “Age Attestation on Computing Devices” (effective July 1, 2028) will require operating system providers to request age information from users at account setup and provide app developers with age signals. For devices where account setup was completed before the effective date, operating system providers have until January 1, 2029, to request age information from users. Illinois establishes similar requirements. Unlike the laws in the first group of states, these laws do not require parental consent for minors to download or purchase apps, and instead only require parents to provide age information for minors.

Minor Social Media Laws

States have continued to enact laws that regulate children and teens’ access to social media. South Carolina, Indiana, Idaho, Mississippi, New York, Minnesota, Louisiana, and Illinois all enacted new laws. Additionally, the Sixth Circuit lifted the stay on Ohio’s Parental Notification by Social Media Operators Act, which was enjoined in 2024. Common elements of these laws include:

  • Parental Controls: Many of these laws require parental consent to create and maintain teen accounts. Some laws also require certain parental supervision tools.
  • Age Assurance: Despite the legal challenges to age assurance requirements, some laws continue to include some form of ongoing “age estimation” requirement based on platform use.
  • Targeted Advertising and Sale of Data: Certain states enacted provisions explicitly barring targeted paid commercial advertising to teens, but the laws differ in scope.
  • Feeds and Design Features: State legislatures continue to regulate “addictive” features and interfaces. Some states bar the use of these interfaces and/or features for teens, while others gate these features behind user or parental consent.

Mental Health Warning Labels

This year, New York enacted a new law that amends SB 4505, which was passed in 2025 and requires social media platforms to display warning labels to users. The new law prescribes specific language to be included in warning labels, establishes requirements and restrictions for the display of warning labels, and limits the scope of the law to social media platforms that offer certain feeds, autoplay, and/or infinite scroll.

Regulation of AI Companions

Following the trend from 2025, state legislatures have continued to enact laws concerning minors’ use of AI companions. New laws were signed this year in Washington, Oregon, Idaho, Nebraska, Iowa, Georgia, Connecticut, Colorado, and Hawaii. New York’s bill, which would prohibit operators from providing minors with certain “unsafe AI companion features,” passed the legislature and was returned to the Senate for further action. Note that these states generally govern AI services designed for companionship. Common elements of these laws include:

  • Disclosures: Most states will require the covered operators to provide “clear and conspicuous” notice to minor users that the service is artificially generated and not human.
  • Sexually Explicit Content or Suggestive Dialogue: Many laws will also require operators to prevent or take reasonable measures to prevent the service from generating sexually explicit content or suggestive dialogue with minors.
  • Engagement Techniques: Many states have provisions prohibiting the covered services from utilizing certain “manipulative engagement techniques” with minors. Additionally, these states will generally require operators to adopt reasonable measures prohibiting the covered service from generating statements that prompt an emotional response, emotional dependence, or return for companionship or support.
  • Parental Controls: For U13 account holders, Idaho, Nebraska, and Iowa will mandate that operators offer tools for parents or guardians to manage the account holder’s privacy and account settings. These three states will also require operators to offer related tools for parents of minors above the age of thirteen as appropriate and based on relevant risks. Georgia, Connecticut, and Colorado will require operators to make these tools available for parents or guardians of account holders under the age of 18.

Age-Appropriate Design Code (“AADC”) Laws

This year, several AADC-style bills have seen movement. South Carolina enacted HB 3431 (effective February 5, 2026) which is the first AADC law to require annual independent third-party audit reports to the Attorney General that are publicly posted. Nebraska (effective July 17, 2026) amended its existing AADC law. New Jersey A4015 has passed both chambers and is awaiting the Governor’s signature.

Federal Developments

Both the Senate and House have continued to consider legislation addressing children and teen privacy and online safety. Next week, the Senate Commerce, Science, and Transportation Committee plans to hold a hearing on several bills concerning minors. Despite this activity, significant differences remain between the House and Senate approaches to online safety legislation, and it remains unclear whether any of the bills will move forward in their current form.

Tags: AI
Photo of Lindsey Tonsager Lindsey Tonsager

Lindsey Tonsager is a recognized leader in representing companies before federal and state regulators, and is renowned for advising on minor protection, AI, and state comprehensive privacy laws.

Lindsey chairs the firm’s global Data Privacy and Cybersecurity practice. She advises clients in their…

Lindsey Tonsager is a recognized leader in representing companies before federal and state regulators, and is renowned for advising on minor protection, AI, and state comprehensive privacy laws.

Lindsey chairs the firm’s global Data Privacy and Cybersecurity practice. She advises clients in their strategic and proactive engagement with the Federal Trade Commission, the U.S. Congress, the California Privacy Protection Agency, and State Attorneys General on proposed changes to data protection laws, and regularly represents clients in responding to investigations and enforcement actions involving their privacy and information security practices.

Lindsey’s practice focuses on helping clients launch new products and services that implicate the laws governing the use of artificial intelligence; data processing for robotics, autonomous vehicles, and other connected devices; biometrics; online advertising; the collection of personal information from children, teens, and students online; e-mail marketing; disclosures of video viewing information; and new technologies.

Lindsey also assesses privacy and data security risks in complex corporate transactions where personal data is a critical asset or data processing risks are otherwise material. In light of a dynamic regulatory environment where new state, federal, and international data protection laws are always on the horizon and enforcement priorities are shifting, she focuses on designing risk-based global privacy programs for clients that can keep pace with evolving legal requirements and efficiently leverage the clients’ existing privacy policies and practices. She conducts data protection assessments to benchmark against legal requirements and industry trends and proposes practical risk mitigation measures.

Read more about Lindsey TonsagerEmail
Show more Show less
Photo of Jenna Zhang Jenna Zhang

Jenna Zhang advises clients across industries on data privacy, cybersecurity, and emerging technologies. 

Jenna partners with clients to ensure their compliance with the rapidly evolving federal and state privacy and cybersecurity laws. She supports clients in designing new products and services, drafting privacy…

Jenna Zhang advises clients across industries on data privacy, cybersecurity, and emerging technologies. 

Jenna partners with clients to ensure their compliance with the rapidly evolving federal and state privacy and cybersecurity laws. She supports clients in designing new products and services, drafting privacy notices and terms of use, responding to cyber and data security incidents, and evaluating privacy and cybersecurity risks in corporate transactions. In particular, she advises clients on substantive requirements relating to children’s and student privacy, including COPPA, FERPA, age-appropriate design code laws, and social media laws.

As part of her practice, Jenna regularly represents clients in data privacy investigations and enforcement actions brought by the Federal Trade Commission and state attorneys general. She also supports clients in proactive engagement with regulators and policymakers to ensure their perspectives are heard.

Jenna also maintains an active pro bono practice with a focus on supporting families in adoptions, guardianships, and immigration matters.

Read more about Jenna ZhangEmail
Show more Show less
Photo of Natalie Maas Natalie Maas

Natalie is an associate in the firm’s San Francisco office, where she is a member of the Food, Drug, and Device, and Data Privacy and Cybersecurity Practice Groups. She advises pharmaceutical, biotechnology, medical device, and food companies on a broad range of regulatory…

Natalie is an associate in the firm’s San Francisco office, where she is a member of the Food, Drug, and Device, and Data Privacy and Cybersecurity Practice Groups. She advises pharmaceutical, biotechnology, medical device, and food companies on a broad range of regulatory and compliance issues.

Natalie also maintains an active pro bono practice, with a particular focus on health care and reproductive rights.

Read more about Natalie MaasEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Inside Privacy
  • Organization:
    Covington & Burling LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo