Children's Privacy

California Child Online Safety Laws: Design and Product Requirements

California Child Online Safety Laws: Design and Product Requirements

On September 10, 2026, California’s governor signed AB 2246 and AB 1709. AB 2246 rewrites the state’s age-appropriate design provisions, changing requirements for children’s personal information and privacy settings. AB 1709 prohibits covered platforms from providing users under 16 with the addictive features defined in the law, including recommendation feeds and autoplay that meet its definitions. Both laws were signed and filed that day, and neither contains a separate delayed operative date or an urgency clause. Their January 1, 2027 effective date follows from the general rule in Article IV, section 8(c)(1) of the California Constitution.

Businesses need to examine several parts of their products: how they identify users’ ages, whether they can recommend content based on children’s browsing histories, whether autoplay is available, and which privacy protections are enabled by default for children’s accounts. Even businesses that already handle children’s data in accordance with COPPA need to review these features.

I. Key changes to age-appropriate design requirements and restrictions on addictive features

1. AB 2246: Scope and changes to age-appropriate design requirements

AB 2246 repeals and replaces the relevant provisions of the 2022 California Age-Appropriate Design Code Act. It continues to protect consumers under 18.

To determine whether AB 2246 applies, a company must first assess whether it is a business within the meaning of the CCPA. It must then determine whether its product is “likely to be accessed by children.” The statutory indicators include the proportion of child users, advertising directed at children, design elements that appeal to children, and the company’s own audience research. A product need not have been developed specifically for children to fall within the law’s scope if the applicable conditions are met.

After the 2022 law passed, NetChoice, an internet industry trade association, brought a lawsuit arguing that the provisions violated the U.S. Constitution. The court subsequently issued a preliminary injunction suspending enforcement while the case proceeded. In March 2026, the court of appeals narrowed the injunction, but some data-use restrictions, dark-pattern provisions, and the specific data protection impact assessment requirements remained enjoined. AB 2246 rewrites this law, whose enforcement has been restricted by litigation.

High-privacy default settings, age estimation, and restrictions on profiling by default were already part of the earlier law. The main changes narrow certain exceptions and adjust businesses’ duties to prevent harm to children.

Issue2022 textChanges under AB 2246
Default privacy settingsGenerally required a high level of privacy, with an exception where a business could demonstrate a compelling reason that a different setting served children’s best interestsRetains high-privacy defaults and removes this exception
Profiling by defaultRequired appropriate safeguards and satisfaction of conditions relating to service necessity or children’s best interestsStill requires safeguards; profiling must be necessary to provide a service with which the child is actively and knowingly engaged, or necessary to enhance the child’s safety, privacy, or education
Unnecessary data processingAllowed an exception where a business could demonstrate a compelling reason that the processing served children’s best interestsRemoves this exception while retaining other expressly specified statutory circumstances
Data protection impact assessmentsRequired specific assessments, periodic reviews, and submission to the Attorney General on requestRemoves this particular assessment regime and separately requires reasonable steps to prevent the risks of harm specified in the law

The new harm-prevention duty includes reasonably foreseeable physical or financial harm and severe, reasonably foreseeable psychological or emotional harm. The text also makes clear that this provision does not impose a duty to monitor, screen, or remove third-party content, or require particular content-ranking, recommendation, or editorial outcomes. Businesses must separately comply with assessment duties imposed by other laws.

2. AB 1709: Scope and restrictions on addictive features

AB 1709 principally covers platforms that provide an “addictive feature” as a significant part of their service. It excludes, among other services, those where user interactions are limited to commercial transactions or consumer reviews, and services operating a feed primarily for cloud storage. A user under this law is a person who resides in California and accesses a platform or seeks to create an account.

Platforms subject to AB 1709 must not provide users under 16 with the addictive features defined in the law. They may allow these users to create or retain accounts, but cannot make those features available to them or lift the restriction merely because a parent consents.

The law lists addictive feeds and autoplay, and authorizes the Attorney General to bring other features within the restrictions through regulations. For feeds, a central question is whether the platform uses information associated with a user or device to select, recommend, or prioritize multiple items of user-generated or shared content. The text also provides exceptions for expressly requested content, private communications, and other circumstances, so the way recommendations operate remains relevant.

3. Comparison with COPPA: Scope and obligations

COPPA and its implementing Rule principally cover two categories of online services: those directed to children under 13 that collect their personal information, and other services that have actual knowledge that they are collecting personal information from children under 13.

COPPA requires businesses to notify parents about their data practices and obtain verifiable parental consent where required. Businesses must also limit collection, safeguard data, and comply with retention and deletion requirements. The 2025 amendments to the Rule strengthened requirements for separate parental consent, including for disclosures of children’s information to third parties for targeted advertising.

ComparisonCOPPA and its implementing RuleAB 2246AB 1709
Age rangeUnder 13Under 18Feature prohibition applies to users under 16
Principal requirementsRegulates the collection, use, and disclosure of children’s personal informationRegulates data processing and default settings, and requires prevention of specified harmsRestricts the provision of addictive features to children
Can parental consent replace other obligations?No; security, minimization, and other duties still applyConsent does not override necessity and default-setting requirementsNo general exception allowing prohibited features on the basis of parental consent

For example, where a platform knows that a California user is 15, the user’s age alone does not bring them within COPPA’s rules for children under 13. However, if the platform falls within these California laws, it must still examine whether it profiles the user by default, how privacy options are configured, and whether features such as autoplay may be provided. Dividing users only into under-13s and everyone else for COPPA purposes is insufficient to meet the requirements of these two California laws.

II. Compliance requirements for key product functions

1. Obtaining age signals and managing features by age group

AB 2246 allows businesses either to estimate child users’ ages or to extend the privacy and data protections afforded to children to all consumers. Age estimation must achieve a reasonable level of certainty appropriate to the risks arising from the business’s data practices. AB 1709 imposes a separate requirement: before providing addictive features, platforms must verify age under the Digital Age Assurance Act.

The Digital Age Assurance Act was established by AB 1043 in 2025. Civil Code section 1798.505, added by that law, expressly makes the title operative on January 1, 2027. AB 1856, signed on September 10, 2026, modifies the process. During account setup, the operating system obtains the age or birth date of the device’s primary user. App stores and developers then obtain age-bracket information through an interface, known as an “age signal.” Signals must distinguish at least four groups: under 13, ages 13–15, ages 16–17, and adults.

Developers must request a signal when an application is downloaded and launched, and use it as the primary indicator of the user’s age. Where a business already has clear and convincing information showing that the user’s age differs from the signal, it must use that information rather than deliberately disregard it.

Once a signal is received, the product must use it to determine which features are available. Users aged 13–15 remain protected by AB 1709’s feature prohibition. Users aged 16–17 are outside that direct prohibition, but this does not automatically permit platforms to provide addictive features to them: platforms must still meet age-verification requirements and assess other applicable rules, including SB 976. AB 2246’s child privacy protections may also continue to apply. The law also treats the developer as having knowledge of the user’s age bracket for the related websites and access points specified in the statute. An application therefore cannot impose restrictions only on its mobile version while allowing users to re-enable the features through those related web access points.

If age cannot be verified under the Digital Age Assurance Act, section 22684(a)(2), added by AB 1709, requires platforms instead to rely on an age determination under Health and Safety Code section 27001(a)(1)(B). The referenced provision requires a reasonable determination that the user is not a minor, while section 27000(d) of that chapter defines a minor as a person under 18.

These are two different age thresholds: AB 1709’s direct feature prohibition concerns users under 16, whereas the fallback verification provision refers to an under-18 threshold. The fallback therefore cannot simply be described as proving that a user is at least 16. For users aged 16–17 whose age cannot be verified through an age signal, platforms need to examine subsequent regulations or authoritative interpretations to establish how the provisions work together; reaching age 16 alone does not justify providing restricted features.

This does not mean every application must collect users’ identity documents itself. Developers should limit requests to necessary information and should not repurpose age-determination data for advertising profiles. Section 1798.502, as amended by AB 1856, sets a deadline before July 1, 2027 for certain existing devices and applications: device account setup must have been completed before January 1, 2027; applications must have been downloaded before that date and meet the statutory condition concerning updates on or after January 1, 2026. This does not mean that AB 1709’s feature prohibition is also deferred until July.

2. Profiling by default and personalized recommendations

The same recommendation system requires separate assessment under the two laws. Under AB 2246, businesses need to check whether the product analyzes children’s interests or behavior by default and whether the safeguards and necessity conditions for profiling are met. Under AB 1709, they need to check whether users under 16 are being provided with a prohibited addictive feed.

For a short-video service, for example, a platform that continuously recommends other users’ videos based on past viewing, clicks, or device information needs to assess the definition of an addictive feed and its exceptions. A user actively searching for a video or expressly requesting a particular creator’s content is not subject to the same conditions as additional recommendations generated from a profile built over time.

Even where a tab is labeled “Following,” the platform must still assess the exceptions if it uses the user’s browsing history or other information to adjust recommendations beyond the user’s choice of creators to follow. It must also examine whether videos play automatically: some feed exceptions require audio and video not to play automatically, so changing the recommendation algorithm alone may be insufficient.

3. Autoplay restrictions and feature settings

AB 1709 lists autoplay among addictive features. Assessing a particular product also requires considering whether the feature exploits users’ psychological vulnerabilities, is intended to maximize engagement, and foreseeably leads to compulsive use. The label “autoplay” alone is not enough to reach a conclusion.

If autoplay falls within the prohibition, switching it off by default while allowing users under 16 to turn it back on is still insufficient. Testing can examine three common situations: whether playback begins on entering a page, whether another video starts when the current one ends, and whether swiping to the next item starts playback. The app and web versions should apply consistent age restrictions.

4. Default privacy settings and location data

AB 2246 requires a high level of privacy by default for children and removes the earlier exception allowing different defaults on children’s best-interests grounds. Businesses need to check who can see personal information when an account is created, whether profiling begins when a feature is first enabled, and whether protections remain in place after settings are reset.

Children’s precise geolocation must generally not be collected, sold, or shared by default. An exception applies only where strictly necessary to provide the service requested by the child. Collection must not continue beyond the necessary period, and a prominent indication must remain visible to the child throughout collection.

Providing an off switch does not establish that the defaults comply. If profiling or data processing that fails the above requirements begins before users have had a chance to change their settings, businesses need to revise the feature’s startup process so that privacy protections apply from the outset.

References

AB 2246, chaptered text: https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB2246; AB 1709, chaptered text: https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260AB1709; AB 2273 (2022): https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202120220AB2273; FTC COPPA FAQs: https://search.ftc.gov/business-guidance/resources/complying-coppa-frequently-asked-questions; 2025 COPPA Rule amendments: https://www.federalregister.gov/documents/2025/04/22/2025-05904/childrens-online-privacy-protection-rule; California Constitution, Article IV, section 8: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CONS&sectionNum=SEC.%208.&article=IV; CCPA business scope: https://cppa.ca.gov/faq; Ninth Circuit opinion of March 12, 2026: https://cdn.ca9.uscourts.gov/datastore/opinions/2026/03/12/25-2366.pdf; AB 1856, chaptered text: https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB1856; SB 976: https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB976; Attorney General SB 976 rulemaking page: https://www.oag.ca.gov/sb976; AB 1043, Digital Age Assurance Act and section 1798.505 operative date: https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260AB1043.

Related reading

Kaamel
info@kaamel.com
340 E Middlefield Rd, Mountain View, CA 94043
AICPA Drata
© 2026 Kaamel Inc. All rights reserved.