
The landscape of children’s and teens’ privacy and online safety regulation continues to evolve at a rapid pace. In the absence of comprehensive federal legislation, state legislatures are driving a patchwork of privacy protections, spanning age verification mechanisms, social media restrictions, addictive design prohibitions, and data minimization requirements. Meanwhile, litigation is emerging as a critical gatekeeper determining which of these enacted laws actually take effect. This Legal Update summarizes the key mid-year legislative developments and emerging trends that businesses should continue to monitor. For an in-depth review of the privacy landscape for children and teens, please see our previous Legal Update.
STATE LEGISLATURES AS PRIMARY DRIVER
State legislatures remain the primary engine of children’s privacy and online-safety regulation. As of the time of writing, state activity has clustered around four principal categories: social media access and design restrictions; age-appropriate design code obligations; app-store or device-level age-assurance requirements; and harmful-content age-verification laws.
The most active category remains social media and online-safety legislation. As of July 2026, 21 states have passed social media laws regulating minors’ use of online platforms. Separately, five states have enacted standalone age-appropriate design code legislation, including California AB 2273, Maryland HB 603, Nebraska LB 504 as amended by LB 838, Vermont S.69, and South Carolina HB 3431 (effective February 5, 2026); and three states have enacted comparable minor-specific privacy duties through broader privacy statutes, including the Connecticut Data Privacy Act (SB 3 as amended by SB 1295), Colorado SB 24-041, and Montana SB 297.
States also continue to experiment with infrastructure-level approaches. Four states have enacted App Store Accountability Acts, with Alabama HB 161 (effective January 1, 2027) as the most recent. As of the date of this update, 26 states had enacted age-verification laws targeting minors’ access to harmful content, with West Virginia HB 4412 (effective June 12, 2026) and Iowa HF 864 (effective July 1, 2026) among the most recent.
At the federal level, several bills remain pending but none have yet been enacted, including the KIDS Act (HR 7757), which passed the House on June 29, 2026, while COPPA 2.0 (HR 6291) passed the Senate by unanimous vote earlier this year, and now awaits further House action. Other pending proposals include the Don’t Sell Kids’ Data Act (HR 6292), the RESET Act (HR 6488), the Algorithmic Transparency and Choice Act (HR 6253), the Safe Messaging for Kids Act (HR 6257), and the GUARD Act (S 3062). The Senate Commerce Committee is also expected to conduct a markup of several privacy and online safety-related bills on July 29, including the Kids Online Safety Act. The absence of enacted federal legislation means that, for now, businesses must continue to navigate a complex, state-by-state compliance landscape.
AGE VERIFICATION AS A CORE REQUIREMENT…
One Step Forward, Two Steps Back: Bill C-36 Modernizes Canada’s Privacy Law, Then Delays It to 2030
Canada’s private sector privacy law is more than 25 years old and there is broad consensus…






