On September 10, 2026, California’s governor signed AB 2246, a bill that repeals and replaces the California Age-Appropriate Design Code Act (“CAADCA”). AB 2246 reenacts a substantial portion of the CAADCA’s substantive requirements, without carrying forward some of its original exceptions.
Applicability
AB 2246 applies to businesses that provide an online service, product, or feature likely to be accessed by children. The bill defines a child as any consumer under 18 years of age.
A business’s online service, product, or feature is “likely to be accessed by children” if it:
- is directed to children as defined by the Children’s Online Privacy Protection Act;
- is determined, based on competent and reliable evidence regarding audience composition, to be routinely accessed by a significant number of children;
- contains advertisements marketed to children;
- is substantially similar to or the same as an online service, product, or feature routinely accessed by a significant number of children;
- has design elements that are known to be of interest to children, including games, cartoons, music and celebrities who appeal to children; or
- determines based on internal company research that a significant amount of the audience of the online service, product, or feature is children.
An online service, product, or feature does not include a broadband Internet access service, a telecommunications service or the delivery or use of a physical product.
Key Provisions
Businesses that provide an online service, product, or feature likely to be accessed by children must:
- estimate users’ ages with reasonable certainty, as appropriate to the risks arising from the business’s data management practices pursuant to California’s Digital Age Assurance Act, or apply children’s privacy protections to all consumers;
- configure all default privacy settings provided to children by the online service, product, or feature to settings that offer a high level of privacy;
- provide any privacy information, terms of service, policies and community standards concisely, prominently and using clear language suited to the age of children likely to access that online service, product, or feature;
- provide an obvious signal to the child when the child is being monitored or tracked if the online service, product, or feature allows the child’s parent, guardian or any other consumer to monitor the child’s online activity or track the child’s location;
- provide prominent, accessible and responsive tools to help children, or if applicable their parents or guardians, exercise their privacy rights and report concerns;
- if collecting precise location information of a child, provide an obvious sign to the child for the duration of the business’s collection of such information; and
- take reasonable steps to prevent reasonably foreseeable physical or financial harm, severe and reasonably foreseeable psychological or emotional harm to a reasonable child, highly offensive intrusion on privacy rights protected by state or federal law and adverse discrimination in violation of state or federal law.
- However, this requirement is not to be construed as imposing a duty on the business to monitor, screen, or remove third-party content, restrict lawful speech, or require any specific content-ranking, recommendation, or editorial outcomes.
Businesses are prohibited from:
- profiling a child by default unless the business can demonstrate that both of the following criteria are met:
- appropriate safeguards are in place to protect children; and
- the profiling is necessary to (1) provide the online service, product, or feature with which the child is actively and knowingly engaged, or (2) enhance the safety, privacy, or education of a child.
- collecting, selling or sharing any precise geolocation information of children by default unless strictly necessary for the business to provide the service, product or feature requested;
- If necessary, then the business may only collect, sell, or share the child’s precise geolocation information for the limited time that the collection of precise geolocation information is necessary to provide the service, product, or feature.
- using dark patterns to lead or encourage children to provide personal information beyond what is reasonably expected to provide that online service, product, or feature or to forgo privacy protections; and
- retaining any personal information collected to estimate age or age range for any other purpose or retaining that personal information longer than necessary to estimate age.
Notably, any provision of a contract entered into by a child or a child’s parent or guardian is voidable at the child’s election if the contract was entered into as a result of a design feature of an online service, product, or feature likely to be accessed by children. This includes provisions of a contract or other agreement governing the terms of service for that online service, product, or feature.
Enforcement
The California Attorney General and public prosecutors may enforce AB 2246. Violations of the bill are subject to an injunction and civil penalties, assessed per affected child, of (1) up to $5,000 for each negligent violation, or (2) up to $15,000 for each intentional violation.
Search
Recent Posts
Categories
- Behavioral Advertising
- Centre for Information Policy Leadership
- Children’s Privacy
- Cyber Insurance
- Cybersecurity
- Enforcement
- European Union
- Events
- FCRA
- Financial Privacy
- General
- Health Privacy
- Identity Theft
- Information Security
- International
- Marketing
- Multimedia Resources
- Online Privacy
- Security Breach
- U.S. Federal Law
- U.S. State Law
- Workplace Privacy
Tags
- Aaron P. Simpson
- Accountability
- Adequacy
- Advertisement
- Advertising
- Age Appropriate Design Code
- Age Verification
- Alabama
- American Privacy Rights Act
- Anna Pateraki
- Anonymization
- Anti-terrorism
- APEC
- Apple Inc.
- Argentina
- Arkansas
- Article 29 Working Party
- Artificial Intelligence (AI)
- Attorney General
- Audit
- Australia
- Austria
- Automated Decisionmaking
- Baltimore
- Bankruptcy
- Belgium
- Biden Administration
- Big Data
- Binding Corporate Rules
- Biometric Data
- Blockchain
- Bojana Bellamy
- Brazil
- Brexit
- British Columbia
- Brittany Bacon
- Brussels
- Business Associate Agreement
- BYOD
- California
- California Privacy Protection Agency
- CAN-SPAM
- Canada
- Cayman Islands
- CCPA
- CCTV
- Chatbot
- Children’s Online Privacy Protection Act (COPPA)
- Chile
- China
- Chinese Taipei
- Christopher Graham
- CIPA
- Class Action
- Clinical Trial
- Cloud
- Cloud Computing
- CNIL
- Colombia
- Colorado
- Committee on Foreign Investment in the United States
- Commodity Futures Trading Commission
- Compliance
- Computer Fraud and Abuse Act
- Congress
- Connecticut
- Consent
- Consent Order
- Consumer Protection
- Consumer Rights
- Cookies
- Coronavirus/COVID-19
- Council of Europe
- Council of the European Union
- Court of Justice of the European Union
- CPRA
- Credit Monitoring
- Credit Report
- Criminal Law
- Critical Infrastructure
- Croatia
- Cross-Border Data Flow
- Cross-Border Data Transfer
- Cyber Attack
- Cybersecurity
- Cybersecurity and Infrastructure Security Agency
- Data Breach
- Data Brokers
- Data Controller
- Data Localization
- Data Minimization
- Data Privacy Framework
- Data Processor
- Data Protection Act
- Data Protection Authority
- Data Protection Impact Assessment
- Data Protection Officer
- Data Security
- Data Transfer
- David Dumont
- David Vladeck
- Deceptive Trade Practices
- Delaware
- Denmark
- Department of Commerce
- Department of Defense
- Department of Health and Human Services
- Department of Homeland Security (DHS)
- Department of Justice
- Department of the Treasury
- Design
- Digital Markets Act
- Digital Services Act
- District of Columbia
- Do Not Call
- Do Not Track
- Dobbs
- Dodd-Frank Act
- DORA
- DPIA
- E-Privacy
- E-Privacy Directive
- Ecuador
- Ed Tech
- Edith Ramirez
- Electronic Communications Privacy Act
- Electronic Privacy Information Center
- Electronic Protected Health Information
- Elizabeth Denham
- Employee Monitoring
- Encryption
- ENISA
- EU Data Protection Directive
- EU General Data Protection Regulation (GDPR)
- EU Member States
- European Commission
- European Data Protection Board
- European Data Protection Supervisor
- European Parliament
- European Union
- Facial Recognition Technology
- FACTA
- Fair Credit Reporting Act
- Fair Information Practice Principles
- Federal Aviation Administration
- Federal Bureau of Investigation
- Federal Communications Commission
- Federal Data Protection Act
- Federal Trade Commission
- FERC
- Financial Data
- FinTech
- Florida
- Food and Drug Administration
- Foreign Intelligence Surveillance Act
- France
- Franchise
- Fred Cate
- Freedom of Information Act
- Freedom of Speech
- FTC
- Fundamental Rights
- GDPR
- Genetic Data
- Geofencing
- Geolocation
- Geolocation Data
- Georgia
- Germany
- Global Privacy Assembly
- Global Privacy Enforcement Network
- Gramm Leach Bliley Act
- Hacker
- Hawaii
- Health Data
- Health Privacy
- HIPAA
- HITECH Act
- Hong Kong
- House of Representatives
- Hungary
- Illinois
- India
- Indiana
- Indonesia
- Information Commissioners Office
- Information Sharing
- Insurance Provider
- Internal Revenue Service
- International Association of Privacy Professionals
- Internet
- Internet of Things
- Iowa
- IP Address
- Ireland
- Israel
- Italy
- Jacob Kohnstamm
- Japan
- Jason Beach
- Jay Rockefeller
- Jenna Rode
- Jennifer Stoddart
- Jersey
- Jessica Rich
- John Delionado
- John Edwards
- Kentucky
- Korea
- Large Language Model
- Latin America
- Laura Leonard
- Law Enforcement
- Lawrence Strickling
- Legislation
- Liability
- Lisa Sotto
- Litigation
- Location-Based Services
- London
- Louisiana
- Madrid Resolution
- Maine
- Malaysia
- Maryland
- Massachusetts
- Meta
- Mexico
- Michigan
- Microsoft
- Minnesota
- Missouri
- Mobile
- Mobile App
- Mobile Device
- Montana
- Morocco
- MySpace
- Natascha Gerlach
- National Institute of Standards and Technology
- National Labor Relations Board
- National Science and Technology Council
- National Security
- National Security Agency
- National Telecommunications and Information Administration
- Nebraska
- Netherlands
- Nevada
- New Hampshire
- New Jersey
- New Mexico
- New York
- New Zealand
- Nigeria
- Ninth Circuit
- North Carolina
- North Dakota
- North Korea
- Norway
- Obama Administration
- OCPA
- OECD
- Office for Civil Rights (OCR)
- Office of Foreign Assets Control
- Ohio
- Oklahoma
- Opt-In Consent
- Opt-Out
- Oregon
- Outsourcing
- Pakistan
- Parental Consent
- Payment Card
- PCI DSS
- Penalty
- Pennsylvania
- Personal Data
- Personal Health Information
- Personal Information
- Personally Identifiable Information
- Peru
- Philippines
- Poland
- PRISM
- Privacy
- Privacy and Information Security Law
- Privacy By Design
- Privacy Notice
- Privacy Policy
- Privacy Rights
- Privacy Rule
- Privacy Shield
- Profiling
- Protected Health Information
- Purpose Limitation
- Ransomware
- Record Retention
- Red Flags Rule
- Rhode Island
- Richard Thomas
- Right to Be Forgotten
- Right to Privacy
- Risk Assessment
- Risk-Based Approach
- ROSCA
- Rosemary Jay
- Russia
- Safe Harbor
- Salesforce
- Sanctions
- Schrems
- Scott Kimpel
- SECURE Data Act
- Securities and Exchange Commission
- Security Rule
- Senate
- Sensitive Data
- Serbia
- Service Provider
- Singapore
- Smart Grid
- Smart Metering
- Social Media
- Social Security Number
- South Africa
- South Carolina
- South Dakota
- South Korea
- Spain
- Spyware
- Standard Contractual Clauses
- State Attorneys General
- Steven Haas
- Stick With Security Series
- Stored Communications Act
- Student Data
- Supreme Court
- Surveillance
- Surveillance Pricing
- Sweden
- Switzerland
- Taiwan
- Targeted Advertising
- Telecommunications
- Telemarketing
- Telephone Consumer Protection Act
- Tennessee
- Terry McAuliffe
- Texas
- Text Message
- Thailand
- Transparency
- Transportation Security Administration
- Trump Administration
- United Arab Emirates
- United Kingdom
- United States
- Unmanned Aircraft Systems
- Uruguay
- Utah
- Vermont
- Video Privacy Protection Act
- Video Surveillance
- Virginia
- Viviane Reding
- Washington
- Whistleblowing
- Wireless Network
- Wiretap
- ZIP Code