On July 28, 2026, the New York Attorney General (“AG”) released final rules (the “Rules”) implementing the Stop Addictive Feeds Exploitation for Kids Act (“SAFE Act”). The Rules establish requirements for how social media companies must restrict addictive features on their platforms for users under the age of 18. The SAFE Act goes into effect on January 25, 2027, giving covered platforms approximately six months to develop and implement compliance programs.
As we previously reported, the SAFE Act was signed into law by New York Governor Kathy Hochul in June 2024 and prohibits covered social media platforms from providing algorithmically personalized feeds and nighttime notifications to users under 18 unless they obtain verifiable parental consent. The legislature charged the AG with promulgating rules to establish standards for age assurance and parental consent before the statute could take effect. The AG issued an advance notice of proposed rulemaking on August 1, 2024, published proposed rules on September 15, 2025, and incorporated public input and industry research to develop the final rules.
Key provisions of the Rules are discussed below.
Applicability
The Rules interpret the statute’s “significant portion” standard to mean an online platform where 20% or more of time spent by monthly active users is spent on “addictive feeds,” measured over any six-month period.
An “addictive feed” is defined as an online platform, or a portion thereof, in which multiple pieces of media from an online platform are: (1) shared or generated by users; and (2) concurrently or sequentially recommended, selected or prioritized for display to a user based, in whole or in part, on (i) information persistently associated with the user or the user’s device, or (ii) the user’s previous interactions with media generated or shared by other users, including the user’s interactions on different online platforms, media or the pages, groups, or other user-generated media the user requests, subscribes to, otherwise selects, or a combination thereof.
Certain activities are excluded from the definition, including recommendations in response to a search inquiry, the display of specific media in response to express and unambiguous user requests, recommendations based on user-selected privacy and accessibility settings and the display of media that is a direct and private communication. The Rules do not apply to platforms with fewer than five million monthly active users or fewer than 20,000 monthly active users who are covered minors, except platforms with a primary user base of minors.
Age Assurance
Rather than mandating a specific technology, the Rules establish a framework for evaluating whether age assurance methods are sufficiently accurate, reliable and privacy-protective. The Rules identify three categories of age assurance: (1) age estimation; (2) age inference; and (3) age verification.
“Age estimation” is defined as using analysis of a physical or behavioral feature to draw a conclusion regarding an individual’s age or age status. “Age inference” is defined as using verified information other than age to draw a conclusion regarding an individual’s age or age status. “Age verification” is defined as using generally accepted identification, including government-provided identification, or validation against an official records source, to confirm an individual’s age or age status.
Parental Consent
The Rules establish a multi-step consent process. First, the covered platform operator must provide the minor with notice that the operator cannot legally provide the minor an addictive feed without verifiable parental consent, and obtain valid consent from the minor to request verifiable parental consent for an addictive feed. Second, if the minor provides such consent, a covered platform operator must provide the parent with notice that the operator cannot legally provide the minor an addictive feed without verifiable parental consent and offer the parent access to a method of verifiable parental consent.
The Rules also specify as follows:
- Covered platform operators are prohibited from disclosing to parents, in any notice provided to comply with the Rules, information revealing the minor’s activity on the platform, such as the minor’s search history or topics of interest.
- Parents and minors must have the option to withdraw consent at any time.
- If a parent refuses consent, the covered platform operator may renew a request for consent only at the request of the minor, and the mechanism for refusing consent must be at least as easy to use as the mechanism for granting consent.
Certification and Recordkeeping
A covered platform operator must obtain a certification annually for each age assurance method it offers. The certification must include certain testing and must be documented in a written report, including testing protocols used and results. Covered platform operators must maintain copies of all test results, reports and certifications for no less than 10 years.
Enforcement
Companies that fail to comply by the January 25, 2027, effective date face fines of up to $5,000 per violation, enforceable by the New York AG.
Search
Recent Posts
Categories
- Behavioral Advertising
- Centre for Information Policy Leadership
- Children’s Privacy
- Cyber Insurance
- Cybersecurity
- Enforcement
- European Union
- Events
- FCRA
- Financial Privacy
- General
- Health Privacy
- Identity Theft
- Information Security
- International
- Marketing
- Multimedia Resources
- Online Privacy
- Security Breach
- U.S. Federal Law
- U.S. State Law
- Workplace Privacy
Tags
- Aaron P. Simpson
- Accountability
- Adequacy
- Advertisement
- Advertising
- Age Appropriate Design Code
- Age Verification
- Alabama
- American Privacy Rights Act
- Anna Pateraki
- Anonymization
- Anti-terrorism
- APEC
- Apple Inc.
- Argentina
- Arkansas
- Article 29 Working Party
- Artificial Intelligence (AI)
- Attorney General
- Audit
- Australia
- Austria
- Automated Decisionmaking
- Baltimore
- Bankruptcy
- Belgium
- Biden Administration
- Big Data
- Binding Corporate Rules
- Biometric Data
- Blockchain
- Bojana Bellamy
- Brazil
- Brexit
- British Columbia
- Brittany Bacon
- Brussels
- Business Associate Agreement
- BYOD
- California
- CalPrivacy
- CAN-SPAM
- Canada
- Cayman Islands
- CCPA
- CCTV
- Centre for Information Policy Leadership (CIPL)
- Chatbot
- Children’s Online Privacy Protection Act (COPPA)
- Chile
- China
- Chinese Taipei
- Christopher Graham
- CIPA
- Class Action
- Clinical Trial
- Cloud
- Cloud Computing
- CNIL
- Colombia
- Colorado
- Committee on Foreign Investment in the United States
- Commodity Futures Trading Commission
- Compliance
- Computer Fraud and Abuse Act
- Congress
- Connecticut
- Consent
- Consent Order
- Consumer Protection
- Consumer Rights
- Cookies
- COPPA
- Coronavirus/COVID-19
- Council of Europe
- Council of the European Union
- Court of Justice of the European Union
- CPPA
- CPRA
- Credit Monitoring
- Credit Report
- Criminal Law
- Critical Infrastructure
- Croatia
- Cross-Border Data Flow
- Cross-Border Data Transfer
- Cyber Attack
- Cybersecurity
- Cybersecurity and Infrastructure Security Agency
- Data Breach
- Data Brokers
- Data Controller
- Data Localization
- Data Minimization
- Data Privacy Framework
- Data Processor
- Data Protection Act
- Data Protection Authority
- Data Protection Impact Assessment
- Data Protection Officer
- Data Security
- Data Transfer
- David Dumont
- David Vladeck
- Deceptive Trade Practices
- Delaware
- Denmark
- Department of Commerce
- Department of Defense
- Department of Health and Human Services
- Department of Homeland Security (DHS)
- Department of Justice
- Department of the Treasury
- Design
- Digital Markets Act
- District of Columbia
- Do Not Call
- Do Not Track
- Dobbs
- Dodd-Frank Act
- DORA
- DPIA
- E-Privacy
- E-Privacy Directive
- Ecuador
- Ed Tech
- Edith Ramirez
- Electronic Communications Privacy Act
- Electronic Privacy Information Center
- Electronic Protected Health Information
- Elizabeth Denham
- Employee Monitoring
- Encryption
- ENISA
- EU Data Protection Directive
- EU General Data Protection Regulation (GDPR)
- EU Member States
- European Commission
- European Data Protection Board
- European Data Protection Supervisor
- European Parliament
- European Union
- Facial Recognition Technology
- FACTA
- Fair Credit Reporting Act
- Fair Information Practice Principles
- Federal Aviation Administration
- Federal Bureau of Investigation
- Federal Communications Commission
- Federal Data Protection Act
- Federal Trade Commission
- FERC
- Financial Data
- FinTech
- Florida
- Food and Drug Administration
- Foreign Intelligence Surveillance Act
- France
- Franchise
- Fred Cate
- Freedom of Information Act
- Freedom of Speech
- Fundamental Rights
- GDPR
- Genetic Data
- Geofencing
- Geolocation
- Geolocation Data
- Georgia
- Germany
- Global Privacy Assembly
- Global Privacy Enforcement Network
- Gramm Leach Bliley Act
- Grok
- Hacker
- Hawaii
- Health Data
- HIPAA
- HITECH Act
- Hong Kong
- House of Representatives
- Hungary
- Illinois
- India
- Indiana
- Indonesia
- Information Commissioners Office
- Information Sharing
- Insurance Provider
- Internal Revenue Service
- International Association of Privacy Professionals
- International Commissioners Office
- Internet
- Internet of Things
- Iowa
- IP Address
- Ireland
- Israel
- Italy
- Jacob Kohnstamm
- Japan
- Jason Beach
- Jay Rockefeller
- Jenna Rode
- Jennifer Stoddart
- Jersey
- Jessica Rich
- John Delionado
- John Edwards
- Kentucky
- Korea
- Large Language Model
- Latin America
- Laura Leonard
- Law Enforcement
- Lawrence Strickling
- Legislation
- Liability
- Lisa Sotto
- Litigation
- Location-Based Services
- London
- Louisiana
- Madrid Resolution
- Maine
- Malaysia
- Maryland
- Massachusetts
- Meta
- Mexico
- Michigan
- Microsoft
- Minnesota
- Missouri
- Mobile
- Mobile App
- Mobile Device
- Montana
- Morocco
- MySpace
- Natascha Gerlach
- National Institute of Standards and Technology
- National Labor Relations Board
- National Science and Technology Council
- National Security
- National Security Agency
- National Telecommunications and Information Administration
- Nebraska
- NEDPA
- Netherlands
- Nevada
- New Hampshire
- New Jersey
- New Mexico
- New York
- New Zealand
- Nigeria
- Ninth Circuit
- North Carolina
- North Dakota
- North Korea
- Norway
- Obama Administration
- OCPA
- OECD
- Office for Civil Rights (OCR)
- Office of Foreign Assets Control
- Ohio
- Oklahoma
- Online Behavioral Advertising
- Online Privacy
- Opt-In Consent
- Opt-Out
- Oregon
- Outsourcing
- Pakistan
- Parental Consent
- Payment Card
- PCI DSS
- Penalty
- Pennsylvania
- Personal Data
- Personal Health Information
- Personal Information
- Personally Identifiable Information
- Peru
- Philippines
- Poland
- PRISM
- Privacy
- Privacy and Information Security Law
- Privacy By Design
- Privacy Notice
- Privacy Policy
- Privacy Rights
- Privacy Rule
- Privacy Shield
- Profiling
- Protected Health Information
- Purpose Limitation
- Ransomware
- Record Retention
- Red Flags Rule
- Rhode Island
- Richard Thomas
- Right to Be Forgotten
- Right to Privacy
- Risk Assessment
- Risk-Based Approach
- ROSCA
- Rosemary Jay
- Russia
- Safe Harbor
- Salesforce
- Sanctions
- Schrems
- Scott Kimpel
- SECURE Data Act
- Securities and Exchange Commission
- Security Rule
- Senate
- Sensitive Data
- Serbia
- Service Provider
- Singapore
- Smart Grid
- Smart Metering
- Social Media
- Social Security Number
- South Africa
- South Carolina
- South Dakota
- South Korea
- Spain
- Spyware
- Standard Contractual Clauses
- State Attorneys General
- Steven Haas
- Stick With Security Series
- Stored Communications Act
- Student Data
- Supreme Court
- Surveillance
- Surveillance Pricing
- Sweden
- Switzerland
- Taiwan
- Targeted Advertising
- Telecommunications
- Telemarketing
- Telephone Consumer Protection Act
- Tennessee
- Terry McAuliffe
- Texas
- Text Message
- Thailand
- Transparency
- Transportation Security Administration
- Trump Administration
- United Arab Emirates
- United Kingdom
- United States
- Unmanned Aircraft Systems
- Uruguay
- Utah
- Vermont
- Video Privacy Protection Act
- Video Surveillance
- Virginia
- Viviane Reding
- Washington
- Whistleblowing
- Wireless Network
- Wiretap
- ZIP Code