Sections

Commentary

Congress should make children’s privacy the on-ramp to a national privacy law for all

August 5, 2026


  • Legislation focused specifically on children’s privacy is currently advancing on the Hill, but the issue would be better addressed as a component of comprehensive privacy legislation.
  • Risks to children’s privacy online include exposure to digital environments organized around surveillance and monetization incentives, not just access to content.
  • A children-first strategy may be the most politically viable path forward right now, but it should be treated as the beginning of a more comprehensive discussion that results in everyone being protected from online predators.
Several small cartoon representations of people are linked by brown handdrawn lines representing a network.
Jamillah Knowles & Reset.Tech Australia / https://betterimagesofai.org / © https://au.reset.tech/ / https://creativecommons.org/licenses/by/4.0/

The Senate Commerce Committee marked up five children’s online safety bills on Aug. 5, unanimously advancing the Kids Online Safety Act (KOSA). The markup came five weeks after the U.S. House of Representatives passed the Kids Internet and Digital Safety (KIDS) Act on June 29 by a 267-117 vote, marking the first time any version of the Kids Online Safety Act (KOSA) has cleared the chamber. The package, assembled from portions of 14 bills, bundles a revised KOSA with an updated Children and Teens’ Online Privacy Protection Act (COPPA 2.0), new rules for artificial intelligence (AI) chatbots and gaming platforms, data broker disclosure requirements, and age verification mandates for websites where more than one-third of the material is harmful to minors. Its prospects in the Senate remain uncertain. The Senate’s KOSA co-authors have called the House version unacceptable for dropping the “duty of care” provision. Sen. Marsha Blackburn (R-Tenn.) is negotiating with the White House to pair the Senate’s KOSA with federal preemption of some state AI laws.

Children’s privacy would be better protected as a component of comprehensive privacy legislation, because the practices that put children at risk, including invasive inference, profiling, brokered data flows, and engagement-optimized design, also cause harm to all ages. Putting this cart before the horse might also have implications on establishing a national data privacy standard. However, current comprehensive data privacy proposals do not have bipartisan support, leading to a more specific children’s package to move, and it can create targeted protections in the absence of a stronger comprehensive bill. If done correctly, a bill targeting children’s privacy can become the on-ramp to a national privacy law, rather than a detour.

Children’s privacy is a subset of harms that affect all Americans

The central risk to children’s privacy online is exposure to digital environments organized around surveillance and monetization incentives, not just access to content. Online services that children use are shaped by business models that reward more data through deepened inferences, online engagement, and longer online retention times. A Harvard study estimated that major social media platforms earned more than $11 billion in U.S. advertising revenue from minors in 2022. So long as minors are a material revenue source, platforms will not be able to (or want to) meaningfully mitigate harms to children without changing core revenue structures.

While COPPA has provided the basis for protecting children online, children’s digital lives have changed faster than the law has been updated. Social media became the default social infrastructure for teens. Now these platforms have been optimized for engagement in ways that magnify data collection. COPPA requires operators to obtain verifiable parental consent before collecting personal information from children under 13, but it applies only to services that are directed at children or that have actual knowledge that they have child users.

The proposed legislation also focus on children under 13, but the reliance on an “actual knowledge” standard has long created predictable gaps, especially for mixed-age services. In its 2022 case against Epic Games, the Federal Trade Commission (FTC) alleged that Fortnite’s privacy policy disavowed being directed to children while the company avoided learning users’ ages. Unwinding that took a $520 million resolution, including the largest civil penalty the agency has ever obtained for a rule violation, to change one company’s privacy options. The FTC took action against TikTok and ByteDance in 2024 alleging repeated COPPA violations despite years of prior regulatory scrutiny. Firm-by-firm enforcement at that scale is not shifting industry-wide incentives.

Nor does the youth digital ecosystem stop at social media feeds. It extends to app stores, games, advertising technology, data brokers, and AI chatbots marketed as companions. Recent data-broker enforcement actions show how downstream markets can turn seemingly mundane signals, including sensitive location data, into high-risk datasets. The Federal Trade Commission’s (FTC) September 2024 social media surveillance report similarly found that major platforms engaged in extensive data collection and monetization practices while providing inadequate safeguards for children and teens. A statute that governs only services likely to be accessed by minors would leave the resale market intact. Additionally, it would not protect adults’ data flows, from which information about children can be inferred. Research supports these conclusions: A 2023 surgeon general’s advisory concluded that the effects of social media on youth mental health are real but heterogeneous, and that current safeguards and transparency are insufficient relative to the scale of use. The National Academies of Sciences, Engineering, and Medicine reached a similar conclusion in their 2024 consensus report: Platform design and data practices—not access alone—are meaningful levers for reducing risk.

If children become the “exception” the law protects, platforms will still have incentives to build surveillance-based advertising and recommendation systems for everyone else, then those systems should be adapted around more complicated age gates. Blanket bans on children’s internet or social media use can push activity to less regulated corners of the internet, increase pressure for intrusive age-verification requirements, and invite constitutional challenges.

But a children’s safety package is the vehicle that exists

In recent years, Congress has recognized the need to protect children’s privacy and update COPPA: In July 2024, the Senate passed a children’s online safety package by a 91-3 vote, but the House never acted. In March, the Senate passed its own version of COPPA 2.0, and the House Energy and Commerce Committee advanced an earlier, party-line version of the KIDS Act. After Chairman Brett Guthrie (R-Ky.) and Ranking Member Frank Pallone (D-N.J.) struck a bipartisan deal on revised text in late June, the full House passed the package a week later. This package would extend COPPA-style protections to teens through age 17, adopt a “know or should have known” knowledge standard, restrict targeted advertising to minors, and set a federal floor that preserves stronger state protections.

Understanding that the current KIDS Act package may be the most politically viable path does not mean that the current draft meets the standard to meaningfully protect children. The administration’s own National Policy Framework for Artificial Intelligence, released in March, argues that Congress should create “commercially reasonable, privacy protective, age-assurance requirements” for AI services “likely to be accessed by minors,” and “affirm that existing child privacy protections apply to AI systems, including limits on data collection for model training and targeted advertising.” There are two constraints that could block the legislation’s success.

The first is the constitutional record, which has narrowed the options for online safety regulations. In Free Speech Coalition v. Paxton, the Supreme Court upheld Texas’ age-verification requirement for sites publishing material obscene to minors, applying intermediate rather than strict scrutiny on the theory that the law only incidentally burdens adults’ access to protected speech. In March, the 9th U.S. Circuit Court of Appeals held that NetChoice had not carried its burden of showing that the California Age-Appropriate Design Code Act’s coverage definition or its age estimation mandate is facially unconstitutional under the First Amendment, and it lifted the injunction as to those provisions. The court affirmed the preliminary injunction against the act’s four data use restrictions and dark patterns prohibition, which it found likely too vague to enforce. Arkansas’s social media age-verification law was also blocked by the U.S. District Court in 2025 on First Amendment and vagueness grounds; the state’s appeal is now pending before the 8th U.S. Court of Appeals. These mixed constitutional rulings  have prolonged uncertainty.

The second constraint is political. Children’s safety has become a bargaining chip in a larger AI federalism fight. The White House is working with Blackburn on a package that would pair the Senate’s version of KOSA—including its duty of care provision—with the NO FAKES Act, age-verification requirements, and the preemption of some state AI laws. KOSA’s Democratic co-author has rejected linking the two, arguing preemption should not be part of kids’ safety legislation.

How children’s privacy legislation could pave the way for broader protections

A better approach for policymakers would be to focus on the underlying data and design incentives that create risk cutting across young people and adult online users. Treating data minimization as a duty and not a consumer right means that if a service is likely to be used by minors, it should not be allowed to collect, infer, or retain data beyond what is necessary to provide the requested service. Rules built around necessity, proportionality, and use limitations are more effective than rules built around barring children, and adults, from particular services. FTC changes to the COPPA rule have focused on limiting companies’ ability to monetize children’s data as a condition of access and on tightening consent requirements for disclosures and targeted advertising—items that point in the right direction. The House-passed KIDS Act is perhaps a good mirror for more effective legislation by expanding age coverage into adolescence, restricting behavioral advertising to children and teens, and adding new data broker obligations.

While legislating for age assurance may be appropriate in narrow contexts, privacy-preserving approaches remain institutionally difficult. If lawmakers make age-gating the main compliance mechanism, they will put more pressure on online platforms and intermediaries to collect sensitive information such as personal identification factors, biometrics, or other persistent identifiers that can have discriminatory outputs. Further, the KIDS Act’s age verification mandate for adult websites has drawn warnings from digital rights groups that compliance could require all users to submit personal information to verify their age. Companies would likely need to build a de facto identity layer of the internet to comply with these laws, even as data breaches and misuse risks remain persistent. If Congress responds by only building age gates, it will leave these underlying incentives intact, while creating pressure for more intrusive identity verification systems across the internet, and the rules might also be invasive to vulnerable populations who lack verifiable identification resources. Any age-assurance system should be proportionate, secure, and prohibited from being repurposed for advertising or unrelated profiling through strict use limitations.

The current House-passed package sets a federal floor that preserves stronger state protections, unlike the approach of the Republican-led comprehensive privacy bill, the SECURE Data Act. Preemption remains a large obstacle to bipartisan comprehensive legislation, and enacting a children’s privacy bill with a floor would demonstrate that a national standard need not set the ceiling on privacy protections. While passing a children’s privacy bill could help the passage of a comprehensive bill by resolving certain political sticking points on data privacy, it may diminish some of the present political urgency toward acting on data privacy.

When it’s all said and done, children’s online privacy bills should be tied to getting a national privacy baseline. A children-first strategy may be the most politically viable path forward right now, but it should be treated as the beginning of a more comprehensive discussion that results in everyone being protected from online threats. Otherwise, Congress will have created a protected class of users while normalizing the idea that privacy protections are optional for adults.

The Brookings Institution is committed to quality, independence, and impact.
We are supported by a diverse array of funders. In line with our values and policies, each Brookings publication represents the sole views of its author(s).