Children and teen online privacy laws
26 regulations worldwide that deal with children, with every phased deadline and the official source for each.
26 regulations
Add to calendar
- Connecticut Data Privacy Act (CTDPA)
Connecticut
AmendedPrivacyChildrenNext: Oct 1, 2026 PA 26-64 (SB 4) amendments take effect
- India DPDP Act
India
EnactedPrivacyChildrenNext: Nov 13, 2026 Consent Manager registration rule in force (12 months)
- EU AI Act
European Union
AmendedAIBiometricsNext: Dec 2, 2026 New bans on sexual deepfakes and CSAM generation; Art 50(2) grace period ends
- Australia Privacy Act
Australia
AmendedPrivacyChildrenNext: Dec 10, 2026 Children's Online Privacy Code must be registered
- CCPA / CPRA
California
AmendedPrivacyAINext: Jan 1, 2027 ADMT requirements compliance date
- AmendedPrivacyChildren
Next: Jan 1, 2027 Amended thresholds and third-party duties take effect
- New Hampshire Privacy Act
New Hampshire
AmendedPrivacyChildrenNext: Jan 1, 2027 Ban on selling personal data of children under 13 (HB 1460)
- Indonesia PDP Law
Indonesia
AmendedPrivacyBreach notificationNext: Jan 16, 2027 Implementing regulation GR 33/2026 takes effect
- AmendedPrivacyChildren
Next: Apr 1, 2027 Discretionary 60-day cure period ends
- GDPR
European Union
AmendedPrivacyBreach notificationNext: Apr 2, 2027 GDPR Procedural Regulation applies
- California SB 243 (companion chatbots)
California
In forceAIChildrenNext: Jul 1, 2027 First annual report to Office of Suicide Prevention
- Australia Social Media Minimum Age
Australia
In forceChildrenOnline safetyEffective Dec 10, 2025
- Brazil ECA Digital
Brazil
In forceChildrenOnline safetyEffective Mar 17, 2026
- China PIPL
China
In forcePrivacyData residencyEffective Nov 1, 2021
- Colorado Privacy Act (CPA)
Colorado
AmendedPrivacyChildrenEffective Jul 1, 2023
- COPPA Rule
United States (Federal)
AmendedPrivacyChildrenEffective Apr 21, 2000
- Digital Services Act
European Union
In forceOnline safetyChildrenEffective Nov 16, 2022
- In forcePrivacyChildren
Effective Jul 1, 2024
- Japan APPI
Japan
AmendedPrivacyChildrenEffective Apr 1, 2005
- AmendedPrivacyChildren
Effective Oct 1, 2024
- New Jersey NJDPA
New Jersey
AmendedPrivacyChildrenEffective Jan 15, 2025
- Oregon OCPA
Oregon
AmendedPrivacyChildrenEffective Jul 1, 2024
- TAKE IT DOWN Act
United States (Federal)
In forceOnline safetyAIEffective May 19, 2025
- UK Online Safety Act
United Kingdom
In forceOnline safetyChildrenEffective Mar 17, 2025
- Vietnam PDPL
Vietnam
In forcePrivacyData residencyEffective Jan 1, 2026
- Virginia VCDPA
Virginia
AmendedPrivacyChildrenEffective Jan 1, 2023
Upcoming deadlines
October 20261 deadline
PA 26-64 (SB 4) amendments take effect
Prohibits controllers and third parties from selling precise geolocation data and enacts data broker and other consumer protection provisions.
November 20261 deadline
Consent Manager registration rule in force (12 months)
Rule 4 (registration and obligations of Consent Managers) comes into force one year after publication.
December 20263 deadlines
- EU AI ActEuropean Union
New bans on sexual deepfakes and CSAM generation; Art 50(2) grace period ends
New Art 5(1)(ba)/(bb) prohibitions on AI systems that generate non-consensual intimate imagery of identifiable persons or child sexual abuse material apply. Generative AI systems placed on the market before 2 Aug 2026 must comply with the Art 50(2) marking duty by this date (new Art 111(4)).
Children's Online Privacy Code must be registered
OAIC must develop and register the Children's Online Privacy Code within 24 months of Royal Assent.
Automated decision-making transparency applies
Privacy policies must disclose the kinds of personal information used in substantially automated decisions that significantly affect individuals (24 months after assent).
January 20276 deadlines
ADMT requirements compliance date
Businesses using ADMT for significant decisions must comply with Article 11 (pre-use notice, opt-out, access rights) by this date (11 CCR 7200(b)).
Browsers must support opt-out preference signal (AB 566)
Businesses that develop or maintain a browser must include consumer-configurable functionality to send an opt-out preference signal (Civ. Code 1798.136, operative Jan 1, 2027).
Data broker registration required
Data brokers may not sell or license brokered personal data in Connecticut unless registered with the Department of Consumer Protection ($2,500 initial fee).
Amended thresholds and third-party duties take effect
Applicability drops to 10,000 consumers (or 5,000 + 20% revenue from sale) and new third-party duties (12D-107A) apply.
- New Hampshire Privacy ActNew Hampshire
Ban on selling personal data of children under 13 (HB 1460)
HB 1460 (2026, ch. 168) prohibits controllers from selling the personal data of a child under 13.
Implementing regulation GR 33/2026 takes effect
Detailed PDP implementing rules (DPIA, cross-border, children's consent) apply, 6 months after the 16 Jul 2026 enactment.
April 20272 deadlines
Discretionary 60-day cure period ends
The Division's discretionary notice-and-cure (at least 60 days) applies only to violations occurring on or before April 1, 2027 (Com. Law 14-4614).
May 20271 deadline
Main data fiduciary obligations apply (18 months)
Rules 3, 5-16, 22 and 23 (notice, security safeguards, breach notification, retention, children's consent, SDF duties, cross-border) come into force 18 months after publication.
July 20271 deadline
First annual report to Office of Suicide Prevention
Operators begin annual reporting on crisis referrals and detection protocols.
August 20271 deadline
- EU AI ActEuropean Union
Legacy GPAI models must comply; national AI sandboxes operational
Providers of GPAI models placed on the market before 2 Aug 2025 must comply (Art 111(3)). Each Member State must have at least one national AI regulatory sandbox operational (Art 57(1) as amended by the Omnibus).
December 20272 deadlines
- EU AI ActEuropean Union
High-risk obligations apply to Annex III systems
Chapter III Sections 1-3 (high-risk requirements and provider/deployer obligations) apply to AI systems classified high-risk under Art 6(2) and Annex III (employment, credit scoring, education, biometrics, essential services and similar). Deferred from 2 Aug 2026 by Regulation (EU) 2026/1744.
Risk assessments for pre-existing processing due
Risk assessments must be completed and documented for high-risk processing that began before Jan 1, 2026 and continues after (11 CCR 7155(b)).
April 20282 deadlines
First risk assessment submission to CPPA
Businesses must submit required risk assessment information and attestation for assessments conducted in 2026 and 2027 (11 CCR 7157(a)(1)); annually by April 1 thereafter.
Cybersecurity audit due: revenue over $100M
First cybersecurity audit report (covering Jan 1, 2027 - Jan 1, 2028) and certification due for businesses with 2026 annual gross revenue over $100M (11 CCR 7121(a)(1)).
August 20281 deadline
- EU AI ActEuropean Union
High-risk obligations apply to Annex I product-embedded systems
Chapter III Sections 1-3 apply to AI systems classified high-risk under Art 6(1) and Annex I (safety components of products covered by EU harmonisation legislation). Deferred from 2 Aug 2027 by Regulation (EU) 2026/1744.
October 20281 deadline
Data brokers must process state deletion mechanism requests
Registered data brokers must access the DCP accessible deletion mechanism at least every 45 days and process deletion requests.
April 20291 deadline
Cybersecurity audit due: revenue $50M-$100M
First cybersecurity audit report (covering 2028) due for businesses with 2027 annual gross revenue between $50M and $100M (11 CCR 7121(a)(2)).
April 20301 deadline
Cybersecurity audit due: revenue under $50M
First cybersecurity audit report (covering 2029) due for covered businesses with 2028 annual gross revenue under $50M (11 CCR 7121(a)(3)); annual by April 1 thereafter.
August 20301 deadline
- EU AI ActEuropean Union
Public-authority high-risk systems must comply
Providers and deployers of high-risk AI systems intended for use by public authorities that were placed on the market before the Chapter III application date must comply (Art 111(2), as replaced by the Omnibus).
December 20301 deadline
Past deadlines
August 20263 deadlines
- Digital Services ActEuropean Union
ChatGPT designated as VLOSE; Reddit and Roblox as VLOPs
Commission designated ChatGPT as a very large online search engine and Reddit and Roblox as very large online platforms. They have four months (by January 2027) to meet VLOP/VLOSE obligations.
- EU AI ActEuropean Union
General application: transparency obligations, GPAI fines, most other rules
The AI Act's general date of application. Article 50 transparency obligations (chatbot disclosure, deepfake labelling, machine-readable marking of synthetic content) and Commission fines on GPAI providers (Art 101) apply. Not deferred by the Omnibus.
Profiling impact assessments apply
Impact assessment requirements apply to profiling activities created or generated on or after Aug 1, 2026 (Conn. Gen. Stat. 42-522 as amended).
July 20265 deadlines
2026 APPI amendment act promulgated
Amendment enacted by the Diet on 10 July 2026 and promulgated; main provisions take effect by cabinet order within two years of promulgation.
Ban on selling precise geolocation data (SB 338)
Controllers may not sell consumers' precise geolocation data (1,750-ft radius), replacing the prior consent-based treatment.
Mandatory 30-day cure period expires
The Division's duty to issue a cure notice before enforcement ends on the first day of the 18th month after the effective date (N.J.S.A. 56:8-166.17(b)).
PA 25-113 (SB 1295) amendments take effect
Thresholds drop to 35,000 consumers or any sensitive-data processing or data sale; expanded sensitive data, minors' protections, and LLM-training disclosure in privacy notices.
June 20261 deadline
A5328 sensitive data sale ban takes effect
A5328, signed June 30, 2026, prohibits selling sensitive personal data; the ban took effect on signing.
May 20261 deadline
Platform notice-and-removal process required
Covered platforms must have a clear notice-and-removal process and remove valid reported content within 48 hours (Sec. 3, one year after enactment).
April 20263 deadlines
Full compliance with amended COPPA Rule
Operators must comply with all amended provisions (separate third-party disclosure consent, written retention policy, written security program, updated notices); excludes Safe Harbor provisions 312.11(d)(1), (d)(4) and (g), which had earlier dates.
Fee notification window closes (2026/27)
Fee-liable providers must notify Ofcom before the notification window for the first charging year closes.
MODPA applies to personal data processing
The act applies to personal data processing activities from April 1, 2026 (Section 2 of ch. 455).
March 20261 deadline
ECA Digital in force
Art. 41-A (as set by Law 15.352/2026, following MP 1.319/2025) fixes entry into force on 17 March 2026.
February 20261 deadline
SB 854 preliminarily enjoined (NetChoice v. Jones)
E.D. Va. preliminarily enjoined enforcement of the SB 854 social media time-limit provisions on First Amendment grounds; Virginia has appealed.
January 202610 deadlines
Under-16 social media time limit (SB 854) takes effect
Social media platforms must use commercially reasonable age determination and cap users under 16 at 1 hour/day unless a parent consents. A preliminary injunction issued Feb 27, 2026 bars enforcement.
PDPL and Decree 356/2025 take effect
Personal data protection obligations, DPIA/TIA filing and penalty framework apply; Decree 13/2023 replaced.
Sale ban on precise geolocation and under-16 data (HB 2008)
Selling precise geolocation (1,750-ft radius) and the personal data of consumers the controller knows or willfully disregards are under 16 is prohibited.
Universal opt-out signals must be honored
Controllers must honor opt-out preference signals such as Global Privacy Control.
Cure period sunsets
The AG's 30-day notice-and-cure requirement expires; enforcement can proceed without a cure opportunity.
- New Hampshire Privacy ActNew Hampshire
Mandatory 60-day cure period expires
The AG's obligation to issue a cure notice ended Dec 31, 2025; from Jan 1, 2026 cure opportunities are discretionary (RSA 507-H:11 II-III).
Opt-out preference signals must be honored
Controllers must allow opt-out of targeted advertising and sale via opt-out preference signals (12D-106).
New CCPA regulations take effect
ADMT, risk assessment, cybersecurity audit and updated CCPA regulations become effective; risk assessments required for new high-risk processing.
Chatbot safeguards apply
AI disclosure, suicide and self-harm protocols, and minor protections apply.
December 20252 deadlines
Mandatory 60-day cure period expires
Mandatory notice-and-cure ends Dec 31, 2025; from Jan 1, 2026 DOJ decides whether to offer a cure using statutory factors.
Social media minimum age obligation applies
Age-restricted platforms must take reasonable steps to prevent under-16s from holding accounts.
November 20252 deadlines
DPDP Rules published; Board and procedural rules in force
Rules 1, 2 and 17-21 (Data Protection Board constitution and functioning) take effect on publication in the Official Gazette.
October 20254 deadlines
SB 243 signed
SB 243 chaptered (ch. 677).
SB 297 amendments take effect; cure period eliminated
Lower thresholds (25,000 / 15,000 + 25%), minors' data protections, AG assessment demands; the 60-day cure period is removed.
MODPA takes effect
Act takes effect; data protection assessments apply to processing activities on or after Oct 1, 2025.
Minors' data amendment (SB 24-041) effective
Controllers offering online services to minors must use reasonable care, conduct assessments, and obtain consent for targeted ads, sale and certain profiling of minors.
September 20251 deadline
ADMT, risk assessment and cybersecurity audit regulations approved
OAL approves the CCPA Updates, Cybersecurity Audit, Risk Assessment, ADMT and Insurance regulations and files them with the Secretary of State.
August 20251 deadline
- EU AI ActEuropean Union
GPAI, governance, notified bodies and penalties apply
Chapter III Section 4 (notifying authorities), Chapter V (general-purpose AI model obligations), Chapter VII (governance), Chapter XII (penalties, except Art 101) and Art 78 apply (Art 113(b)).
July 20254 deadlines
Protection of children duties apply
Children's safety duties and Protection of Children Codes take effect, including highly effective age assurance; children's risk assessments due by 24 July 2025.
Universal opt-out mechanism must be honored
Controllers that sell personal data or process it for targeted advertising must honor user-selected universal opt-out signals within six months of the effective date (N.J.S.A. 56:8-166.11).
OCPA applies to nonprofits
Nonprofit organizations meeting the thresholds become subject to OCPA.
Biometric identifier amendment (HB 24-1130) effective
Any controller processing biometric identifiers must adopt a written biometric policy, give notice, obtain consent and follow retention/deletion rules.
June 20251 deadline
Amended COPPA Rule takes effect
The April 2025 amendments to 16 CFR Part 312 became effective; during the transition operators could comply with either the pre-2025 or the amended Rule.