The California Age-Appropriate Design Code Act
United States • California
RAI-US-CA-AB2273-2022AB 2273
California's AB 2273 mandates 'privacy by design' for online services accessed by children under 18, with key provisions now enforceable despite legal challenges.
Summary
Read full text ↗Plain English
Overview
The California Age-Appropriate Design Code Act (AB 2273), signed into law on September 15, 2022, represents a landmark effort by the State of California to enhance online privacy and safety for children. Modeled after the United Kingdom's Age-Appropriate Design Code, this Act introduces stringent requirements for businesses that provide online services, products, or features likely to be accessed by individuals under the age of 18. The core philosophy of the Act is to mandate a 'design-by-default' approach, compelling technology companies to proactively integrate privacy, safety, and well-being considerations into the very architecture of their online offerings, rather than treating them as afterthoughts. This proactive stance aims to mitigate potential harms to children before they manifest, addressing concerns ranging from data exploitation to exposure to harmful content and manipulative design practices. The legislation was initially slated to become enforceable on July 1, 2024, marking a significant shift in how online platforms must interact with younger users.
However, the implementation journey of the California Age-Appropriate Design Code Act has been marked by significant legal challenges. Shortly after its enactment, a preliminary injunction was granted in September 2023, temporarily blocking its enforcement following a lawsuit filed by NetChoice, an industry trade association, on First Amendment grounds. This legal battle introduced uncertainty regarding the Act's future and its full scope. In a pivotal development on March 12, 2026, the U.S. Court of Appeals for the Ninth Circuit issued a ruling that partially upheld and partially vacated the preliminary injunction. This decision means that while some key provisions of the Act, such as age estimation and default privacy settings, are now permitted to take effect as of April 3, 2026, other aspects, particularly those involving vague terms like "materially detrimental" or "best interests," remain enjoined or subject to further litigation. The Act's ambition to create a safer digital environment for minors, extending protections beyond the federal Children's Online Privacy Protection Act (COPPA) to cover individuals up to 18 years old, continues to shape the discourse around online child safety and privacy in the United States and potentially globally.
Definitions
The California Age-Appropriate Design Code Act establishes several critical definitions that delineate its scope and application. Central to the Act is the definition of a "child" as any individual under 18 years of age. This broad interpretation significantly expands the protective reach compared to federal laws like COPPA, which traditionally focuses on children under 13. By encompassing teenagers, the Act acknowledges the evolving digital landscape and the unique vulnerabilities faced by adolescents online. This expanded definition necessitates that businesses consider a wider age range when designing and implementing their privacy and safety protocols, moving beyond the traditional understanding of child-directed content to include platforms and services that are merely 'likely to be accessed' by minors.
Another pivotal term is "online service, product, or feature likely to be accessed by children." This definition is not limited to services explicitly targeting minors but extends to any online offering that meets specific criteria. These criteria include being defined as child-directed by COPPA, being routinely accessed by a significant number of children, or where internal company research indicates children represent a significant portion of the audience. It also covers services substantially similar to those children routinely access or that display ads marketed to children. Crucially, the Act clarifies that this definition does not include broadband internet access services or telecommunications services, thus focusing its regulatory efforts squarely on content and interaction platforms. The Act also introduces the concept of a "Data Protection Impact Assessment (DPIA)," requiring businesses to conduct a systematic evaluation of risks to children arising from their data management practices. Furthermore, "dark patterns" are explicitly prohibited, defined as manipulative design choices that encourage children to compromise their privacy or engage in actions detrimental to their well-being. Lastly, "age estimation" becomes a key obligation, requiring businesses to either reasonably ascertain a user's age or apply child-level protections to all users, underscoring the Act's preventative design philosophy.
Governance and Institutional Framework
The enforcement and oversight of the California Age-Appropriate Design Code Act are primarily entrusted to two key state entities: the California Attorney General (AG) and the California Privacy Protection Agency (CPPA). The Attorney General is empowered to initiate legal actions, including seeking injunctions and imposing civil penalties against businesses found to be in violation of the Act's provisions. This authority underscores the state's commitment to holding companies accountable for their online practices concerning minors. The AG's office is expected to play a crucial role in investigating complaints, ensuring compliance, and pursuing remedies for harms caused to children by non-compliant online services. The Act's framework allows for a robust enforcement mechanism, providing the necessary legal tools to address both negligent and intentional violations, thereby reinforcing the protective intent of the legislation.
Complementing the Attorney General's enforcement powers, the California Privacy Protection Agency (CPPA), established under the California Privacy Rights Act (CPRA), is also vested with administrative authority to implement and enforce the Age-Appropriate Design Code Act. The CPPA's role extends to developing regulations and providing guidance to businesses, particularly small and medium-sized enterprises, to facilitate compliance. A significant institutional component created by the Act is the California Children's Data Protection Working Group. This taskforce is mandated to evaluate best practices for the Act's implementation and to provide recommendations to the Legislature. The working group comprises experts in children's data privacy, physical and mental health, technology, and children's rights, ensuring a multidisciplinary approach to addressing the complex challenges of online child safety. This collaborative framework aims to ensure that the Act's provisions are effectively translated into practical, enforceable standards that protect children while fostering innovation.
Key Focus Areas
The California Age-Appropriate Design Code Act introduces several key obligations for businesses, fundamentally reshaping how online services interact with children. A primary requirement is the mandate to configure all default privacy settings offered by an online service, product, or feature to the highest level of privacy, unless the business can demonstrate a compelling reason that a different setting is in the best interests of children. This 'privacy by default' principle aims to ensure that children are automatically afforded the strongest protections without needing to navigate complex settings. This provision is critical in preventing the inadvertent sharing of personal information and limiting exposure to potentially harmful content or interactions. The Act prioritizes the well-being of the child, shifting the burden onto businesses to justify any deviation from the highest privacy standards.
Another central focus is the requirement for businesses to conduct and maintain Data Protection Impact Assessments (DPIAs) for any new online service, product, or feature likely to be accessed by children before it is offered to the public. These assessments must systematically identify and mitigate risks of material detriment to children arising from the business's data management practices. Furthermore, the Act imposes strict limitations on the collection, sale, sharing, or retention of children's personal information, permitting it only for reasons strictly necessary to provide the requested service, unless a compelling reason in the child's best interest can be demonstrated. The Act also explicitly prohibits the use of "dark patterns" to influence children's decisions regarding privacy or to encourage actions detrimental to their well-being. Additionally, businesses are largely restricted from collecting precise geolocation information by default for children, and if collected, an obvious and continuous signal must be displayed. Transparency is also a key element, requiring privacy information, terms of service, and community standards to be provided concisely, prominently, and in clear, age-appropriate language. These provisions collectively aim to create a digital environment that is safer, more transparent, and inherently respectful of children's rights and developmental stages.
Implementation Framework
The implementation framework for the California Age-Appropriate Design Code Act places a significant onus on businesses to proactively adapt their online services, products, and features to meet the Act's child-centric design principles. Commencing with the original effective date of July 1, 2024, and now with key provisions taking effect as of April 3, 2026, businesses are required to integrate privacy and safety considerations into the initial design and development stages. This involves a fundamental shift from reactive measures to a 'privacy by design' and 'safety by design' approach. A cornerstone of this framework is the mandatory completion of Data Protection Impact Assessments (DPIAs) for any online offering likely to be accessed by children. These assessments are not merely a formality but a critical tool for identifying, documenting, and mitigating potential risks to children's physical and mental well-being before a service is launched. Businesses must maintain documentation of these DPIAs for as long as the online service is likely to be accessed by children, demonstrating ongoing vigilance and accountability.
Beyond DPIAs, the implementation framework mandates several operational changes. Businesses must implement mechanisms to estimate the age of child users with a reasonable level of certainty or, alternatively, apply the full suite of child-level privacy protections to all users. This requirement ensures that appropriate safeguards are in place regardless of precise age knowledge. Furthermore, the Act necessitates that privacy policies, terms of service, and community standards are presented in clear, concise, and age-appropriate language, making them understandable to the children they are designed to protect. This moves beyond legal jargon to foster genuine comprehension and informed consent, where applicable. The prohibition of dark patterns and the restrictions on the collection and use of personal information, particularly geolocation data, require businesses to re-evaluate their user interfaces and data handling practices. The overall framework emphasizes a continuous compliance cycle, where businesses are expected to regularly review and update their practices to align with the evolving understanding of children's online safety and the guidance provided by regulatory bodies.
Monitoring and Evaluation
Monitoring and evaluation under the California Age-Appropriate Design Code Act are multifaceted, involving both proactive assessments by businesses and oversight by state authorities. A cornerstone of the monitoring framework is the mandatory Data Protection Impact Assessment (DPIA). Businesses are required to conduct these assessments before offering any new online service, product, or feature likely to be accessed by children. These DPIAs serve as a self-regulatory mechanism, compelling companies to systematically identify and document potential risks to children's well-being arising from their data management practices. The documentation of these assessments must be maintained for the entire duration that the online service is likely to be accessed by children, providing a continuous record of risk identification and mitigation efforts. This proactive evaluation ensures that potential harms are considered and addressed at the design stage, rather than reactively after issues have arisen.
The California Attorney General (AG) and the California Privacy Protection Agency (CPPA) play a critical role in the external monitoring and evaluation of compliance. The AG has the authority to request DPIAs from businesses, which must be provided within five business days of a written request. This allows the AG's office to scrutinize a business's risk assessments and ensure they are adequately addressing potential harms to children. Furthermore, the Act established the California Children's Data Protection Working Group, tasked with evaluating best practices for implementation and providing support to businesses. This working group is also responsible for delivering a report to the Legislature regarding recommendations and best practices, contributing to the ongoing evolution of regulatory guidance. The CPPA, in consultation with this taskforce, is also empowered to adopt necessary regulations, ensuring that the Act remains responsive to technological advancements and emerging challenges in children's online safety. This combination of internal business assessments, regulatory oversight, and expert working group input forms a comprehensive system for monitoring and evaluating the effectiveness of the Act.
Penalties, Liability, and Appeals
The California Age-Appropriate Design Code Act establishes significant penalties for non-compliance, underscoring the state's serious commitment to protecting children online. Businesses found in violation of the Act's provisions can face substantial civil penalties. For negligent violations, the penalty can be up to $2,500 per affected child for each violation. In cases of intentional violations, the penalties escalate significantly, reaching up to $7,500 per affected child for each violation. Given the potential for a large number of affected children on widely used online platforms, these fines could amount to millions or even billions of dollars, serving as a powerful deterrent for non-compliance. The California Attorney General is authorized to seek these civil penalties, as well as injunctions, to compel businesses to adhere to the Act's requirements. Any penalties, fees, and expenses recovered are intended to be deposited into the Consumer Privacy Fund, with the aim of offsetting the costs incurred by the Attorney General in enforcing the Act.
The Act's liability framework has been subject to considerable legal scrutiny and ongoing appeals. Following its enactment, a preliminary injunction was granted in September 2023, temporarily halting enforcement of the entire statute. This injunction was challenged by the California Attorney General, leading to a significant ruling by the U.S. Court of Appeals for the Ninth Circuit on March 12, 2026. The Ninth Circuit's decision partially upheld and partially vacated the injunction. Specifically, the court invalidated certain obligations, such as those related to using personal information "materially detrimental" to a child's well-being or not in their "best interests," on the grounds that these statutory terms were unconstitutionally vague. However, the ruling revived other key design requirements, including age estimation and the implementation of the most protective privacy settings by default. This mixed outcome means that while some provisions are now enforceable as of April 3, 2026, others remain enjoined or will require further litigation at the district court level to clarify their enforceability, creating a complex and evolving landscape for businesses regarding their potential liability.
Relationship to Other Instruments
The California Age-Appropriate Design Code Act (CAADCA) operates within a broader landscape of privacy and child protection legislation, both at the state and federal levels, and draws significant inspiration from international models. Crucially, the CAADCA explicitly declares that its provisions further the purposes and intent of the California Privacy Rights Act of 2020 (CPRA). The CPRA, which established the California Privacy Protection Agency (CPPA), provides the overarching framework for consumer privacy in the state, and the CAADCA builds upon this foundation by introducing specific protections for minors. This relationship means that businesses already subject to CPRA compliance will need to integrate the additional, more stringent requirements of the CAADCA when dealing with child users, particularly concerning data processing and privacy settings. The CPPA's role in enforcing both acts ensures a cohesive approach to privacy regulation within California.
The CAADCA also significantly expands upon the federal Children's Online Privacy Protection Act (COPPA). While COPPA primarily focuses on online services directed at children under 13 and requires parental consent for data collection, the CAADCA extends protections to all individuals under 18 years of age. Furthermore, the CAADCA applies to any online service, product, or feature "likely to be accessed by children," a broader trigger than COPPA's "directed to children" standard. This wider scope and higher age threshold mean that many businesses previously outside of COPPA's direct purview may now be subject to the CAADCA's obligations. Internationally, the CAADCA is explicitly modeled on the United Kingdom's Age-Appropriate Design Code (UK AADC), which became enforceable in September 2021. This foundational influence is evident in many of the CAADCA's core principles, such as privacy by default, the prohibition of dark patterns, and the requirement for Data Protection Impact Assessments. By mirroring a successful international framework, California aims to leverage established best practices in child online safety, positioning itself as a leader in this domain within the United States.
International Alignment
The California Age-Appropriate Design Code Act (CAADCA) demonstrates a clear international alignment, primarily by drawing significant inspiration from the United Kingdom's Age-Appropriate Design Code (UK AADC). The UK AADC, which became enforceable in September 2021, set a global precedent for how online services should be designed to protect children's privacy and safety. California's decision to model its legislation on this successful framework highlights a recognition of international best practices in addressing the complex challenges of the digital environment for minors. This alignment is evident in shared principles such as prioritizing the best interests of the child, implementing privacy by default settings, prohibiting manipulative design features (dark patterns), and requiring proactive risk assessments through Data Protection Impact Assessments (DPIAs). The intent behind this modeling is to ensure that California's legislation is robust, effective, and informed by real-world experience in regulating technology companies that operate across borders.
Given California's status as a global hub for technology and social media companies, the CAADCA is expected to have a far-reaching influence beyond state borders, potentially fostering a broader international alignment in child online safety standards. Many major technology companies already made adjustments to their services to comply with the UK AADC, and these changes often have a global impact due to the integrated nature of online platforms. The CAADCA's similar requirements mean that these companies may further standardize their child protection measures across their services, regardless of the user's geographical location, to ensure compliance in a key market like California. This ripple effect could encourage other jurisdictions, both within the United States and internationally, to consider similar legislative approaches, thereby contributing to a more harmonized global standard for age-appropriate online design. The Act's emphasis on the United Nations Convention on the Rights of the Child also underscores a commitment to universally recognized principles of child protection in the digital realm, further solidifying its international relevance.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Bill Introduced | 2022-02-16 | Assembly Bill 2273 introduced in the California Legislature. |
| Approved by Senate | 2022-08-30 | Unanimously agreed to and enacted in the Senate. |
| Signed by Governor | 2022-09-15 | Approved by Governor Gavin Newsom. |
| Original Effective Date | 2024-07-01 | Initial date for the Act to become enforceable. |
| Children's Data Protection Working Group Report Due | 2024-01-01 | Working group to submit report to the Legislature regarding recommendations and best practices. |
| CPPA Regulations Adoption Due | 2024-04-01 | California Privacy Protection Agency, in consultation with the taskforce, to adopt necessary regulations. |
| Preliminary Injunction Granted | 2023-09-18 | U.S. District Court for the Northern District of California granted a preliminary injunction, blocking enforcement. |
| Attorney General Appeals Injunction | 2023-10-18 | California Attorney General Robert Bonta filed a notice of appeal. |
| Ninth Circuit Partially Vacates Injunction | 2026-03-12 | U.S. Court of Appeals for the Ninth Circuit issued a ruling partially upholding and partially vacating the preliminary injunction. |
| Key Provisions Become Enforceable | 2026-04-03 | Following the Ninth Circuit's mandate, many previously enjoined provisions became effective. |
Compliance Checklist
| Check | Required Action |
|---|---|
| Identify Covered Services | Determine if your online service, product, or feature is 'likely to be accessed by children' (under 18) based on the Act's criteria. |
| Conduct Data Protection Impact Assessments (DPIAs) | Complete and maintain DPIAs for all covered services, assessing and mitigating risks to children's well-being. Document a timed plan to address identified risks. |
| Implement Privacy by Default | Configure all default privacy settings for child users to the highest level of privacy, unless a compelling reason for an alternative, child-beneficial setting can be demonstrated. |
| Ensure Age-Appropriate Language | Provide privacy policies, terms of service, and community standards concisely, prominently, and using clear language suited to the age of children likely to access the service. |
| Implement Age Estimation or Universal Protections | Estimate the age of child users with a reasonable level of certainty, or apply the privacy and data protections afforded to children to all users. |
| Prohibit Dark Patterns | Eliminate any design elements that lead or encourage children to forego privacy protections or take actions detrimental to their physical or mental health or well-being. |
| Limit Data Collection and Use | Restrict the collection, sale, sharing, or retention of personal information from children to only what is necessary to provide the service, unless a compelling reason in the child's best interest exists. |
| Restrict Geolocation Data | Do not collect, sell, or share precise geolocation information of a child by default. If strictly necessary, provide an obvious and continuous signal to the child during collection. |
| Provide Parental Monitoring Transparency | If the service allows parental or guardian monitoring, provide an obvious signal to the child that monitoring is taking place. |
| Establish Privacy Tools | Provide prominent, accessible, and responsive tools to help children (and their parents/guardians, where applicable) exercise their privacy rights and report concerns. |
Sources and References
| Source | Type |
|---|---|
| California Assembly Bill 2273 (Chaptered) | legal |
| California Attorney General Press Release on Appeal (October 18, 2023) | government |
| U.S. Court of Appeals for the Ninth Circuit Decision in NetChoice v. Bonta (March 12, 2026) | legal |
The California Age-Appropriate Design Code Act requires online services, products, and features likely to be accessed by anyone under 18 to prioritize their privacy and safety through proactive design.
This law applies broadly to any online service, not just those explicitly targeting minors. If your platform is routinely accessed by a significant number of children, or if your company's research shows they're a major audience, you're likely in scope. A "child" is defined as anyone under 18, significantly expanding protections beyond federal laws like COPPA, which focus on those under 13. Broadband internet and telecommunications services are exempt.
Businesses must adopt a "privacy by design" approach, meaning: - Default privacy settings must be at the highest level for children, unless there's a compelling, child-beneficial reason otherwise. - You must conduct Data Protection Impact Assessments (DPIAs) for new services, identifying and mitigating risks to children's well-being. - "Dark patterns"—manipulative designs that encourage children to compromise their privacy or act against their best interests—are prohibited. - The collection, sale, sharing, or retention of children's personal information is restricted to what's strictly necessary for the service, and precise geolocation data cannot be collected by default.
While initially slated for 2024, key provisions of the Act became enforceable on April 3, 2026, following a partial lifting of a legal injunction. Non-compliance carries significant civil penalties. Negligent violations can cost up to $2,500 per affected child, while intentional violations can reach $7,500 per child. The California Attorney General can seek these fines and injunctions.
A key surprise for many is the Act's expansive definition of "child" as anyone under 18. This means platforms not traditionally thought of as "for kids" may now need to implement these stringent protections for their teenage users, requiring a re-evaluation of user demographics and design choices.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
Related Regulations
Age appropriate design: a code of practice for online services
United Kingdom87% similar
New Jersey Age-Appropriate Design Code
New Jersey, United States87% similar
California AB 1831 - AI-Generated Child Sexual Abuse Material
United States86% similar
Walker Montgomery Protecting Children Online Act
United States85% similar
California SB 243 - Companion Chatbot Disclosure Requirements
United States85% similar
© Regulations.AI — created on 20-May-2026 using Gemini 2.5 Flash