COPPA was enacted in 1998 and last meaningfully amended in 2013. GDPR-K — the children's provisions of the EU General Data Protection Regulation — entered force in 2018. Between them, these two instruments constitute the global baseline for children's data protection. Both are showing their age. COPPA's under-13 line, "actual knowledge" trigger, and verifiable parental consent mechanism are mismatched to social media, AI, and connected devices. GDPR-K's variable age threshold (13-16 across member states) and reliance on parental consent that few platforms verify rigorously have produced more form than function. Both regimes were drafted for a web of websites accessed from desktop computers. The web has moved.
Begin with COPPA. The statute targets "operators" of websites or online services "directed to children" or with actual knowledge of users under 13. It requires verifiable parental consent, parental access to data, limits on retention, and prohibitions on conditioning participation on more data than is reasonably necessary. The FTC enforces. Penalties can reach $51,744 per violation (2024 adjustment). Major enforcement actions — YouTube ($170M, 2019), TikTok ($5.7M and $92M, 2019 and 2024), Epic Games ($275M, 2022), Amazon Alexa ($25M, 2023), Microsoft Xbox ($20M, 2023) — have signalled FTC seriousness. But the statute's architecture creates predictable failure modes: platforms structure themselves to avoid "actual knowledge" by not asking ages; "directed to children" is interpreted narrowly; the "verifiable parental consent" mechanisms are weak (credit-card $0 charges, signed forms) and easily defeated.
Then GDPR-K. Article 8 requires parental consent for processing of personal data of children below the digital-consent age, set at 16 by default with member-state option to lower to 13. Recital 38 specifies that children "merit specific protection." Article 12 requires information to be provided to children "in clear and plain language that the child can easily understand." Enforcement is by national Data Protection Authorities, with the European Data Protection Board coordinating. The Irish DPC's enforcement against TikTok (€345M, 2023) and Instagram (€405M, 2022) signalled that Europe will act on children's data violations. But the same Irish DPC has been criticized for slow enforcement and small initial fines that are later raised under EDPB pressure. The European model has more teeth than COPPA but less consistent bite.
What comes next is contested but its shape is becoming visible. Six trajectories are clear. First, age limits will rise: the under-13 line is being replaced by under-16, under-17, or under-18 lines across jurisdictions. Second, behavioural advertising to minors will be restricted or banned: the UK ICO Code, California AADC, EU DSA, and proposed federal US legislation all converge here. Third, age-appropriate design will become mandatory: defaults will favour privacy, recommendations will be restricted for minors, and dark patterns will be prohibited. Fourth, AI-specific provisions will appear: training-data restrictions, deletion rights for content involving minors, prohibitions on AI companion services for under-16s. Fifth, enforcement budgets will rise: the FTC, ICO, and DPAs cannot keep pace at current funding. Sixth, private rights of action will proliferate: state AG enforcement plus consumer class actions will distribute enforcement beyond regulators.
The conceptual move underneath all six trajectories is from notice-and-consent to data-minimization. Notice-and-consent — the architecture of the 1990s — assumes a user can read a privacy policy, understand it, and make a meaningful choice. Children cannot. Most adults cannot. Data-minimization — collect only what is necessary, retain only as long as necessary, share only with whom is necessary — does not depend on user comprehension. It depends on regulatory specification and enforcement. The shift from notice to minimization is the most important policy move of the next decade. Parents who organize collectively should pull in this direction.
There is also a generational reckoning underway. The children who grew up under COPPA's protections — millennials and elder Gen Z — are now adults discovering that their childhood data is in training corpora, breach databases, and persistent platform records. Some are litigating. More are politically active in ways that distinguish them from prior generations on technology policy. They are the most pro-regulation cohort in modern US polling on tech issues. They will be the legislators of the 2030s. Collective parenthood now should anticipate that constituency and build infrastructure that they can inherit and extend.
The risk in the transition is overreach. Statutes drafted in panic — moral, electoral, technological — tend to be poorly tailored and to produce backlash that resets the conversation. KOSA, the UK Online Safety Act, and several state laws have features that civil-liberties groups credibly fear. The 1,000-page manual takes no fixed position on each individual provision but observes that the most durable laws will be those drafted with input from regulators, platforms, civil society, and children themselves. Children themselves are the missing constituency. Their participation is required by Article 12 of the CRC and largely absent from US legislative practice. Collective parenthood that takes its children's voices seriously will produce better law than collective parenthood that speaks only for them.