SB 836, titled the Children and Teens’ Online Privacy Protection Act, would substantially amend the Children’s Online Privacy Protection Act of 1998 (COPPA) to extend and modernize privacy protections for minors online. The bill expands coverage beyond websites and online services to include online applications, mobile applications, and services offered through connected devices. It also adds a new protected category of “teen” for users ages 13 through 16, and broadens the definition of personal information to include persistent identifiers, geolocation data, biometric information, photos, videos, audio files, and other linked or linkable data collected online.
The bill would prohibit operators from collecting, using, disclosing, maintaining, or retaining minors’ personal information for individual-specific advertising, except in limited circumstances such as contextual advertising or responses to a user’s specific request. It also requires stronger notice, verifiable consent, deletion, correction, access, and security obligations, including teen-specific rights to review and delete data. In addition, it addresses educational technology arrangements, limits retention and foreign storage/transfer of minors’ data without notice, and directs the FTC to study common verifiable consent mechanisms, publish certain safe-harbor materials, issue guidance on knowledge of a user’s age, and report to Congress on enforcement and oversight.
The bill’s impact on state law is significant but not absolute: it would preempt state laws only where they conflict with the federal requirements, while expressly preserving the ability of states to enact stronger protections for children and teens. It would also expand enforcement authority by clarifying the role of state attorneys general and updating provisions governing FTC administration, safe harbors, and enforcement reporting. In practical terms, the bill would impose new compliance obligations on online platforms, app developers, mobile services, ad-tech providers, and operators of connected devices that collect data from children or teens.
Overall sentiment appears favorable toward stronger youth privacy protections, as reflected by the bill’s passage in the Senate and its broad consumer-protection framing. The legislation is structured as a modernization of COPPA rather than a wholesale rewrite, suggesting an effort to build on existing law while responding to newer technologies and data practices. There is no recorded committee transcript or vote breakdown in the provided material, so the available record does not show organized opposition or detailed debate.
The main points of contention likely center on the bill’s expanded scope and compliance burden. Potentially disputed issues include the inclusion of teens, the broadened definition of personal information, limits on advertising and profiling, requirements tied to deletion and correction rights, and the standard for determining when an operator has “knowledge fairly implied on the basis of objective circumstances” that a user is under 17. The bill also anticipates concerns from operators by directing the FTC to assess common consent mechanisms and by requiring regulatory flexibility analysis for small entities, indicating awareness that app developers, schools, and online services may view implementation costs and age-determination obligations as burdensome.
SB 836 would amend COPPA’s core definitions and enforcement provisions, expanding the statute to cover online applications, mobile applications, and connected devices, and extending privacy protections from children to teens ages 13 through 16. It would create new federal requirements for notice, consent, data minimization, retention limits, deletion, correction, access, and security, while restricting individual-specific advertising and clarifying permissible contextual advertising and internal operations uses. It also updates FTC safe-harbor, reporting, guidance, and study obligations, and authorizes state attorneys general to enforce the amended provisions. State laws would be preempted only to the extent of conflict, and states could still adopt stronger protections.
The overall sentiment reflected in the available record is supportive of stronger online privacy protections for minors. The bill passed the Senate, and its text frames the changes as a modernization of existing child privacy law to address current digital platforms and data practices. No committee transcript or vote details were provided, so there is no documented floor or committee opposition in the supplied materials.
Likely areas of contention include the bill’s expanded coverage to teens and to mobile apps, online applications, and connected devices; the broader definition of personal information, especially persistent identifiers and biometric data; and the restrictions on targeted advertising and profiling. Operators may also object to the new deletion, correction, and access rights, the retention and cross-border transfer limits, and the standard for determining when a company has knowledge that a user is a child or teen. The bill tries to address some of these concerns by allowing contextual advertising, preserving certain internal operations uses, and directing the FTC to study common verifiable consent mechanisms and issue guidance, but those provisions may not fully resolve compliance concerns for platforms, ad-tech firms, schools, and small entities.