Broader Protections for Kids Under New CCPA Amendment
California is imposing tough new rules on processing the data of anyone under the age of 18. Learn the requirements, business impact, and compliance steps.

Update: California Governor Gavin Newsom has since vetoed this legislation and it will not become law.
The California Assembly has significantly increased privacy protections for minors under the California Consumer Privacy Act (CCPA). Other states such as Virginia and Colorado have also amended their privacy legislation to enhance protections for children, but with the passage of AB 1949, California has upped the ante.
See what the new changes mean for businesses.
Protecting Consumers Under 16 Under 18
The CCPA already has some additional privacy requirements when it comes to younger consumers. Currently, businesses may not sell or share the personal information of consumers under the age of 16 without their affirmative consent; if the consumer is under the age of 13, their parent or guardian must consent.
The first big change in AB 1949 is raising the age threshold from under-16 to under-18. That is, businesses may not sell or share the personal information of anyone under the age of 18 without their consent. (The under-13 threshold remains in place.)
The second big change is that businesses will also be prohibited from collecting, using, or disclosing any personal information from consumers under the age of 18 without their consent. This is a major expansion of existing protections for minors; in fact, it seems to make the restrictions on selling or sharing minors’ data entirely redundant.
A Privacy Signal for Minors?
Businesses must follow the rules described above when they have actual knowledge that the consumer is under the age of 18 or 13. Knowing that, many companies may think they’re off the hook because they don’t knowingly process the personal information of minors unless their services are geared towards children.
That may continue being the case for now, but AB 1949 highlights an aspect of the CCPA that is seldom talked about: the contemplation of an opt-out signal that identifies the consumer as being a minor.
In theory, devices or browsers could send a signal to websites and apps (similar to Global Privacy Control) that identifies the consumer as under-13 or under-18. The CCPA authorizes the California Privacy Protection Agency (CPPA) to create regulations about how such a signal would function. So far, the CPPA has not addressed this issue in any regulations.
AB 1949 puts the signal in the spotlight by clarifying that receipt of such a signal would constitute actual knowledge that a consumer is a minor. In other words, if a website detected the signal, it would have to follow the under-18 or under-13 data processing rules with respect to that consumer. By bringing attention to this issue, AB 1949 may increase the pressure on the CPPA to make the children’s opt-out signal a regulatory priority.
If and when that happens, a lot more businesses may have to figure out how to navigate the tough new rules on children’s data.
The provisions of AB 1949 will take effect on January 1, 2025.
Privacy work that stays current — without adding more chaos.
TrueVault helps lean ecommerce teams keep privacy workflows current as vendors, tracking tools, and privacy laws keep changing.










