The FTC’s updated COPPA Rule reached its enforcement deadline on April 22, 2026. Three months in, the practical consequences are landing on publishers who never considered themselves child-directed — and the state law layering on top is where the real complexity lives.
01What changed, and what didn’t
The federal liability standard is still “actual knowledge” that a user is under 13. That is the part that hasn’t changed, and it’s the part publishers have historically leaned on.
What the FTC did clarify is helpful: if you are doing age gates or age checks in good faith and not using that data for anything else, the agency has signalled it won’t treat that alone as a COPPA violation. That removes a genuine chilling effect — publishers previously worried that asking a user’s age created the knowledge that triggered liability. Good-faith age assurance is now safer than willful ignorance.
The state layer is where it gets hard. Multiple states have enacted youth privacy laws with incompatible definitions:
| Age thresholds vary | some protect minors under 16, others extend to 17 or 18. |
|---|---|
| Maryland | bans personal data sales and targeted advertising to minors outright. |
| Other states | permit targeting only under stricter conditions with consent. |
| Separate age-verification mandates | now apply to sites and app stores. |
And several state laws experiment with a “should have known” standard rather than actual knowledge — a materially higher bar that ignorance no longer satisfies. As one practitioner put it this week: “It’s getting really, really complex,” and “not knowing who’s in your audience isn’t good enough anymore.”
02The programmatic problem
Publishers can no longer simply self-attest that their content isn’t child-directed; platforms are expected to actively identify child-directed inventory. OpenX has responded by building a dedicated marketplace for vetted child-directed inventory with external COPPA Safe Harbor oversight.
The signalling layer remains weak. The COPPA RTB signal exists but is binary — a single flag with no gradation — and many DSPs respond to it by refusing the traffic entirely. The perverse result: flagging your inventory honestly can cost you all demand for it, which is a direct disincentive to compliant signalling. This is the classic pattern where a well-intentioned signal, poorly designed, punishes the honest party.
Children's privacy has quietly become the strictest regime in digital advertising, and it now applies by audience rather than by intent.
03Why this matters for publishers
- This is not just a kids’ media problem. General-audience publishers with gaming, sports, music, entertainment or education content carry mixed audiences. Under a “should have known” standard in some states, “we’re not a children’s site” stops being a defence you can assert without evidence.
- Compliance currently reduces revenue. Flag the inventory correctly and DSPs may drop it. Until either the signal gains nuance or curated marketplaces like OpenX’s scale, honest publishers take the yield hit and the sloppy ones don’t. Budget for that gap rather than being surprised by it.
- Fifty definitions is an operational cost, not a legal one. Different ages, different consent rules, different targeting bans by state means geo-conditional ad serving logic. That is engineering work with a deadline, not a memo from counsel.
04What publishers should do
05The bottom line
Children’s privacy has quietly become the strictest regime in digital advertising, and it now applies by audience rather than by intent. The FTC has made good-faith age checking safe; the states have made not knowing dangerous. For publishers, that combination points one way — find out who is actually in your audience, write it down, and build the plumbing to treat different users differently. The publishers who do it deliberately this year will be selling compliant inventory while everyone else is explaining themselves.