If your website or app serves users under 17, or if minors could reasonably access your platform, you have a compliance challenge that goes beyond COPPA. The Kids Online Safety Act (KOSA), reintroduced in the 119th Congress as S.1748, represents a significant expansion of federal obligations for digital platforms that reach young users. Unlike COPPA, which focuses primarily on data collection from children under 13, KOSA extends to a broader age range, imposes affirmative design requirements, and creates duties of care that will require changes to your terms of service, privacy policy, and product design.
Many platform operators and app developers are still treating KOSA as a distant legislative concern. That is a miscalculation. The bill has advanced with substantial bipartisan support, and several states have already enacted laws mirroring KOSA’s framework. Even before federal enactment, the legal and commercial risk of platforms that fail to consider KOSA-style obligations is already materializing in litigation and state enforcement actions.
This guide explains what KOSA requires, who it covers, what your legal documents must address, and how to begin preparing your platform now.
1. KOSA vs. COPPA: What Changed and Why It Matters
The Children’s Online Privacy Protection Act (COPPA) has governed the online collection of personal data from children under 13 since 1998, with the FTC updating its rules most recently in 2013. COPPA requires verifiable parental consent before collecting personal data from children under 13, prohibits targeted advertising directed at that age group, and requires operators to provide parental access and deletion rights. COPPA compliance remains mandatory and enforcement has intensified in recent years.
KOSA goes further in three critical ways. First, it extends protections to minors up to age 17, not just children under 13. Second, it imposes an affirmative duty of care, requiring covered platforms to act in the best interests of minor users and to prevent algorithmic or design features that may cause harm. Third, it requires covered platforms to provide specific protective defaults for minor users, including turning off certain recommendation algorithms, restricting data-driven personalization, and enabling parental monitoring tools.
KOSA also gives both the FTC and state attorneys general enforcement authority, with civil penalties available for violations. The combination of broader age coverage, affirmative design obligations, and dual enforcement authority makes KOSA a materially different compliance challenge than COPPA.
2. Which Businesses KOSA Covers
KOSA applies to “covered platforms,” which the bill defines as online platforms, online video games, messaging applications, and video streaming services that are accessed by a significant number of minors. The definition is intentionally broad to prevent large platforms from claiming exemption based on narrow product category definitions.
Businesses that need to assess KOSA applicability include social media platforms, content publishing platforms, gaming and entertainment apps, educational technology products, marketplace apps where minors frequently transact, and any subscription or freemium service with a significant user base under 17.
KOSA excludes broadband internet access services, certain enterprise platforms, and platforms that are not primarily consumer-facing. However, the exemptions are narrow, and legal analysis of whether your platform qualifies for an exemption requires careful review of your actual user base and product design.
A critical point that many platform operators miss: KOSA does not require you to actually know that your users are minors. If minors are “reasonably likely” to access your platform based on its content, marketing, or audience, you may be covered. This standard is similar to how the FTC has applied COPPA to platforms that did not explicitly target children but operated in contexts where child access was foreseeable.
3. What KOSA Requires of Covered Platforms
KOSA imposes a duty of care requiring covered platforms to prevent and mitigate harms to minors from platform features and design choices. Specific harms the legislation targets include promotion of eating disorders, self-harm and suicide, substance use, depictions of sexual exploitation, and the exploitation of minors’ psychological vulnerabilities for commercial purposes.
Under the duty of care framework, platforms must conduct and document assessments of whether their design features, recommendation systems, and data practices may cause harm to minor users. This is not a passive obligation. It requires proactive internal analysis and documentation of how product decisions affect minor users.
KOSA also requires covered platforms to turn on specific safety defaults for minor users, including disabling algorithmic content recommendations by default, turning off push notifications during certain hours, setting account defaults to private, and restricting targeted advertising. Platforms must give parents tools to monitor minor users’ accounts, though with specific limitations to protect minor users’ own privacy interests.
4. What Your Terms of Service and Privacy Policy Must Address Under KOSA
KOSA creates specific documentation and disclosure requirements that affect both your privacy policy and your terms of service.
Your privacy policy must disclose whether your platform is accessible to minors, what default privacy settings apply to minor users, how parental supervision tools function, what data you collect from minor users and how you use it, and whether any data collected from minors is used for targeted advertising. If you currently do not segment your privacy policy disclosures by user age group, KOSA compliance will require you to revise that structure.
Your terms of service must address age-appropriate design requirements, describe the safety defaults available to minor users, explain how parents can request account review or monitoring, and set out what content restrictions apply to minor user accounts. Terms that currently treat all users identically, with a single age-gating clause and a reference to your privacy policy, will not satisfy KOSA’s disclosure framework.
Data minimization obligations under KOSA go beyond what COPPA requires. Covered platforms must limit data collection from minor users to what is reasonably necessary for the services they request. This means reviewing every data collection point that a minor user could reach and documenting the business necessity for each one. If your current data practices are justified by general business purposes, that justification is unlikely to survive KOSA’s minor-specific minimization analysis.
5. State-Level KOSA Equivalents Already in Effect
Even before federal KOSA enactment, several states have passed laws that impose similar obligations on platforms accessible to minors. California’s Age-Appropriate Design Code Act, effective September 2024, imposes data protection impact assessment requirements, default privacy settings for users under 18, and prohibitions on profiling minor users. Maryland, Connecticut, and other states have enacted similar frameworks.
If your platform operates nationally and does not currently comply with California’s Age-Appropriate Design Code or comparable state laws, you are already facing enforcement risk under existing statutes. Federal KOSA compliance builds on this state-level framework rather than replacing it.
6. How to Prepare Your Platform for KOSA Compliance
Platform operators should begin with a KOSA readiness assessment that covers three areas: user base analysis (what percentage of your users are under 17 and how you know), design and algorithm review (which recommendation, notification, and personalization features are active by default for all users), and document review (whether your current terms of service and privacy policy address minor-specific disclosures).
The next step is a data flow mapping exercise that identifies every point where your platform collects, processes, or shares data from user accounts that could belong to a minor. This mapping supports both your KOSA duty of care assessment and the data minimization analysis required by the law.
Your legal documents need revision before your product changes do. Terms of service and privacy policy updates can be made immediately and help establish good-faith compliance intent. Product-level changes to default settings, algorithm behavior, and parental monitoring tools are more complex, but your legal documentation should reflect what you intend to implement even before the technical changes are complete.
A technology attorney familiar with children’s online privacy requirements can help you conduct a KOSA gap analysis, revise your terms and privacy policy to reflect minor-specific obligations, structure your parental consent and monitoring disclosures, and document your duty of care assessment in a form that supports your defense against regulatory scrutiny.
Frequently Asked Questions
Has KOSA passed into law yet?
As of 2026, KOSA has been reintroduced in the 119th Congress as S.1748 and has advanced with bipartisan support. Federal enactment has not yet occurred at the time of this writing. However, multiple states have enacted KOSA-equivalent legislation that is already in effect, including California’s Age-Appropriate Design Code Act. Platforms should prepare for KOSA compliance regardless of federal enactment status.
Does KOSA apply if my platform requires users to be 18 or older?
If your platform requires users to be 18 or older through your terms of service, KOSA applicability depends on whether minors can reasonably be expected to access your platform despite that restriction and whether you have implemented meaningful age verification. An age gate that requires only a checkbox or self-reported date of birth is unlikely to be treated as adequate for the purposes of KOSA’s coverage analysis.
Does KOSA replace COPPA?
No. KOSA and COPPA apply independently. COPPA continues to govern the collection of personal data from children under 13 with its existing consent and notice requirements. KOSA creates separate obligations that extend to minors up to age 17 and impose design and duty-of-care requirements that COPPA does not address. Compliance with COPPA does not satisfy KOSA, and vice versa.
What is a data protection impact assessment under KOSA?
Under both California’s Age-Appropriate Design Code and the KOSA framework, a data protection impact assessment for minor users is a documented analysis of how your platform’s data practices, algorithmic design, and product features affect the best interests of minor users. It identifies potential harms, assesses their likelihood and severity, and documents the steps taken to mitigate them. This assessment is not a one-time document; it must be updated when you make material product changes.
Can targeted advertising to minors continue under KOSA?
KOSA prohibits covered platforms from using personal data collected from minor users for targeted advertising without explicit parental consent. Default account settings for minor users must disable targeted advertising. This is a more restrictive standard than current FTC guidance under COPPA and represents a material change for platforms that currently monetize through behavioral advertising without segmenting minor user accounts.
Conclusion
KOSA represents a fundamental shift in how US law treats platforms that reach young users. Waiting for final federal enactment before taking action is a risk your platform cannot afford, given that state-level enforcement under California’s Age-Appropriate Design Code and similar laws is already underway. Your terms of service and privacy policy need to reflect these obligations before regulators or plaintiffs start asking questions.
If you need your terms of service and privacy policy reviewed for children’s online safety compliance, contact Hansen Tong at TOSLawyer.com. A technology law specialist can help you understand exactly what your platform needs to address and get your legal documents in order before compliance becomes an enforcement issue.
