Legis
Technology
AB 2246, Chapter 187, Statutes of 2026 · Thursday 10 September 2026

Online service, product, or feature: access by children

California sets child-safety and privacy rules for online services likely to be accessed by people under 18.

The law requires child-facing online businesses to use high-privacy defaults, limit data practices, and address specified risks of harm. State enforcers can seek injunctions and penalties of up to $15,000 per affected child for intentional violations.

What the law does

  • Requires businesses to estimate a child user's age at a risk-appropriate level of certainty or extend child privacy and data protections to every consumer.
  • Requires high-privacy default settings, child-appropriate privacy notices, clear signals when a child is monitored or location-tracked, and accessible privacy-rights and reporting tools.
  • Limits default profiling, unnecessary collection, sale, sharing, retention, and reuse of children's personal information, as well as default collection of precise geolocation.
  • Bars dark patterns that push children to provide extra personal information or give up privacy protections.
  • Requires reasonable steps to prevent foreseeable physical or financial harm, severe foreseeable psychological or emotional harm, unlawful privacy intrusions, and unlawful discrimination.
  • Lets a child void a contract entered because of a covered service's design feature.
  • Authorizes the Attorney General or a public prosecutor to enforce the law, but creates no private right of action.

Who it affects

  • Businesses offering online services, products, or features reasonably expected to be accessed by children.
  • Children under 18 who use those services, products, or features.