California Repeals the Age-Appropriate Design Code and Replaces It With a New Kids' Privacy Law
Independently fact-checked against primary sources (last audited September 22, 2026). · 4 primary sources cited on this page. How we verify our legal content

California Repeals the Age-Appropriate Design Code and Replaces It With a New Kids' Privacy Law
Governor Gavin Newsom signed AB 2246 on September 10, 2026, repealing the California Age-Appropriate Design Code Act outright and enacting a new Civil Code title in its place. The replacement drops the data protection impact assessment requirement that a federal appeals court had left enjoined, doubles the civil penalties, and adds a right for a child to void a contract.
Information last verified on September 22, 2026. This is a developing story; we update it as the record changes.
Jurisdiction scope: This article addresses California law, specifically Title 1.81.47 of Part 4 of Division 3 of the Civil Code as repealed and re-enacted by AB 2246. It does not address the federal Children's Online Privacy Protection Act, other states' minors' privacy statutes, or California's separate app store and device-level age signal legislation.
What Happened
On September 10, 2026 the Governor approved Assembly Bill 2246, authored by Assemblymember Wicks, and it was filed with the Secretary of State the same day as Chapter 187 of the Statutes of 2026. The chaptered text describes it as "An act to repeal and add Title 1.81.47 (commencing with Section 1798.99.28) of Part 4 of Division 3 of the Civil Code, relating to business."
The structure is unusual and it is the whole story. Section 1 of the bill is a single sentence repealing the entire title. Section 2 adds a new title bearing the same number and heading, "Online Services, Products, or Features Likely to be Accessed by Children."
The title being repealed is the California Age-Appropriate Design Code Act, enacted as AB 2273 in 2022 and signed on September 15, 2022 as Chapter 320 of the Statutes of 2022. It was the first US statute of its kind, modeled on the United Kingdom's children's code, and a number of other states drafted from it.
It also never took full effect. NetChoice sued, and in NetChoice, LLC v. Bonta, No. 23-2969 (9th Cir. Aug. 16, 2024), the Ninth Circuit affirmed the district court's preliminary injunction "insofar as it enjoined enforcement of California Civil Code sections 1798.99.31(a)(1)-(4), (c), 1798.99.33, 1798.99.35(c)," and vacated the remainder of the injunction. The provisions left enjoined were the data protection impact assessment report requirement and the provisions the court found could not be severed from it.
AB 2246 is the Legislature's answer. Rather than amending around an injunction, it deletes the act and writes a new one.
What the New Law Actually Says
The new Title 1.81.47 runs from Civil Code section 1798.99.28 through section 1798.99.34. Here is what is in it.
Who is covered
Section 1798.99.28 borrows the definitions in Civil Code section 1798.140, the CCPA definitions section, unless the new chapter says otherwise. It then defines its own key terms. A "child" is a consumer under 18 years of age, not under 13 as under the federal COPPA framework described in our COPPA compliance guide.
"Likely to be accessed by children" is defined through six indicators, including that the service is directed to children as COPPA defines that term, that competent and reliable audience-composition evidence shows it is routinely accessed by a significant number of children, that it carries advertising marketed to children, that it is substantially similar to such a service, that it has design elements known to be of interest to children such as games, cartoons, music and celebrities who appeal to children, or that internal company research shows a significant amount of its audience is children.
The definition of "online service, product, or feature" carves out broadband internet access service, telecommunications service as defined in 47 U.S.C. section 153, and the delivery or use of a physical product.
The five things a covered business must do
Section 1798.99.29(a) requires a covered business to do all of the following:
- Estimate the age of child users with a reasonable level of certainty appropriate to the risks arising from the business's data management practices, or apply the privacy and data protections afforded to children to all consumers.
- Configure all default privacy settings provided to children to settings that offer a high level of privacy.
- Provide privacy information, terms of service, policies and community standards concisely, prominently, and in clear language suited to the age of children likely to access the service.
- Where a parent, guardian or other consumer can monitor the child's activity or track the child's location, provide an obvious signal to the child when that is happening.
- Provide prominent, accessible and responsive tools to help children, or their parents or guardians, exercise privacy rights and report concerns.
The seven things a covered business must not do
Section 1798.99.29(b) prohibits a covered business from profiling a child by default unless it can demonstrate appropriate safeguards and the profiling is either necessary to provide the service the child is actively and knowingly engaged with or necessary to enhance the child's safety, privacy or education. It prohibits collecting, selling, sharing or retaining personal information that is not necessary to provide the service the child is actively and knowingly engaged with. It bars using a child's personal information for any purpose other than the one it was collected for, with a carve-out for safety, integrity, security, measurement, auditing, system improvement and compliance with the title itself.
Two provisions target location, and a third targets age-estimation data. A business may not collect, sell or share precise geolocation information of children by default unless collection is strictly necessary to provide the requested service, and then only for the limited time necessary. It may not collect precise geolocation at all without an obvious sign to the child for the duration of the collection. Separately, it may not retain personal information collected to estimate age for any other purpose or longer than necessary, with age assurance required to be proportionate to the risks and data practices of the service.
Finally, the section prohibits dark patterns that lead or encourage children to provide more personal information than is reasonably expected or to forego privacy protections.
Section 1798.99.29(c) adds that nothing in the section requires a business to prevent or preclude a child from accessing or viewing any piece of media or category of media.
The harms provision, and the speech carve-out attached to it
Section 1798.99.30(a) requires a covered business to take reasonable steps to prevent four risks of harm to children: reasonably foreseeable physical or financial harm; severe and reasonably foreseeable psychological or emotional harm to a reasonable child; a highly offensive intrusion on privacy rights protected by state or federal law; and adverse discrimination in violation of state or federal law.
Subdivision (b) then limits that duty in terms drawn straight from the First Amendment litigation over the old act. Nothing in the section, it says, may be construed to impose a duty to monitor, screen or remove third-party content, to restrict lawful speech, or to require any specific content ranking, recommendation, or editorial outcomes.
Contract voidability
Section 1798.99.31 is new in substance, not just in numbering. Any provision of a contract entered into by a child, or by a child's parent or guardian, is voidable at the child's election if the contract was entered into as a result of a design feature of a covered online service, including the terms of service for that service.
Penalties and who enforces
Section 1798.99.32 sets the civil penalty at not more than $5,000 per affected child for each negligent violation and not more than $15,000 per affected child for each intentional violation, recoverable only in a civil action brought by the Attorney General in the name of the people or by a public prosecutor. Penalties recovered by the Attorney General go to the Consumer Privacy Fund. Subdivision (c) states that nothing in the chapter may be interpreted to serve as the basis for a private right of action under the chapter or any other law. Subdivision (d) authorizes the Attorney General to solicit broad public participation and adopt regulations clarifying the chapter's requirements.
Those penalty figures are double the old ones. The repealed 2022 act set them at not more than $2,500 per affected child for each negligent violation and not more than $7,500 per affected child for each intentional violation.
Section 1798.99.33 exempts the information and entities described in Civil Code section 1798.145(c). Section 1798.99.34 is a severability clause, a notable inclusion given that severability was the precise issue that decided the scope of the injunction against the old act.
What Is Gone
Reading the new title end to end, the most consequential change is an absence. There is no data protection impact assessment requirement anywhere in sections 1798.99.28 through 1798.99.34.
Under the repealed act, former section 1798.99.31 required a business to complete a Data Protection Impact Assessment before offering a new online service likely to be accessed by children, identifying the purpose of the service, how it used children's personal information, and the risks of material detriment to children, and to document the risks and a mitigation plan. That report requirement, and the provisions that referred to it, are what the Ninth Circuit left enjoined.
The old act's "best interests of the child" framing and its "materially detrimental" standard are also absent from the new text. In their place is the reasonable-steps-to-prevent-four-named-harms structure of section 1798.99.30, bounded by the speech carve-out in subdivision (b).
When It Takes Effect
AB 2246 contains no urgency clause. Under the California Constitution's default rule for statutes enacted in a regular session, it takes effect January 1, 2027.
Analysis: Why This Matters
The following is analysis from the Recording Law Editorial Team.
The California Age-Appropriate Design Code Act mattered less for what it did, which was largely blocked, than for what it started. It was copied. Other legislatures used its structure, its vocabulary and in places its text. Repealing it is therefore not only a California event.
The design of the replacement reads as a direct response to the litigation record. The provision that drew the constitutional fire, a requirement that companies assess and report on the risk that their content or design would harm children, is gone. The duty that replaces it is framed around enumerated harms rather than around an open-ended best-interests standard, and it is immediately followed by a subdivision disclaiming exactly the obligations that made the old act look like a content-moderation mandate: no duty to monitor, no duty to screen or remove third-party content, no restriction of lawful speech, no required ranking or editorial outcome. Section 1798.99.29(c) does similar work from the other direction by stating that nothing requires a business to keep a child from viewing any media. The Legislature also wrote in a severability clause, which is a sensible thing to do after a case in which severability determined how much of the statute survived.
Whether that is enough is not something anyone should predict, and we will not. What can be said is that the provisions most obviously drawn on privacy and data-practice grounds, high-privacy defaults, data minimization tied to what the child is actively engaged with, restrictions on default profiling and on default precise geolocation, and a dark-patterns prohibition, are the ones that the Ninth Circuit's vacatur of the rest of the injunction left in a different posture than the DPIA requirement. Those are the ones the new act builds on.
Two provisions deserve attention because they are new rather than salvaged. The doubled penalties change the arithmetic for a service with a large young audience, since the unit is per affected child. And the contract voidability right in section 1798.99.31 is a quiet but real addition: it gives a minor a remedy tied to design features rather than to data practices, in a statute that otherwise gives private parties no cause of action at all. How those two fit together, an individual unwinding right alongside an express bar on a private right of action, is the kind of question the Attorney General's regulatory authority under section 1798.99.32(d) exists to work through.
For readers tracking the wider picture, our comparison of state privacy laws and our survey of children's online privacy laws by state both carry the old California act as enacted in 2022; both need to reflect the repeal, and we are updating them.
How This Affects You
If you operate an online service that is likely to be accessed by Californians under 18, the compliance object changes on January 1, 2027. The old act's assessment-and-report obligation is not a live obligation under the new title. The affirmative duties in section 1798.99.29(a) and the prohibitions in section 1798.99.29(b) are, and so is the reasonable-steps duty in section 1798.99.30(a). General descriptions like these are not a compliance plan for any particular business.
If you are a parent, the practical change is mostly in defaults and signals. High privacy by default, a visible indicator when a child is being monitored or tracked by a parent or another consumer, limits on default profiling and on default precise geolocation, and accessible tools to exercise rights and report concerns are all required conduct rather than assessment paperwork.
If you are wondering whether you can sue, the statute answers directly. Section 1798.99.32 puts enforcement with the Attorney General and public prosecutors and states that nothing in the chapter is the basis for a private right of action. The one individual remedy in the new title is the contract voidability right in section 1798.99.31.
This is general legal information, not legal advice. It covers California law and reflects sources verified on September 22, 2026. Laws change and this story is developing; consult a lawyer licensed in your jurisdiction about your specific situation.
Related articles
- California data privacy laws: CCPA, CPRA and consumer rights
- Children's online privacy laws by state
- COPPA compliance guide
- State privacy laws compared
Last updated: 2026-09-22. This is a developing story; details verified as of 2026-09-22.
Frequently Asked Questions
Did California repeal the Age-Appropriate Design Code Act?
Yes. Section 1 of AB 2246, Chapter 187 of the Statutes of 2026, repeals Title 1.81.47 of Part 4 of Division 3 of the Civil Code, which was the California Age-Appropriate Design Code Act. Section 2 of the same bill adds a new Title 1.81.47 in its place.
When does the new California children's privacy law take effect?
AB 2246 was approved on September 10, 2026 and carries no urgency clause, so it takes effect January 1, 2027 under California's default rule for statutes enacted in a regular session.
Does the new law still require a data protection impact assessment?
No. The new Title 1.81.47, Civil Code sections 1798.99.28 through 1798.99.34, contains no data protection impact assessment requirement. The DPIA report requirement was in former section 1798.99.31 of the repealed act, and it is the provision the Ninth Circuit left preliminarily enjoined in NetChoice, LLC v. Bonta in August 2024.
What are the penalties under the new California law?
Civil Code section 1798.99.32 provides for an injunction and a civil penalty of not more than $5,000 per affected child for each negligent violation, or not more than $15,000 per affected child for each intentional violation. The repealed 2022 act set those amounts at $2,500 and $7,500.
Can a parent or child sue a company under the new law?
Not for a violation of the chapter. Section 1798.99.32 allows civil actions only by the Attorney General or a public prosecutor, and subdivision (c) states that nothing in the chapter may be interpreted to serve as the basis for a private right of action under the chapter or any other law. Separately, section 1798.99.31 lets a child void a contract provision entered into as a result of a design feature.
Who counts as a child under the California law?
Civil Code section 1798.99.28(b)(1) defines a child as a consumer under 18 years of age unless otherwise specified, which is broader than the under-13 scope of the federal Children's Online Privacy Protection Act.
How does a business know whether its service is likely to be accessed by children?
Section 1798.99.28(b)(3) lists six indicators, including that the service is directed to children as COPPA defines that term, that audience-composition evidence shows it is routinely accessed by a significant number of children, that it carries advertising marketed to children, that it is substantially similar to such a service, that it has design elements known to be of interest to children such as games, cartoons, music and celebrities who appeal to children, or that internal company research shows a significant share of its audience is children.
Does the new law require platforms to remove content?
No. Section 1798.99.30(b) states that nothing in that section may be construed to impose a duty to monitor, screen or remove third-party content, to restrict lawful speech, or to require any specific content ranking, recommendation, or editorial outcomes. Section 1798.99.29(c) separately says nothing requires a business to prevent a child from accessing or viewing any piece or category of media.
Updates
Independently fact-checked against the cited primary sources
Sources and References
- Assembly Bill 2246, Chapter 187, Statutes of 2026, chaptered text repealing and adding Title 1.81.47 of the Civil Code, California Legislative Information(leginfo.legislature.ca.gov).gov
- AB 2246 bill history and Legislative Counsel's Digest, approved by the Governor September 10, 2026(leginfo.legislature.ca.gov).gov
- Assembly Bill 2273, Chapter 320, Statutes of 2022, the California Age-Appropriate Design Code Act as enacted(leginfo.legislature.ca.gov).gov
- NetChoice, LLC v. Bonta, No. 23-2969 (9th Cir. Aug. 16, 2024), published opinion(cdn.ca9.uscourts.gov).gov