Get Started
Menu
HomePromptsArticlesToolsWorkflowsGuidesNewsShop

Meta Settlement Gives Legal Pass for Kids’ Data

kids’ data
← AI News
AI News

Meta Settlement Gives Legal Pass for Kids’ Data

Meta’s deal with 29 states includes a narrow carve-out for children’s data, allowing limited use to train age-detection tools under guardrails.

Technology News

Meta’s settlement with 29 state attorneys general does more than add child-safety requirements and financial penalties. It also gives the company a limited legal pass to retain certain kids’ data for a specific purpose: training and testing age-assurance tools meant to detect users under 13.

The arrangement matters because it sits at the center of a case focused on child safety and online privacy. Under the deal, Meta must develop, train, and begin testing a model designed to identify under-13 users on its platforms within a year of the agreement taking effect. The model is not described as AI-based in the settlement itself, but Meta’s current age-detection systems use AI.

At the same time, the states agreed not to bring past, present, or future COPPA claims — or similar state-law claims — over Meta’s use of children’s data for this narrow purpose. COPPA, the federal Children’s Online Privacy Protection Act, generally limits how websites and apps collect and keep personal data from children under 13.

That combination creates the core privacy trade-off in the settlement: Meta gets room to use some children’s data to improve detection of underage users, while being barred from using that data for ad targeting, marketing, or algorithmic optimization. The agreement says Meta should be able to carry out the age-assurance work without violating COPPA, but it also shields the company from a broad set of legal claims tied to that data use.

What The Kids’ Data Carve-Out Means

The kids’ data carve-out is narrow in theory, but significant in practice. It appears to allow Meta to keep some information about children under 13 so it can train and test systems intended to detect and remove underage users from its platforms. The settlement includes guardrails, and an independent auditor will monitor compliance.

Even so, experts quoted in the reporting say enforcement may be difficult. Data retained for one purpose can be hard to isolate from broader company systems, and questions could arise if signals or insights derived from that data end up influencing other Meta products or models.

What is not clear from the settlement is equally important: the document does not specify exactly what children’s data Meta will keep, how much behavioral information that may include, or how long the company can retain it. It also leaves open how the models may evolve after Meta meets the settlement’s requirements.

Why The Privacy Trade-Off Matters

The deal highlights a tension that is becoming familiar in platform regulation. Companies are under pressure to do more to keep children off services that are not meant for them, yet those protections can require some level of data retention and analysis to work effectively.

That is why the settlement could matter beyond Meta. It shows one possible path for balancing child-safety compliance with privacy restrictions: limited retention, specific use cases, and outside monitoring. But it also raises the question of whether a carve-out intended for age detection could be hard to police once the data exists inside a large, interconnected company.

Some legal observers say the states’ willingness to grant protection is not unusual given standard privacy guardrails, such as data minimization rules used to verify deletion requests. The unresolved issue is that COPPA is primarily enforced by the Federal Trade Commission, which is not a party to the settlement. That means it is not clear whether federal regulators have agreed to the same compromise.

What To Watch Next

For readers, the immediate practical question is how Meta will implement the settlement in a way that keeps kids’ data separated from other systems. The next steps to watch are the development timeline for the under-13 detection model, the scope of data Meta retains, and the findings of the independent auditor.

Future disputes could hinge on whether Meta stays within the settlement’s boundaries. Lawyers cited in the reporting note that if the company uses the data outside those lines, the release from claims would not apply. But any challenge could still be complicated, because it would depend on proving exactly how the data was used.

There is also a broader policy implication: by insulating Meta from certain COPPA and state-law claims, the settlement may make future enforcement actions harder if questions later arise. In that sense, the deal does not just resolve one case. It also sets up a test for how far privacy concessions can go when child safety is the stated goal.

Was this useful?
Scroll to Top