Loading...

Meta Exempts Itself From Child Data Laws in $18B Settlement

Key takeaways

  • Meta secured an exemption from child data protection laws in its $18 billion settlement, allowing the company to collect data from users under 13 to train an age-detection model.
  • The settlement bars Meta from using children's data for advertising, marketing, or algorithmic optimization, but leaves unclear how much data Meta retains, for how long, and what happens to insights derived from it.
  • States gave up future rights to sue Meta over this specific data use, potentially limiting their enforcement tools even if questions arise later about how the data was actually handled.
  • The arrangement reflects a broader tension in AI development: many protective systems require access to sensitive personal data, forcing regulators to choose between enabling technology and preventing misuse.

Meta has secured a curious legal arrangement in its $18 billion settlement with 29 state attorneys general. While the agreement requires the company to pay billions and implement new safety measures, it also grants Meta a significant exemption: state officials have agreed not to pursue existing child safety laws against the company regarding how it collects and uses data from young users.

The exemption is narrow in scope—limited to Meta’s training and testing of an age-detection system—but it raises questions about enforcement and whether regulators have struck the right balance between protecting children and enabling protective technology.

The Settlement’s Core Child Safety Requirement

Meta must develop, train, and begin testing a model designed to identify which users on its platforms are under 13 years old. The timeline is tight: the company has one year from when the agreement becomes effective. The current age-detection tools Meta uses rely on artificial intelligence technology, though the settlement doesn’t explicitly mandate an AI-based approach.

This requirement exists because Meta has previously failed to protect children on its platforms adequately. The $18 billion payout reflects the severity of those failures, and the settlement includes additional safeguards to prevent future harm.

How COPPA Normally Works and What the Exemption Changes

The Children’s Online Privacy Protection Act, known as COPPA, normally prevents websites and apps from collecting and retaining large amounts of personal data from users under 13. It’s a federal law designed to protect minors from data exploitation and to constrain companies’ business models built on children’s behavioral data.

Meta’s settlement agreement creates an exception to COPPA specifically for developing its age-assurance model. The states have agreed not to pursue any past, present, or future claims under COPPA—or similar state laws—related to Meta’s use of children’s data in connection with age detection. That’s a significant concession. By signing on, the state attorneys general surrendered legal tools they might otherwise have used in future disputes over this same issue.

This exemption acknowledges a genuine technical problem. To detect which users are actually under 13, Meta likely needs to examine patterns in how young people use the platform: what accounts look like, what behavior signals appear in underage accounts, what data suggests someone’s true age. That analysis might technically violate COPPA’s data-minimization requirements, even if the purpose is protective rather than exploitative.

Philip N. Yannella, a privacy law partner at Blank Rome, said data-minimization guardrails for compliance purposes are “pretty typical” in privacy law. But he raised an important caveat: COPPA is enforced primarily by the Federal Trade Commission, not by states. The FTC is not a party to Meta’s settlement, so it remains unclear whether the agency has separately agreed to the same exemption. That ambiguity could matter if questions arise later about data retention or use.

Close-up view of Facebook app on a modern smartphone, emphasizing technology.

Guardrails on What Meta Can Do With the Data

Prohibited Uses

The settlement is explicit about what Meta cannot do with children’s data. The company is barred from using information from users under 13 for advertising, marketing, or algorithmic optimization. Those are the highest-risk uses in terms of exploitation and manipulation. Preventing Meta from building targeted ads for children or personalizing feed content based on underage users addresses the core concern that originally prompted the enforcement action.

Unanswered Questions

What remains less clear is everything else. The agreement doesn’t specify what data Meta will retain for training the model, how much behavioral information that includes, or how long the company will store it. It doesn’t address how Meta will handle insights or patterns derived from that data, or whether those derived signals could theoretically feed into other company systems over time.

An independent auditor will monitor Meta’s compliance, which provides some external oversight. That’s significant—it means the company cannot simply self-report its adherence to the terms. Still, auditing for data isolation is notoriously difficult. Companies often struggle to keep information technically and organizationally separate from the rest of their infrastructure, even when that separation is the explicit goal.

The Enforcement Problem

When States Can Still Sue

If Meta uses the data beyond the settlement’s stated boundaries, states can still pursue legal action. Joshua Wurtzel, a partner at Schlam Stone & Dolan LLP, emphasized this point: the exemption only applies to uses within the settlement’s terms. If Meta steps outside those lines, the states’ agreement not to sue no longer holds.

Why Enforcement Is Complicated

But that enforcement mechanism has a weakness. Legal disputes over whether Meta’s use of the data fell within the settlement’s terms could become complicated and drawn out. The company and states would need to litigate over the boundaries—over what “age detection” means in practice, over whether data crossed into other systems, over whether insights derived from the data count as prohibited uses. Those are the kind of factual questions that generate expensive, years-long litigation.

Peter Jackson, a data attorney at Greenberg Glusker LLP, suggested the carve-out could have a chilling effect on future enforcement. “The Settlement Agreement’s age-assurance measures bear all the hallmarks of a heavy, and perhaps hasty, negotiation,” he said. By exempting Meta from COPPA claims today, states may have limited their legal tools for tomorrow, even if questions arise about how the data was actually used.

A Broader Pattern in AI Development

This situation reflects a tension appearing across the AI industry. Many new AI systems—especially those designed to help consumers with various tasks—require substantial access to personal data to function well. The systems need deep behavioral insight to work effectively.

Meta’s situation with age detection follows the same pattern. The company genuinely may need extensive data about how young people use social media in order to identify which accounts belong to them. There’s no obvious way to build an accurate age classifier without examining the patterns of actual young users.

The question facing regulators is how to allow such beneficial systems to develop while preventing data misuse. Meta’s settlement attempts to answer it through the combination of a narrow exemption, explicit restrictions on downstream uses, and independent auditing. Whether that combination will prove sufficient in practice remains to be seen.

Frequently Asked Questions

What must Meta do under the settlement?

Meta must develop, train, and begin testing a model to detect users under 13 on its platforms within one year of the agreement taking effect.

Why did states agree to exempt Meta from child data protection laws?

The exemption acknowledges that building an accurate age-detection model may require Meta to collect and analyze data from young users in ways that would normally violate COPPA, but the settlement restricts this data to age-detection purposes only and bars its use for advertising, marketing, or algorithmic optimization.

Can states still sue Meta over this data use in the future?

States can sue only if Meta uses the data beyond the settlement's stated boundaries—specifically for purposes other than age detection. However, such legal disputes could be complicated because they would hinge on whether Meta's actual use fell within the settlement's terms.

Written by
Adrian Voss

Adrian Voss covers AI applied to finance and business — trading algorithms, fraud detection, and how large language models are changing corporate decision-making.