Meta settlement limits state claims over children’s data for age assurance

Meta’s proposed settlement with attorneys general from 29 US states would require the company to pay up to $18 billion, add child-safety measures and develop, train and begin testing an age-assurance model for identifying users under 13 within one year of the agreement taking effect. The settlement also contains a narrowly framed but consequential legal protection for Meta’s handling of children’s data.
The states agree not to bring past, present or future claims under the Children’s Online Privacy Protection Act (COPPA), or comparable state laws, when the data is retained and used for the limited purpose of training and testing Meta’s age-assurance model. The agreement says Meta should not need to violate COPPA to build or deploy the system.
A restricted use case with a broad-looking release
The arrangement sits alongside the larger child-safety case described in the wider Meta child-safety settlement, while creating a defined pathway for Meta to process data needed to determine whether an account belongs to a child. Meta’s existing age-detection tools use AI technology, although the settlement does not explicitly require the new model to be AI-based.
Its guardrails are explicit. Meta may not use data from people under 13 for advertising targeting, marketing or algorithmic optimisation. The data and behavioural signals are intended solely to identify and remove underage users from Meta’s platforms.
Philip N. Yannella, co-chair of Blank Rome’s Privacy, Security & Data Protection practice, said data-minimisation controls of this kind are typical in privacy compliance, including when organisations verify that deletion requests have been honoured. He also noted that COPPA is a federal law primarily enforced by the Federal Trade Commission, which is not a party to the state settlement.
Isolation and oversight will determine the outcome
The document does not specify what data Meta will retain for model training, how much behavioural information it may include, or how long it will be held. It also leaves open how the model and its data practices may change after Meta fulfils the settlement terms.
Keeping sensitive data technically and organisationally separate is difficult in large platforms. Questions may arise if data, behavioural signals or insights derived from them reach other systems over time. An independent auditor will monitor compliance, rather than leaving oversight solely to Meta.
Joshua Wurtzel of Schlam Stone & Dolan LLP said the release and covenant not to sue would not apply if Meta used the data outside the settlement’s boundaries. However, future disputes could still turn on whether a particular use fell within those boundaries. Peter Jackson, a Data & IP attorney at Greenberg Glusker LLP, said the release could be a hurdle that discourages enforcement actions.
What organisations should take from the terms
The case illustrates a broader tension for data-intensive AI systems: effective age assurance may require detailed insight into user behaviour, while privacy rules demand strict limits on collection, retention and reuse. Businesses using sensitive data for a narrowly defined model should make purpose limits operational through isolated data flows, clear retention rules, auditable access controls and evidence that derived signals are not reused outside the approved function.

