Micron Document

KIDS 00 history of childrens online safety
page 1 / 2

A History of U.S. Children's Online-Safety Law
synthesized-overview . retrieved 2026-06-28
sources: Wikipedia, MTSU First Amendment Encyclopedia, FTC, Harvard JOLT, Congress.gov

archived for offline mesh reading
------------------------------------------------------------

How the United States arrived at the 2026 KIDS Act — three decades of trying (and
mostly failing) to regulate what minors encounter online, always colliding with the
First Amendment.

1. The 1990s: the first attempts, and the birth of Section 230

- **1996 — Communications Decency Act (CDA).** Congress's first attempt to police
"indecent" online material shown to minors. In **Reno v. ACLU (1997)** the Supreme
Court struck the anti-indecency provisions as unconstitutionally broad — a foundational
ruling that the internet gets full First Amendment protection.
- **The survivor: Section 230.** One fragment of the CDA lived on — **47 U.S.C. § 230**,
which shields platforms from liability for third-party content. Ironically, the statute
meant to *restrict* content became the legal foundation that *protects* it. Section 230
is the backdrop to every child-safety fight since: you cannot easily sue a platform for
what its users post, so reformers instead target platform **design and data practices**.
- **1998 — Child Online Protection Act (COPA).** Congress's second try at "harmful to
minors" content. Never took effect: enjoined immediately, ruled unconstitutional in
**Ashcroft v. ACLU (2004)**, permanently enjoined **2009**. A cautionary tale about
content-based restrictions.
- **1998 — Children's Online Privacy Protection Act (COPPA).** The one that *survived* —
because it regulated **data collection, not speech.** Effective April 2000, enforced by
the **FTC** (16 CFR Part 312), it requires verifiable parental consent before collecting
personal information from children **under 13**. Its "under-13" line and "actual
knowledge" standard shaped a generation of product design (hence "13+" sign-up ages).

**The lesson Congress learned:** regulate *conduct, privacy, and design* — not *content* —
or the courts will strike it down. Every modern bill, KOSA included, is an attempt to
thread that needle.

2. The 2000s–2010s: the social-media era outruns the law

COPPA was written for a web of static homepages. Then came smartphones (2007+), the
App Store, Facebook, YouTube, Instagram, Snapchat, and TikTok. Recommendation algorithms,
infinite scroll, push notifications, and engagement-optimized design created harms COPPA
never contemplated — and COPPA's under-13 cutoff left **teenagers entirely uncovered.**

The FTC updated the COPPA Rule in **2013** and again in **April 2025**, but rulemaking
could not keep pace, and Section 230 blunted litigation. Pressure built for new statutes.

3. 2021: the catalyst — Frances Haugen and the "Facebook Files"

In **2021**, Facebook product manager **Frances Haugen** leaked internal research to the
*Wall Street Journal* (the "Facebook Files") and testified to the Senate. The documents
showed the company's *own* research finding Instagram worsened body image and mental
health for a meaningful share of teen girls. This was the political spark: bipartisan
outrage that platforms knew about harms and buried them.

4. 2022–2024: the KOSA era begins

Out of the Haugen moment came two bills that would travel together for the next four years:

- **Kids Online Safety Act (KOSA)** — Sens. **Richard Blumenthal (D-CT)** and **Marsha
Blackburn (R-TN)**, introduced **Feb 16, 2022.** Its signature idea: a **"duty of care"**
requiring platforms to prevent and mitigate specified harms to minors (self-harm,
eating disorders, substance abuse, sexual exploitation, etc.).
- **COPPA 2.0 (Children and Teens' Online Privacy Protection Act)** — Sens. **Ed Markey
(D-MA)** and **Bill Cassidy (R-LA)** — extends privacy protection to teens under 17,
bans targeted ads to minors, adds an "eraser button," and upgrades the knowledge
standard.

These stalled in the 117th Congress, were reintroduced May 2023 (after a Biden State of
the Union push), and in **July 2024 the Senate passed them together, 91–3** — the first
major tech-regulation vote since 1998. But the package **died in the House** at the end of
the 118th Congress amid First Amendment objections and a messy duty-of-care markup.

*(For the detailed road from here to the 2026 KIDS Act, see
[[01-lead-up-to-the-kids-act]] and [[02-legislative-timeline]].)*

5. Meanwhile, the states didn't wait

As Congress stalled, **states filled the vacuum** — age-appropriate design codes
(California 2022), social-media age-verification and parental-consent laws (Utah, Texas,
Arkansas, Ohio, Mississippi), and app-store age-verification laws (2025). Nearly all drew
immediate First Amendment challenges, mostly from **NetChoice** and **CCIA**. The result
is a contradictory patchwork — the very thing the federal KIDS Act's **preemption** clause
is meant to resolve (and which state AGs resent). *(See [[../Legal Landscape/00-courts-and-state-laws]].)*


< prev page 1/2 next >