State Comprehensive Privacy Laws

New York's Child Data Protection Act: Nine Sections, a Consent Form With Four Conditions, and Rules Still Unproposed

Key Takeaways

  • Senate Bill 7695-B was signed as Chapter 121 of 2024 on June 20, 2024 and took effect one year later, on June 20, 2025
  • Article 39-FF runs from § 899-ee to § 899-mm; the rulemaking section is § 899-kk, and scope and remedies follow it at §§ 899-ll and 899-mm
  • For users 13 to 17, processing is lawful only if strictly necessary for one of nine listed purposes or covered by an informed consent request meeting four statutory conditions
  • A declined or revoked consent cannot be requested again for the following calendar year, and a device signal declining consent bars the request altogether
  • The Attorney General may seek civil penalties of up to $5,000 per violation under § 899-mm; as of September 21, 2026 the office's rulemaking library lists only a 2024 advance notice for this Act

Article 39-FF and Its Effective Date

The New York Child Data Protection Act began as Senate Bill 7695-B, sponsored by Senator Gounardes. The Legislature's bill record shows it passed the Senate on June 6, 2024, passed the Assembly on June 7 after being substituted for A.8149-A, and was signed as Chapter 121 on June 20, 2024. Section 3 of the bill reads: "This act shall take effect one year after it shall have become a law." The Attorney General's implementation guidance gives the result as June 20, 2025.

The bill summary lists the addition as "Art 39-FF §§899-ee - 899-mm." The article on the Senate's laws site has nine sections: definitions (899-ee), privacy protection by default (899-ff), processors (899-gg), ongoing coverage (899-hh), user-provided age flags (899-ii), third-party operators (899-jj), rulemaking (899-kk), scope (899-ll) and remedies (899-mm). A citation that stops at § 899-kk omits the section that sets the penalty.

Section 899-ll limits the article to "conduct that occurs in whole or in part in the state of New York." Conduct is wholly outside the state only if the data was collected while the user was outside New York, none of its use occurred in New York, and no data collected in New York is used. The same section provides that nothing in the article imposes liability on an operator subject to COPPA that is "inconsistent with the treatment of such activities or actions" under 15 U.S.C. 6502.

Who Is a Covered User

Under § 899-ee(1), a covered user is a user in New York of a website, online service, application or connected device, "or portion thereof," who is either "actually known by the operator" to be a minor, or using a service "primarily directed to minors." A minor is anyone under 18. The two tests are joined by "or."

That word matters because the Attorney General's own advance notice of proposed rulemaking, dated August 1, 2024, summarizes the Act as applying "where both of the following are true" and then lists the two tests. The notice's first question to the public describes them as alternatives, and the statute's text controls.

"Primarily directed to minors" means a service or portion of one "targeted to minors." Linking to a child-directed site does not make a service child-directed, but a service is deemed directed to minors when it has actual knowledge that it is collecting personal data directly from users of another service primarily directed to minors. The May 2025 guidance adds that the operator's knowledge follows the account: an age associated with an account is actual knowledge wherever the operator recognizes the user, including on other devices or other services reached with the same log-in.

An "operator" is anyone who runs a covered service and controls the purposes and means of processing. A "third-party operator" is an operator that is not the one the user intentionally interacts with or that collects data from the user's current interactions; the 2024 advance notice gives "the operator of a pixel or API that gathers data from a website run by another operator" as the example.

Under 13, COPPA Decides

Section 899-ff(1)(a) permits processing of a covered user "twelve years of age or younger" to the extent "permitted under 15 U.S.C. § 6502 and its implementing regulations." The guidance reads this as adopting COPPA wholesale for that age group, including when parental consent is needed and how it is obtained, and says operators of services within the Act's "primarily directed" standard for young children also fall within COPPA's "directed to children" standard. The rest of this account concerns users aged 13 to 17, where the Act supplies its own rules.

Strictly Necessary Processing

For a covered user 13 or older, § 899-ff(1)(b) allows processing only if it is "strictly necessary" for a purpose in subdivision two, or informed consent has been obtained. The nine purposes are: providing or maintaining a specific product or service the user requested; the operator's internal business operations; identifying and repairing technical errors; protecting against malicious, fraudulent or illegal activity; legal claims; complying with laws; complying with a governmental inquiry, subpoena or summons; security incidents; and protecting the vital interests of a natural person.

The internal operations purpose carries an exclusion written into the statute: it "shall not include any activities related to marketing, advertising, research and development, providing products or services to third parties, or prompting covered users to use" the service "when it is not in use." The guidance notes that COPPA's comparable internal-operations exception has no such proviso.

The guidance measures the requested-service purpose by "the expectations of a reasonable covered user." Its examples: processing to provide customer support generally needs no separate consent; a budgeting service marketed as tracking spending may process spending data but not unrelated real-time GPS coordinates; and an operator cannot bring behavioral advertising or profiling within the exception simply by marketing the service as personalized. It also reads the fraud purpose to cover frequency capping of advertising, and the internal operations and vital interests purposes together to cover trust, health and safety policies.

Informed Consent for Teenagers

Processing that is not strictly necessary needs informed consent, obtained either through a device signal under § 899-ii or through a request. Section 899-ff(3)(a) sets four conditions on the request. It must:

  1. Be made separately from any other transaction or part of a transaction
  2. Be made without any mechanism that has "the purpose or substantial effect of obscuring, subverting, or impairing" the user's decision
  3. State clearly and conspicuously that the processing is not strictly necessary and that the user may decline without losing continued use of the service
  4. Present the option to refuse "as the most prominent option"

Consent is "freely revocable at any time" and must be "at least as easy to revoke as it was to provide." If a user declines or revokes, the operator may not ask again for that processing "for the following calendar year," though it may offer a mechanism the user can use unprompted. Subdivision four bars withholding, degrading or charging more for a product or feature because consent was not given, unless the processing is strictly necessary to provide it. Subdivision five prohibits an operator from buying or selling a covered user's personal data, or allowing a processor or third-party operator to do so, with no consent route, subject only to § 899-jj.

Two timing duties follow. Within 30 days of learning a user is a covered user, § 899-ff(6) requires the operator to delete that user's data unless COPPA, strict necessity or consent permits keeping it, to direct its processors to do the same, and to notify third-party operators it knows received the data. Under § 899-hh, an operator that learns a user is no longer a covered user may not process the data previously protected until it receives informed consent, and must tell the user the protections may no longer apply.

Device and Browser Signals

Section 899-ii works in two directions. Subdivision one requires an operator to treat a user as a covered user if the user's device "communicates or signals that the user is or shall be treated as a minor," through a browser plug-in, privacy setting, device setting "or other mechanism that complies with regulations promulgated by the attorney general." Subdivision two requires an operator to honor "clear and unambiguous" device signals granting or declining consent, and to ask for consent directly when a signal is unclear. Where a device signals that consent is declined, § 899-ff(3)(d) bars the operator from requesting it.

Subdivision one depends on regulations that do not yet exist. The guidance says the office "will promulgate rules on relevant factors or characteristics that can make an age flag one that an operator must respect," and that until those rules are final it "will exercise discretion in pursuing enforcement action on this provision" for operators otherwise making good-faith efforts to comply.

Processors and Third-Party Operators

Section 899-gg bars disclosing a covered user's data to a third party without a written, binding agreement. The agreement must limit the processor to the operator's instructions, require it to assist with deletion, make compliance information available, allow assessments by the operator or an independent assessor, and give advance notice before data moves to further processors. A processor must provide evidence of deletion within 30 days of a deletion request.

Section 899-jj relieves a third-party operator of §§ 899-ff and 899-gg if it received "reasonable written representations" that the user gave informed consent, or if it has no actual knowledge either that the user is a minor or that the first-party service is primarily directed to minors. Section 899-ff(7) supplies the other half: before letting a third-party operator collect data, the first-party operator must tell it when the service is primarily directed to minors or the data concerns a covered user.

Attorney General Enforcement and Rules

Section 899-mm authorizes the Attorney General to sue to enjoin violations, obtain restitution, disgorgement "including but not limited to the destruction of unlawfully obtained data," damages, and "civil penalties of up to five thousand dollars per violation." The article contains no provision authorizing a private action. Section 899-kk authorizes rules "necessary to effectuate and enforce" the article.

Rulemaking has gone one step. The advance notice of August 1, 2024 asked questions about the "primarily directed" test, bundled services, internal operations and teen consent, with comments due September 30, 2024. The guidance dated May 19, 2025 followed, stating that the office "intends to issue rules" and that until rules are "proposed and finalized" it will exercise enforcement discretion and weigh good-faith compliance "consistent with the plain language of the statute and this guidance."

The Attorney General's Protecting Children Online page, read on September 21, 2026, sets out a complete record for the companion SAFE for Kids Act: advance notice, a proposed rule released September 15, 2025 and final rules. The release announcing those final rules gives July 29, 2026 for State Register publication and January 25, 2027 for the SAFE for Kids Act's effective date. For the Child Data Protection Act the same page lists only the 2024 advance notice. No proposed rule under § 899-kk appears there, and this publication found no Attorney General action announced under article 39-FF.

Background

For the underlying law rather than this development: New York privacy law, Technology & SaaS privacy law.

Frequently Asked Questions

When did New York's Child Data Protection Act take effect?
On June 20, 2025. The bill was signed as Chapter 121 of the Laws of 2024 on June 20, 2024, and its section 3 set the effective date at one year after it became law. The Attorney General's guidance gives the same date.
Does the Child Data Protection Act let a 15-year-old consent to data processing?
Yes. For covered users 13 or older, § 899-ff lets the user give informed consent to processing that is not strictly necessary, provided the request is separate, free of manipulative design, states that declining will not end use of the service, and makes refusal the most prominent option. Consent cannot authorize a sale, which § 899-ff(5) prohibits.
How often can an operator ask a teenager for consent under New York law?
If a covered user declines or revokes consent, § 899-ff(3)(c) bars another request for that processing for the following calendar year. If the user's device signals that consent is declined, § 899-ff(3)(d) bars the request entirely. In both cases the operator may offer a mechanism the user can use on their own initiative.
Has the New York Attorney General adopted rules under the Child Data Protection Act?
Not as of September 21, 2026. The office published an advance notice on August 1, 2024 and implementation guidance dated May 19, 2025, which says rules on age flags and other terms will follow. Its rulemaking library lists no proposed rule for this Act.
What are the penalties under article 39-FF?
Section 899-mm lets the Attorney General seek injunctions, restitution, disgorgement including destruction of unlawfully obtained data, damages, and civil penalties of up to $5,000 per violation. The article does not provide a private right of action.

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.