Skip to content

Hashed Salted Vol 5 Issue 2

Hashed & Salted | A Privacy and Data Security Update

Welcome to the children’s privacy issue of Hashed & Salted!

As we did in last year’s issue, we’re providing updates on developments in children’s privacy. Over the past year, it seems we’ve been living by the adage “the more things change, the more they stay the same.” While there continues to be significant focus on children’s privacy, in many ways much has stayed exactly the same. The federal government has expressed full-throated prioritization of children’s and teens’ online safety, including privacy and limiting exposure to harmful social media and AI content. The Federal Trade Commission (FTC) has hosted workshops, announced children’s privacy is one of its top priorities and expressly stated that it intends to broaden the scope of its enforcement beyond Children’s Online Privacy Protection Act (COPPA) Rule compliance.

At the same time, the agency’s enforcement actions over the past year have been fairly routine. The most significant federal regulatory development is that obligations related to compliance with the agency’s amended COPPA Rule are finally in effect as of April 22. The amendments, and had been in the works for a number of years, were finalized in January 2025 and became effective in April 2025.

Given the FTC has indicated that it is examining or intends to examine a number of areas related to online safety and the privacy of children and teens—including whether platform product designs harm children and teens in ways that can be challenged under Section 5 of the FTC Act, age-verification and age-estimation technologies and the impact of AI chatbot companions on children and teens—perhaps we will see the agency move into enforcement mode in these areas in the coming year.

On the legislative front, Congress continues to introduce children’s privacy legislation, some of which is new and some of which repeats previously introduced bills, but it has yet to succeed in getting any bill to pass both chambers. As a result, the trend of states attempting to fill the gap with their own laws continues. Yet, even at the state level, where legislatures have continually introduced and passed new children’s online privacy, age-appropriate design code, and app store and social media bills, much of the legislation is mired in court challenges, and some laws have been enjoined from taking effect, leaving enforcement in flux and businesses with whiplash.

In this year’s issue, partner Nerissa Coyle McGinn and associate Chanda Marlowe once again have given us a comprehensive look back at the developments over the past year. In “Children’s Online Privacy in 2026: Congress Stalls (Again), FTC Signals Priorities,” they explore the recent developments in federal children’s privacy regulation; in “Children’s Online Privacy in 2026: More State App Store, Design Code and Social Media Laws Enacted—Then Delayed,” they look at the proliferation of state laws seeking to address the online safety of children and teens and the court challenges to those laws.

While federal and state legislators and regulators grapple with developing and enforcing a legal framework in this area, technology and social media companies have been faced with a growing number of suits seeking to impose liability for harms allegedly suffered by minors using their platforms and services. In our third article of this issue, partner Nerissa Coyle McGinn offers insight into the implications of recent court holdings on children’s privacy, in “What Do the New Social Media Verdicts and Settlements Mean for Children’s Privacy?”

In our team member spotlight, Washington, D.C., associate Ryan Smith talks about how his work in government, digital advertising and cybersecurity incident response has given him a front-row seat to developments that continue to shape privacy law and compliance, how the online interactions and digital footprints of today’s kids and teens are vastly different than they were when COPPA—the first comprehensive children’s privacy law—was enacted in 1998, and how he’s handled his share of emergency situations, from data breaches to middle-of-the-night pet rescues.

In This Issue:

Children’s Online Privacy in 2026: Congress Stalls (Again), FTC Signals Priorities

Another year, another round of failed attempts by Congress to pass broad children’s privacy legislation, despite the federal government’s push to protect all minors online. Meanwhile, the FTC’s amended COPPA Rule took effect in April, and the agency is now contemplating using its enforcement powers beyond COPPA.

Read more here.

Children’s Online Privacy in 2026: More State App Store, Design Code and Social Media Laws Enacted—Then Delayed

In the absence of comprehensive federal legislation, states continue to enact their own regulations aimed at online safety and privacy for children and teens, including age-appropriate design code and app store accountability acts, as well as social media and privacy laws. Many of these laws are being challenged in court, however, and several have been blocked from taking effect, leaving many businesses uncertain about whether and how to comply.

Read more here.

What Do the New Social Media Verdicts and Settlements Mean for Children’s Privacy?

Cases alleging that social media negatively impacts children’s mental health and exposes them to predators have drawn multimillion-dollar awards against social media platforms and settlements in states across the country. But what exactly do these developments mean in practical terms for children’s online privacy and safety?

Read more here.

Team Member Spotlight: Ryan Smith

How did you develop your area of focus?

In law school I served as a law clerk in the United States Senate and worked on an investigation into a data privacy breach. I really enjoyed it; privacy is something that impacts everyone, and it feels a lot less abstract than other areas of the law. It also brings in a lot of stakeholders, from individuals to businesses to the government. I started my legal career working in digital advertising, which is a great window into how privacy laws are implemented and how businesses handle new (and rapidly changing) requirements. I enjoyed working in an area of the law that was developing—there’s a lot untested in privacy, and as a junior practitioner I felt like I had a front-row seat to developments that would impact the rest of my career.

After that, I worked in cybersecurity incident response for a bit. I spent a lot of time thinking about the collection of data, and I wanted to help businesses respond to unauthorized disclosure. It was a bit like working in an emergency room—high stakes, time-sensitive, anxious clients. I worked with a wide array of clients: some large entities that had an army ready to go and some mom-and-pop-sized entities that needed a lot more direct guidance. It taught me a lot about how a lawyer functions as a counselor.

I think I’m fortunate to have worn a lot of hats as a lawyer, and I try to keep those different perspectives in mind when I counsel my clients now. I’ve been in the room when the government is scrutinizing a business’s data collection practices. I’ve been in the room with a business trying to develop a workable compliance strategy. I’ve spoken with individuals whose personal information was compromised in an incident and understood how they felt. All of that goes into how I think about privacy law now.

What is exciting you/grabbing your attention right now?

The desire at all levels of government to update requirements around children’s privacy has been percolating for a long time, and it represents a great opportunity to think creatively about how to responsibly handle data. Different states and countries are taking vastly different approaches that make compliance challenging. I understand the reason for this push: The world has changed substantially since COPPA was passed more than 25 years ago. I was a kid online once, and as a privacy lawyer now I think about my digital footprint from the ’90s and wonder what I was inadvertently revealing about myself. The ways kids today interact with the internet is so different from when I was on dial-up, and those footprints are even larger and present more compliance challenges. But Congress has been trying to pass COPPA 2.0 and KOSA for years now and hasn’t quite succeeded—and I don’t know if an election year is when they will manage to pull it off. We’ll see where things land.

What would people be surprised to learn about you?

About 10 years ago, my apartment building caught on fire and I rescued my neighbor’s pet guinea pig at 2 a.m. in the snow.

Events Spotlight

Loeb & Loeb’s 2026 AI Summit Brings Industry Leaders Together in Chicago

  • Loeb & Loeb hosted its second Chicago AI Summit on July 14, bringing together in-house counsel from leading companies in diverse industries—including health care, technology, consumer products, financial services, food and beverage, manufacturing, transportation, retail, media and communications, sports and entertainment, and professional services—for a morning of discussions on the evolving legal, regulatory and business considerations surrounding AI. The event included a fireside chat with Gabriel Hayduk, global data protection officer at Whirlpool Corporation, who shared insights into the company’s AI initiatives and how its legal department is leveraging AI to drive efficiency, enhance legal service delivery and better support business objectives. A presentation by Kenneth Adler, chair of the firm’s Technology & Sourcing practice, and Liz Allen, chair of the Emerging Technologies practice, examined the current AI legal and technical landscape, offering insights into recent regulatory developments and emerging trends shaping AI innovation and adoption. And two sessions of roundtables led by Loeb lawyers explored critical issues in AI including privacy, intellectual property, governance, talent and production, advertising law, contracting, and employment law.

Key Takeaways from the 2026 Chicago AI Summit: Privacy Roundtables

  • During the privacy roundtables, hosted by Caroline Hudson, deputy chair, Privacy, Security & Data Innovations, participants from different backgrounds and industries engaged in a robust conversation about managing privacy compliance at the intersection of internal and external AI applications, raising several practical concerns faced by organizations today, including data stewardship and limitations on use of company data to train AI models, drawbacks of risk-based approaches to AI use cases, and the critical need for comprehensive contract terms, compliance programs and disclosures regardless of industry.

In Case You Missed It

Loeb Named in BTI Consulting Group’s ‘Client Service A-Team’ Report for 2026

  • Loeb & Loeb is proud to be named to BTI Consulting Group’s “Client Service A-Team” for 2026, a list of top law firms based exclusively on direct feedback from corporate counsel. The annual report identifies the firms most highly regarded by Fortune 1000 companies and other large organizations, and serves as a widely recognized benchmark for client experience.

Loeb & Loeb Earns Top Rankings in Legal 500 United States Guide for 2026

Loeb & Loeb Honored Among Leading Firms in 2026 Chambers USA Guide

  • The 2026 edition of Chambers USA honored 43 of Loeb & Loeb’s lawyers and 19 of the firm’s practice areas for excellence. The firm was recognized in Privacy & Data Security: The Elite (Nationwide). Jessica Lee, chair, Privacy, Security & Data Innovations, was ranked in Nationwide Artificial Intelligence, Nationwide Privacy & Data Security: Adtech, and Nationwide Privacy & Data Security: Privacy.

Does the New Federal Data Privacy Bill Have a Snowball’s Chance of Passing?

  • Jessica Lee, Loeb’s chief privacy and security partner and chair of the firm’s Privacy, Security & Data Innovations practice, is quoted in an AdExchanger article analyzing the prospects of the SECURE Data Act, a newly introduced federal privacy bill aimed at establishing a single national data privacy standard.

State Age-Appropriate Website Design Laws Pick Up Steam

  • Loeb partner Nerissa Coyle McGinn is quoted in a recent Corporate Counsel article discussing the expanding wave of state age appropriate design laws and the growing uncertainty these laws create for companies operating online services.

Unpacking California’s Record CCPA Settlement with GM Over Connected Vehicle Data Sales

  • In the largest proposed settlement under the California Consumer Privacy Act (CCPA) to date, General Motors LLC and its subsidiary OnStar will pay $12.75 million in civil penalties for allegedly collecting, retaining and later selling driver- and driving-related data from hundreds of thousands of California OnStar subscribers. The May 8 enforcement action filed by the California Attorney General and the district attorneys of several counties, with the support of the California Privacy Protection Agency, asserts violations of the CCPA, California’s Unfair Competition Law and California’s False Advertising Law.

App Store Age Verification Laws Trigger New Federal and State Children’s Privacy Requirements

  • Starting in January 2026, three state app store age verification laws were set to take effect: Texas’ App Store Accountability Act, Utah’s App Store Accountability Act and Louisiana’s App Store Accountability Act. California’s app store age verification law, the Digital Age Assurance Act, passed in September 2025 and is set to take effect Jan. 1, 2027; several other states also introduced age verification legislation in 2025. While their names would suggest these laws are focused on regulating app stores, they also impose significant obligations on app developers.

Quick Takes


Sign up for our Hashed & Slated newsletter by creating an account and selecting Privacy, Security & Data Innovation as your area of interest here.