Meta’s EUR 15 billion settlement with attorneys general from 29 states carries a provision that has drawn scrutiny for a case built around child safety: the states have agreed not to sue the company under existing child safety laws over how it retains and uses children’s data.
The concession applies to a specific purpose. It allows Meta to collect and hold information needed to train and test an age-assurance model, and it comes with certain limits. Still, granting that legal cover in a dispute centered on protecting minors is a notable policy choice, and one that may be hard to enforce in practice.
What the settlement requires of Meta
Under the agreement, Meta must develop, train, and begin testing a system designed to identify which users on its platforms are under the age of 13. That work has to start within a year of the document’s effective date. The agreement does not require the system to be AI-based, though Meta’s current age-detection tools already rely on AI.
The deal also draws a clear line on advertising. Meta cannot use data from users under 13 for ad targeting, marketing, or algorithmic optimization. Instead, the company is expected to isolate children’s behavioral signals and other data and use them only to detect and remove under-13 accounts.
The COPPA question
Federal law, specifically the Children’s Online Privacy Protection Act, or COPPA, generally requires websites and apps to limit how they collect and retain children’s personal information. The settlement states that Meta should not have to violate COPPA to train or deploy its age-assurance models. It also records that the state attorneys general have agreed “fully, finally, and forever” not to bring past, present, or future COPPA claims, or claims under similar state laws, tied to Meta’s use of children’s data.
Philip N. Yannella, a partner at law firm Blank Rome and co-chair of its Privacy, Security and Data Protection practice, said the arrangement is not unreasonable. “These kinds of data minimization guardrails are pretty typical for privacy compliance: e.g., verifying compliance with deletion requests,” he said. He added an important caveat: COPPA is a federal law enforced primarily by the Federal Trade Commission rather than the states. Because the FTC is not a party to this settlement, it remains unclear whether the agency has separately agreed to the same compromise.
Enforcement and open questions
Keeping data technically and organizationally separated from the rest of a company’s systems is difficult, yet that is what Meta is being asked to do. An independent auditor will monitor the company’s compliance, which means oversight does not rest on Meta’s word alone.
Policing the limitation could still prove complicated. The information could, in theory, flow into other Meta systems over time, raising questions about whether the data or the insights drawn from it end up used elsewhere in the company. The agreement does not spell out what data Meta will keep to train the model, how much behavioral information that might include, or how long the company will retain it. How these models evolve as Meta meets the settlement’s terms is also unspecified.
The settlement bars state attorneys general from raising COPPA or similar state-law claims over this use of children’s data, and it requires Meta to begin testing its under-13 detection model within one year of the agreement’s effective date.
Source
Image: techcrunch.com