New York’s SAFE for Kids Act: Final Rules Released—What Companies Need to Know Before January 2027
The New York Office of the Attorney General (OAG) has now released the final rules implementing the SAFE for Kids Act, providing companies with detailed guidance on how to comply before the law takes effect on January 25, 2027.
While the SAFE for Kids Act specifically applies to certain social media platforms, the operational expectations around age assurance, parental consent, and privacy-preserving implementation reflect broader regulatory trends that many organizations serving minors should be watching.
For organizations operating social platforms, gaming experiences, AI applications, and other digital services used by minors, the question is no longer what might the rules require—it’s how to implement them effectively while protecting user privacy.
The good news? Companies still have time to prepare. The law becomes effective on January 25, 2027, making now the right time to evaluate your age assurance and parental consent strategy.
What counts as an “addictive feed” and who’s covered?
- “Addictive feeds” = feeds personalized by algorithms using a user’s/device’s data to recommend/prioritize content in a way that extends time on platform.
- Covered operators may not provide addictive feeds to minors without either (a) determining the user is not a minor (via compliant age assurance), or (b) obtaining verifiable parental consent for minors.
- Nighttime notifications (12–6am ET) about addictive feeds are similarly restricted without VPC.
- Certain platforms may be exempt, but if exemptions lapse, operators get 180 days on the first instance (30 days on subsequent) to comply.
Age assurance: standards, accuracy, and options
Platforms must use commercially reasonable and technically feasible methods to determine whether a user is an adult before providing access to algorithmically personalized feeds or nighttime notifications. Key requirements include:
-
Offer one or more age assurance methods, including at least one alternative that does not require a government-issued ID. Age assurance methods must meet required accuracy benchmarks and be validated through annual testing.
- If age assurance results are inconclusive (and the platform has no actual knowledge that the user is a minor), operators may presume the user is an adult only if all required methods have been completed and at least one meets the total accuracy minimum.
- If using a government-issued ID, platforms must accept both U.S. and non-U.S. IDs and provide at least one alternative method that does not require government-issued identification.
- Explain age assurance methods and data handling practices to users; designs cannot discourage completion or facilitate circumvention.
- Monitor for circumvention, conduct annual accuracy testing, and maintain records, including false positives, false negatives, inconclusive results, and testing against attempted attacks.
- Provide an appeals process for users incorrectly classified as minors without requiring government-issued ID as the only path to appeal.
- Information collected for age assurance may only be used for age assurance or parental consent purposes and must be deleted or de-identified immediately after its intended use.
- Platforms must collect only the minimum amount of personal information necessary to determine age.
- Users must be able to update their age status once they turn 18.
- Platforms should retain documentation demonstrating compliance with annual testing and accuracy requirements.
Verifiable Parental Consent (VPC): Key Requirements
To enable an addictive feed or nighttime notifications for a minor:
- Minor approval to request parental consent (the minor must first consent to the platform contacting their parent).
- Parent notice: Clear disclosure that the requested feature requires parental consent under New York law, that the minor may continue to access the platform without the restricted feature, and that consent can be withdrawn at any time.
- Parent age assurance: Before granting consent, the parent must complete an age assurance process to confirm they are an adult.
- Parent verification methods: Offer at least one option that does not require a government-issued ID (unless already collected for another legal purpose), and at least one option that does not require creating an account or making a purchase.
- Accessibility: Provide instructions in the 12 most commonly spoken languages in New York and offer an easy mechanism for parents and minors to withdraw consent.
- COPPA alignment: For users under 13 or child-directed services, COPPA-compliant consent methods may be used if they also satisfy the SAFE for Kids Act’s additional requirements.
- Renewals: If a parent declines consent, platforms may only request consent again at the minor’s request.
- Withdrawal of consent: Both the parent and the minor must be able to withdraw consent at any time.
- Access to the platform: A minor who does not receive parental consent may not be prevented from generally accessing the platform or its content. The restrictions apply only to addictive feeds and
nighttime notifications.
Data use, retention, and privacy
- Collect minimum necessary data for compliance; use it only for compliance; encrypt in transit/at rest; delete promptly (with narrow retention for legal compliance + method metrics).
- Maintain 10-year records of method usage, outcomes, and testing results.
- Provide no additional parental access to a minor’s activity beyond what’s required. Notices must not reveal a minor’s personalized attributes, content selections, specific content, or other users’ identities.
Timelines & enforcement
- Final Rules Published: July 29, 2026
- SAFE for Kids Act Effective Date: January 25, 2027
- Potential Enforcement: Civil penalties of up to $5,000 per violation, along with other enforcement actions authorized by the Attorney General.
What Changed Between the Proposed and Final Rules?
The final regulations maintain the overall framework introduced in the proposed rules while providing additional clarity around:
- acceptable age assurance methods
- privacy-preserving implementation
- annual testing and audit expectations
- parental consent workflows
- data minimization and deletion requirements
- user rights when they turn 18
- technology-neutral approaches to compliance
For many organizations, the biggest takeaway is that the implementation expectations are now clear enough to begin planning and deployment.
Preparing for January 2027
- Assess coverage & scope
- Determine if your properties are covered; map NY user exposure; identify any exemptions and contingencies.
- Determine if your properties are covered; map NY user exposure; identify any exemptions and contingencies.
- Design a compliant feed fallback
- Build a non-algorithmic feed option (e.g., follows-only, chronological) accessible to minors without VPC—and ensure parity of access/quality per the rules.
- Build a non-algorithmic feed option (e.g., follows-only, chronological) accessible to minors without VPC—and ensure parity of access/quality per the rules.
- Select & validate age assurance methods
- Choose multiple methods (incl. a non-ID option).
- Plan annual certification/testing (accuracy, false pos/neg, circumvention).
- Prepare the appeals workflow.
- Implement verifiable parental consent (VPC) flows
- Minor pre-consent step → parent notice → parent method options.
- Support withdrawal anytime; log events; localize to 12 languages.
- Engineer privacy-by-design
- Minimize data; encrypt; limit retention; segregate compliance data; document deletion timelines.
- Minimize data; encrypt; limit retention; segregate compliance data; document deletion timelines.
- Update UX copy & notices
- Draft clear, conspicuous notices for minors and parents (no hidden disclosures; no dark patterns).
- Draft clear, conspicuous notices for minors and parents (no hidden disclosures; no dark patterns).
- Vendor governance
- If you rely on third parties for age assurance/VPC, you remain responsible. Contract for accuracy, privacy, testing, and records.
- If you rely on third parties for age assurance/VPC, you remain responsible. Contract for accuracy, privacy, testing, and records.
- Plan for 18th birthdays
- Offer a path for minors to update age status when they turn 18.
How PRIVO Supports SAFE for Kids Act Compliance
PRIVO’s privacy-preserving platform helps organizations operationalize the SAFE for Kids Act by providing:
Privacy-preserving Age Assurance
- Multiple verification methods
- Non-ID options
- Configurable workflows
- Annual testing support
Verified Parental Consent
- Parent identity verification
- Consent collection
- Consent withdrawal
- Ongoing relationship management
Compliance Operations
- Audit documentation
- Consent records
- Data minimization
- API integration
- Jurisdiction-aware workflows
Beyond New York
While the SAFE for Kids Act applies in New York, organizations are increasingly facing age assurance and parental consent requirements across multiple jurisdictions. Building flexible, privacy-preserving compliance capabilities today can help support future regulatory obligations worldwide.
Preparing for January 2027 starts now.
Implementing age assurance, parental consent, and privacy-by-design often requires coordination across legal, engineering, product, privacy, customer support, and trust & safety teams. Starting early gives organizations time to evaluate solutions, test implementations, and prepare for compliance before the law takes effect.
👉 Want help? Contact PRIVO to get started.




