Update: July 9, 2026
Texas has established one of the nation’s most comprehensive frameworks governing how digital services interact with children and teens. Together, the Texas App Store Accountability Act (TASAA), the SCOPE Act (HB 18), and the Texas Data Privacy and Security Act (TDPSA) create layered responsibilities for app stores, app developers, and organizations that collect or process children’s personal information.
The legal landscape continues to evolve. TASAA is currently enforceable while ongoing constitutional challenges proceed through the courts, and portions of the SCOPE Act remain subject to litigation. Organizations should be prepared to comply with the requirements currently in effect while continuing to monitor future legal developments.
Below, we explain how these three laws work together, what responsibilities belong to app stores versus developers, and why app store parental consent does not replace the in-app consent obligations required under laws such as COPPA and GDPR.
The Texas App Store Accountability Act (TASAA) establishes a shared compliance framework between app stores and app developers designed to help protect minors online. Although the law continues to face constitutional challenges, Texas is currently permitted to enforce TASAA while the litigation proceeds.
The law divides responsibility between app stores, which manage age verification and download-level parental consent, and developers, which remain responsible for implementing age-appropriate experiences and complying with applicable privacy laws within their apps.
Developers must:
App stores must:
Key Takeaway: The app store’s parental consent covers the download or purchase event. It does not replace any parental consent developers may still need to obtain under COPPA, GDPR, or other applicable laws for account creation, personal information collection, messaging, profiling, or other ongoing in-app activities.
2) Securing Children Online through Parental Empowerment (SCOPE) Act: Big Ambitions, Partial Injunction
The SCOPE Act (HB 18) targets minors’ social experiences (age registration, content filtering, ads limits, parental tools and consent). A federal court has blocked key provisions (e.g., content filtering and broad age-verification mandates). The case is on appeal, so requirements may change.
Low-regret prep while litigation continues:
Continue age capture/registration in account flows (and log immutable age status/changes).
Keep parental-consent workflows ready for higher-risk features (posting, messaging, data sharing).
Maintain a feature flag/toggle approach so stricter controls can be re-enabled quickly if the injunction narrows.
The Texas Data Privacy and Security Act applies to most companies doing business in Texas (with SBA “small business” carve-outs). It grants Texans rights to access, correct, delete, portability, and to opt out of sales, targeted ads, and certain profiling. It requires privacy notices, data minimization, security, and Data Protection Assessments (DPAs) for targeted ads, sales, profiling with risk, and sensitive data (which includes children’s data).
Enforcement: Texas AG only, with a 30-day cure period.
Note: If you comply with COPPA’s verifiable parental consent online, TDPSA treats that as satisfying parental-consent requirements for children’s data.
| Touchpoint | Primary Duty | What Must Happen |
|---|---|---|
| Pre-download / purchase | App Store | Verify age category; link to verified parent account for minors; obtain per-transaction parental consent; disclose rating/reasons/data summary; pass consent status to developer. |
| In-app engagement | Developer | Apply age-appropriate experiences; obtain in-app consent where required (COPPA/GDPR/SCOPE Act); limit/minimize data; provide parental controls; honor revocations. |
| General privacy | Controller (most companies) | TDPSA notice/rights (access, correct, delete, portability, opt-outs), security, data minimization, DPAs for targeted ads/sales/profiling/sensitive data; special handling of kids’ data. |
Account & Age Handling
Parental Consent & Controls
Data Practices (TDPSA)
App Store Interfaces (TASAA Prep)
Operational Resilience
How PRIVO Bridges the Gaps
Smart Age Gate™, Age Aware™ Signal , Age Verification – Privacy-preserving age-assurance that aligns with TASAA’s “commercially reasonable” standard and interoperates with app-store signals.
PRIVO iD Platform – End-to-end parental consent (download-level and in-app), revocations, and audit logs that satisfy COPPA/GDPR and support SCOPE Act and TDPSA documentation.
Kids Privacy Assured Program – Ongoing alignment with privacy regulations protecting children.
Texas is connecting the dots between platform-level access control (TASAA), social engagement safeguards (SCOPE), and baseline privacy rights (TDPSA). The smartest path is an interoperable compliance stack that separates download consent (app store) from in-app consent and data duties (developer) — all backed by strong privacy engineering and clear parental engagement.
PRIVO helps you do exactly that — in Texas and beyond.
🔗 Contact us to learn how PRIVO’s Age Aware™ Solutions can help your organization comply with the Texas laws and other emerging regulations requiring age verification and consent.
Status Disclaimer: This post is for general information and reflects our understanding as of July 2026. SCOPE and TASAA litigations are ongoing and may change obligations; consult counsel for specific advice.
#AgeVerification #TASAA #AgeAssurance #ChildPrivacy #ParentalConsent #PRIVO