Artifact GuideUSMinors

US CCPA Minors

A business with actual knowledge must obtain affirmative authorization before selling or sharing personal information of a consumer under 16, with the authorizing person depending on whether the consumer is under 13 or aged 13 to 15.

Separate the under-13 parent-or-guardian path from the age-13-to-15 consumer path, and keep the resulting sale-and-sharing block synchronized across every affected system.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
4

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

A business with that a consumer is under 16 cannot sell or share that consumer's personal information without affirmative authorization. A parent or guardian authorizes for a consumer under 13; a consumer aged 13 through 15 can authorize for themselves. A business that willfully disregards age is deemed to have actual knowledge.

Search this module

Find a question or answer quickly

4 of 4 questions
Question 1

What should teams do about Minors under the US CCPA?

First determine whether the business sells or shares the minor's personal information and what facts give the business of age. Do not collect extra age or identity data without a defined need, but do not ignore account records, birth dates, product design, support contacts, or other facts already known to the business.

For a consumer under 13, establish, document, and use a reasonable method to determine that the person authorizing is the parent or guardian. Section 7070 examples include a signed consent form, a payment method that notifies the primary account holder, a staffed toll-free call, videoconference or in-person verification, and a government-ID check followed by prompt deletion of the identification. This CCPA authorization is additional to any verifiable parental consent required by the federal Children's Online Privacy Protection Act.

For ages 13 through 15, establish, document, and use a reasonable process that lets the consumer affirmatively opt in. After either age path produces authorization, tell the parent, guardian, or consumer about the continuing right to opt out and how to exercise it. The privacy policy must describe the applicable processes.

  • Block sale and sharing by default once the business has that the consumer is under 16.
  • Use separate authorization paths for under-13 consumers and consumers aged 13 through 15.
  • Record the authorization method, person authorizing, scope, timestamp, and systems released from the block.
  • Keep refusal and revocation effective across advertising, data, account, and vendor systems.
  • If an opted-in minor later opts out, wait at least 12 months before asking the consumer to opt in again, except where the regulations allow an earlier transaction-specific prompt.

When does the CCPA require opt-in for a consumer under 16?

A business with that a consumer is under 16 must obtain affirmative authorization before selling or sharing that consumer's personal information. Willful disregard of age counts as actual knowledge. The rule applies to sale and sharing, not to every collection or use of a minor's personal information, although other privacy laws may impose separate duties.

Who can authorize sale or sharing for a minor under the CCPA?

A parent or guardian must authorize for a consumer under 13. A consumer who is at least 13 and less than 16 may authorize for themselves. The business must keep the age-band decision and use the corresponding process; an under-13 consumer cannot self-authorize under this rule.

How can a business verify a parent or guardian for a child under 13?

Section 7070 requires a reasonable, documented method. Its examples include a signed form returned by mail, fax, or scan; a payment method that notifies the primary account holder; a staffed toll-free call; videoconference; in-person verification; or checking government identification against a database and promptly deleting the identification after verification. The appropriate method depends on the process and risk.

Does CCPA authorization replace COPPA parental consent?

No. Section 7070 states that CCPA consent to sale or sharing is additional to any verifiable parental consent required by the federal Children's Online Privacy Protection Act. A service involving children under 13 must assess COPPA and any other child or teen privacy law separately.

What must happen after a minor opts in?

The business must inform the parent or guardian of an under-13 child, or the consumer aged 13 through 15, of the continuing right to opt out of sale or sharing and the process for doing so. It must preserve the authorization and enforce the resulting status across the affected account, advertising, transfer, and vendor systems.

Does turning 16 automatically authorize sale or sharing?

No. Turning 16 ends the CCPA's special under-16 authorization rule, but it does not convert a prior refusal or opt-out into consent. Existing sale-and-sharing opt-outs remain effective until the consumer later consents through a compliant process.

Citations
Question 2

Which boundary questions should teams resolve?

The CCPA's special rule is tied to sale or sharing and , not to every collection of information about a person under 18. Other laws, including the federal Children's Online Privacy Protection Act, may impose separate duties for child-directed services or collection from children under 13.

  • Separate ordinary collection from sale or sharing; the CCPA authorization described here applies to sale or sharing.
  • Separate a consumer under 13 from one aged 13 through 15 because the authorizing person changes.
  • Assess from the facts the business has, including whether it willfully disregarded age.
  • Check other child and teen privacy laws separately; this page cannot determine their application.
Citations
Question 3

What evidence should teams keep for Minors under the US CCPA?

Keep evidence of the age signal, the applicable age band, the authorization process, and the downstream block. Avoid retaining more identity data than the method reasonably requires.

  • Age-knowledge inputs and the documented decision on or willful disregard.
  • Sale and sharing inventory for minors, default block, and downstream enforcement tests.
  • Parent or guardian verification for under-13 consumers, or consumer opt-in for ages 13 through 15.
  • Privacy-policy disclosure, authorization or refusal record, revocation, re-prompt date, owner, and review date.
Citations
Question 4

Which mistakes create risk when handling Minors under the US CCPA?

Using the wrong age band, ignoring facts that establish , or recording consent without changing system behavior breaks the authorization process.

  • Letting a consumer under 13 authorize for themselves.
  • Demanding parent authorization from a consumer aged 13 through 15 under this CCPA rule.
  • Treating silence, a preselected control, or acceptance of broad terms as affirmative authorization.
  • Ignoring age information already held by the business or willfully avoiding age facts.
  • Recording the opt-in in one database while advertising or data-transfer systems continue using a default state.
Citations
Primary sources

References and citations

Related guides

Explore more topics

California Data Brokers: CCPA, Registration, and DROP Duties
Decide whether a CCPA business is also a California data broker and track registration, privacy metrics, DROP deletion, vendor, and audit duties.
CCPA Consumer Rights Workflow: Requests, Clocks, and Evidence
Route CCPA requests by right, apply the correct verification and response rule, coordinate downstream action, and retain a clear decision record.
CCPA Contract Classification: Service Provider or Third Party?
Classify CCPA recipients from their actual processing and contracts, then document the clauses, restrictions, monitoring, and opt-out consequences.
CCPA Dark Patterns: Rules, Examples, and Review Checklist
Check a CCPA privacy interface for clear language, symmetrical choices, unnecessary steps, and other designs that can invalidate consent.
CCPA Deadlines and Compliance Calendar
Track CCPA request clocks, annual duties, DROP dates, and phased 2026-2030 deadlines for risk assessments, ADMT, and cybersecurity audits.
CCPA Do Not Sell or Share Guide
Classify CCPA sales and sharing, provide valid opt-out methods, honor preference signals, stop disclosures within 15 business days, and notify recipients.
CCPA Do Not Sell or Share: Implementation and Testing
Implement CCPA sale-or-sharing opt-outs across links, GPC, consent state, ad tech, recipients, confirmation, privacy disclosures, and evidence.
CCPA Do Not Sell or Share: Scope and Implementation
Determine whether a transfer is a CCPA sale or sharing, provide the required opt-out path, honor preference signals, and propagate the choice.
CCPA DSAR Workflow: Intake, Verification, and Response
Run CCPA data-subject requests from intake through verification, search, exception review, downstream action, response, and retained evidence.
CCPA Financial Incentives: Notice, Consent, and Data Value
Assess a loyalty, discount, payment, or service program under the CCPA and document notice, opt-in, withdrawal, and data-value requirements.
CCPA Global Privacy Control (GPC): team obligations and technical implementation
Implement Global Privacy Control as a CCPA sale and sharing opt-out across browsers, devices, known accounts, and relevant downstream systems.
CCPA Notice at Collection: Timing, Content, and Examples
Place a CCPA notice where consumers encounter it before collection and disclose categories, purposes, retention, sale or sharing, and required links.
CCPA Opt-Out Signal Workflow: Detect, Apply, and Test GPC
Process CCPA opt-out preference signals across browsers, devices, profiles, accounts, offline data, conflicts, recipients, and confirmation controls.
CCPA Penalties and Fines: Current Amounts
See current CCPA fines, civil penalties, security-breach damages, adjustment rules, and the facts needed before estimating exposure.
CCPA Personal and Sensitive Information Categories
Classify personal and sensitive personal information under the current CCPA, including exclusions and the duties each category can trigger.
CCPA Privacy Policy Template: Required Content and Review
Draft and maintain a CCPA privacy policy covering data practices, rights, request methods, GPC handling, minors, contacts, and the last-updated date.
CCPA Risk Assessments, Cybersecurity Audits, and ADMT
Apply California's regulations effective January 1, 2026 for risk-assessment triggers, phased cybersecurity audits, ADMT rights, evidence, reviews, and CPPA submissions.
CCPA vs CPRA: What Changed and Which Rules Apply
Compare the original CCPA with the CPRA amendments and learn why current California privacy work must use the CCPA as amended, not two separate laws.
CCPA vs GDPR: Scope, Rights, Duties, and Evidence
Compare the California CCPA and EU GDPR by scope, roles, legal basis, rights, advertising transfers, contracts, security, deadlines, and enforcement.
Does the CCPA apply to my business? Threshold guide
Apply the CCPA revenue, data-volume, and sale-or-sharing revenue thresholds, then check California nexus, control, joint ventures, roles, and exemptions.
US CCPA Applicability Test Guide
Apply the CCPA entity-by-entity: test California nexus, for-profit control, current thresholds, related-entity routes, exemptions, and processing roles.
US CCPA Compliance Checklist
A verifiable CCPA checklist for scope, data mapping, notices, rights, opt-outs, contracts, retention, security, risk assessments, audits, ADMT, and evidence.
US CCPA Compliance Guide
Build a CCPA operating model for entity scope, data mapping, notices, rights, opt-outs, contracts, retention, security, assessments, audits, ADMT, and evidence.
US CCPA Dark Patterns Guide
Review CCPA privacy interfaces for plain language, symmetry, minimal steps, neutral presentation, valid consent, and reliable opt-out operation.
US CCPA Data Broker Crossover Guide
Test whether a CCPA business is also a California data broker, then assign registration, metrics, DROP, deletion, downstream, and audit duties.
US CCPA DSAR Verification Guide
Verify CCPA know, delete, correct, and ADMT-access requests with request-specific, secure, minimized methods without adding friction to opt-outs.
US CCPA Enforcement and Penalties Guide
Understand CPPA investigations, Attorney General civil actions, CCPA administrative orders, current penalties, and the limited security-breach private action.
US CCPA Financial Incentives Guide
Decide whether a CCPA financial-incentive rule applies, then document the notice, data-value method, opt-in, withdrawal, and nondiscrimination checks.
US CCPA GPC Signal Guide
Implement Global Privacy Control under the CCPA across browsers, devices, accounts, ad technology, downstream recipients, and consumer notices.
US CCPA Minors Guide
Apply the CCPA opt-in rules for selling or sharing personal information of consumers under 16, including age bands, authorization, notices, and evidence.
US CCPA Notice at collection Guide
Build a CCPA Notice at Collection for online and offline collection points, including categories, purposes, sale or sharing, retention, links, and change control.
US CCPA Personal and Sensitive PI Categories Guide
Classify CCPA personal information and sensitive personal information, apply exclusions, and map each category to notices, rights, retention, security, sale, and sharing.
US CCPA Privacy Law FAQ
Direct answers on CCPA scope, rights, notices, opt-outs, GPC, minors, sensitive information, financial incentives, and data brokers.
US CCPA Privacy Notices and Disclosures Guide
Choose and maintain each CCPA consumer notice: privacy policy, collection, sale or sharing, sensitive-information limits, financial incentives, and ADMT.
US CCPA Privacy Policy Guide
Build and maintain a CCPA privacy policy covering online and offline practices, 12-month disclosures, consumer rights, request methods, and annual updates.
US CCPA Requirements Guide
Plain-language CCPA requirements covering scope, minimization, notices, rights, opt-outs, contracts, security, records, risk assessments, audits, and ADMT.
US CCPA Scope and Thresholds Guide
CCPA scope and threshold reference covering the current $26,625,000 revenue threshold, the 100,000-consumer-or-household test, related entities, and exemptions.
US CCPA Service Provider Contractor and Third Party Contracts Guide
Classify CCPA recipients and check the distinct contract terms for service providers, contractors, and third parties before disclosing personal information.
US CCPA Service Provider Contractor Contracts Guide
Check CCPA service-provider and contractor agreements for specific purposes, use restrictions, consumer-request support, subcontractors, and remediation.
US CCPA Thresholds Guide
Apply the CCPA business thresholds per legal entity, including the 2025 CPI-adjusted revenue amount, volume and sale-or-sharing tests, and control routes.
What must a CCPA privacy policy include?
A practical guide to CCPA privacy-policy content, placement, annual updates, consumer rights, request methods, and supporting evidence.
What must CCPA service-provider contracts include?
Required CCPA contract terms, role checks, subcontractor flow-downs, oversight rights, and evidence for service providers and contractors.
What should teams do about consumer request verification under the CCPA?
Choose a proportionate CCPA verification method for know, delete, and correct requests without collecting unnecessary identity data.
When does the CCPA require risk assessments or cyber audits?
CCPA triggers, deadlines, evidence, retention, and submission duties for risk assessments and annual cybersecurity audits.