Artifact GuideCalifornia CCPACCPA minors

US CCPA Minors

A business with actual knowledge must obtain affirmative authorization before selling or sharing personal information of a consumer under 16: parental authorization for under 13 and the consumer's authorization for ages 13 to 15.

This guide explains the CCPA rules for consumers under 16, including the need for affirmative authorization before selling or sharing their personal information, while separating under-13 parental consent from the 13-to-15 age group.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

A business with actual knowledge that a consumer is under 16 cannot sell or share that consumer's personal information unless it first receives affirmative authorization. A parent or guardian must authorize for a child under 13; a consumer aged 13 through 15 may authorize personally. This rule is an opt-in for sale and sharing, not a general permission to collect or use children's data.

Section 1

How should teams handle Minors' personal information under the US CCPA?

A business that has actual knowledge it sells or shares personal information of a consumer under 16 must get affirmative authorization before doing so. For consumers under 13, that authorization must come from a parent or guardian; for consumers at least 13 and under 16, the consumer can give the authorization themselves. The business must establish, document, and follow the applicable process and describe it in its privacy policy.

Determine whether the business has actual knowledge of age, including knowledge it willfully disregards. Then map every disclosure that may be a sale or sharing. Do not begin that sale or sharing until the correct person completes the age-appropriate authorization process.

  • Under 13: use a reasonable method to verify that the person authorizing is the child's parent or guardian. The regulations list examples including a signed consent form, a qualifying payment-card transaction, trained staff by telephone or videoconference, an in-person check, or a government-ID check followed by prompt deletion of the ID.
  • Ages 13 through 15: use a two-step process in which the consumer clearly requests to opt in and separately confirms the choice.
  • Explain the right to opt out later and provide a method that meets the ordinary sale-or-sharing opt-out requirements. After an opt-out, the business generally must wait at least 12 months before asking the consumer to opt in again, unless a regulatory exception applies.
  • Describe the minors process in the privacy policy and keep the production flow consistent with that description.
Section 2

Who should own California CCPA minors decisions, and what evidence should prove them?

Product and engineering should enforce the age state and block covered disclosures; privacy or legal should classify sale and sharing and approve the authorization language; advertising and vendor owners should suppress downstream transfers; and support should handle later opt-outs.

Keep the age-band decision, authorization method, identity or parental-verification result, confirmation record, notice version, timestamp, later opt-out, 12-month solicitation hold, and downstream suppression evidence. Minimize the information collected solely to verify age or parental authority; when government identification is used to verify a parent or guardian, delete it promptly after verification.

  • Test under-13, ages 13 through 15, age-unknown, and age-16-or-older states.
  • Confirm that sale and sharing remain off while authorization is incomplete or fails.
  • Confirm that an opt-out reaches advertising, audience, identity, analytics, and downstream-recipient systems.
  • Review age signals and audience design when the service, marketing, or user population changes.
Section 3

Which edge cases should teams check before relying on a California CCPA minors decision?

The CCPA does not require every general-audience business to ask every visitor's age. The trigger is actual knowledge, including willful disregard, and the facts of the product, audience, account data, and collection flow matter.

Compliance with the CCPA minors rule does not establish compliance with the federal Children's Online Privacy Protection Act or other child-safety and privacy laws. COPPA uses different scope and consent tests, and section 7070 states that CCPA consent for sale or sharing is additional to any verifiable parental consent required under COPPA. Separately, personal information of consumers the business actually knows are under 16 is sensitive personal information under the regulations, which can trigger risk-assessment and other controls even when no sale or sharing occurs.

  • Do not use a parent or guardian authorization method for a 13-to-15-year-old as a substitute for the consumer's required two-step opt-in.
  • Do not infer authorization from continued use, a preselected control, acceptance of general terms, or failure to opt out.
  • Do not restart sale or sharing after a GPC or direct opt-out without a later valid opt-in.
  • Escalate uncertain age knowledge, mixed-audience services, and data flows that combine minor and household profiles.
Section 4

How should teams operationalize California CCPA minors controls?

Build the default state so sale and sharing stay off for a known under-16 consumer. Route the consumer to the correct authorization flow, record completion, and activate only the disclosures covered by that authorization.

Recheck the control when the consumer changes age band, withdraws, sends an opt-out preference signal, or when the business adds a new recipient or advertising use.

  • Identify the age knowledge, age band, affected profile, and each proposed sale or sharing flow.
  • Select and test the under-13 parental method or the 13-to-15 two-step consumer method.
  • Record authorization before activating the covered disclosure and preserve the notice version.
  • Provide and test later opt-out handling, including GPC where applicable.
Primary sources

References and citations

oag.ca.gov
Referenced sections
  • Official California AG regulations page documenting the CCPA rulemaking history and effective regulations that implementation teams should cite.
"make it easier for consumers to exercise their CCPA rights"
Related guides

Explore more topics

California Data Brokers: CCPA, Registration, and DROP Duties
Decide whether a CCPA business is also a California data broker and track registration, privacy metrics, DROP deletion, vendor, and audit duties.
CCPA Consumer Rights Workflow: Requests, Clocks, and Evidence
Route CCPA requests by right, apply the correct verification and response rule, coordinate downstream action, and retain a clear decision record.
CCPA Contract Classification: Service Provider or Third Party?
Classify CCPA recipients from their actual processing and contracts, then document the clauses, restrictions, monitoring, and opt-out consequences.
CCPA Dark Patterns: Rules, Examples, and Review Checklist
Check a CCPA privacy interface for clear language, symmetrical choices, unnecessary steps, and other designs that can invalidate consent.
CCPA Deadlines and Compliance Calendar
Track CCPA request clocks, annual duties, DROP dates, and phased 2026-2030 deadlines for risk assessments, ADMT, and cybersecurity audits.
CCPA Do Not Sell or Share Guide
Classify CCPA sales and sharing, provide valid opt-out methods, honor preference signals, stop disclosures within 15 business days, and notify recipients.
CCPA Do Not Sell or Share: Implementation and Testing
Implement CCPA sale-or-sharing opt-outs across links, GPC, consent state, ad tech, recipients, confirmation, privacy disclosures, and evidence.
CCPA Do Not Sell or Share: Scope and Implementation
Determine whether a transfer is a CCPA sale or sharing, provide the required opt-out path, honor preference signals, and propagate the choice.
CCPA DSAR Workflow: Intake, Verification, and Response
Run CCPA data-subject requests from intake through verification, search, exception review, downstream action, response, and retained evidence.
CCPA Financial Incentives: Notice, Consent, and Data Value
Assess a loyalty, discount, payment, or service program under the CCPA and document notice, opt-in, withdrawal, and data-value requirements.
CCPA Global Privacy Control (GPC): team obligations and technical implementation
Implement Global Privacy Control as a CCPA sale and sharing opt-out across browsers, devices, known accounts, and relevant downstream systems.
CCPA Minors: Opt-In Rules for Consumers Under 16
Apply the CCPA's under-13 parent authorization and age-13-to-15 consumer opt-in rules for sale or sharing of personal information.
CCPA Notice at Collection: Timing, Content, and Examples
Place a CCPA notice where consumers encounter it before collection and disclose categories, purposes, retention, sale or sharing, and required links.
CCPA Opt-Out Signal Workflow: Detect, Apply, and Test GPC
Process CCPA opt-out preference signals across browsers, devices, profiles, accounts, offline data, conflicts, recipients, and confirmation controls.
CCPA Penalties and Fines: Current Amounts
See current CCPA fines, civil penalties, security-breach damages, adjustment rules, and the facts needed before estimating exposure.
CCPA Personal and Sensitive Information Categories
Classify personal and sensitive personal information under the current CCPA, including exclusions and the duties each category can trigger.
CCPA Privacy Policy Template: Required Content and Review
Draft and maintain a CCPA privacy policy covering data practices, rights, request methods, GPC handling, minors, contacts, and the last-updated date.
CCPA Risk Assessments, Cybersecurity Audits, and ADMT
Apply California's regulations effective January 1, 2026 for risk-assessment triggers, phased cybersecurity audits, ADMT rights, evidence, reviews, and CPPA submissions.
CCPA vs CPRA: What Changed and Which Rules Apply
Compare the original CCPA with the CPRA amendments and learn why current California privacy work must use the CCPA as amended, not two separate laws.
CCPA vs GDPR: Scope, Rights, Duties, and Evidence
Compare the California CCPA and EU GDPR by scope, roles, legal basis, rights, advertising transfers, contracts, security, deadlines, and enforcement.
Does the CCPA apply to my business? Threshold guide
Apply the CCPA revenue, data-volume, and sale-or-sharing revenue thresholds, then check California nexus, control, joint ventures, roles, and exemptions.
US CCPA Applicability Test Guide
Apply the CCPA entity-by-entity: test California nexus, for-profit control, current thresholds, related-entity routes, exemptions, and processing roles.
US CCPA Compliance Checklist
A verifiable CCPA checklist for scope, data mapping, notices, rights, opt-outs, contracts, retention, security, risk assessments, audits, ADMT, and evidence.
US CCPA Compliance Guide
Build a CCPA operating model for entity scope, data mapping, notices, rights, opt-outs, contracts, retention, security, assessments, audits, ADMT, and evidence.
US CCPA Dark Patterns Guide
Review CCPA privacy interfaces for plain language, symmetry, minimal steps, neutral presentation, valid consent, and reliable opt-out operation.
US CCPA Data Broker Crossover Guide
Test whether a CCPA business is also a California data broker, then assign registration, metrics, DROP, deletion, downstream, and audit duties.
US CCPA DSAR Verification Guide
Verify CCPA know, delete, correct, and ADMT-access requests with request-specific, secure, minimized methods without adding friction to opt-outs.
US CCPA Enforcement and Penalties Guide
Understand CPPA investigations, Attorney General civil actions, CCPA administrative orders, current penalties, and the limited security-breach private action.
US CCPA Financial Incentives Guide
Decide whether a CCPA financial-incentive rule applies, then document the notice, data-value method, opt-in, withdrawal, and nondiscrimination checks.
US CCPA GPC Signal Guide
Implement Global Privacy Control under the CCPA across browsers, devices, accounts, ad technology, downstream recipients, and consumer notices.
US CCPA Notice at collection Guide
Build a CCPA Notice at Collection for online and offline collection points, including categories, purposes, sale or sharing, retention, links, and change control.
US CCPA Personal and Sensitive PI Categories Guide
Classify CCPA personal information and sensitive personal information, apply exclusions, and map each category to notices, rights, retention, security, sale, and sharing.
US CCPA Privacy Law FAQ
Direct answers on CCPA scope, rights, notices, opt-outs, GPC, minors, sensitive information, financial incentives, and data brokers.
US CCPA Privacy Notices and Disclosures Guide
Choose and maintain each CCPA consumer notice: privacy policy, collection, sale or sharing, sensitive-information limits, financial incentives, and ADMT.
US CCPA Privacy Policy Guide
Build and maintain a CCPA privacy policy covering online and offline practices, 12-month disclosures, consumer rights, request methods, and annual updates.
US CCPA Requirements Guide
Plain-language CCPA requirements covering scope, minimization, notices, rights, opt-outs, contracts, security, records, risk assessments, audits, and ADMT.
US CCPA Scope and Thresholds Guide
CCPA scope and threshold reference covering the current $26,625,000 revenue threshold, the 100,000-consumer-or-household test, related entities, and exemptions.
US CCPA Service Provider Contractor and Third Party Contracts Guide
Classify CCPA recipients and check the distinct contract terms for service providers, contractors, and third parties before disclosing personal information.
US CCPA Service Provider Contractor Contracts Guide
Check CCPA service-provider and contractor agreements for specific purposes, use restrictions, consumer-request support, subcontractors, and remediation.
US CCPA Thresholds Guide
Apply the CCPA business thresholds per legal entity, including the 2025 CPI-adjusted revenue amount, volume and sale-or-sharing tests, and control routes.
What must a CCPA privacy policy include?
A practical guide to CCPA privacy-policy content, placement, annual updates, consumer rights, request methods, and supporting evidence.
What must CCPA service-provider contracts include?
Required CCPA contract terms, role checks, subcontractor flow-downs, oversight rights, and evidence for service providers and contractors.
What should teams do about consumer request verification under the CCPA?
Choose a proportionate CCPA verification method for know, delete, and correct requests without collecting unnecessary identity data.
When does the CCPA require risk assessments or cyber audits?
CCPA triggers, deadlines, evidence, retention, and submission duties for risk assessments and annual cybersecurity audits.