So often children’s safety is construed to somehow exclude children’s privacy. Children need oversight to be sure, but when does oversight turn into surveillance, and to what extent does surveillance create harm? This week, Meta’s facing a legal battle that squarely calls out the harm it caused children in the form of addictive design informed by the overcollection of their personal data.
Twenty-nine states argue Meta collected data from kids under 13 without parental consent, a COPPA violation, then used it to train engagement algorithms. They want that data collection barred, the existing data deleted, and any algorithms trained on it purged. Judge Yvonne Gonzalez Rogers is deciding the case, with exposure estimates ranging from $200 billion to $1.4 trillion (!) depending on who's asked. And it’s landing just weeks after a New Mexico court hit Meta with an additional $942 million over similar claims, so the company’s not having a great year in terms of data privacy litigation.
But maybe Meta can take comfort in the fact that children’s data privacy and safety is trending this week. France's Constitutional Council blocked its own under-15 social media ban over weak privacy protections in the age-verification scheme, not because judges disagreed with the goal, but because the safeguards built into the age check didn't hold up.
With Oakland, Santa Fe, and France all asking questions about how data privacy factors into children’s safety within two weeks of each other, businesses handling children’s data should pay close attention to what answers these jurisdictions find.
Best,
Arlo
Highlights From Osano
In Case You Missed It...
Blog: Why Companies Are Leaving OneTrust in 2026
Unpredictable renewal pricing, months-long implementations, and support that favors the biggest accounts—mid-market teams are naming the same friction points as they evaluate OneTrust alternatives this year.
Top Privacy Stories of the Week
Meta's $1.4 Trillion Question Heads to Trial
A coalition of 29 state attorneys general took Meta to trial this week in Oakland, arguing Facebook and Instagram were engineered to be addictive to kids. The stakes are high: Meta's own lawyers put the maximum exposure at $1.4 trillion, while the states argue for something closer to $200 billion. However it lands, the case will put a real price tag on what engagement-by-design costs once regulators decide it's gone too far.
California Fines a Second Data Broker in Under a Week
California's privacy regulator has now hit two data brokers with fines in under a week, and the second one landed on Cybba, a Boston firm that sells geolocation data, browsing activity, and behavioral inferences to advertisers, for failing to register as a data broker. The fine itself is modest at $52,400, but the agency's enforcement chief called it a "steady drumbeat" he doesn't expect to slow down.
Washington's AG Publishes First-Ever Data Privacy Report
Washington's Attorney General published the state's first-ever data privacy report this week. The TL;DR on its findings: businesses over-collect, consent flows are designed to confuse rather than inform, sensitive data changes hands too easily, and consumers have almost no visibility into who's holding their information once a broker gets it. For any company still treating consent as a box to check on a cookie banner, this report is a preview of where enforcement priorities are headed.
France Blocks Its Own Teen Social Media Ban
France's Constitutional Council blocked President Macron's ban on social media for kids under 15 this week. The law didn't fall because judges think keeping 14-year-olds off Instagram is a bad idea; it fell because the age-verification checks needed to enforce it didn't adequately protect users' privacy, and because the ban was broader than the risks it was meant to address. Macron has already ordered a rewrite aimed at taking effect before spring 2027.
22 states + DC sue the Trump Administration Over Commercial Drivers' Data
Twenty-two states and DC are suing the Trump administration to stop it from seizing a database containing the Social Security numbers, names, and birth dates of 17 million commercial truck drivers. The federal government demanded the records last month and, when the database's operator raised legal concerns, threatened to cut off the funding that keeps the system running unless it complied by August 17.
Like What You See in the Privacy Insider newsletter?
There's more to explore:
📱 The Osano Subreddit
Join our official subreddit to stay up to date on the latest news, analysis, guidance, and content from Osano!
📖 The Privacy Insider: How to Embrace Data Privacy and Join the Next Wave of Trusted Brands
The book inspired by this newsletter: Osano CEO, Arlo Gilbert, covers the history of data privacy and how companies can start building a privacy program from the ground up. More details here.
If you’re interested in working at Osano, check out our Careers page!
Arlo Gilbert
Arlo Gilbert
Arlo Gilbert is the CIO & co-founder of Osano. A native of Austin, Texas, he has been building software companies for more than 25 years in categories including telecom, payments, procurement, and compliance. In 2005 Arlo invented voice commerce, he has testified before congress on technology issues, and is a frequent speaker on data privacy rights.
