State Privacy Law Updates

Texas App Store Law Now Enforceable Following SCOTUS Ruling: What App Developers Should Do

After months of uncertainty over whether and when Texas’s App Store Accountability Act (“Texas’s App Store Law”) would take effect, on the Supreme Court has ruled that it will not stand in the way of its enforcement while the Fifth Circuit considers constitutional challenges. The law which in part requires app stores to verify users’ ages and obtain parental consent to allow minors to download or purchase apps or to make in-app purchases and requires app developers to ingest those age signals is now in effect and enforceable.

Organizations subject to the law should be prepared to immediately comply or risk an enforcement action. Our analysis and recommendations are below.

As similar age-assurance laws in Alabama, California, Louisiana, and Utah now seem more likely to survive similar injunctive relief efforts and constitutional challenges, organizations should start preparing to comply with these laws as well. Look for our upcoming post comparing and contrasting the requirements under these other laws.

What did the SCOTUS decide and what happens next?

Texas’s App Store Accountability Act-- was set to take effect on January 1, 2026. The law was preliminarily enjoined from enforcement by a lower court on the basis that it likely violated the First Amendment under strict scrutiny. On June 1, 2026, the Fifth Circuit stayed the injunction pending its review, concluding that the law would likely survive intermediate scrutiny and that “The balance of equities and public interest are clearcut in Texas’s favor.” A trade group submitted an emergency request to the Supreme Court to vacate the stay. On Monday, July 6, 2026, the Supreme Court ruled, in a one sentence order, denying the request with the effect of making the law immediately enforceable.

While the law is still pending review by the Fifth Circuit for constitutionality challenges, those challenges seem less likely to prevail given the Fifth Circuit’s strong statements in favor of Texas in its prior ruling staying the injunction and the SCOTUS ruling supporting that stay. In the meantime, while the Texas State AG has not stated whether it will enforce the law immediately or wait for the Fifth Circuit to decide the constitutional issues, the AG may be emboldened to act more immediately given the Fifth Circuit’s supportive statements.

What are the requirements of Texas App Store Law?

The following summarizes requirements under the Texas App Store Law. While there are numerous requirements for app stores, we focus primarily on requirements for app developers.

Age and consent information ingestion and verification. The Texas app store law and similar state age-verification laws will require app stores to collect age information from account holders and for app developers to ingest age category data and status of parental consent from the app store and use it to verify age. Ingestion of age information that includes ages of children and minors triggers a complex set of obligations under other laws, including COPPA and state laws that apply if you have actual knowledge that someone is a child or a minor. The Texas Data Privacy and Security Act (TDPSA), in particular, is triggered if you gain actual knowledge of a child under 13 using your services. Under the TDPSA, data about a child is considered sensitive data and subject to requirements beyond those under COPPA, including requirements to conduct a data protection assessment.

Safe-harbor. The Texas App Store Law does not address what happens if an app developer has inconsistent information about age that it may have collected through its own age-gating process as compared to what it receives from an app store. But under the law, a software application has incentive to rely on the age of the app store as it is not liable for requirements to verify age if it has relied on the age category and consent information from the app store (and otherwise complies with the law). Relying on more robust means to determine age than the current self-declaration method used by many app stores (i.e., when a user simply states their age without confirming evidence) can create interesting issues for app developers. Further, many more app developers are relying on more robust means of age verification because UK regulators have recently advised against relying on self-declaration for age gating.

Age rating designation. App developers will need to assign age ratings to their apps, document the elements that led to that rating, and provide the rating and such elements to the app store.

Notice of significant changes. App developers will need to notify app stores about any significant changes to the terms of service or privacy policy of their application. App stores will in turn need to provide new notice and obtain new parental consent for any significant changes. A change is significant if it (1) changes the type or category of personal data collected, stored, or shared by the developer; (2) affects or changes the rating of the software application or the content or elements that led to that rating; (3) adds new monetization features to the software application, including: (A) new opportunities to make a purchase in or using the software application; or (B) new advertisements in the software application; or (4) materially changes the functionality or user experience of the software application.

Limits on use of age and consent information. App developers may only use age and consent information obtained from app stores to 1) enforce age-based restrictions in their application, 2) ensure compliance with laws and regulations, and 3) implement safety features and default settings. App developers may not share or disclose personal data of users obtained from the app stores in connection with the law.

What should app developers do?

  • Comply with Texas’s law. If you have not already, review the obligations under the app law to assess if and how it applies to your organization. Develop a strategy to quickly come into compliance.

  • Understand app store rules. Review (and have your engineers review) Apple (here and here) and Google’s (here) developer pages for information about how to ingest age information and how to provide age rating and related documentation. Both platforms have indicated they will only send signals in each state as they go into effect. Google has stated that they have begun rolling out their Play Age Signals API "for new users in Texas who created their accounts after May 28, 2026," while Apple describes its Declared Age Range API as available "in certain regions, where legally required."

  • Determine your strategy for ingesting age signals. Decide on whether you will ingest age signals for all states or just states with laws currently in effect (Google currently only makes Texas available where Apple appears to allow ingestion of age range for all states). In making this decision review and assess COPPA and Texas’ and other state laws that have obligations triggered by knowledge that a user is a child or a teen.

  • Formalize how you handle receiving age signals. Formalize processes for when you gain knowledge of users’ ages through these age signals or other means. Determine your strategy for compliance with laws triggered by knowledge of age and whether blocking, deletion, or obtaining parental or teen consent is appropriate under these laws.  

  • Consider your strategy for responding to conflicting age signals. If you currently age gate, you may receive conflicting information about age from app stores. Decide what approach you will use to resolve conflicting age signals. Evaluate the relative risks of your approach taking into consideration other state laws with clearer guidelines.

  • Get ready for additional laws set to take effect early next year. Although Texas  is the only state app store law currently in effect and enforceable, get ready for Alabama (January 1, 2027 - for new accounts after October 2, 2026; October 1, 2027, for accounts in existence on October 2, 2026) California (January 1, 2027), and Louisiana (July 1, 2027), and Utah (May 6, 2027).

Susan Hintze is the founder and co-managing partner of Hintze Law. Recognized by Chambers, Legal 500, & Best Lawyers, Susan serves on the International Association of Privacy Professionals (IAPP) Board of Directors and is an IAPP Westin Emeritus Fellow. She is also co-chair of the firm’s Regulatory Defense Group.

Emily Litka Sanford is a Senior Associate at Hintze Law. Emily focuses her practice on global privacy and emerging AI laws and regulations.

Hansy Piou is an Associate at Hintze Law. Hansy has experience with global data protection issues, including kids’ global privacy laws, AADC, privacy impact assessments, GDPR, and privacy statements.



Hintze Law PLLC is a Chambers-ranked and Legal 500-recognized, boutique law firm that provides counseling exclusively on privacy, data security, and AI law. Its attorneys and data consultants support technology, ecommerce, advertising, media, retail, healthcare, and mobile companies, organizations, and industry associations in all aspects of privacy, data security, and AI law. 

California’s Jam City Enforcement Action Highlights Importance of Opt-Out Mechanisms

On November 21st, 2025, the California Attorney General announced a $1.4 million dollar settlement with the mobile app gaming company, Jam City, Inc., the sixth such settlement by California regulators under the California Consumer Privacy Act (CCPA). The AG had sued Jam City, whose mobile gaming apps collect personal information such as device identifiers, IP addresses, and usage data, alleging that it had failed to offer appropriate methods to opt out of sale and sharing of personal data in violation of the CCPA.

The Complaint

In May 2024, an AG investigation found that 20 of Jam City’s 21 apps did not provide a link or setting for consumers to opt-out of the sale of their personal information or sharing of such data for behavioral advertising across Jam City’s apps and other apps and platforms.

The complaint thus alleges that Jam City did not provide CCPA compliant opt-out methods on its apps or its website. In addition to the lack of controls on the 20 apps, the 21st app provided a “Data Privacy” setting that allegedly did not reference the CCPA and was unclear about whether enabling the setting would effectuate an opt-out request. Additionally, the “Cookies and Interest Based Advertising” section of privacy policy on Jam City’s website “told consumers that they could email Jam City at ccpaoptout@jjamcity.com to stop targeted advertisements,” a method the AG claimed was allegedly insufficient under the CCPA.

The complaint further alleges that Jam City did not acquire opt-in consent to sell or share the personal information of consumers it knew to be less than 16 years old. Jam City allegedly age-gates several of its apps and provides “child-versions” which do not collect or share personal information with third parties. However, Jam City allegedly failed to properly age-gate six of its apps, only providing the child-versions to consumers who declared they were under 13. As a result, Jam City was improperly selling or sharing the data of consumers between 13 and 16 years old, including via cross-context behavioral advertising without obtaining opt-in consent.

The Settlement

The settlement orders Jam City to comply with the CCPA’s opt-out provisions, specifically requiring:

  • Implementing a consumer-friendly, easy to execute opt-out process with minimal steps and in the case of mobile apps or connected devices, such opt-out process being available in a setting or menu option that leads the consumer to a page, setting, or control that enables the consumer to opt-out the sale and sharing of the consumer’s personal information either immediately, or in the alternative, via a link to the notice of right to opt-out of sale/sharing in the privacy notice,;

  • Effectuating of a consumer opt-out l across all of Jam City’s mobile apps for any personal information associated with the consumer,;

  • Providing means by which the consumer can confirm the processing of their opt-out request; and

  • Avoiding language or design likely to confuse a reasonable consumer that choices related to the collection of personal information, other than the opt-out process, constitute a compliant opt-out method or must be selected to opt-out.

Additionally, the settlement also requires compliance with special rules for consumers under 16 years old:

  • Where Jam City implements an age-screening mechanism,

    • Designing the mechanism in a neutral manner that does not default to 16+ and does not suggest that certain features are unavailable to consumers under 16 years old;

    • Directing consumers who submit an age under 13 years old to a child-version of the app; and

    • Directing consumers who submit an age of at least 13 years old and less than 16 years old to a child-version of the app or obtain their affirmative authorization to sell or share their personal information before directing them to a non-child-version of the app.

  • Directing all third parties to whom Jam City sold or shared personal information collected prior to October 1, 2024, from consumers who submitted ages under 16 years old in any Jam City mobile apps to delete such personal information.

Takeaways

With its recent investigations and settlement actions, the California Privacy Protection Agency has shown its willingness to enforce the CCPA, especially its opt-out provisions. The Jam City settlement order to effectuate opt-outs wherever the business identifies the consumer is similar to the California’s AG recent settlement order against Sling TV, which was ordered to “provide an opt-out mechanism within the Sling TV app on various living-room devices, so consumers accessing Sling TV on various devices do not need to go to Sling TV’s website to opt-out.” This robust enforcement of implementation of opt-out measures comes from the CCPA regulation requiring businesses to comply with a customer’s previously given opt-out signal “where the consumer is known to the business."

Moreover, recent California legislation is a part of a national trend of increased concern for children’s online privacy and safety. Laws with additional requirements for processing minors’ data are being complemented with app store age-verification laws, such as California’s Digital Age Assurance Act, which provide developers knowledge of whether consumers are minors.

This enforcement action highlights the political momentum for minors’ online privacy and the CCPA’s increased enforcement activity. Consider the following actions to address the concerns raised in this enforcement action:

  • Review all platforms, both apps and websites where you collect personal information to confirm choice mechanisms for consumer rights are clear and conspicuous so that users can easily effectuate those rights and understand those requests are being processed.

  • Implement choice mechanisms to properly regulate processing in accordance with data protection law and the consumer’s age.

  • Effectuate opt-out requests so that the consumer is opted out of such processing across apps, devices, and services where the business has information connecting the identity of the consumer.

  • Ensure age-gating processes comply with regulatory guidance, including not defaulting to an age above the relevant age range or suggesting a particular age range is required to access certain features.

  • Be mindful of data practices and obligations with respect to minors’ data, especially as more states pass legislation protecting children and teens’ privacy, in particular, if you are an app publisher, be prepared to put in place processes to properly handle child and teen data as you may gain knowledge of age under coming age assurance laws.


Hintze Law PLLC is a Chambers-ranked and Legal 500-recognized, boutique law firm that provides counseling exclusively on privacy, data security, and AI law. Its attorneys and data consultants support technology, ecommerce, advertising, media, retail, healthcare, and mobile companies, organizations, and industry associations in all aspects of privacy, data security, and AI law. 

Hansenard Piou is an Associate at Hintze Law PLLC with experience in global data protection issues, including kids’ global privacy laws, AADC, privacy impact assessments, GDPR, and privacy statements.  

Washington Marijuana Retailer Sued Under My Health My Data Act for Website Pixel Use

Washington Marijuana Retailer Sued Under My Health My Data Act for Website Pixel Use

by Sam Castic and Felicity Slater

A class action suit was recently filed against the companies that operate Uncle Ike's, a Seattle-area marijuana retailer. The suit filed in Washington federal court alleges common law tort claims, ECPA claims, and a claim under the My Health My Data Act (‘MHMDA’ or ‘the Act’). 

Read More

California Passes Digital Age-Assurance Act Into Law

California Passes Digital Age-Assurance Act Into Law

By Hansenard Piou

On October 13th, 2025, Governor Newsom signed the Digital Age Assurance Act (AB 1043) into law. Introduced by co-authors Assembly Member Buffy Wicks and Senator Tom Umberg, the law establishes age-assurance requirements for computer and mobile operating system providers and app stores as well as app developers with an aim to protect children’s online safety. The Digital Age Assurance Act enters into effect on January 1, 2027.

Read More

California Opt Me Out Act Signed into Law

California Opt Me Out Act Signed into Law

By Cameron Cantrell

On October 8, 2025, California’s Governor Newsom signed AB 566—the California Opt Me Out Act—into law. The California Opt Me Out Act, using the same definitions as the CCPA, requires any business that develops or maintains an internet browser to build in an opt-out preference signal (“OOPS”) functionality. The law takes effect on January 1, 2027.

Read More