South Carolina Takes a Hard Line on Age-Appropriate Design – Audits, Parental Controls, Employee Personal Liability, and More

The recently enacted South Carolina Age Appropriate Design Code Act (S.C. Code Sec. 39-80-10 et seq.) (the “Act”) has the potential to become one of the country’s most consequential privacy laws. It combines prescriptive privacy-by-design controls with restrictions on facilitating targeted advertising to minors under 18, and requires annual independent compliance audits and reports that are publicly posted, coupled with unusually aggressive penalties, including potential personal liability for officers and employees for “willful and wanton” violations. Unlike some other states’ privacy laws that have given entities time to make technical and policy changes before their effective date, South Carolina took a different route. The Act took effect immediately upon enactment in February 2026, and the first audit reports were required to be submitted to the South Carolina Attorney General by July 1, 2026.

Soon after the Act was enacted, trade association NetChoice filed suit in the United States District Court for the District of South Carolina (Columbia Division) to challenge the Act, including on First and Fourteenth Amendment grounds. NetChoice also moved for a preliminary injunction to stop the Act from taking effect, but as of publication, the District Court has yet to rule on the motion. While the case remains pending, South Carolina’s Office of the Attorney General has established a webpage to accept audit reports required under the Act and has not indicated it will pause enforcement.

Below, we highlight some of the key provisions of the Act and how the Act applies to entities that process the data of minors.

Entities in Scope: California Consumer Privacy Act (CCPA)-Like Thresholds Plus Likely Access by Minors

The Act applies to “covered online services,” (i.e., legal entities that (a) meet revenue or data-processing thresholds similar to those in the CCPA and (b) provide a website, mobile application, or other internet-accessible product, service, or feature that is “reasonably likely to be accessed by minors.”)  The Act includes familiar data-level exemptions for personal data covered by the Gramm-Leach-Bliley Act (GLBA) and Health Insurance Portability and Accountability Act of 1996 (HIPAA), but it does not categorically exempt financial institutions or HIPAA covered entities, or nonprofits that otherwise meet the Act’s threshold triggers.

The revenue/data-based threshold test covers legal entities that do business in South Carolina and: (a) have annual gross revenue above $25 million; (b) buy, receive, sell, or share the personal data of 50,000 or more “consumers, households or devices,” alone or in combination with affiliates, subsidiaries, or a parent company; or (c) derive at least 50% of annual revenue from selling or sharing consumers’ personal data.

An entity that meets these threshold criteria must then determine whether its online service (e.g., website or mobile app or game) is “reasonably likely to be accessed by minors.” The Act defines “reasonably likely” access to mean when an entity either: (a) has actual knowledge that a consumer is under 18 or (b) directs the service to children under 13 within the meaning of the Children’s Online Privacy Protection Act (COPPA). The Act clarifies that if the entity attributes an age to a consumer for advertising or any other purpose, the entity is presumed to have actual knowledge of the consumer’s age. Entities with apps that do not otherwise collect age or age-range information may want to consider the potential impact of features offered in app stores that give parents and guardians the ability to instruct the app store to share the age range of their minor children (e.g., under 16, under 18) with app developers.

Independent Compliance Audits—To Be Posted on the South Carolina Attorney General’s Website

One of the Act’s notable features is its requirement that covered entities conduct annual independent audits of the controls and design features required for minors, discussed in greater detail below. The audit report, required to be prepared by an independent third party, must be submitted to the South Carolina Attorney General by July 1 each year with subsequent publication on the Attorney General’s website.

The audit reports must describe how the covered entity implements the required controls and features for minors. They also must disclose whether the covered entity received notifications from parents/guardians, schools, or minors alleging harm to minors, and how the business responded to them. Affected entities must also disclose the number of such notifications received. The reports must also describe algorithms used to recommend content to minors and assess the extent to which minors are likely to access the business’s online service(s).

The audit reports must be prepared by an independent third party and will be made available on the Attorney General’s website for public review—potentially inclusive of plaintiffs’ lawyers and regulators from other jurisdictions.

User Controls: Options for Adults, Defaults for Minors

The Act requires covered entities to provide all users—adults and minors—tools to manage various aspects of their experience, including, without limitation, the ability to:

  • Disable design features not necessary to provide the online service (e.g., website, app, game);
  • Limit time spent on the online service;
  • Set a monetary limit on purchases or transactions conducted through the online service;
  • Opt out of personalized recommendation systems; and
  • Restrict social-connectivity features including likes, comments, clicks, views, location sharing, and user connections.

Adults must be offered tools to make these choices for themselves and on behalf of their minor children. For minors, the Act requires the heightened privacy-protective options to be set by default, such as disabling non-necessary design features and restricting social connectivity features.

Minors: No Targeted Advertising, Limits on Profiling and Personalized Recommendations

The Act targets much of the personalization ecosystem that is a mainstay of both digital advertising and content delivery for online entities. Consistent with some of the most stringent privacy laws in other states (e.g., Maryland and Oregon), the Act prohibits covered entities from facilitating targeted advertising to minors, with no provisions for opt-in consent. Additionally, by default, a business cannot profile a minor, such as by generating inferences about their personal preferences or behavior, with a narrow exception if a minor requests this be done in connection with providing a service in which the minor is “actively and knowingly engaged.” (e.g., an online game the minor is playing). Further, “personalized recommendation systems,” defined as automated systems that “suggest, promote, or rank” content, are to be turned off by default for minors.

Robust Parental Controls and Harm Reporting Tools

The Act also requires entities to provide tools that give parents substantial control over their minor children’s use of websites, apps, online games, and other online services. Among other things, parents must be able to:

  • Manage account and privacy settings;
  • Restrict purchases; and
  • View total time spent on the service and impose time limits or time-of-day restrictions.

Importantly, these controls apply to all minors under 18.

Parents, schools, and minors also must have a mechanism to notify entities if their online service is perceived as causing harm to minors.

Transparency and Data Minimization

Covered entities must provide comprehensive, easy-to-understand descriptions of design features, privacy protections for minors, and parental controls, along with instructions for using each. If a business uses a “personalized recommendation system”—a fully or partially automated system that suggests, promotes, or ranks content—it must explain how the system delivers information to minors and how minors or their parents may opt out.

The Act’s strict data-minimization requirements are tied to the specific features with which a minor “knowingly engages.” That formulation is significantly more restrictive than the approach taken in several other privacy laws, which generally assess minimization by reference to what is necessary to provide features or services on a website, app, or game.

Penalties and Enforcement

The South Carolina Attorney General has exclusive enforcement authority, and the Act’s penalty provisions are aggressive. The Act is enforced under the South Carolina Unfair Trade Practices Act, with some notable additions:

  • The possibility of personal liability for employees and officers of a covered business for “willful and wanton” violations of the Act; and
  • Trebling financial damages incurred as a result of a violation of the Act.

Going Forward

Entities that own, operate, control, or provide online services or features (including a website, app, or online game) and that conduct business in South Carolina may want to consider assessing if the Act applies to them and, if so, consider the following:

  • Mapping data collected about minors under 18;
  • Conducting a gap assessment of the design and choice architecture requirements in the Act against the online service or features offered by the entity;
  • Revisiting backend controls and architecture that could be needed to manage restrictions on the processing of minors’ personal data;
  • Designing and implementing parental controls, reporting mechanisms and systems to respond to, document, and log actions taken in response to any harm reports; and
  • If applicable, retaining an independent auditor to prepare an audit report for the entity’s submission to the Attorney General.

This post is as of the posting date stated above. Sidley Austin LLP assumes no duty to update this post or post about any subsequent developments having a bearing on this post.