New rules are making it harder for ad tech companies to ignore children’s privacy. OpenX’s Julie Rooney explains how shifting regulations and state laws are changing compliance strategies. The industry faces stricter enforcement and new operational hurdles.
Ad tech companies can no longer rely on outdated strategies to sidestep children’s privacy requirements. Julie Rooney, Chief Privacy Officer and Deputy General Counsel at OpenX, said that recent updates to the Children’s Online Privacy Protection Act (COPPA) and a surge of new state laws are forcing platforms to take a more proactive approach. The Federal Trade Commission’s revised COPPA Rule, which became enforceable in April, has raised the bar for compliance, making it clear that ignorance about a user’s age is no longer a viable defense.
Rooney noted that while the latest COPPA changes were relatively straightforward-mainly clarifying existing expectations and providing guidance on age gating-the broader landscape is becoming increasingly complex. States are introducing their own youth privacy laws, with varying definitions of who qualifies as a minor and different restrictions on data use and targeted advertising. For example, Maryland now bans the sale of personal data and targeted ads to minors, while other states require stricter consent or age verification before certain features are unlocked.
For intermediaries like OpenX, liability hinges on what they know about a user’s age. While COPPA still uses an “actual knowledge” standard, some new state laws are experimenting with a “should have known” approach. Rooney explained that the FTC expects platforms to do more than simply trust publisher self-attestation. OpenX now uses a vendor to review app and site content, flagging likely child-directed properties instead of relying solely on publisher claims.
Sending compliant signals about child-directed inventory remains a challenge. The long-standing COPPA RTB signal is binary and often leads demand-side platforms to drop such traffic, discouraging its use. The IAB’s Global Privacy Platform offers more granular options, but adoption is still limited due to complexity. Rooney said OpenX is developing a dedicated marketplace for children’s and teens’ inventory, where publishers and advertisers are vetted and external oversight is provided through a COPPA Safe Harbor program. This approach aims to create a trusted channel for monetizing child-directed content, which has historically been difficult due to risk aversion among buyers.
Rooney also addressed the KIDS Act, which recently passed the House with strong bipartisan support. The bill would extend privacy protections to teens, restrict targeted advertising to minors, and require more protective default settings around features like autoplay. While the bill’s future in the Senate remains uncertain, Rooney estimated its chances of becoming law within two years at about 60 percent. She added that children’s privacy is one of the few areas where bipartisan agreement is strong.
As the regulatory environment evolves, ad tech companies are under pressure to adapt quickly. Rooney’s comments reflect a broader industry shift toward more rigorous compliance and operational transparency. For those interested in how other publishers are navigating regulatory and engagement challenges, a recent story on Swedish newsrooms’ use of the Core Model offers additional perspective: Swedish local newsrooms boost engagement with new metrics.