Jury selection began on August 12, 2026, in an Oakland federal trial involving claims that Meta’s Facebook and Instagram platforms harmed young users. Opening statements were scheduled for August 18.
The trial involves claims by California, Colorado, Kentucky, and New Jersey within broader multidistrict litigation involving numerous states. The states allege, among other things, that Meta deployed harmful or compulsive product features, misled the public about youth risks, and collected or used certain information associated with children under 13 without complying with the Children’s Online Privacy Protection Act, or COPPA.
Meta disputes the allegations. The court’s pretrial rulings did not establish liability, and the factual and legal issues remain subject to adjudication.
Why does this matter beyond Meta? The litigation places four ordinary business functions in the same courtroom:
- product design;
- collection and use of data;
- public marketing and safety statements; and
- internal risk analysis.
Any company operating an app, game, website, connected product, or online community should examine how those functions interact when minors may use the product.
The Case Is About More Than Third-Party Content
The states’ case is not limited to objectionable material posted by users. The remaining claims concern alleged conduct by Meta itself, including specified product features, data practices, public statements, and the company’s alleged knowledge concerning effects on younger users.
That distinction matters under section 230 of the Communications Decency Act. Section 230 may limit claims that treat an interactive computer service as the publisher or speaker of third-party content. It is not a universal exemption from laws governing a company’s own statements, data practices, or independent product conduct.
In its June 29, 2026 summary-judgment order, the court treated section 230 as a limitation on the states’ theories rather than complete immunity from the litigation. The court permitted a narrowed set of claims involving specified features and alleged business practices to proceed. The order did not find Meta liable; it determined that material issues remained for trial.
The COPPA Issue Remains Disputed
COPPA applies to operators of commercial websites and online services directed to children under 13 that collect, use, or disclose personal information. It also applies to certain other operators that have actual knowledge they are collecting personal information from a child under 13.
In the Meta litigation, the court found factual disputes concerning whether Meta had actual knowledge, including through the company’s account-review and age-related processes. The court also addressed the states’ theory that willful blindness could support actual knowledge.
The record established that Meta had not provided COPPA parental notice, obtained parental consent, or provided the parental review mechanism for the practices at issue. Meta’s position was that those requirements were not triggered because it lacked the required actual knowledge. The court did not resolve liability; it left the disputed coverage and knowledge issues for trial.
That distinction should be preserved in any publication about the case. Failure to use a COPPA consent process is not, by itself, a violation unless COPPA applies to the operator and the relevant collection, use, or disclosure.
Lesson One: Determine Whether COPPA Applies
COPPA coverage depends on the nature of the product, its audience, the information collected, and what the operator knows.
The Rule can apply to:
- websites and online services directed primarily to children under 13;
- mixed-audience services that meet the Rule’s child-directed criteria but do not primarily target children; and
- general-audience services that have actual knowledge they are collecting personal information from a child under 13.
The term “online service” is broad. Depending on their characteristics, mobile apps, games, connected devices, voice services, and other Internet-connected products may be covered.
Personal information is not limited to a child’s name. It can include specified persistent identifiers, online contact information, photographs, audio or video containing a child’s image or voice, geolocation information, and other defined information.
The amended COPPA Rule became effective on June 23, 2025. The general compliance deadline was April 22, 2026. Among other changes, the amendments:
- added certain biometric and government-issued identifiers to the definition of personal information;
- created a separate-consent requirement for certain disclosures to third parties, including disclosures related to targeted advertising;
- strengthened limits on retaining children’s information;
- modified notice, security, and deletion requirements; and
- clarified aspects of mixed-audience services.
A statement in the terms of service that users must be at least 13 does not, by itself, eliminate risk. At the same time, COPPA’s actual-knowledge standard is more demanding than merely showing that children may use a general-audience service.
Account records, age changes, user reports, linked accounts, human review, internal studies, and the operator’s response to those signals may become important evidence concerning actual knowledge.
Lesson Two: Public Statements Should Match the Internal Record
California’s Unfair Competition Law covers unlawful, unfair, or fraudulent business acts and practices, including specified misleading advertising. The False Advertising Law separately prohibits certain untrue or misleading advertising made with the knowledge standard stated in the statute.
Whether a particular statement is actionable depends on its wording, context, audience, evidence, materiality, standing, and available remedies. A statement is not automatically unlawful merely because a critic disagrees with it.
Risk increases when external assurances and internal evidence materially diverge. A business may represent that a product is safe, privacy-protective, age-appropriate, or designed to reduce harmful use. Internally, product teams may possess research, testing, complaints, incident reports, or escalation records identifying unresolved risks.
Litigation may then focus on the company’s knowledge trail:
- What information did the company possess?
- Who reviewed it?
- What mitigation was considered?
- What was changed or rejected?
- Did the public description remain accurate?
- When should the description have been updated?
The answer is not to suppress unfavorable information or rely on vague disclaimers. Businesses should use a documented process through which legal, privacy, engineering, marketing, safety, and executive teams evaluate material evidence and correct public statements that no longer accurately describe the product.
Lesson Three: Engagement Features Can Create Legal Risk
Digital products commonly seek to increase return visits, session length, sharing, purchases, or advertising exposure. Those objectives are not inherently unlawful.
Risk can increase when a company has credible evidence that a particular feature may harm a vulnerable group but continues or expands the feature without a documented review, reasonable mitigation, or accurate public communication.
A product-risk review should consider:
- who is reasonably likely to use the feature;
- what signals indicate use by minors;
- whether default settings increase or reduce risk;
- whether safeguards can be bypassed;
- what business metric rewards the feature;
- whether safer alternatives have been tested; and
- whether public statements accurately describe the safeguards.
Notifications, appearance-modification tools, recommendation systems, streaks, repeated rewards, multiple-account functionality, and frictionless sharing may warrant closer review when younger users are foreseeable.
This does not mean that any particular feature is inherently unlawful. The relevant question is how the feature operates, what evidence exists concerning its effects, what the company knows, and how it responds.
Lesson Four: Internal Records May Become Central Evidence
Product specifications, experiments, executive communications, trust-and-safety metrics, age-detection systems, complaints, research, risk memoranda, and decisions concerning proposed safeguards may bear on knowledge, intent, causation, and remedies.
A company that cannot reconstruct its own decision-making may have difficulty explaining why a reasonable choice was made.
Useful decision records should identify:
- the available evidence;
- known uncertainties;
- the person responsible for the decision;
- alternatives considered;
- the reasons for the selected course;
- safeguards adopted; and
- the date for reassessment.
Records should be maintained under a consistent retention policy. Once litigation or a government investigation is reasonably anticipated, ordinary deletion practices may need to be suspended through an appropriately implemented legal hold.
A legal hold should preserve relevant records without encouraging indiscriminate retention of unrelated personal information.
A Seven-Step Review for Online Businesses
1. Map the data. Identify every category of user information collected, including information collected through cookies, device identifiers, analytics tools, advertising services, plug-ins, and software development kits.
2. Identify the actual and intended audience. Review marketing, visual content, app-store descriptions, user demographics, support records, and product features that may indicate a child-directed, mixed-audience, or general-audience service.
3. Define age signals and escalation procedures. Document which facts may indicate that a user is under 13, who receives those signals, what happens next, and whether reports and linked accounts are evaluated consistently.
4. Test notice and consent procedures. If COPPA applies, confirm that required parental notice is direct, clear, complete, and delivered before covered collection, use, or disclosure. Verify that the consent method satisfies the current Rule.
5. Review vendors and retention. Inventory advertising, analytics, cloud, moderation, and age-assurance vendors. Evaluate contractual safeguards, disclosure practices, security, necessity, and deletion schedules.
6. Compare public claims with internal evidence. Compare website copy, safety reports, presentations, regulatory responses, and other external statements with internal research, testing, and incident data. Address material inconsistencies through a documented process.
7. Establish product-risk governance. Assign decision owners, use cross-functional review for youth-facing features, preserve testing and mitigation records, monitor complaints and emerging evidence, and create an investigation and litigation-response protocol.
Age Verification Creates Its Own Privacy Issues
Businesses increasingly use age gates, identity documents, facial age estimation, or third-party age-assurance services. These tools may reduce one form of risk while requiring the collection of sensitive information.
In February 2026, the FTC announced limited enforcement discretion for operators of general-audience and mixed-audience services that collect, use, or disclose personal information solely to determine a user’s age without first obtaining parental consent.
The policy is subject to conditions, including:
- using the information only to determine age;
- deleting it promptly when no longer necessary;
- providing clear notice;
- using reasonable security safeguards;
- limiting disclosures to suitable service providers;
- obtaining appropriate assurances from vendors; and
- taking reasonable steps to select a method likely to produce sufficiently accurate results.
This is an enforcement policy, not unrestricted permission to collect identity or biometric information. It does not authorize using age-verification information for advertising, profiling, model training, or unrelated commercial purposes.
What to Watch During the Trial
As the trial proceeds, businesses should watch:
- which statements the states contend were deceptive and how those statements are evaluated in context;
- what evidence is admitted concerning product design, internal research, age signals, and alleged youth harms;
- how the court separates claims concerning Meta’s own conduct from claims based on third-party content;
- how the factfinder evaluates actual knowledge under COPPA; and
- what remedies are requested and ultimately permitted if liability is established.
Because the case is ongoing, this article should be updated after a verdict, settlement, material post-trial ruling, or appeal. News reports should not be allowed to convert disputed allegations into established facts.
Practical Takeaway
The Meta trial is newsworthy because of the defendant’s size, but its business lesson is broadly applicable: product design, data collection, public claims, and internal evidence should not be managed in separate silos.
A company whose product may be used by minors should determine which laws apply, develop a defensible response to age signals, ensure that public statements remain consistent with current evidence, review vendors and retention practices, and preserve a record showing that material risks were actually evaluated.
Legal Authorities and Public Resources
- California Attorney General, June 30, 2026 Meta trial release
- In re Social Media Adolescent Addiction/Personal Injury Products Liability Litigation, June 29, 2026 summary-judgment order
- FTC, Complying with COPPA: Frequently Asked Questions
- COPPA Final Rule Amendments, 90 Fed. Reg. 16918
- FTC Age-Verification Enforcement Policy Statement
- California Business and Professions Code § 17200
- California Business and Professions Code §§ 17500–17509
- 15 U.S.C. §§ 6501–6506
- 16 C.F.R. Part 312
- 47 U.S.C. § 230
Related practice areas: Civil Litigation · Business and Corporate Governance