Arkansas has significantly broadened the landscape of online privacy compliance for businesses interacting with young users. On July 1, 2026, the Arkansas Children and Teens' Online Privacy Protection Act, enacted through HB 1717, took effect. The Act extends protections modeled on the federal Children's Online Privacy Protection Act (COPPA) beyond children under 13 to include teenagers aged 13 through 16. For companies that collect data from minors in Arkansas, this represents a meaningful expansion of legal obligations and a departure from the long-standing federal under-13 baseline.
At the core of the new law are two central requirements. First, businesses must obtain verifiable consent before collecting personal data from covered minors. Second, the Act prohibits targeted advertising directed at users under 17. Together, these provisions demand a careful reassessment of consent flows, age-gating mechanisms, data intake procedures, and advertising technology stacks. Companies that previously relied on COPPA-aligned frameworks tailored to children under 13 will likely find that their existing infrastructure is insufficient to capture the expanded population of teens now protected under Arkansas law.
Enforcement authority under the Act is vested exclusively in the Arkansas Attorney General. The statute does not create a private right of action, meaning individual consumers cannot bring lawsuits directly against businesses for alleged violations. While this narrows litigation risk from class actions and private plaintiffs, it also concentrates significant regulatory power in a single office. For businesses, this makes proactive compliance and, where appropriate, constructive engagement with the Attorney General's office particularly important. Enforcement priorities and interpretive guidance from that office will likely shape how obligations under the Act are applied in practice.
Businesses operating online platforms, mobile applications, advertising networks, and any service accessible to Arkansas minors should evaluate their data collection and advertising practices now. Key steps include reviewing age-verification tools, updating privacy policies, refining consent mechanisms, and auditing advertising partners to ensure that targeted advertising is not being served to users under 17. Vendor contracts and data-sharing arrangements may also require revision to reflect the broader scope of protected users.
This article is provided for general informational purposes only and does not constitute legal advice. Clients should seek tailored guidance regarding their specific circumstances.