DPIA / risk assessment
Every jurisdiction with a known obligation of this type, with age brackets, citations, and verification dates.
6 jurisdictions with a known requirement · 45 none known · 0 unknown (unresearched or not yet decomposed)
Arkansas
Conduct quarterly audits to identify design features that foster compulsive or addictive behavior in minor users.
Statute’s own ages: Applies to platform duties toward minor users (under 16).
California
Complete a Data Protection Impact Assessment before offering a new online service, product, or feature likely to be accessed by children, and address identified risks.
Statute’s own ages: Applies to services likely to be accessed by users under 18.
Colorado
Use reasonable care to avoid any heightened risk of harm to minors caused by an online service, product, or feature, and conduct a data protection assessment where a heightened risk of harm to minors is present.
Statute’s own ages: Applies to 'minors' (consumers under 18); consent for under-13 is given by a parent/guardian, and by the minor for ages 13-17.
Connecticut
Use reasonable care to avoid any heightened risk of harm to minors caused by an online service, product, or feature, and conduct a data protection assessment for any such service that presents a heightened risk of harm to minors.
Statute’s own ages: Applies to minors (consumers under 18); no narrower statutory subdivision for this duty.
Maryland
Complete a data protection impact assessment for each online product reasonably likely to be accessed by children, documenting risks to minors and mitigation steps; the first assessments were due by 2026-04-01.
Statute’s own ages: Protects consumers aged 17 and under ('child'/'minor' = under 18); the Act does not sub-tier by age for the DPIA duty.
Mississippi
Develop and implement a strategy to prevent or mitigate a known minor's exposure to harmful material and covered harms.
Statute’s own ages: Minor = under 18