Statewiseby[codeliance]Alpha

DPIA / risk assessment

Every jurisdiction with a known obligation of this type, with age brackets, citations, and verification dates.

← Back to matrix
Covered entity

6 jurisdictions with a known requirement · 45 none known · 0 unknown (unresearched or not yet decomposed)

Arkansas

Social Media Safety Act amendments (Act 900 of 2025 / SB 611)EnjoinedResearchedlast verified 2026-07-04
Under 1313–15

Conduct quarterly audits to identify design features that foster compulsive or addictive behavior in minor users.

Statute’s own ages: Applies to platform duties toward minor users (under 16).

Ark. Act 900 of 2025 (SB 611): quarterly-audit duty per Digital Policy Alert and Inside Privacy analyses; section pin pending primary-text verification

California

California Age-Appropriate Design Code Act (AB 2273)In forceResearchedlast verified 2026-07-04
Under 1313–1516–17Enjoined

Complete a Data Protection Impact Assessment before offering a new online service, product, or feature likely to be accessed by children, and address identified risks.

Statute’s own ages: Applies to services likely to be accessed by users under 18.

Cal. Civ. Code § 1798.99.31(a)(1)-(a)(4)

Colorado

Colorado Privacy Act, Protections for Children's Online Data (SB 24-041)In forceResearchedlast verified 2026-07-04
Under 1313–1516–17

Use reasonable care to avoid any heightened risk of harm to minors caused by an online service, product, or feature, and conduct a data protection assessment where a heightened risk of harm to minors is present.

Statute’s own ages: Applies to 'minors' (consumers under 18); consent for under-13 is given by a parent/guardian, and by the minor for ages 13-17.

Colo. Rev. Stat. § 6-1-1308.5 (SB 24-041): section pin pending primary-text verification

Connecticut

Connecticut Data Privacy Act, Minor Protections (SB 3 / Public Act 23-56, amended by SB 1295)In forceResearchedlast verified 2026-07-04
Under 1313–1516–17

Use reasonable care to avoid any heightened risk of harm to minors caused by an online service, product, or feature, and conduct a data protection assessment for any such service that presents a heightened risk of harm to minors.

Statute’s own ages: Applies to minors (consumers under 18); no narrower statutory subdivision for this duty.

Conn. Gen. Stat. § 42-515 et seq. (Public Act 23-56, as amended by SB 1295 of 2025), section pin pending primary-text verification

Maryland

Maryland Age-Appropriate Design Code Act ("Maryland Kids Code", HB 603 / SB 571)In forceResearchedlast verified 2026-07-04
Under 1313–1516–17from 2026-04-01

Complete a data protection impact assessment for each online product reasonably likely to be accessed by children, documenting risks to minors and mitigation steps; the first assessments were due by 2026-04-01.

Statute’s own ages: Protects consumers aged 17 and under ('child'/'minor' = under 18); the Act does not sub-tier by age for the DPIA duty.

Md. Code Ann., Com. Law, Maryland Age-Appropriate Design Code subtitle (HB 603, Ch. 461, 2024), section pin pending primary-text verification

Mississippi

Walker Montgomery Protecting Children Online Act (HB 1126)Enforceable pending appealResearchedlast verified 2026-07-04
Under 1313–1516–17

Develop and implement a strategy to prevent or mitigate a known minor's exposure to harmful material and covered harms.

Statute’s own ages: Minor = under 18

Miss. Code § 45-63 (HB 1126, 2024 R.S.); section pin pending verification