Every parent wants to know their child is safe online. Congress has an opportunity to make that a reality, but only if it gets the policy right.
Good policy should protect children without requiring Americans to surrender more of their personal information, burdening innovators with unnecessary regulation, or replacing parents with government mandates. Two bills under consideration in Congress, the Parents Over Platforms Act (POPA) and the App Store Accountability Act (ASAA), both seek to address online child safety, but they take very different approaches.
POPA Protects Privacy by Minimizing Data Collection
The biggest distinction between the two bills is how they treat personal information.
The App Store Accountability Act requires app stores to verify every user’s age using “commercially reasonable methods” and categorize users into age groups before allowing access to apps. Depending on the implementation, this could require users to provide government-issued identification, credit card information, or biometric verification.
POPA takes a different approach. Rather than requiring broad identity verification, it directs app stores to generate an age signal, which is a tool that securely shares a user’s general age range with an app. These indicate whether someone is a minor or an adult, and should be shared with developers only when necessary and with appropriate user or parental consent.
In an era of frequent data breaches, minimizing the amount of sensitive information companies collect is itself a powerful privacy safeguard.
Parents Need Better Controls, Not More Permission Slips
The ASAA requires parents to approve app downloads for minors, placing app stores at the center of every download decision. Supporters argue this empowers families, but critics note that requiring continual approvals could create “consent fatigue,” making parents more likely to approve requests without carefully reviewing them.
POPA instead gives parents centralized tools to manage their children’s online experiences while allowing developers to create age-appropriate products based on standardized age signals. Rather than requiring parents to respond to every individual request, POPA seeks to make parental oversight more practical and sustainable.
Shared Responsibility Is Better Than Shifting Responsibility
Children’s safety doesn’t end once an app has been downloaded.
Many online risks arise through changing content, new features, social interactions, or updates that occur long after installation. That’s why POPA distributes responsibility between app stores and developers. App stores provide the age assurance framework, while developers remain responsible for designing age-appropriate experiences and complying with child safety standards.
The ASAA, by contrast, focuses much of its regulatory framework on the download process itself. While that may improve parental awareness, many policy analysts argue it does little to address the ongoing experiences children have in apps.
Innovation and Safety Don’t Have to Be Opposites
America’s app economy includes millions of developers, many of them small businesses.
Broad compliance mandates requiring age verification, consent management, and ongoing regulatory obligations can disproportionately burden smaller developers that lack the compliance resources of major technology companies.
Several technology policy organizations have argued that POPA’s narrower framework better preserves innovation while still advancing meaningful child safety protections. Protecting children online shouldn’t mean making it harder for entrepreneurs to build the next generation of useful applications.
The Bottom Line
Congress doesn’t have to choose between protecting children and protecting privacy.
Lawmakers can strengthen online safety while respecting parental authority, limiting unnecessary data collection, and encouraging innovation. One approach seems to strike a better balance in that regard. We will follow how both approaches move through Congress and where lawmakers eventually land.

