The KIDS Act Just Passed the House: What K-12 IT Directors Need to Know
COPPA is expanding to cover all minors under 17. Targeted ads to students are being banned. The biggest update to children's online privacy law in 25 years is moving through Congress — and it changes the compliance game for every school district.
On June 29, 2026, the U.S. House of Representatives passed the Kids Internet and Digital Safety Act — better known as the KIDS Act — in a bipartisan 267-117 vote. The bill is the most significant update to children's online privacy law in over two decades, and it changes the compliance landscape for every K-12 district in the country.
If you're an IT director, technology coordinator, or district administrator, this isn't just another headline to scan and forget. The KIDS Act rewrites the rules around student data, targeted advertising, and platform accountability in ways that directly affect the tools you deploy, the vendors you work with, and the policies you enforce.
Here's what you need to know — and what you should be doing right now.
What Is the KIDS Act?
The Kids Internet and Digital Safety Act is a comprehensive bill that does three major things:
1. Expands COPPA to Cover Teens Up to Age 17
The original Children's Online Privacy Protection Act (COPPA), passed in 1998, only protected children under 13. That was a different internet. In 1998, teens weren't carrying smartphones in their pockets, social media didn't exist, and AI chatbots weren't writing their homework.
The KIDS Act extends COPPA protections to all minors under 17. That means:
- Verifiable parental consent is now required before online services can collect, use, or disclose personal information from anyone under 17
- Data minimization rules apply — companies can only collect what is strictly necessary for the service
- Deletion rights are strengthened — parents and teens can request that personal data be deleted, and companies must comply within a reasonable timeframe
For schools, this is seismic. Every EdTech platform your students use — from Google Classroom to Canvas to Kahoot — must now comply with these expanded requirements for all students, not just elementary schoolers.
2. Bans Targeted Advertising to Minors
Under the KIDS Act, online platforms are prohibited from using personal data to serve targeted advertisements to anyone under 17. This includes:
- Behavioral advertising based on browsing history
- Algorithmic content recommendations designed to maximize engagement
- Lookalike audience targeting that uses student data profiles
This is a direct response to the ongoing lawsuits against Meta, Snap, and other platforms accused of designing addictive experiences for children. But it also has implications for EdTech: vendors that serve ads in their free tiers (or share data with advertising partners) will need to fundamentally change their business models.
3. Preserves State Authority
One of the most contentious aspects of earlier versions of the bill was a preemption clause that would have prevented states from passing stronger protections. The final version explicitly preserves state authority:
- States can pass and enforce their own online safety laws, including duty of care requirements
- Existing state lawsuits against tech companies can continue
- The KIDS Act is a "floor, not a ceiling" — states can go further
This matters because states like California, New York, Texas, and Florida already have their own student data privacy laws, and several are considering stricter measures.
What's Missing: The "Duty of Care" Debate
The KIDS Act passed without a duty of care provision — a requirement that would force tech companies to design their platforms to be safe for children by default. The Senate's 2024 Kids Online Safety Act (KOSA) included this provision, but it was stripped from the House version.
Critics, including the American Federation of Teachers and Common Sense Media, argue that without duty of care, the bill addresses symptoms rather than causes. As a coalition of youth safety organizations put it:
"The harm to young people is built into the design of these products, not stemming from content. Stripping the duty of care removes the most important obligation requiring these products to be designed safely in the first place."
Supporters of the House version counter that the duty of care provision was too vague and could be weaponized for censorship. By preserving state authority, the KIDS Act allows states to implement their own duty of care requirements without a one-size-fits-all federal mandate.
What this means for schools: Don't wait for platform redesigns. The duty of care debate will continue for years. In the meantime, your web filter, your monitoring tools, and your acceptable use policies are your students' first line of defense.
How the KIDS Act Affects K-12 Web Filtering
Your EdTech Vendors Must Change
The expanded COPPA provisions mean that every EdTech vendor serving students under 17 must now:
- Obtain verifiable consent before collecting personal data (in school contexts, this typically flows through the district's consent under FERPA, but the interaction between COPPA 2.0 and FERPA has not been fully clarified)
- Minimize data collection to what is strictly necessary for the educational purpose
- Provide transparent privacy policies written in language that parents and students can actually understand
- Delete data on request within a defined timeframe
Action item: Audit your EdTech stack. Which vendors are collecting more data than they need? Which ones serve ads in their free tiers? Which ones share data with third parties? The KIDS Act gives you leverage to demand better data practices from your vendors — and to drop the ones that don't comply.
Web Filtering Becomes a Compliance Tool
Here's the angle most analyses miss: the KIDS Act doesn't just regulate platforms. It creates a compliance environment where your web filter is a critical enforcement mechanism.
Consider this scenario: A student visits a website that collects personal information without proper consent mechanisms. Under the old COPPA, this was only a concern for students under 13. Under the KIDS Act, it's a concern for every student in your district.
Your web filter can:
- Block non-compliant platforms that haven't updated their consent mechanisms
- Monitor for data collection violations by inspecting outgoing requests for personal information
- Enforce your approved app list more strictly, limiting students to vetted EdTech tools
- Log attempted access to provide an audit trail for compliance documentation
The shift: Web filtering used to be about blocking bad content. Under the KIDS Act, it's also about protecting student data — blocking platforms that don't meet the new consent and data minimization requirements.
The "Techlash" Context
The KIDS Act doesn't exist in a vacuum. It arrives alongside a broader backlash against technology in schools:
- 38 states have enacted or are considering cellphone restrictions during the school day
- Los Angeles Unified voted to limit screen time across all grade levels, with a focus on eliminating screens entirely for elementary students
- Tennessee and Kansas are weighing outright bans on certain EdTech in lower grades
- Parents are pushing back on screen time with more organized advocacy than ever before
For IT directors, this creates a paradox: you're being asked to reduce technology exposure while simultaneously being told to strengthen your digital compliance infrastructure. The KIDS Act adds compliance pressure that requires more sophisticated technical controls — exactly the kind of tools that the techlash movement wants to eliminate.
The smart approach: Position your web filter and monitoring stack as safety and compliance infrastructure, not "more technology." A cloud proxy filter that protects student privacy and enforces COPPA 2.0 compliance is fundamentally different from a gamified EdTech app. Make that distinction clear in your communications to parents and board members.
Your KIDS Act Compliance Checklist (Summer 2026)
The KIDS Act still needs to pass the Senate and be signed by the President, but the direction is clear. Smart IT directors are preparing now. Here's your summer checklist:
1. Audit Your EdTech Vendor Agreements
- List every EdTech platform used by students (start with Google Admin Console and MDM reports)
- Check each vendor's privacy policy for COPPA compliance language — does it cover ages 13-16?
- Identify vendors that serve ads in their free tiers
- Flag vendors that don't offer a Data Processing Agreement (DPA) or Student Data Privacy Agreement (SDPA)
- Prioritize replacing non-compliant vendors before the 2026-2027 school year
2. Update Your Acceptable Use Policy (AUP)
- Add language acknowledging expanded COPPA protections for students under 17
- Clarify that the district's consent (via FERPA) extends to COPPA-covered services used for educational purposes
- Include a process for parents to request deletion of their child's data from EdTech platforms
- Address AI tools explicitly — which are approved, which are blocked, and why
3. Strengthen Your Web Filtering Strategy
- Ensure your filter can block specific platforms (not just categories) — you'll need to block individual vendors that aren't COPPA 2.0 compliant
- Enable SSL inspection to monitor outgoing data from student devices (HTTPS means you can't see what data is being sent without it)
- Set up alerts for students accessing unapproved EdTech platforms
- Review your off-campus filtering — COPPA compliance doesn't stop at the school door
4. Communicate with Stakeholders
- Brief your superintendent and school board on the KIDS Act and its implications
- Prepare a parent FAQ explaining how the district protects student data
- Work with teachers to review which EdTech tools are approved and why some may be removed
- Document everything — if the KIDS Act becomes law, you'll want an audit trail showing you prepared proactively
How KyberGate Helps With KIDS Act Compliance
KyberGate's cloud proxy architecture is uniquely positioned to help districts navigate the post-KIDS Act landscape:
Full SSL Inspection
Unlike DNS-only filters, KyberGate performs real SSL inspection on all HTTPS traffic. This means you can see — and control — what data student devices are sending to EdTech platforms. If a non-compliant app is trying to collect personal information, KyberGate can detect and block it.
Granular Platform Control
KyberGate lets you allow or block individual domains and subdomains, not just broad categories. When a vendor fails to update their consent mechanisms for COPPA 2.0, you can block that specific platform while keeping the rest of your EdTech stack accessible.
Comprehensive Audit Logging
Every request through KyberGate is logged with the device identity, timestamp, destination, and action taken. This creates the audit trail you need to demonstrate compliance — whether it's for a CIPA audit, a parent inquiry, or a future COPPA 2.0 enforcement action.
Works on Every Platform, Everywhere
The KIDS Act applies to all student devices, not just the ones inside your school building. KyberGate's cloud proxy architecture provides the same protection on Chromebooks, iPads, and Windows devices — whether they're at school, at home, or anywhere in between.
COPPA compliance isn't just about content filtering anymore. It's about data protection. KyberGate gives you the visibility and control to enforce both.
What Happens Next?
The KIDS Act now moves to the Senate. Given that the Senate passed its own version (KOSA) 91-3 in 2024, there's strong bipartisan support for children's online safety legislation. However, the duty of care debate could delay a final bill, and differences between the House and Senate versions will need to be reconciled in conference.
Our prediction: Some version of expanded COPPA protections will become law before the end of 2026. The core provisions — extending protections to teens, banning targeted advertising to minors, and strengthening data rights — have overwhelming bipartisan support. The question isn't whether, but when.
The bottom line for IT directors: You have a window right now to prepare. Use the summer to audit your vendors, update your policies, and deploy the technical infrastructure you'll need. Districts that prepare now will have a compliance advantage when the final law takes effect. Districts that wait will be scrambling.
Key Takeaways
- COPPA is expanding to age 17. Every EdTech vendor your students use will need to meet stricter consent, data minimization, and deletion requirements.
- Targeted ads to minors are being banned. Free-tier EdTech tools that rely on advertising revenue will need to change their business models or lose access to the K-12 market.
- States can go further. The KIDS Act preserves state authority to pass stronger protections, meaning compliance is a moving target.
- Your web filter is now a compliance tool. SSL inspection, platform-level blocking, and audit logging aren't just about content safety — they're about data privacy enforcement.
- Prepare now. Audit vendors, update policies, and deploy infrastructure this summer. Don't wait for the Senate vote.
Ready to future-proof your compliance infrastructure?
Start a Free 30-Day Pilot — Deploy KyberGate on 10 devices in under 30 minutes. Full SSL inspection, granular platform control, and compliance-ready audit logs included.
View Transparent Pricing — Starting at $5/device/year. No quotes, no sales calls, no surprises.
Read the CIPA Compliance Checklist — Stay ahead of every compliance requirement for the 2026-2027 school year.
Ready to future-proof your compliance?
KyberGate provides SSL inspection, granular platform control, and compliance-ready audit logs — starting at $5/device/year.
Request a Demo