In committee
Sammy’s Law
This bill requires large social media platforms to let approved parental-control software connect directly to accounts used by kids under 17. When authorized by a parent or a teenager aged 13 or older, these tools can monitor online interactions, manage privacy settings, and alert parents to specific dangers such as cyberbullying, self-harm, sexual exploitation, or drug use. To protect privacy, the software companies must be based in the United States, register with the Federal Trade Commission, undergo independent security audits, and delete collected data within 14 days unless it relates to a detected threat.
People affected—Not determinable from the text provided; the bill applies broadly to children under 17 and their parents who use qualifying large social media platforms, but the text contains no census or exact population figure.
Fiscal magnitude—no CBO estimate published
Reach62provisional · pending reviewrigor: heuristic llm
What this bill touches.
Market protections+50Big-tech & platforms+60Courts & liability−35Personal data & privacy+40Federal vs. state/local+45
Who it helps · who it burdens.
Who it helps
- Parents and legal guardians of minor social media usersGrants parents the legal right to delegate account access to registered third-party safety software to monitor and manage their child's social media settings and receive alerts regarding specific risks such as suicide, abuse, violence, or harassment (Sec. 4(a)(1), Sec. 4(f)(1)(C)).
- Children and youth social media usersEnables children aged 13 to 16 to directly authorize safety software to help manage their accounts, and entitles all children under 17 to clear notices and summaries whenever safety software access is enabled or data is transferred (Sec. 3(1), Sec. 4(a)(1), Sec. 4(a)(4), Sec. 4(b)(1)(A)(vii)).
- Third-party safety software providersGains guaranteed access to real-time APIs and hourly data feeds from major social media platforms when authorized by a family (Sec. 4(a)(1)).
- Large social media platform providersReceives statutory immunity from civil liability in federal and state courts for transferring user data to safety software providers when acting in good-faith compliance with the law and FTC guidance (Sec. 4(e)).
Who it burdens
- Third-party safety software providersMust register with the FTC, maintain domestic ownership and data storage, hire independent auditors for initial security reviews and annual audits, delete user data within 14 days, and strictly limit data disclosures to authorized safety risks and legal requests (Sec. 4(b)(1)-(2), Sec. 4(f)).
- Large social media platform providersMust build and maintain continuous real-time APIs for third-party safety apps, transfer user data at least hourly, implement cybersecurity safeguards, provide data transfer summaries to users, and face FTC enforcement for noncompliance (Sec. 4(a)(1)-(4), Sec. 5(a)).
- Federal Trade Commission (FTC)Required to create and manage a provider registration registry, review annual audits, publish audit summaries, issue guidance within 180 days, run consumer education, conduct biannual compliance reviews, and administer a complaint intake process (Sec. 4(b)-(d), Sec. 5(b)-(d)).
Who opposes it
- State and local governmentsPreempts states and localities from establishing or enforcing separate laws that require social media platforms to provide safety software APIs (Sec. 6(a)).