New York's SAFE for Kids Act: A Compliance Nightmare for Dating Apps
Key Points
- •New York's SAFE for Kids Act takes effect on 25 January 2027, targeting platforms where 20 per cent or more of user time involves algorithmically-recommended feeds.
- •Covered platforms must obtain verifiable parental consent before presenting algorithmic feeds or nighttime notifications to users under 18 years old in New York.
- •Match Group banned under-18 users from Tinder globally in 2024, but smaller dating platforms face new age-assurance compliance and infrastructure expenses.
- •New York regulations require platforms to maintain age-assurance certification documentation for 10 years and individual determination records for five years.
Match Group's legal team is likely poring over the New York Attorney General's final SAFE for Kids Act rules right now with a single question: does Tinder's Discovery feed count as an 'addictive feed'? According to the final regulations published on 28 July, they've got until 25 January 2027 to work it out—and the answer could force a choice between parental consent workflows or fundamentally redesigning how younger users experience the product. The statute targets 'addictive social media platforms', defined as any service where 20 per cent or more of monthly active user time happens on feeds that display user-generated content selected via algorithmic recommendation.
That threshold is measured over any six-month period, creating a moving target that dating platforms with social discovery features, user-generated video carousels, or TikTok-style browsing may inadvertently hit. The kicker: platforms meeting this definition must obtain verifiable parental consent before showing algorithmic feeds or sending nighttime notifications to anyone under 18. Dating apps have long treated themselves as categorically different from social platforms. But New York's definition doesn't care about your product positioning—it cares about time-on-feed and algorithmic recommendation.
This could be the regulation that finally forces dating platforms to reckon with what they actually are: algorithmically-curated feeds of people. The 20 per cent threshold sounds generous until you calculate how much time users spend swiping versus messaging. For discovery-heavy apps—particularly those courting Gen Z with short-form video or social-first features—that's a compliance landmine. Smaller operators without Match or Bumble's legal resources are about to discover that 'we don't allow under-18s anyway' isn't the regulatory shield they thought it was.
Create a free account
Unlock unlimited access and get the weekly briefing delivered to your inbox.
What Actually Qualifies as an Addictive Feed
The final rules define an 'addictive feed' with surprising specificity: multiple pieces of user-generated media, recommended or prioritised based on information 'persistently associated' with the user or device, or based on prior interactions with content. Crucially, those interactions can span multiple platforms. That last point matters.
If a dating app uses signals from a user's Instagram activity, Facebook likes, or cross-platform browsing behaviour to inform match recommendations—something several apps do via Meta's Ad platform integrations—those signals count. The feed doesn't need to be endless scrolling to qualify. It needs to be personalised and algorithmic.
The distinction between 'user initiates discovery session' and 'platform surfaces recommended profiles' is legally fuzzy, and the Attorney General's office has yet to issue guidance on borderline cases.
New York carved out exemptions for search results, express requests for specific content, privacy settings adjustments, and private messaging. What's conspicuously absent: clarity on whether match recommendations triggered by a swipe constitute an 'express request' or algorithmic curation. Dating platforms with straightforward chronological feeds or purely location-based sorting likely escape. But any app that surfaces 'Top Picks', curates a 'For You' page, or uses collaborative filtering to recommend matches based on behavioural patterns is in murkier territory.
Age Assurance Just Got Expensive
Compliance isn't just about legal interpretation—it's about infrastructure. The final rules mandate annual certification of age-assurance methods against accuracy thresholds, including false positive rates, false negative rates, circumvention detection, and data handling practices. At least one method, plus an appeals process, must function without government-issued ID.
For smaller platforms that have historically relied on self-declaration or simple date-of-birth entry, this creates immediate operational cost. Age estimation technology providers like Yoti and Onfido charge per verification. Annual certification adds compliance overhead. Record retention requirements—10 years for certification documentation, five years for individual determinations—demand storage infrastructure most dating platforms don't currently maintain.
Match Group moved preemptively, banning under-18s from Tinder globally in 2024 and implementing identity verification pilots. Bumble has tested government ID verification in select markets. But mid-tier and independent operators face a cost-versus-compliance calculus: invest in age-assurance infrastructure that may exceed their current trust and safety budgets, or redesign products to stay under the 20 per cent threshold.
Measured over any six-month period, it means platforms must continuously monitor time-on-feed metrics. A viral feature, seasonal usage spike, or product experiment that temporarily pushes discovery engagement above 20 per cent could trigger compliance requirements mid-year.
There's no safe harbour for good-faith efforts or temporary breaches.
Parental Consent as Product Killer
Assuming a platform determines it's covered, the consent workflow is operationally complex. Operators must notify the minor that algorithmic feeds and nighttime notifications require parental approval, obtain the minor's consent to contact the parent, notify the parent, provide a mechanism for granting consent, and maintain withdrawal options for both parties. For dating apps, this isn't just inconvenient—it's potentially product-destroying.
The entire value proposition relies on immediacy and autonomy. Requiring a 17-year-old to ask permission before swiping fundamentally alters the user experience. Most platforms will simply prohibit access for under-18s rather than build consent infrastructure, which means New York has effectively created an age floor without calling it one.
That's precisely what happened after Tinder's litigation and reputational crisis around underage users. The regulatory pressure made retention of minors untenable. New York's law formalises that dynamic for any platform unlucky enough to meet the 'addictive' threshold. What makes this framework particularly precedent-setting: it's not a dating-specific regulation. It's a social media law that happens to catch dating apps in its net.
If other states adopt similar frameworks—and California, Massachusetts, and Maryland are all considering variants—the compliance burden multiplies. Multi-state age-assurance certification, jurisdiction-specific consent workflows, and conflicting definitions of 'addictive' could fragment product strategy across state lines. The effective date of 25 January 2027 gives platforms 18 months to make the call: redesign to stay under the threshold, build expensive compliance infrastructure, or exit the under-18 segment entirely.
For an industry already grappling with trust crises, regulatory scrutiny, and investor pressure to demonstrate sustainable growth, New York's legislation just added another variable to an already complicated equation.
Key Takeaways
- •Dating app operators must continuously monitor engagement metrics because crossing the 20 per cent feed threshold in any six-month window triggers full statutory compliance obligations.
- •Multi-state regulatory fragmentation across New York, California, Massachusetts, and Maryland will likely force independent dating platforms to ban minors completely rather than implement localized parental consent workflows.
- •Compliance teams face significant mandatory technical overhead due to annual third-party age-assurance accuracy audits and long-term data retention requirements.
Frequently Asked Questions
Policy & Regulation Desk
The DII Regulatory Monitor tracks legislation, enforcement action, safety rules and compliance across dating industry markets.
Comments
Join the discussion
Industry professionals share insights, challenge assumptions, and connect with peers. Sign in to add your voice.
Your comment is reviewed before publishing. No spam, no self-promotion.
