Meta has agreed to an up to $18bn settlement that could reshape how teenagers use Facebook and Instagram.
For CX leaders, the story reaches beyond child safety and social media regulation. It raises urgent questions about Gen Z engagement, social customer service, and customer data privacy.
The settlement introduces new protections for known teen users. These include a default two-hour daily limit across Facebook and Instagram, muted notifications overnight and during school hours, hidden likes for teens, and stronger age-identification measures.
But one detail should stand out for customer engagement teams. Direct messaging will not count toward the daily use limit.
That means the feed may close after two hours, while the inbox stays open.
Why Meta’s Settlement Matters for Social CX
The settlement gives brands a clear signal. Social CX strategies that depend on public feeds may face new limits with younger audiences.
Feed-based discovery, creator content, and paid social will still matter. But they now compete inside a tighter window when brands try to reach known teen users.
DM-based engagement could become more important as a result. Instagram and Messenger already act as support channels, shopping assistants, complaint desks, and loyalty touchpoints for many brands. Virginia Attorney General Jay Jones, Attorney General of Virginia, framed the settlement as a major child-safety intervention:
“I am elated to announce a settlement agreement that will put an end to these dangerous practices and deliver meaningful relief that will protect children from online harm.”
For CX teams, that regulatory pressure now has a practical consequence. The public feed may become a less dependable engagement surface for younger customers and the inbox may become the more durable channel.
The Feed Gets Restricted, but the Inbox Stays Open
The DM exemption could make messaging one of the most important channels for Gen Z customer relationships.
For retail, travel, entertainment, banking, and telecoms brands, this matters. Younger customers often expect brands to answer questions where the relationship already exists. They may not want to switch from Instagram to email, a web form, or a phone line. They want help inside the channel they already use.
Conversational commerce fits that behavior. A customer can ask about sizing, delivery, returns, product availability, or appointment booking inside a message thread. A chatbot can triage a simple query. A human agent can step in when the issue needs care.
But brands should avoid treating DMs as another place to push promotions. The inbox is more personal than the feed. Poor targeting, clumsy automation, or repetitive outreach can damage trust quickly. Useful, consent-based engagement will matter more than volume.
Social Customer Service SLAs May Need a Reset
Meta’s new notification rules also create a direct operational issue for contact centers.
Notifications for younger users will be muted between midnight and 6 am. They will also be muted on school days between 8 am and 3 pm.
That matters for asynchronous support. A brand may send a message at 10 am, but the customer may not see it until after school hours. This can distort response-time reporting. It can also make standard social care metrics look weaker than the experience really is.
CX teams will need to separate internal response speed from customer visibility. An agent may reply quickly, while the customer’s next action may arrive hours later. That creates new planning questions. Should teams change outbound message timing for younger audiences?
Should social queues include age-aware expectations where legally and ethically appropriate? Should automated workflows explain when a response may be delayed because of platform-level controls?
The answer will vary by sector. But the broader lesson is clear, platform design now shapes customer service delivery as much as agent performance does.
The Data Privacy Warning Is Even Bigger
The settlement also raises a deeper issue for CX leaders: customer data privacy.
The case centered on the Children’s Online Privacy Protection Act and Meta’s historic gathering and use of data belonging to children under 13.
Meta has not admitted wrongdoing. That should still make every CX leader look again at their data stack.
Many businesses now rely on Customer Data Platforms, behavioral analytics, personalization engines, loyalty programs, and AI-driven targeting.
These tools can improve customer journeys when brands use data responsibly. They can also create major exposure when consent, identity, and age assurance are weak. New Jersey Attorney General Jennifer Davenport, Attorney General of New Jersey, positioned the agreement around practical protections for children:
“As a parent, protecting your kids is always your North Star. And this agreement achieves critical protections for our children today.”
The warning for brands is direct. A personalized customer journey can create risk when the business cannot prove lawful data collection, clear consent, and age-appropriate handling.
The risk grows when brands personalize experiences for unknown or underage users. A journey that feels seamless to a marketer may look invasive to a regulator.
Privacy by design needs to move from legal language into CX operations. That means collecting less data when possible, making consent clear, and building age-appropriate journeys. It also means knowing when not to personalize. Sometimes the best customer experience is restraint.
What Brands Should Do Next
Brands do not need to abandon social engagement with younger audiences. But they do need to treat Meta’s settlement as a planning moment.
First, CX teams should audit how much of their youth-facing engagement depends on feed visibility. If discovery and service rely heavily on the public timeline, those journeys may become more fragile.
Second, contact centers should review social messaging SLAs. Metrics should account for platform rules that affect when customers see notifications and when they can reasonably respond.
Third, marketing and CX teams should align on DM governance. Automated messages, chatbot flows, handoff rules, escalation paths, and consent standards all need clear ownership.
Finally, data leaders should test whether onboarding, identity, and personalization processes protect minors. CDPs and AI tools need guardrails that reflect age, consent, and data minimization.
The future of Gen Z CX will likely feel more private, more conversational, and more regulated. For brands, that is a compliance challenge, a relationship challenge, and an opportunity to show up with care when customers choose to start a conversation.
Join the conversation: Join our LinkedIn community (40,000+ members): https://www.linkedin.com/groups/1951190/
Get the weekly rundown: Subscribe to our newsletter: http://cxtoday.com/sign-up