What Federal Age Verification Mandates Could Mean for Privacy and Security
Industry, parents, and policymakers are all deeply concerned about youth safety and protecting younger users online. Leading digital services offer a range of online safety tools that empower parents to protect their children and decide what is appropriate for their families. Because these tools are effective and enable parents to make granular-level details about access for their children, decisions about what sensitive information to share—and what not to—should be led by parents. Indeed, no website or digital service should be forced to collect birth certificates or other sensitive identifying data that could be exploited by bad actors.
In its continued effort to protect kids online, Congress has recently introduced several bills. Two of these, the App Store Accountability Act and the Parents Over Platforms Act are worth highlighting further, especially for their divergences on compliance obligations.
Legislating the online experience is complex, to say the least. Careful definitions and approaches are crucial to this debate. In particular, the complications of age assurance, including mandatory age verification and the many concerns it raises, should be central to this important discussion. Getting those provisions wrong means running afoul of one of the most sacred constitutional protections which ensures free speech, community access, and the opportunity to engage with others.
While these bills approach the issues from differing perspectives, they share a central theme: required verification of a user’s age. Importantly, mandatory age verification may compel companies to collect more sensitive data than they would otherwise need to provide a useful consumer experience. Forcing increased collection of sensitive, personally-identifiable information creates exploitable targets for malicious actors, increases the burden on digital services, and contradicts important privacy principles such as data minimization.
Below is a chart that outlines these proposals, including how they apply age verification requirements:
| Bill | Summary | Compliance Requirements |
| App Store Accountability Act (H.R. 3149/S. 1586) | Requires app stores to provide age-gating and ensure age verification for users accessing apps. | App stores must implement age-verification mechanisms.Requires collecting or validating sensitive personal information to determine age from all users.Parental controls must be used on all apps. |
| Parents Over Platforms Act (H.R. 6333) | Requires app stores to request age categories “with reasonable certainty.” | App stores can either request age information or provide a tool for age categories.Age categories are compiled into “age signals” which may be provided to developers if an app provides a minor and adult with different experiences.App stores must share age signals with developers if requested by the user, or a parent of a user under 18. |
As with all internet-based mandates, lawmakers risk expanding data collection by digital services without increasing meaningful protections, while undermining important constitutional protections for children online. In contrast, a comprehensive federal privacy law that establishes strong privacy and security standards is the best solution to promote safety and limit burdens on speech.
Fortunately, leading services are providing protections and other measures to empower the next generation in digital spaces while also offering parental tools that protect young users from harmful material. These safeguards allow for positive, educational, and age-tailored experiences online.
Congress should avoid age verification policies that force app stores, developers, or other digital services to verify users’ identities or ages. Rather than one-size-fits-all obligations, digital services should have the flexibility to tailor protective measures based on the nature of the service, the type of content, and the risks posed.