
Congress’ Age Verification Proposals Are Flawed in Different Ways
Faced with multiple options for protecting children online and a growing patchwork of state legislation, Congress has turned to age verification as a potential solution to some of children and parents’ problems. The logic is straightforward: In order to extend extra protections to children, online services need to know their users’ ages. However, putting that theory into practice is far more complicated. Age verification requirements carry many risks and can end up creating new privacy and security problems. If Congress moves forward with age verification legislation, it needs to balance kids’ safety and users’ privacy and avoid overburdening online services in ways that will ultimately harm users’ online experiences.
At the moment, four age verification bills take center stage in Congress: the App Store Accountability Act (ASAA), Parents Over Platforms Act (POPA), Parents Decide Act (PDA), and Digital Age Assurance Act (DAAA). Each of these bills takes a different approach to age verification, and while none strike the right balance yet, each have their own strengths and weaknesses that highlight key concerns in the age verification debate.
Age Verification and Parental Consent Requirements
Comparing the four main age verification bills facing Congress reveals two similar but distinct approaches to age verification. ASAA and POPA require app stores to verify their users’ ages and send age signals to app developers, whereas the PDA and DAAA shift that requirement to operating systems, which send age signals to app developers and website operators, though DAAA also requires app developers and website operators to inform operating systems if they have age information that conflicts with the operating system’s age signal.
Both app store and operating system approaches to age verification are less burdensome than requiring users to register their age independently on every single app and website, but the operating system approach is more comprehensive. By requiring app stores to verify users’ ages and provide that information to app developers, Congress would leave web browsers out of the equation entirely. But children can just as easily access age-inappropriate content or engage in age-inappropriate activities on websites as they can in apps. Indeed, users can access many of the same services through both apps and websites.
In addition to age verification, all four bills contain provisions related to parental consent. ASAA and DAAA both require app stores and operating systems, respectively, to link a parent or legal guardian’s account to each child’s account. ASAA also requires app stores to obtain parental consent before the minor can download an app or make an in-app purchase. PDA requires operating systems to ask a parent or legal guardian to verify each minor’s date of birth.
POPA requires app developers to restrict minors from activities designated for adults only and obtain parental consent before allowing minors to engage in activities designated as unsuitable for minors without parental guidance or supervision—in the absence of legal requirements, developers can make these designations themselves—but does not prescribe a specific mechanism for obtaining or verifying consent.
There are multiple ways online services can verify users’ ages or parental authority over another user, and each of these methods comes with different strengths and weaknesses. Some are more accurate but more invasive, whereas others are less invasive but also less accurate. The least invasive but least accurate method of age verification relies on self-reporting: asking users to provide their date of birth or check a box to indicate they are over a certain age. PDA takes this approach, requiring operating systems to collect users’ dates of birth, but then goes a step further by asking parents to verify each child’s age. It instructs the Federal Trade Commission (FTC) to issue regulations instructing operating systems on how to verify parents’ ages.
The most accurate but most invasive method of age verification requires users to provide a valid government-issued ID in order to prove their age. In doing so, users also provide their full name, gender, home address, and photograph—personal information unnecessary for age verification. Digital forms of government-issued identification could solve some of these concerns. If designed right, digital IDs would allow users to only share necessary information. Individuals could verify that they are over a certain age without providing their exact date of birth, let alone all the other information a physical ID would reveal. This approach would maximize both accuracy and privacy but is currently not an option in the United States, which lacks widespread digital IDs.
Finally, artificial intelligence tools can estimate users’ ages from an image of their face. Combined with privacy protections requiring online services to delete users’ images after the age estimation process is complete, this would minimize the amount of personal information users have to give up in order to verify their age. Of course, age estimation technology is not perfectly accurate and likely never will be—no form of age verification is—but it is constantly improving, and this approach is an improvement on self-reporting, in terms of accuracy, and on physical ID checks, in terms of privacy.
ASAA allows app stores to use any commercially available method that is “reasonably designed to ensure accuracy.” Similarly, POPA allows app stores to use “commercially reasonable efforts” to determine the user’s age category with a “reasonable level of certainty.” DAAA likewise avoids prescribing a specific age verification method. This technologically agnostic approach to age verification allows online services to determine which method of age assurance will minimize privacy risks and the risk of harm to children, work within their business model, and cause users the least inconvenience. Flexibility also leaves room for technological innovation that makes age verification more accurate and less invasive.
ASAA, POPA, and DAAA include data minimization provisions that restrict how app stores, operating systems, app developers, and website operators use age verification data. Under ASAA, app stores cannot collect and store more data than they need for age verification. Under both ASAA and POPA, app developers can only use age verification data to comply with age verification requirements or implement safety features or privacy protections. Under DAAA, app developers, website operators, and operating systems cannot collect more data than they need for age verification and cannot sell that data, combine it with other information about a user, or use it for profiling, engagement optimization, or targeted advertising. Operating systems must deidentify or delete the data when a user deletes their account.
Finally, ASAA and DAAA include provisions that link their age verification requirements to existing children’s privacy law. The Children’s Online Protection and Privacy Act (COPPA) imposes certain requirements on online services directed to children under 13 or those directed to a general audience that have “actual knowledge” that a user is under 13. ASAA and DAAA both specify that data obtained for age verification constitutes “actual knowledge” of a user’s age. These requirements would have the likely unfortunate side effect of incentivizing more online services to block users under 13 entirely to avoid facing additional compliance burdens or potential liability.
Other Measures in Age Verification Bills
In addition to age verification and parental consent requirements, ASAA requires app developers to provide notice to app stores of any significant changes to their terms of service or privacy policy, such as changes to the app’s age rating, monetization features, or categories of data the app collects, stores, and shares. App stores must then notify users of all ages and minors’ parental accounts of these changes. Meanwhile, POPA requires app developers that allow minors to provide privacy and online safety information to minors’ parents.
POPA also forbids app developers from delivering personalized ads to minors, defined as advertising based on a user’s activities over time and across non-affiliated websites and apps to predict the user’s preferences or interests. DAAA more broadly prohibits all targeted advertising to children, with the exception of contextual advertising, which relies on the content or keywords on the app or web page a user visits—for example, placing ads for a skincare brand alongside a video of an online creator demonstrating their skincare routine. DAAA also prohibits monetizing children’s data.
Calls to ban targeted advertising to children face a feasibility problem. Online services, especially free ones, rely on targeted advertising as an important source of revenue.
If Congress bans targeted advertising to children, online services are likely to either stop offering content aimed at children, show even more (but less relevant) ads to make up for the reduced effectiveness of switching to only contextual advertising, or start charging higher prices for content that was once low-cost or free. This would have the strongest negative effect on low-income households with less disposable income to spend on children’s entertainment and educational content.
Compliance and Enforcement
All four bills give enforcement power to the FTC. ASAA and DAAA also give enforcement power to the state attorneys general. Centralized FTC enforcement promotes consistency and provides expert oversight, and including the state attorneys general enables other government authorities to step in when the FTC lacks the time or resources to investigate a potential violation.
In order to facilitate compliance, ASAA directs the FTC to issue guidance to app stores and developers on how to carry out the bill’s requirements, though it prohibits the FTC from bringing an enforcement action against an app store or developer solely for failing to follow this guidance. PDA instead directs the FTC to issue regulations that instruct operating systems on how to comply with the bill. DAAA instructs the FTC to issue rulemakings, but unlike PDA, it doesn’t include details on what those rules must address. ASAA also directs the FTC to establish a mechanism for app stores to certify their compliance with the bill’s requirements. This certification lasts one year.
All four bills establish some form of safe harbor for covered entities. POPA and PDA protect app stores and operating systems, respectively, from liability for violations if they comply or make a good faith effort to comply with the bills’ requirements. DAAA’s liability shield for operating systems is far more limited, only protecting them in cases of outages or technical errors that prevent them from providing age signals.
ASAA protects app developers from liability for violations if they can demonstrate they made a good faith effort to comply, relied on age data from a covered app store, and conform to industry standards or best practices for age ratings and content descriptions. POPA and DAAA include more limited protections for app developers—and website operators, in the DAAA’s case—that apply when they receive an erroneous age signal from app stores or operating systems, respectively.
Guidance, certification, and safe harbors are all useful compliance tools for online services. First, online services can comply more easily if they have detailed guidance from a rulemaking authority—in this case, the FTC—rather than relying on their own interpretations of the law. This guidance should, like the billComparison_HTMLs themselves, remain technologically and commercially agnostic and avoid inflexible requirements that limit online services’ options. Certification programs, in turn, offer online services greater assurance that their compliance is adequate. Finally, safe harbors shield online services that operate in good faith and free up authorities to focus on bad actors.
Finally, ASAA and POPA fully preempt state-level age verification laws, establishing a consistent national standard. DAAA only preempts state laws that conflict with the bill and allows states to pass laws more restrictive than DAAA, acting as a floor instead of a ceiling. PDA does not preempt state laws. By failing to fully preempt state laws, DAAA and PDA would allow the patchwork of age verification requirements to grow unimpeded, which would complicate compliance, increase costs, and likely frustrate consumers with conflicting requirements.
Conclusion
Protecting children online is an important policy goal, but age verification is not a silver bullet. As Congress considers legislation in this area, lawmakers should recognize that every age verification requirement involves tradeoffs between accuracy, privacy, convenience, and implementation costs.
Rather than treating age verification as an end in itself, Congress should view it as one tool within a broader strategy for protecting children online. Any federal framework should balance safety and privacy, preserve innovation in age verification technologies and age-appropriate online services for children, and establish a clear, uniform national standard that provides certainty for both users and online services.
Table 1: Comparing the App Store Accountability Act, Parents Over Platforms Act, Parents Decide Act, and Digital Age Assurance Act
|
Provisions |
App Store Accountability Act |
Parents Over Platforms Act |
Parents Decide Act |
Digital Age Assurance Act |
|
AGE VERIFICATION |
||||
|
Level |
App store |
App store |
Operating system |
Operating system |
|
Means |
Not specified |
Not specified |
Not specified |
Not specified |
|
Parental consent mechanism |
Parental accounts |
Not specified |
Not specified |
Parental accounts |
|
Data minimization |
Yes |
Yes |
No |
Yes |
|
Establishes actual knowledge |
Yes |
No |
No |
Yes |
|
OTHER MEASURES |
||||
|
Notification of significant changes |
Yes |
No |
No |
No |
|
Ban on targeted advertising |
No |
Yes |
No |
Yes |
|
ENFORCEMENT |
||||
|
FTC |
Yes |
Yes |
Yes |
Yes |
|
State attorneys general |
Yes |
No |
No |
Yes |
|
Certification |
Yes |
No |
No |
No |
|
Safe harbor |
Yes |
Yes |
Yes |
Yes |
|
State preemption |
Full |
Full |
None |
Partial |
|
FTC |
Yes |
Yes |
Yes |
Yes |
