Age Signal Privacy for Youth

Full Title:
Digital Age Assurance Act of 2026

Summary#

This bill would require operating systems on phones, tablets, and computers to make users give their date of birth or age and to sort users into one of four age brackets. Apps, app stores, browsers, and certain websites would have to ask the operating system for a simple, privacy-focused "age signal" and use it as their main way to know a person's age. The law also bans targeted advertising to children and stops people from selling children's personal data to data brokers.

  • Main change: Operating system providers must collect a user’s date of birth or age, create an age-bracket (under 13; 13–15; 16; 17+), and provide that bracket as a signal to apps, browsers, and covered websites on request.
  • Who must ask for the signal: App developers, app stores, browser providers, and “covered internet websites” (websites that by law must verify age before giving access) must request the signal the first time a user runs an app, visits a covered site, or accesses an app store or browser on a device.
  • Limits on use of the age data: Age bracket data must be minimized, secured, not sold, not used for profiling/targeted ads or combined with other personal data, and deleted or deidentified when an account is deleted.
  • Child protections: If a user is a child (under 17), the OS must require linking that child account to a parent or guardian and let the parent view the child’s age bracket.
  • Enforcement: The Federal Trade Commission (FTC) enforces the law and can issue civil penalties (up to $2,500 per negligent violation or $7,500 per knowing violation, which can be multiplied if children are affected). State attorneys general can also sue on behalf of residents.
  • Antitrust rules: The bill bars operating systems and app stores from applying age rules to third-party apps that are stricter than the rules they apply to their own apps and from using collected age data to gain competitive advantage.

What it means for you#

  • Users (general):

    • You will be asked to provide your date of birth or age when you create or update an account on an operating system 18 months after the law starts.
    • Apps and some websites will rely on an age bracket signal from your device instead of asking you for age directly.
    • You can expect less targeted advertising to accounts that the platform knows are for children.
  • Parents and guardians:

    • If your child is under 17, the operating system must require the child to link to a parent or guardian account.
    • Parents must be able to view the child's age bracket and will get a notice if a service has different information about the child’s age.
    • Parents may be offered a way to provide corrected age data and should get a decision within 30 days.
  • Children and teens:

    • Services that are inappropriate for a given age bracket can be blocked automatically based on the age signal.
    • The law prohibits targeted advertising to users the provider knows or should know are children.
  • App developers, app-store operators, and website operators:

    • They must request the age signal on first use and treat the signal as the primary indicator of age unless they have clear and convincing evidence it is wrong.
    • They may not ask the operating system for additional information beyond the signal and may not share the signal with third parties.
    • Developers who act in good faith using the signal have a safe harbor from liability for errors in the signal.
  • Operating system providers and browser providers:

    • Must collect date of birth/age, create age brackets, send signals via a secure API or equivalent, and offer verifiable credentials or zero-knowledge proof options where technically feasible.
    • Must limit data retention, secure the data, and delete or deidentify it when accounts are deleted.
    • Are protected from liability for failures to send signals caused by outages if they acted in good faith.
  • Advertisers and data brokers:

    • Targeted advertising to users known or reasonably identifiable as children is banned.
    • Selling or otherwise providing children's personal data to data brokers is unlawful.
  • Government and courts:

    • The FTC writes rules within one year and enforces the law; states can sue too but must notify the FTC in most cases.

Expenses#

No publicly available information.

  • The bill directs the FTC to write rules within one year, which implies administrative rulemaking costs for the agency (not quantified here).
  • Companies may need to build or change systems to collect DOB/age, create secure APIs, support verifiable credentials or zero-knowledge proofs, link child accounts to parents, and delete or deidentify data—these are compliance costs that are not estimated in the bill text.
  • The bill creates civil penalties for violations, which could lead to financial liability for firms that do not comply.
  • State attorneys general and the FTC may incur enforcement and litigation costs; those are not estimated in the bill.

Proponents' View#

  • The bill appears intended to make it easier and more consistent for apps and websites to know a user’s age without exposing extra personal information.
  • This could be seen as improving child safety online by standardizing age checks and enabling automatic enforcement of age-appropriate access.
  • The bill appears designed to limit commercial harms to children by banning targeted ads to known children and banning sale of children’s personal data to data brokers.
  • The interoperability and anticompetition provisions appear intended to prevent operating system or app-store owners from using age data to favor their own apps over third parties.
  • The bill includes privacy-minded features (age brackets, verifiable credentials, zero-knowledge proofs) to reduce sharing of exact birthdates or other personal details.

Opponents' View#

  • One concern is that requiring operating systems to collect birthdates centrally could create a sensitive repository of age data that must be secured; the bill requires safeguards but centralization raises privacy and security questions.
  • The bill does not require any particular method to verify age, and it allows users to input inaccurate information; this may limit how reliably services can identify children.
  • It is unclear how linking child accounts to parent accounts will work in practice across devices and families, and how that will affect access in blended or shared-device situations.
  • Small developers and websites may face technical and cost burdens to implement the required signal requests, verification flows, and data-minimization practices; the bill does not provide funding or transition support.
  • The definition of “covered internet website” is limited to sites that are already required by law to verify age, which may leave gaps in which sites must follow the new rules.
  • The enforcement penalties are per violation; depending on how they are applied, this could lead to large damages exposure, especially where many users are affected — the bill allows multiplying penalties when children are affected.