Technology
Online service, product, or feature: access by children
California sets child-safety and privacy rules for online services likely to be accessed by people under 18.
The law requires child-facing online businesses to use high-privacy defaults, limit data practices, and address specified risks of harm. State enforcers can seek injunctions and penalties of up to $15,000 per affected child for intentional violations.
What the law does
- Requires businesses to estimate a child user's age at a risk-appropriate level of certainty or extend child privacy and data protections to every consumer.
- Requires high-privacy default settings, child-appropriate privacy notices, clear signals when a child is monitored or location-tracked, and accessible privacy-rights and reporting tools.
- Limits default profiling, unnecessary collection, sale, sharing, retention, and reuse of children's personal information, as well as default collection of precise geolocation.
- Bars dark patterns that push children to provide extra personal information or give up privacy protections.
- Requires reasonable steps to prevent foreseeable physical or financial harm, severe foreseeable psychological or emotional harm, unlawful privacy intrusions, and unlawful discrimination.
- Lets a child void a contract entered because of a covered service's design feature.
- Authorizes the Attorney General or a public prosecutor to enforce the law, but creates no private right of action.
Who it affects
- Businesses offering online services, products, or features reasonably expected to be accessed by children.
- Children under 18 who use those services, products, or features.