top of page
background.jpg

​

You May Soon Have to Verify Your Age Just to Use Your Computer

Sep 21
3 min read

Age verification requirements are moving beyond websites. New laws in the United States are set to require operating systems such as Windows to determine the age of their users.

Age verification and biometric data-sharing practices, which are rapidly being introduced under the premise of protecting children from the risks of the digital world, have raised growing concerns that they could end online anonymity and ultimately contribute to a surveillance society.

Recent developments in the United States indicate that these control mechanisms may not remain limited to online platforms. In the near future, you may be required to verify your age—and therefore potentially your identity—even to use your own personal computer.


Three U.S. states—California, Colorado, and Illinois—are preparing to implement laws requiring operating systems such as Windows to verify users’ ages. As these regulations take effect, users of Windows, macOS, Android, and even Linux may be asked to provide their age during device setup and could potentially be required to share information such as biometric data or identity details for verification.


Moreover, these three states may only be the beginning. Federal legislation covering the entire United States is already being discussed. Over time, similar practices could also expand beyond U.S. borders, as has happened with other recent regulatory initiatives.

California’s Digital Age Verification Law

One of the most significant examples of this proposed system is California’s Digital Age Verification Law.


The law is scheduled to take effect on January 1, 2027, and will require closed-source operating systems such as Windows, macOS, Android, and ChromeOS to ask users for their age during device setup.

Applications installed afterward will then be able to automatically obtain the user’s age range from the operating system. This means that each individual application will not need to conduct a separate age-verification process.


You May Need to Scan Your Face to Prove Your Age

At first glance, the law adopted in California does not introduce an extremely strict age-verification system. Under its current form, users only need to declare their age during device setup. In other words, there is currently no requirement to upload an identity document or complete a facial scan.


However, civil liberties organizations such as the Electronic Frontier Foundation (EFF) are concerned that the situation could evolve differently in practice.

According to Aaron Mackey, Deputy Director of Legal Affairs at the EFF, companies such as Apple, Google, and Microsoft may eventually adopt stricter verification mechanisms when these requirements are implemented in practice.


Companies may decide to go beyond the minimum requirements of the law to avoid liability arising from users providing false information. This could potentially result in methods such as facial scanning or identity document verification becoming de facto requirements.

Apple, Google, and Microsoft Are Already Preparing the Infrastructure

For such a system to work, operating systems need standardized interfaces—APIs—that allow age-related information to be shared with applications.

Instead of users providing their date of birth or identity information separately to every application, an application could send a request to the operating system and receive information about the user’s age range.


Apple offers the Declared Age Range API for iOS and macOS. Google is developing the Play Age Signals API for applications distributed through Google Play, while Microsoft is adding a Windows Age API to Windows 11.

This would allow age information collected or managed at the operating-system level to become a standardized signal that applications can use.

Although these developments are currently limited to several U.S. states, considering recent regulatory trends, similar practices may eventually appear on the other side of the Atlantic as well.


Some of the measures we can take to protect our privacy and personal data include:


  • Avoid sharing identity and biometric data unless absolutely necessary.

  • Review the data collection policies of applications that require age verification.

  • Grant applications only the permissions they actually need.

  • Where possible, choose age-verification methods that require minimal personal data rather than sharing identity documents.

  • Regularly review the privacy settings of operating systems and applications.

  • Check how personal data is stored and with whom it is shared.

  • Organizations should use solutions that comply with KVKK/GDPR and data minimization principles.


For more information, you can contact our experts at info@zerosecond.ae.


 
 
 

Comments


bottom of page