惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Cyberwarzone
Cyberwarzone
Help Net Security
Help Net Security
L
LINUX DO - 最新话题
Security Archives - TechRepublic
Security Archives - TechRepublic
A
About on SuperTechFans
www.infosecurity-magazine.com
www.infosecurity-magazine.com
Attack and Defense Labs
Attack and Defense Labs
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
The GitHub Blog
The GitHub Blog
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Webroot Blog
Webroot Blog
T
Tenable Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
Microsoft Security Blog
Microsoft Security Blog
人人都是产品经理
人人都是产品经理
Simon Willison's Weblog
Simon Willison's Weblog
D
Docker
爱范儿
爱范儿
AI
AI
宝玉的分享
宝玉的分享
PCI Perspectives
PCI Perspectives
The Register - Security
The Register - Security
Project Zero
Project Zero
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
IT之家
IT之家
S
Securelist
Scott Helme
Scott Helme
B
Blog
Forbes - Security
Forbes - Security
Google DeepMind News
Google DeepMind News
T
The Blog of Author Tim Ferriss
月光博客
月光博客
P
Proofpoint News Feed
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
F
Fortinet All Blogs
H
Help Net Security
Last Week in AI
Last Week in AI
N
News and Events Feed by Topic
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
MyScale Blog
MyScale Blog
I
InfoQ
P
Privacy International News Feed
V
V2EX
有赞技术团队
有赞技术团队
G
Google Developers Blog
阮一峰的网络日志
阮一峰的网络日志
腾讯CDC
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
S
Schneier on Security
T
Tailwind CSS Blog

Future of Privacy Forum

New Survey: Privacy Concerns Are A Top Barrier to AgeTech Adoption Among Older Adults Navigating Cross-Border Data Transfers in the ASEAN Region: An Analysis of Developments from 2023 to 2026 Mandating “Evidence-Based” Suicide Detection in Chatbots Data Brokers & Beyond: Navigating New Jersey’s Data Broker & “Data Collector” Registration Law - Future of Privacy Forum FPF Hosts Frontiers Workshop on Privacy, AI, and Emerging Infrastructure FPF’s 2026 DC Privacy Forum: Leading Voices in AI, Privacy and Emerging Technology Understanding Data Embassies and Corridors Perseverance Pays Off for Vermont Privacy Efforts Future of Privacy Forum Announces 2026 Career Achievement Award Recipients - Future of Privacy Forum Future of Privacy Forum Releases Comprehensive Report On Algorithmic Personalization in Youth Online Experiences Frontier AI Goes Federal: How the Great American AI Act Compares to State Laws Privacy Becomes You, Bayou State: A Look at the Louisiana Data Privacy Act Comparing Enacted App Store Accountability Acts - Future of Privacy Forum No Silver Bullet, But a Silver Lining? PETs and International Data Transfers Career Choice in the AI Age: What Next for Privacy and Data Professionals? FPF Releases Practitioner Guides on Privacy Enhancing Technologies for Education Stakeholders SB 5 in Five: What to Know About Connecticut’s New AI Law Third Time’s the Charm: Connecticut Enacts Annual Privacy Update - Future of Privacy Forum Colorado Revises Its AI Act: What Changed and Why The EU Commission’s Approach to Age Verification: Mobile Apps, DSA Enforcement, and Challenging National Social Media Bans Taking stock: The Impact of the India AI Impact Summit 2026 The New(ish) Architecture of Consumer Health and Artificial Intelligence Celebrating Another Year of Privacy and AI Governance: FPF at the 2026 IAPP Global Summit - Future of Privacy Forum Adapting the Privacy Profession to Changing Times More Parties, More Risks, More Opportunity? Evolving Governance to Support Cyber Resilience Amidst Evolving Policy and Technological Change Contextualizing the Proposed SECURE Data Act in the State Privacy Landscape FPF on the Securing and Establishing Consumer Uniform Rights and Enforcement Over Data ("SECURE Data") Act The Alabama Personal Data Protection Act Brings Consumer Privacy to the Heart of Dixie The Price is Right: Responsible Uses of Personal Data in Pricing Red Lines under the EU AI Act: Restricting Real-time Remote Biometric Identification Systems for Law Enforcement Purposes The Rest of the West: Oregon and Washington Build on California Chatbot Law Red Lines under the EU AI Act: Understanding the prohibition of biometric categorization for certain sensitive characteristics 2026 Chatbot Legislation Tracker Red Lines under EU AI Act: Unpacking the prohibition of emotion recognition in the workplace and education institutions Privacy Protections Coming Sooner Rather Than Later to the Sooner State Navigating Autonomy and Privacy in Emerging AgeTech: Insights from the FPF Roundtable Incentives or Obligations? The U.S. Regulatory Approach to Voluntary AI Governance Standards Red Lines under the EU AI Act: Understanding the ban of the untargeted scraping of facial images and facial recognition databases
FPF Submits Comments to Inform California Children’s Social Media Protections Rulemaking Process
https://www.facebook.com/FutureofPrivacy · 2026-07-16 · via Future of Privacy Forum

Policy Counsel for U.S. Legislation

Co-authored by Jack Maketa, U.S. Legislation Intern

On June 30, the Future of Privacy Forum (FPF) submitted comments in response to the California Department of Justice’s (the Department’s) ongoing rulemaking process for the “Protecting Our Kids from Social Media Addiction Act” (the Act or SB 976). Signed into law in 2024, SB 976 bars operators of “addictive internet-based services” from providing an addictive feed to a user unless the operator reasonably determines the user is not a minor or, in the case of minors, obtains verifiable parental consent. The law also restricts notifications to minors during school and late-night hours; requires platforms to give parents tools to cap feed time, limit visibility of likes and other engagement metrics, and enable a “private mode”; and requires operators to annually disclose how many minor users they have and how many have parental consent on file. The law’s core provisions take effect on January 1, 2027. On May 15, the Department published a Notice of Proposed Rulemaking (NPRM) setting out draft regulations to guide business compliance with SB 976’s age assurance and parental consent requirements before the law takes effect.

FPF seeks to support balanced, informed public policy and equip regulators with the resources and tools needed to craft effective regulation. FPF submitted comments addressing three aspects of the NPRM. 

1. Age Assurance

FPF encouraged the Department to consider the full range of age assurance methods and technologies available and maintain a flexible approach. The proposed regulations already lay out a performance-based framework for age assurance with a listed sampling of compliant methods for operator consideration. The proposed rules also identify both criteria for compliant age determinations (i.e., reasonably effective at determining users under 18, consistently measurable, and quantifiably testable) and insufficient methods. FPF recommended the Department review our  infographic, Unpacking Age Assurance: Technologies and Tradeoffs, for more detail on how these methods work and their relative privacy and assurance tradeoffs. In particular, FPF flagged its 2026 updates to that resource, which—in line with the Department’s proposed approach—caution against relying on age declaration as a standalone solution, while noting that it can still be useful in a “waterfall” or layered approach. FPF suggests to the Department that inferential data can be a useful tool for affirming age in addition to disproving it.  

2. Verifiable Parental Consent

FPF recommended that the Department consider a VPC framework that does not rely on an approved-methods list, addresses the potential for consent fatigue, and provides further illustrative guidance on consent revocation methods. SB 976’s proposed VPC requirements establish a two-step process: requiring operators to obtain a minor’s own permission before seeking parental consent, and then tying acceptable VPC methods to those already approved under COPPA, which is effectively dependent upon an ‘approved methods’ list. While the rules do direct operators to offer at least one VPC option that doesn’t require an account, a purchase, or government-issued ID—ensuring parents have access to a COPPA-compliant method that doesn’t require disclosing sensitive information—the Department may still need to address other persistent frictions noted in FPF’s VPC research to promote process and compliance efficiency.

Moreover, although additional consent processes may aim to provide minor control over parental releases and data disclosures in VPC efforts, stacking multiple consent prompts can contribute to consent fatigue, where users grow less attentive to each successive request. That risk may be compounded where the two-step process runs alongside other required consents, such as the opt-in consent teens must separately provide for the sale or sharing of their data under the CCPA.

To address these potential challenges in the Department’s proposed rules, FPF offered three considerations for mitigating these frictions: 

  • moving toward a criteria-based or updateable VPC standard rather than relying solely on COPPA’s static list of approved methods—since 2013 the FTC has approved only two new methods, with no new submissions since 2015;
  • requiring clearer notice about why VPC data is collected, how it’s used, and how long it’s retained in order to ease consumer hesitancy; 
  • providing illustrative examples of compliant designs for the “as easy to use as” revocation standard, consistent with the Department’s approach elsewhere in the proposed rules.

3. Data Retention and Use Limitations

Finally, FPF recommended that the Department  align the data retention and use limitations rules with the statutory requirements to better protect user privacy. The proposed regulations would require that data collected for age assurance be minimized to what’s necessary to comply with that section specifically, used for no other purpose, securely held, and deleted immediately once its compliance purpose is served. FPF appreciates the underlying data protection goals but notes that this language is narrower than the statute it implements, which could create unintended compliance outcomes.

The statutory text, Cal. Health & Safety Code § 27001(b), permits data collected for age assurance to be used for compliance with that chapter or with another applicable law and requires deletion once its compliance purpose is served. The proposed regulation omits the “another applicable law” language, limiting permitted use to compliance with SB 976 alone. That gap could create ambiguity about which standard governs, and could also work against the Department’s own goals: operators relying on the narrower regulatory text might need to run duplicative age assurance processes to satisfy other legal obligations, or could be precluded from using age data gathered under SB 976 to meet minor privacy or safety obligations elsewhere in the law. 

FPF recommended that the Department either clarify its intent here or align the regulatory text with the broader statutory language.