skip to main content

Under the Colorado Privacy Act (CPA), individuals and businesses processing the personal data of minors have heightened duties related to data processing, targeted advertising, and profiling.[1] In practice, however, lawmakers determined that many applications and online services lack reliable information about whether a user is a minor, thereby limiting the effectiveness of the CPA’s protections for children. SB26-051 is intended to close that gap by establishing a detailed framework for obtaining users’ age information on public internet websites, software applications, and online services and platforms. This article summarizes SB26-051 and discusses next steps for operating system providers and developers.

SB26-051: Age Attestation on Computing Devices

SB26-051 is detailed and contains numerous definitions that may alter the applicability of the new law to a business or individual. For that reason, individuals or businesses that develop, license, or control the operating system of software on a device (“operating system providers”) or that write, create, maintain, or control software applications (“developers”) should familiarize themselves with the new law and read it in its entirety.

In short, SB26-051 establishes a detailed framework for obtaining age information on public internet websites, software applications, online services, and platforms. The new law provides that on and after July 1, 2028,[2] operating system providers must collect age information from account holders and to translate that information into certain age brackets. Operating system providers must then share the age bracket information in real time with developers to help them determine the age range of the user, including whether the user is a minor. This is called an “age signal.”

A developer that receives an age signal is deemed to have knowledge of the age range of the user to whom that age signal pertains across all platforms of the application and points of access of the application. However, if a developer has clear and convincing information that a user’s age is different than the age indicated by an age signal, the developer must use that information as the primary indicator of the user’s age range.

Application developers must then use the age information to comply with any applicable law, including the CPA, which limits data processing, targeted advertising, and profiling involving minors. Failure to comply with the new law may result in monetary penalties up to $2,500 for negligent violations and $7,500 for intentional violations for each impacted minor. Evidence that a good faith effort has been made to comply with the new law may limit an operating system provider’s liability.

What Next?

Operating system providers and developers should determine whether the new law applies to them and, if so, begin taking steps now to develop, create, manage, and implement the requirements of SB26-051. Failure to have an operational age attestation system in place before July 1, 2028, for new accounts and July 1, 2029, for accounts created prior to July 1, 2028, may result in significant monetary penalties.

Our Team

BHGR’s Privacy & Data Security Group advises clients on compliance with privacy laws in the U.S., EU, and U.K., including work related to privacy policies, data collection and processing practices, data processing contracts, and data breach responses and risks. Our attorneys also negotiate, draft, and review agreements for domestic and international data transfers. If you have questions about SB26-051 and how it affects you or your business, contact us today.

 

Sources

[1] With respect to an account that was set up before July 1, 2028, an operating system provider must provide an accessible interface that allows an account holder to indicate the user’s age information by July 1, 2029, for the purpose of providing an age signal to the developer. The same timing for requesting age information applies to an application last updated on or after July 1, 2027, which is downloaded to a device before July 1, 2028.

[2] See Colo. Rev. Stat. § 6-1-1301 et seq.

This article is informational only. The information provided on this website does not, and is not intended to, constitute legal advice; instead, all information, content, and materials available on this site are for general informational purposes only. Information on this website may not constitute the most up-to-date legal or other information. Readers of this website should contact their attorney to obtain advice with respect to any particular legal matter. No reader, user, or browser of this site should act or refrain from acting based on information on this site without first seeking legal advice from counsel in the relevant jurisdiction. Only your individual attorney can provide assurances that the information contained herein—and your interpretation of it—is applicable or appropriate to your particular situation. All liability with respect to actions taken or not taken based on the contents of this site are hereby expressly disclaimed. The content on this posting is provided “as is;” no representations are made that the content is error-free.