SlideShare a Scribd company logo
1 of 17
Download to read offline
1
© 2023 TrustArc Inc. Proprietary and Confidential Information.
The California Age-Appropriate Design Code Act:
Navigating the New Requirements for Child Privacy
2
Speakers
Joanne B. Furtsch
Director
Privacy Intelligence, Development,
TrustArc
Cody Venzke
Senior Policy Counsel
Surveillance, Privacy, Technology,
ACLU
Hailun Ying
Senior Lead Counsel, Privacy
Roblox
3
Agenda
▪ Review of current trends and why this matters
▪ An overview of CA ADCA bill, its key provisions, and implementation
timelines
▪ A comparison between CA ADCA and the UK’s AADC
▪ A tour of what is happening at the US State and Federal level
▪ What steps you need to take to get into compliance with CA ADCA
▪ Q&A throughout
4
Legal Disclaimer
The information provided during this webinar does not,
and is not intended to, constitute legal advice.
Instead, all information, content, and materials presented
during this webinar are for general informational purposes only.
Anything discussed in the webinar is the speaker's
opinion and does not represent that of their employer.
5
Why does this matter?
● Increasing regulatory scrutiny
● More children’s privacy regulations at the state level
● Expanded scope of laws protecting minors online
● New protections cover minors age 13-17.
6
Current Trends
● Children’s information is seen as particularly sensitive
● Increasing concerns to protect children and teens
● Greater regulatory scrutiny of large online platforms
● Limit monetization of information collected from
children
● Extended reach of child protection requirements
● Increased legislative activity at the US state level
7
What Happens Next?
Sept 2, 2020
UK AADC in force
Sept 2, 2021
Companies expected
to comply with UK
AADC
May 17, 2023
Montana governor signs law
banning Tik Tok from being offered
in app stores within the state
Sept 1, 2023
Arkansas Social
Media Safety Act
goes into effect
Jan 1, 2024
Montana Tik Tok ban
goes into effect
March 1, 2024
Utah Social Media
Regulation Act goes into
effect (3 laws now)
July 1, 2024
CA ADCA goes
into effect
8
What is the California Age-Appropriate Design Code Act
(CA ADCA)?
● Modeled after the UK Age Appropriate Design Code
● Goes into effect July 2024
● Applies to businesses that provide online products, services, or features that likely to be accessed by
children (defined as any individual under age 18).
● Key provisions
○ High level privacy by default (with exceptions)
○ Clear and concise privacy statements, terms of service, and community standards
○ Estimate the age of child users with a reasonable level of certainty
○ Provide signals if monitoring usage
○ Provide prominent, accessible, and responsive tools to help children (or parents/guardian) to
exercise privacy rights
○ Conduct impact Assessments (DPIA’s)
Quick Overview
9
How Did We Get To the CA ADCA?
Started with the UK
Quick Overview of UK Age Appropriate Design Code (AADC)
● Applies to relevant information society services which are likely to be accessed by
children.
● Child is defined as an individual under age 18
● In force since September 2, 2020 requiring businesses to be in compliance by September
2, 2021
● Includes 15 standards for safeguarding children’s privacy
● Designed to work with UK GDPR. If not in compliance with the Code, it will be difficult to
demonstrate compliance with UK GDPR
10
Differences between the CA ADCA and UK AADC
CA ADCA UK AADC
Regulatory Framework
CA ADCA is a standalone law that is
independently enforced.
UK AADC works together with GDPR.
Best Interests of the
Child/Best Interests of
Children
Used in exemptions to default privacy
settings and legislative findings. UN
convention not recognized in the US
making the CA ADCA reference unclear
Based on the UN Convention on the
Rights of the Child
Default Privacy Settings
CA ADCA has an exception for when the
highest level of privacy is the default
setting
UK AADC does not include an
exception
Conducting DPIAs
A timeline for providing DPIAs upon
request is codified for CA ADCA.
The UK AADC only requires DPIAs be
available upon request.
Age Assurance
CA ADCA does include what risk to
consider when balancing data
minimization against age assurance
Take a risk-based approach to
recognize the age of individuals to
apply the UK AADC or apply the code
to all individuals
11
What is Happening in Other States
● Privacy Bills
○ Enacted Legislation — CA, IA, TN, TX
○ Bills Introduced — KY
● Age Appropriate Design Codes
○ Enacted — CA, FL
○ Introduced — IL, MA, MN, NM, NJ, NV, NY, OR, TX
● Social Media Age Minimums and Parental
Consent Requirements
○ Enacted — AR, UT
○ Introduced — CT, KS, LA, MN, NC, NJ, SC, TX
● Addictive Design Bills
○ Enacted — UT
○ Introduced — CA, TX
12
COPPA 2.0
● Reintroduced COPPA 2.0 bill in the US Senate early May 2023
● Extends COPPA protections to teens
● Key Provisions
○ Require consent of teens aged 13-16 prior to collecting their
personal information
○ Ban targeted advertising to children and minors
○ Expand the scope of online services covered under the law by
replacing the “actual knowledge” standard with the “reasonably
likely to be used” standard (similar to CA ADCA and UK AADC)
○ Create an Eraser button (similar to GDPR RTBF) for all users to
eliminate personal information submitted by the user about
children and minors when technologically feasible
○ Establish a Digital Marketing Bill of Rights for teens to limit the
collection of personal information
○ Establish the Youth Marketing and Privacy Division at the FTC
13
Kids Online Safety Act
● Introduced in the US Senate in early May 2023
● Creates online tools for minors and parents and imposes
obligations on “covered platforms” that are “likely to be used” by
minors
● “Covered platforms” are social media, video games, educational
games, messaging applications, video streaming services, and
“online platforms”
● Key Provisions
○ Imposes a duty of care of “covered platforms” to mitigate certain harms
like addiction, mental health disorders, and anxiety
○ Provide minors options to protect their information, disable addictive
features, and opt-out of algorithmic recommendations
○ Provides parents with tools to view or change minors’ account settings
○ Strongest settings to be enabled by default
○ Requires social media platforms to conduct annual independent audits to
assess risks to minors, compliance with the Act, and how they are
mitigating those risks
○ Provides academia and public interest organizations with access to social
media platform data sets to research harms to the safety and well-being
of minors
14
Actions to take now to comply with CA ADCA
Actions to take now
● Assess whether children will be visiting your online services
● Estimate the age of child users accessing your online services
○ Understand how well you know the users of your online
services.
○ Use a risk-based approach
● Leverage UK ICO’s guidance on how to comply with the UK
AADC as a starting point
● Determine which DPIAs need to be completed before July 2024
○ Assess features for dark patterns
○ Use of real-time geo-location
○ Automated processing
15
How TrustArc Can Help
16
16
Q&A
17
17
Thank You!
See http://www.trustarc.com/insightseries for the 2023
Privacy Insight Series and past webinar recordings.
If you would like to learn more about how TrustArc can support you with privacy and
data security compliance, please reach out to sales@trustarc.com for a free demo.

More Related Content

Similar to The California Age Appropriate Design Code Act Navigating the New Requirements for Child Privacy

The Top Privacy Resolutions to make 2022 Your Most Successful Year
The Top Privacy Resolutions to make 2022 Your Most Successful YearThe Top Privacy Resolutions to make 2022 Your Most Successful Year
The Top Privacy Resolutions to make 2022 Your Most Successful YearTrustArc
 
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...Burton Lee
 
Cyber security privacy-and-blockchain-perspective-14 nov2018-v01-public
Cyber security privacy-and-blockchain-perspective-14 nov2018-v01-publicCyber security privacy-and-blockchain-perspective-14 nov2018-v01-public
Cyber security privacy-and-blockchain-perspective-14 nov2018-v01-publicSecunoid Systems Inc
 
2019-06-11 What New US State Laws Mean For Your Business
2019-06-11 What New US State Laws  Mean For Your Business2019-06-11 What New US State Laws  Mean For Your Business
2019-06-11 What New US State Laws Mean For Your BusinessTrustArc
 
U.S. Quarterly Privacy Update
U.S. Quarterly Privacy UpdateU.S. Quarterly Privacy Update
U.S. Quarterly Privacy UpdateTrustArc
 
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...Financial Poise
 
HIPAA, Privacy, Security, and Good Business
HIPAA, Privacy, Security, and Good BusinessHIPAA, Privacy, Security, and Good Business
HIPAA, Privacy, Security, and Good BusinessStephen Cobb
 
Report_PrivacyAmongChildren.pdf
Report_PrivacyAmongChildren.pdfReport_PrivacyAmongChildren.pdf
Report_PrivacyAmongChildren.pdfDaviesParker
 
How your nonprofit can avoid data breaches and ensure privacy
How your nonprofit can avoid data breaches and ensure privacyHow your nonprofit can avoid data breaches and ensure privacy
How your nonprofit can avoid data breaches and ensure privacyTechSoup Canada
 
Post US Election Privacy Updates & Implications
Post US Election Privacy Updates & ImplicationsPost US Election Privacy Updates & Implications
Post US Election Privacy Updates & ImplicationsTrustArc
 
Emerging Trends in Information Security and Privacy
Emerging Trends in Information Security and PrivacyEmerging Trends in Information Security and Privacy
Emerging Trends in Information Security and Privacylgcdcpas
 
CCPA Compliance from Ground Zero: Start to Finish with TrustArc Solutions
CCPA Compliance from Ground Zero: Start to Finish with TrustArc SolutionsCCPA Compliance from Ground Zero: Start to Finish with TrustArc Solutions
CCPA Compliance from Ground Zero: Start to Finish with TrustArc SolutionsTrustArc
 
A Global Marketer's Guide to Privacy
A Global Marketer's Guide to PrivacyA Global Marketer's Guide to Privacy
A Global Marketer's Guide to PrivacyFLUZO
 
Legal Issues For Online Communities - David Deakin
Legal Issues For Online Communities - David DeakinLegal Issues For Online Communities - David Deakin
Legal Issues For Online Communities - David DeakinFeverBee Limited
 
2019 06-19 convince customerspartnersboard gdpr-compliant
2019 06-19 convince customerspartnersboard gdpr-compliant2019 06-19 convince customerspartnersboard gdpr-compliant
2019 06-19 convince customerspartnersboard gdpr-compliantTrustArc
 
[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...
[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...
[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...Kenneth Riley
 
Pli workplace privacy in the year 2013 2013-6-13
Pli workplace privacy in the year 2013   2013-6-13Pli workplace privacy in the year 2013   2013-6-13
Pli workplace privacy in the year 2013 2013-6-13mkeane
 
Privacy issues in data analytics
Privacy issues in data analyticsPrivacy issues in data analytics
Privacy issues in data analyticsshekharkanodia
 

Similar to The California Age Appropriate Design Code Act Navigating the New Requirements for Child Privacy (20)

Kantara Workshop at CIS
Kantara Workshop at CISKantara Workshop at CIS
Kantara Workshop at CIS
 
The Top Privacy Resolutions to make 2022 Your Most Successful Year
The Top Privacy Resolutions to make 2022 Your Most Successful YearThe Top Privacy Resolutions to make 2022 Your Most Successful Year
The Top Privacy Resolutions to make 2022 Your Most Successful Year
 
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
Polina Zvyagina - Airbnb - Privacy & GDPR Compliance - Stanford Engineering -...
 
Cyber security privacy-and-blockchain-perspective-14 nov2018-v01-public
Cyber security privacy-and-blockchain-perspective-14 nov2018-v01-publicCyber security privacy-and-blockchain-perspective-14 nov2018-v01-public
Cyber security privacy-and-blockchain-perspective-14 nov2018-v01-public
 
2019-06-11 What New US State Laws Mean For Your Business
2019-06-11 What New US State Laws  Mean For Your Business2019-06-11 What New US State Laws  Mean For Your Business
2019-06-11 What New US State Laws Mean For Your Business
 
U.S. Quarterly Privacy Update
U.S. Quarterly Privacy UpdateU.S. Quarterly Privacy Update
U.S. Quarterly Privacy Update
 
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
 
HIPAA, Privacy, Security, and Good Business
HIPAA, Privacy, Security, and Good BusinessHIPAA, Privacy, Security, and Good Business
HIPAA, Privacy, Security, and Good Business
 
Report_PrivacyAmongChildren.pdf
Report_PrivacyAmongChildren.pdfReport_PrivacyAmongChildren.pdf
Report_PrivacyAmongChildren.pdf
 
How your nonprofit can avoid data breaches and ensure privacy
How your nonprofit can avoid data breaches and ensure privacyHow your nonprofit can avoid data breaches and ensure privacy
How your nonprofit can avoid data breaches and ensure privacy
 
Post US Election Privacy Updates & Implications
Post US Election Privacy Updates & ImplicationsPost US Election Privacy Updates & Implications
Post US Election Privacy Updates & Implications
 
Emerging Trends in Information Security and Privacy
Emerging Trends in Information Security and PrivacyEmerging Trends in Information Security and Privacy
Emerging Trends in Information Security and Privacy
 
CCPA Compliance from Ground Zero: Start to Finish with TrustArc Solutions
CCPA Compliance from Ground Zero: Start to Finish with TrustArc SolutionsCCPA Compliance from Ground Zero: Start to Finish with TrustArc Solutions
CCPA Compliance from Ground Zero: Start to Finish with TrustArc Solutions
 
A Global Marketer's Guide to Privacy
A Global Marketer's Guide to PrivacyA Global Marketer's Guide to Privacy
A Global Marketer's Guide to Privacy
 
Legal Issues For Online Communities - David Deakin
Legal Issues For Online Communities - David DeakinLegal Issues For Online Communities - David Deakin
Legal Issues For Online Communities - David Deakin
 
2019 06-19 convince customerspartnersboard gdpr-compliant
2019 06-19 convince customerspartnersboard gdpr-compliant2019 06-19 convince customerspartnersboard gdpr-compliant
2019 06-19 convince customerspartnersboard gdpr-compliant
 
The DMA conference 2012
The DMA conference 2012The DMA conference 2012
The DMA conference 2012
 
[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...
[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...
[Title Redacted for Privacy Purposes]: How Internal Audit Can Help Drive Priv...
 
Pli workplace privacy in the year 2013 2013-6-13
Pli workplace privacy in the year 2013   2013-6-13Pli workplace privacy in the year 2013   2013-6-13
Pli workplace privacy in the year 2013 2013-6-13
 
Privacy issues in data analytics
Privacy issues in data analyticsPrivacy issues in data analytics
Privacy issues in data analytics
 

More from TrustArc

TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc
 
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie WorldTrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie WorldTrustArc
 
TrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc
 
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc
 
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data SecurityTrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data SecurityTrustArc
 
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...TrustArc
 
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...TrustArc
 
Nymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesNymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesTrustArc
 
CBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy ComplianceCBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy ComplianceTrustArc
 
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdfEverything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdfTrustArc
 
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...TrustArc
 
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and RecommendationsPrivacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and RecommendationsTrustArc
 
Building Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy CertificationsBuilding Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy CertificationsTrustArc
 
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdfTrustArc
 
Artificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI GovernanceArtificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI GovernanceTrustArc
 
How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023TrustArc
 
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act:  Using Consumer Data and Maintaining TrustThe Ultimate Balancing Act:  Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act: Using Consumer Data and Maintaining TrustTrustArc
 
The Cost of Privacy Teams: What Your Business Needs To Know
The Cost of Privacy Teams: What Your Business Needs To KnowThe Cost of Privacy Teams: What Your Business Needs To Know
The Cost of Privacy Teams: What Your Business Needs To KnowTrustArc
 
TrustArc Webinar_ How Data Privacy Demands Impact Your Marketing Team.pdf
TrustArc Webinar_ How Data Privacy Demands Impact Your Marketing Team.pdfTrustArc Webinar_ How Data Privacy Demands Impact Your Marketing Team.pdf
TrustArc Webinar_ How Data Privacy Demands Impact Your Marketing Team.pdfTrustArc
 
TrustArc Webinar - Rise of Information Technology: How Does it Impact Privacy?
TrustArc Webinar - Rise of Information Technology: How Does it Impact Privacy?TrustArc Webinar - Rise of Information Technology: How Does it Impact Privacy?
TrustArc Webinar - Rise of Information Technology: How Does it Impact Privacy?TrustArc
 

More from TrustArc (20)

TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
 
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie WorldTrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
 
TrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI Innovations
 
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
 
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data SecurityTrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
 
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
 
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
 
Nymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesNymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 States
 
CBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy ComplianceCBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy Compliance
 
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdfEverything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
 
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
 
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and RecommendationsPrivacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
 
Building Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy CertificationsBuilding Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy Certifications
 
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
 
Artificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI GovernanceArtificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI Governance
 
How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023
 
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act:  Using Consumer Data and Maintaining TrustThe Ultimate Balancing Act:  Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
 
The Cost of Privacy Teams: What Your Business Needs To Know
The Cost of Privacy Teams: What Your Business Needs To KnowThe Cost of Privacy Teams: What Your Business Needs To Know
The Cost of Privacy Teams: What Your Business Needs To Know
 
TrustArc Webinar_ How Data Privacy Demands Impact Your Marketing Team.pdf
TrustArc Webinar_ How Data Privacy Demands Impact Your Marketing Team.pdfTrustArc Webinar_ How Data Privacy Demands Impact Your Marketing Team.pdf
TrustArc Webinar_ How Data Privacy Demands Impact Your Marketing Team.pdf
 
TrustArc Webinar - Rise of Information Technology: How Does it Impact Privacy?
TrustArc Webinar - Rise of Information Technology: How Does it Impact Privacy?TrustArc Webinar - Rise of Information Technology: How Does it Impact Privacy?
TrustArc Webinar - Rise of Information Technology: How Does it Impact Privacy?
 

Recently uploaded

Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationSafe Software
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clashcharlottematthew16
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyAlfredo García Lavilla
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 3652toLead Limited
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Patryk Bandurski
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxhariprasad279825
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubKalema Edgar
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitecturePixlogix Infotech
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsMark Billinghurst
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piececharlottematthew16
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticscarlostorres15106
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024The Digital Insurer
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):comworks
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 

Recently uploaded (20)

Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clash
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easy
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptx
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding Club
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC Architecture
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR Systems
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piece
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
Hot Sexy call girls in Panjabi Bagh 🔝 9953056974 🔝 Delhi escort Service
Hot Sexy call girls in Panjabi Bagh 🔝 9953056974 🔝 Delhi escort ServiceHot Sexy call girls in Panjabi Bagh 🔝 9953056974 🔝 Delhi escort Service
Hot Sexy call girls in Panjabi Bagh 🔝 9953056974 🔝 Delhi escort Service
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 

The California Age Appropriate Design Code Act Navigating the New Requirements for Child Privacy

  • 1. 1 © 2023 TrustArc Inc. Proprietary and Confidential Information. The California Age-Appropriate Design Code Act: Navigating the New Requirements for Child Privacy
  • 2. 2 Speakers Joanne B. Furtsch Director Privacy Intelligence, Development, TrustArc Cody Venzke Senior Policy Counsel Surveillance, Privacy, Technology, ACLU Hailun Ying Senior Lead Counsel, Privacy Roblox
  • 3. 3 Agenda ▪ Review of current trends and why this matters ▪ An overview of CA ADCA bill, its key provisions, and implementation timelines ▪ A comparison between CA ADCA and the UK’s AADC ▪ A tour of what is happening at the US State and Federal level ▪ What steps you need to take to get into compliance with CA ADCA ▪ Q&A throughout
  • 4. 4 Legal Disclaimer The information provided during this webinar does not, and is not intended to, constitute legal advice. Instead, all information, content, and materials presented during this webinar are for general informational purposes only. Anything discussed in the webinar is the speaker's opinion and does not represent that of their employer.
  • 5. 5 Why does this matter? ● Increasing regulatory scrutiny ● More children’s privacy regulations at the state level ● Expanded scope of laws protecting minors online ● New protections cover minors age 13-17.
  • 6. 6 Current Trends ● Children’s information is seen as particularly sensitive ● Increasing concerns to protect children and teens ● Greater regulatory scrutiny of large online platforms ● Limit monetization of information collected from children ● Extended reach of child protection requirements ● Increased legislative activity at the US state level
  • 7. 7 What Happens Next? Sept 2, 2020 UK AADC in force Sept 2, 2021 Companies expected to comply with UK AADC May 17, 2023 Montana governor signs law banning Tik Tok from being offered in app stores within the state Sept 1, 2023 Arkansas Social Media Safety Act goes into effect Jan 1, 2024 Montana Tik Tok ban goes into effect March 1, 2024 Utah Social Media Regulation Act goes into effect (3 laws now) July 1, 2024 CA ADCA goes into effect
  • 8. 8 What is the California Age-Appropriate Design Code Act (CA ADCA)? ● Modeled after the UK Age Appropriate Design Code ● Goes into effect July 2024 ● Applies to businesses that provide online products, services, or features that likely to be accessed by children (defined as any individual under age 18). ● Key provisions ○ High level privacy by default (with exceptions) ○ Clear and concise privacy statements, terms of service, and community standards ○ Estimate the age of child users with a reasonable level of certainty ○ Provide signals if monitoring usage ○ Provide prominent, accessible, and responsive tools to help children (or parents/guardian) to exercise privacy rights ○ Conduct impact Assessments (DPIA’s) Quick Overview
  • 9. 9 How Did We Get To the CA ADCA? Started with the UK Quick Overview of UK Age Appropriate Design Code (AADC) ● Applies to relevant information society services which are likely to be accessed by children. ● Child is defined as an individual under age 18 ● In force since September 2, 2020 requiring businesses to be in compliance by September 2, 2021 ● Includes 15 standards for safeguarding children’s privacy ● Designed to work with UK GDPR. If not in compliance with the Code, it will be difficult to demonstrate compliance with UK GDPR
  • 10. 10 Differences between the CA ADCA and UK AADC CA ADCA UK AADC Regulatory Framework CA ADCA is a standalone law that is independently enforced. UK AADC works together with GDPR. Best Interests of the Child/Best Interests of Children Used in exemptions to default privacy settings and legislative findings. UN convention not recognized in the US making the CA ADCA reference unclear Based on the UN Convention on the Rights of the Child Default Privacy Settings CA ADCA has an exception for when the highest level of privacy is the default setting UK AADC does not include an exception Conducting DPIAs A timeline for providing DPIAs upon request is codified for CA ADCA. The UK AADC only requires DPIAs be available upon request. Age Assurance CA ADCA does include what risk to consider when balancing data minimization against age assurance Take a risk-based approach to recognize the age of individuals to apply the UK AADC or apply the code to all individuals
  • 11. 11 What is Happening in Other States ● Privacy Bills ○ Enacted Legislation — CA, IA, TN, TX ○ Bills Introduced — KY ● Age Appropriate Design Codes ○ Enacted — CA, FL ○ Introduced — IL, MA, MN, NM, NJ, NV, NY, OR, TX ● Social Media Age Minimums and Parental Consent Requirements ○ Enacted — AR, UT ○ Introduced — CT, KS, LA, MN, NC, NJ, SC, TX ● Addictive Design Bills ○ Enacted — UT ○ Introduced — CA, TX
  • 12. 12 COPPA 2.0 ● Reintroduced COPPA 2.0 bill in the US Senate early May 2023 ● Extends COPPA protections to teens ● Key Provisions ○ Require consent of teens aged 13-16 prior to collecting their personal information ○ Ban targeted advertising to children and minors ○ Expand the scope of online services covered under the law by replacing the “actual knowledge” standard with the “reasonably likely to be used” standard (similar to CA ADCA and UK AADC) ○ Create an Eraser button (similar to GDPR RTBF) for all users to eliminate personal information submitted by the user about children and minors when technologically feasible ○ Establish a Digital Marketing Bill of Rights for teens to limit the collection of personal information ○ Establish the Youth Marketing and Privacy Division at the FTC
  • 13. 13 Kids Online Safety Act ● Introduced in the US Senate in early May 2023 ● Creates online tools for minors and parents and imposes obligations on “covered platforms” that are “likely to be used” by minors ● “Covered platforms” are social media, video games, educational games, messaging applications, video streaming services, and “online platforms” ● Key Provisions ○ Imposes a duty of care of “covered platforms” to mitigate certain harms like addiction, mental health disorders, and anxiety ○ Provide minors options to protect their information, disable addictive features, and opt-out of algorithmic recommendations ○ Provides parents with tools to view or change minors’ account settings ○ Strongest settings to be enabled by default ○ Requires social media platforms to conduct annual independent audits to assess risks to minors, compliance with the Act, and how they are mitigating those risks ○ Provides academia and public interest organizations with access to social media platform data sets to research harms to the safety and well-being of minors
  • 14. 14 Actions to take now to comply with CA ADCA Actions to take now ● Assess whether children will be visiting your online services ● Estimate the age of child users accessing your online services ○ Understand how well you know the users of your online services. ○ Use a risk-based approach ● Leverage UK ICO’s guidance on how to comply with the UK AADC as a starting point ● Determine which DPIAs need to be completed before July 2024 ○ Assess features for dark patterns ○ Use of real-time geo-location ○ Automated processing
  • 17. 17 17 Thank You! See http://www.trustarc.com/insightseries for the 2023 Privacy Insight Series and past webinar recordings. If you would like to learn more about how TrustArc can support you with privacy and data security compliance, please reach out to sales@trustarc.com for a free demo.