Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

“How Old Are You, Anyway?” California’s New Law Makes Apps Ask… And Remember!

By Liisa Thomas & Kathryn Smith on November 17, 2025
Email this postTweet this postLike this postShare this post on LinkedIn
Universal Blog CA

California is getting serious about age checks online, and businesses should pay attention. Thanks to the passage of AB 1043, starting January 1, 2027, software makers and app stores will need to know the user’s age (or at least their age bracket) and signal it to apps every time a download or launch happens. For businesses that may be unclear whether COPPA or CCPA’s provisions for teenagers apply to their app, this law is aimed at clarifying that ambiguity.

How will it work? Under the new law, operating system providers and app stores will need to generate a digital age bracket signal—identifying whether the user is either (a) a minor (with age brackets of: under 13, 13 to 15, or 16 to 17) or (b) 18 and over. This signal must be transmitted securely, and in real-time, not only when the app is downloaded, but each time it is launched.

The law notes that apps that receive this signal will have “actual knowledge” of the users’ age. As such, this could impact how California examines COPPA compliance. (Which, as a reminder, applies to collection of information online from children including when the site/app has actual knowledge that the user is a child.) This law should also be viewed in conjunction with CCPA, and its provisions governing minors’ personal information.

While there is no private right of action, the law does provide for statutory penalties. Namely, up to $7,500 per intentional violation for each affected child.

Putting it into Practice: Beginning in two years, this law -if not challenged- will impact apps’ knowledge of their users’ age. This could change the calculus for companies on whether or not COPPA and CCPA’s children provisions apply to them. This may be a good time for companies to analyze the impact of these laws on their organizations, even if they have not done so in the past.

Photo of Liisa Thomas Liisa Thomas

Liisa Thomas, a partner based in the Chicago and London offices, is Leader of the firm’s Privacy and Cybersecurity Practice Group.

Read more about Liisa ThomasEmail
Photo of Kathryn Smith Kathryn Smith

Kathryn (“Katie”) Smith is an associate in the Intellectual Property Practice Group in the firm’s Chicago office and a member of the Privacy and Cybersecurity Team. She is certified by the International Association of Privacy Professionals (IAPP) for CIPP/US.

Read more about Kathryn SmithEmail
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Eye On Privacy
  • Organization:
    Sheppard, Mullin, Richter & Hampton LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo