Businesses have had ample warnings lately about the repercussions of collecting personal data from children and minors, but are they heeding those warnings?
Or is it business as usual, with no recognition that new policies may need to be put in place and that the less data collected, the better, regardless of the person’s age?
Both TikTok and Meta learned the hard way recently that gathering and storing children’s data can come with a hefty price tag.
TikTok reached a $400 million settlement with the U.S. Department of Justice, finally putting to rest a lawsuit from two years ago that alleged the company violated children’s privacy laws. Meanwhile, Meta agreed to a $17 billion settlement over allegations that Instagram and Facebook collected data from children under 13 without parental consent. Meta’s social media sites had gone a step further, designing addictive features on their platforms to increase the children’s screen time.
With those significant cases in the news, this is an excellent time for other businesses to reconsider policies in which they are collecting children and minors’ data, a process fraught with potential problems. A breach exposes that information to cybercriminals, both domestic and foreign state actors, leaving businesses to explain to parents how they came to possess the data to begin with. A lawsuit could end in a multimillion-dollar settlement like the ones TikTok and Meta faced.
As they review their policies, a good first step for businesses is to consider why they are collecting the information to begin with, creating liability risks for themselves and identity-theft risks for others.
Age Verification Creates Its Own Problems
Those concerns, and the potential liability, are multiplied when children and minors are involved.
One reason is that state laws often restrict what’s being gathered, so companies that aren’t careful can quickly run afoul of those laws. More than two dozen states require commercial websites to verify a user’s age when a certain percentage of the site’s content is considered harmful to minors. That percentage varies from state to state.
Although those laws seek to protect minors, which is a laudable goal, they can be the start of trouble for companies because age verification has its own pitfalls. In those cases, the government is requiring the company to gather sensitive information from users: their age. Sometimes this is simply by asking people to declare how old they are, and of course, someone could lie, but in other cases, the website may ask for an official document. Either approach has the potential to be a privacy risk.
Businesses, of course, want all types of information from users because it helps them know how to micro-target to those customers. They gather data about gender and about types of items purchased. They file away data about the person’s location and their internet searches. In other words, while building these customer profiles, they also are storing a trove of information that can leave cyber criminals salivating.
And, in some cases, businesses will leave age verification to someone else, contracting with a third party to handle that work. In those cases, companies would be wise to ask questions about how the information is gathered and what security measures are in place to protect the data.
Taking Action Now
What’s really needed, of course, is a better way to verify age without putting someone’s sensitive personal information at risk. A good solution is a verified digital trust token that could be given to people who have a government-issued identity document. This digital credential could protect the specifics of a person’s private information while confirming to online platforms that they are over the age requirements for their platform. That way, businesses wouldn’t need to guess ages using unreliable biometrics or collect and store personal data.
In the meantime, though, businesses need to review their data-gathering procedures, stop collecting information that’s not absolutely necessary, and shore up defenses against cyberattacks for what is collected.
They also need to do a better job of protecting children’s and minors’ data before a breach or a lawsuit forces their hand. Children and their parents have enough worries. They shouldn’t have to fret that every time the child goes online, their private data is being put at risk.
_____
About Raj Ananthanpillai
Raj Ananthanpillai is the founder and CEO of Trua, the first digital identity company to provide continuous Trust with its Trust credential for Life and Trust Token Number. He is also a serial entrepreneur, investor, inventor, and leading authority on digital trust, identity, and privacy. Ananthanpillai has built and grown several impactful tech companies, and his ventures have provided mission-critical solutions for federal agencies, including key contributions to various national security programs such as TSA PreCheck, Fortune 500 companies, and global organizations. His latest book, recently published by Forbes Books, is The Trust Crisis: How Big Tech Stole Your Identity — and the New Model to Take it Back
Join our LinkedIn group Information Security Community!
