Washington – The Computer & Communications Industry Association is testifying today before the California Department of Justice on SB 976, the “Protecting Our Kids from Social Media Addiction Act,” urging state officials to adopt regulations that protect children online without undermining constitutional rights, user privacy, or innovation.
CCIA urges the Office of the Attorney General to adopt clear, objective definitions to ensure rules do not unintentionally capture services beyond those intended by lawmakers or penalize products that curate and personalize content. The association warns that age-verification mandates create significant privacy and security risks by encouraging users to share sensitive information, including government identification or biometric data, increasing the risk of identity theft and data breaches. These requirements also may disadvantage smaller companies, undermine competition, rely on imperfect age-estimation technologies, and incentivize the unnecessary collection and aggregation of user data.
CCIA raises concerns that key provisions of the proposed regulations lack sufficient clarity or scientific support. Terms such as “addiction” or “addictive” remain inadequately defined in the online context, while reporting requirements related to indicators of users’ ages could be susceptible to misuse. CCIA recommends that the OAG forego enforcement of time-based notification restrictions while litigation is pending, clarify operators’ obligations regarding location concealment, and revise data-use limitations to ensure consistency with existing California law.
The following statement can be attributed to Aodhan Downey, State Policy Manager, West Region at CCIA:
“CCIA believes children deserve greater security and privacy online. Overly restrictive regulations that mandate age verification create new privacy risks without meaningfully improving safety. We encourage California lawmakers to pursue evidence-based approaches that protect young people online. We can preserve constitutional rights, protect user privacy, and still provide businesses with clear and workable compliance standards.”