California’s Digital Age Assurance Act (DAAA) Will Require OS Age‑Signal Collection Starting 2027
What Happened – California’s Digital Age Assurance Act, signed in Oct 2025, mandates that Windows, macOS, iOS and Android operating systems collect a user’s age bracket at first‑run and expose a non‑identifying age signal to apps. The requirement takes effect Jan 1 2027 (or July 1 2027 for pre‑2027 setups). An amendment (AB 1856) seeks to exempt open‑source OS projects that distribute under permissive licenses.
Why It Matters for Trust & Control Assurance
- Demonstrates how new privacy‑by‑design regulations translate into a concrete data‑collection control that must be documented and continuously monitored.
- Requires organizations to obtain, store, and audit age‑signal consent evidence – a control that satisfies multiple frameworks (e.g., NIST CSF 2.0 privacy governance).
- Highlights the need for a privacy‑focused consent‑management capability that can surface age‑signal handling as auditable evidence.
Who Is Affected – Consumer‑technology vendors, OS manufacturers, app developers, and enterprises that ship or support Windows, macOS, iOS, Android devices to California residents.
Recommended Actions – Review your product roadmap for age‑signal implementation, map the new requirement to your privacy‑control objectives, and begin collecting audit‑ready evidence of consent and signal transmission. Source: Malwarebytes Labs
Technical Notes – The law does not prescribe a specific technical method; it only requires a non‑identifying age bracket (under 13, 13‑15, 16‑17, 18+) to be signaled to apps. No CVEs or exploits are involved. Source: same