HomeIntelligenceBrief
BREACH BRIEF 🟡 Medium Advisory

California’s Digital Age Assurance Act Forces Major OS Vendors to Collect User Age Brackets Starting 2027

California’s Digital Age Assurance Act will require Windows, macOS, iOS and Android to gather a user’s age bracket at setup and expose a non‑identifying signal to apps. This creates a privacy control that must be documented for audit readiness across frameworks.

Verisq™ Intelligence · 📅 September 03, 2026 · 📰 malwarebytes.com
🟡
Severity
Medium
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
2 recommended
📰
Source
malwarebytes.com

California’s Digital Age Assurance Act (DAAA) Will Require OS Age‑Signal Collection Starting 2027

What Happened – California’s Digital Age Assurance Act, signed in Oct 2025, mandates that Windows, macOS, iOS and Android operating systems collect a user’s age bracket at first‑run and expose a non‑identifying age signal to apps. The requirement takes effect Jan 1 2027 (or July 1 2027 for pre‑2027 setups). An amendment (AB 1856) seeks to exempt open‑source OS projects that distribute under permissive licenses.

Why It Matters for Trust & Control Assurance

  • Demonstrates how new privacy‑by‑design regulations translate into a concrete data‑collection control that must be documented and continuously monitored.
  • Requires organizations to obtain, store, and audit age‑signal consent evidence – a control that satisfies multiple frameworks (e.g., NIST CSF 2.0 privacy governance).
  • Highlights the need for a privacy‑focused consent‑management capability that can surface age‑signal handling as auditable evidence.

Who Is Affected – Consumer‑technology vendors, OS manufacturers, app developers, and enterprises that ship or support Windows, macOS, iOS, Android devices to California residents.

Recommended Actions – Review your product roadmap for age‑signal implementation, map the new requirement to your privacy‑control objectives, and begin collecting audit‑ready evidence of consent and signal transmission. Source: Malwarebytes Labs

Technical Notes – The law does not prescribe a specific technical method; it only requires a non‑identifying age bracket (under 13, 13‑15, 16‑17, 18+) to be signaled to apps. No CVEs or exploits are involved. Source: same

📰 Original Source
https://www.malwarebytes.com/blog/privacy/2026/09/your-phone-or-computer-may-soon-ask-how-old-you-are

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →