
Want to participate in social media, even if you’re just an adult in New York state who wants to keep up with friends and family? Then hand over your digital papers, please! Privacy? The rules are “not a question of privacy”, apparently.
“The final rules for New York’s SAFE for Kids Act require users to verify their age (which means a form of digital ID) before an algorithm can curate their feed or a platform can send notifications after midnight.
“Attorney General Letitia James released the rules on July 28 alongside Governor Kathy Hochul. They take effect January 25, 2027.
“The law is written for under-18s but, as always has to be the case, the age-checking reaches everyone. To keep an algorithmic feed or overnight notifications, a user above 17 has to prove to the platform that they are an adult. Confirming who counts as an adult means collecting government IDs, face scans, phone numbers and email addresses from people who until now typed a birth date and moved on. James rejected the privacy objection to all this. The rules are ‘not a question of privacy,’ she said.
“Platforms can accept a government-issued ID upload and the rules force them to offer at least one other option.
“James’s office also lists a selfie image or video, or an email address or phone number cross-checked against other data that is held on a person. Any of those hands a company something it can tie to a real identity.
“It’s clear that the law isn’t shying away from allowing platforms to collect sensitive user data, including biometrics, and allowing cross-referencing against other data.”
But it’s just like flashing a driver’s license at a liquor store, right?
Nope.
“An ‘acceptable’ check has to meet an accuracy standard. It can wrongly pass a minor off as an adult only so often and the tolerance widens as children get older and harder to tell from adults.
“The rate has to stay at or below 0.1 percent for children up to age 7, 1 percent for ages 8 to 13, 2 percent for 14 and 15, 8 percent at 16, and 15 percent at 17.
“Those ceilings leave out users who refuse to hand over data or whose result comes back inconclusive. The check must also block at least 98 percent of attempts to get around it. “Companies run annual testing, which means a lot of data collection, and keep the results for at least 10 years.
“Information collected to check age or obtain parental consent cannot be used for anything else, and platforms must delete or “de-identify” it immediately after use and collect only the minimum needed.
“We all know the de-identifying data does very little, especially in the AI era where people can be profiled in unlimited new ways and people’s identities can be detected from their usage patterns. And we also know that platforms say they delete user data after use and then don’t.”
All your data are belong to New York, ‘twould seem.





