SAMPLE TERMS OF SERVICE – USER LIMIATION CLAUSES I

The second section in the Sample Terms of Use is a set of terms limiting who can use the website … a series of  “User Limitation Clauses”.  This variety of clauses exists to protect the site operators by excluding classes of users who create additional difficulties: those that can’t make valid agreements, those protected by difficult to comply with regulations, those  whose presence may be disruptive or those who create liability for the site.  The first and most common class of excluded users is younger children, and so our first limitation clause is the following “Age Limitation Clause”

Age Limitation Clause
“To use the Website you must be at least thirteen (13) years old. If you are over 13 but not legally an adult in your country, its laws may still require the permission of your parent or guardian for you to access this Website. When using this website you, and your parent or guardian if applicable, are responsible for complying with the laws of your country or state and these Terms.”

This clause makes it clear that the website is for adult users and is an important step in complying with a variety of regulatory regimes. The regulations for websites with children as a primary audience are far stricter and difficult to comply with then those for a general audience, and are worth avoiding if you can. The European Union’s GDPR (in Article 8, sometimes called “GDPR-K”) and the United State’s COPPA are the primary regulations in this area, and both of these laws require websites to offer greater protection to minors, especially younger children. One cannot collect or process information from web users under thirteen years old and sometimes older children without obtaining parental consent. Similarly, the EU’s new DSA prohibits targeted advertising directed at minors. While the problems of data collection and targeted advertising may seem distant concerns for the sort of small scale and non-profit or community based social-media and forum sites Terms of Service have in mind, it’s still important to include these minimal safeguards. One can’t always know what one’s platform provider, federation, or partners, are doing and the protections for children are some of the ones regulators and the public take most seriously.

Compounding regulatory concerns, under almost every legal system children, especially younger children, cannot provide legal consent to enter contracts, though their guardian can often do so on their behalf.  GDPR-K and COPPA mirror this common law requirement by insisting that web services directed at or provided to children under age thirteen obtain verifiable parental consent to use them. COPPA is limited to sites that are targeted at children, a sometimes vague definition, but the theoretically GDPR applies to all websites, and allows states to determine if parental consent is required for users aged thirteen to sixteen (16 is a common choice, such as in Germany, the Netherlands, Poland, Hungry, and Ireland). Sites need parental consent, with limited exceptions, to collect or process children’s data, which is nearly impossible for a site to avoid. Both of these laws also demand that the site make some effort to verify the age of its users.

Luckily, regulators haven’t regularly used either COPPA or the GDPR-K to fine sites that aren’t specifically targeted at children or engaging in especially exploitative privacy practices. One suspects that this forbearance is the result of the vast scope of these regulations, which make general enforcement impossible without enormous resources. Instead, regulators have chosen to examine the most serious violations and use them to set examples rather than enforcing these laws in an unpredictable but general fashion. Smaller websites, unless they are actively seeking an audience of children, are unlikely to be targeted for minor or unintentional COPPA or GDPR-K violations.

The difficulty of general enforcement is not something most are comfortable depending on to avoid risk, and both regulations appear to almost everything online, requiring sites to obtain verifiable parental consent from minor users, and obtaining what most would think of as verifiable parental consent is an onerous burden. Yet the majority of sites don’t take any active measures to comply with these regulations … and they don’t need to. Unless a site is seeking an audience of children, which can be a difficult question under COPPA, terms of service that give notice that the site doesn’t allow younger users and insists that older children gain parental approval have been sufficient under current law. COPPA may require verified consent (such as a parental signature), but it only applies to sites targeted at children. The GDPR applies more broadly, but it defines verifiable as a “reasonable effort to verify” consent by site operators. So far warnings like this Age Limitation Clause, which obtain the self-declaration of the user that they are over 13 or have obtained parental consent, have been enough to avoid regulatory penalties for most sites. Self-verification is of course obtained by clicking through the Terms of Service generally (as described in our discussion of the Acknowledgement Clause).

Verification and Collection Limitation Clause
Self-declaration may not be enough to verify user age for very much longer.  Some countries such as the United Kingdom and some US states have started considering more identity verification laws for general web use, ostensibly to protect children, but usually also promoted by authoritarian interests. While these sort of requirements are currently, as of September 2024, limited to online financial sites and other special uses, it seems likely that some sort of general use internet identification law will be enacted in the next few years.

When a stricter general purpose identity verification law inevitably appears, they will require either electronic verification, which requires collecting and collating personally identifiable information (or “PII”), or that sites implement tools for the users to provide identity documentation. This could be an expensive or complex process, and compliance with Identity verification laws is likely to conflict with other regulations that encourage limited PII use. Sites trying to avoid liability are likely to find it safer to forbid access to users in jurisdictions with general identity verification laws, at least until the details of the law are worked out. This provision, while only another self-verification, seeks to do so preemptively.

To use this Website your county or State must not have imposed online verification laws for age or identity that require us to collect information. This Website does not provide a means of verifying age and identity through the use of information we collect either through user submitted documentation or automatic verification.

The term may be of limited use in the eventuality that a digital identity law is widely adopted, but has an additional advantage of informing users that the site doesn’t verify identity or intentionally collect data to verify user identity, which can be comforting to security conscious users.

One response to “SAMPLE TERMS OF SERVICE – USER LIMIATION CLAUSES I”

  1. […] these Terms from time to time as we may change them from time to time.2. WHO CAN USE THIS WEBSITE.To use the Website you must be at least thirteen (13) years old. If you are over 13 but not legally an adult in your country, its laws may still require the […]

Leave a Reply

Discover more from Law Office of August Bournique

Subscribe now to keep reading and get access to the full archive.

Continue reading