Skip navigation menu
Hero background image
HEAR from OuR FOUNDER, julie.

Blog & News

BILL ANALYSIS

PKO Analysis: Why the TOTAL Screen Time Act Fails the Digital Identity Framework

Parents deserve tools that protect their kids — not federal systems that quietly build identity infrastructure for minors. The TOTAL Screen Time Act (H.R. 9692) introduced by Rep Harrigan, is being marketed as a simple, bipartisan bill to “help parents manage screen time.”

But when you read the text closely, the bill does something very different.

It creates the first federal technical standard for cross‑device parental controls — and that standard requires identity binding, device‑level enforcement, and cross‑platform synchronization. Under the PKO Digital Safety & Identity Architecture Framework, this bill is an automatic OPPOSE.

Here’s why.

The Four PKO Auto‑Oppose Triggers

PKO has four red lines; any one of which is enough to oppose a bill. Harrigan’s bill triggers all four.

1. Parent–child identity linkage

The bill requires:

“an authentication and authorization model for minors and the parents or guardians of such minors.”

You cannot build this without verifying and binding the parent‑child relationship. That is identity infrastructure.

2. Cross‑device synchronization

The bill requires:

“a screentime limit across covered devices.”

Cross‑device enforcement is identity propagation. It requires shared identifiers, shared permissions, and shared enforcement logic.

3. Identity‑conditioned access to device functionality

To enforce limits “for minors,” the system must classify the user as a minor and link them to a parent. Device behavior changes based on identity classification.

That is identity‑conditioned access.

4. Interoperability mandates

NIST must convene:

  • device manufacturers

  • international standards bodies

  • federal agencies

  • medical organizations

  • privacy boards

This is not a “tool for parents.” It is a multi‑agency, multi‑vendor identity ecosystem.

PKO Framework Score: 4 / 18 → 22% → OPPOSE

Even without the auto‑oppose triggers, the bill fails the PKO framework.

Here’s the breakdown.

CATEGORY 1 — Identity Architecture & Authentication Models

1. Identity verification for minors? YES — required for enforcement.

2. Identity verification for parents? YES — required for authorization.

3. Persistent identity tokens for minors? YES (implied) — needed for cross‑device sync.

4. Identity bound to device use? YES — enforcement depends on identity classification.

5. Permissions propagated across devices/platforms? YES — core function of the bill.

Category 1 score: 5 out of 5 (all negative for PKO)

CATEGORY 2 — Surveillance, Monitoring & Data Flows

6. New data flows between devices/vendors? YES — devices must share enforcement data.

7. New data retention obligations? NO — not specified.

8. New data aggregation points? YES — identity/auth infrastructure across devices.

9. Surveillance creep risk? YES — architecture can be repurposed beyond “screen time.”

10. Third‑party vendor involvement? YES — device manufacturers, standards bodies, and federal agencies.

Category 2 score: 4 out of 5

CATEGORY 3 — Device‑Level Enforcement & Ecosystem Control

11. Device‑level enforcement required? YES — required by the bill.

12. Cross‑device enforcement required? YES — required by the bill.

13. Interoperability between manufacturers/platforms? YES — federal standard + international standards bodies.

14. Control shifted from parents to vendors/federal agencies? YES — parents act through a federally defined architecture.

Category 3 score: 4 out of 4

CATEGORY 4 — Child Autonomy, Safety & Rights

15. Protects minors without identity binding? NO — identity binding is required.

16. Avoids persistent child identifiers? NO — architecture implies them.

17. Avoids identity‑conditioned access? NO — enforcement depends on identity classification.

18. Avoids surveillance expansion? NO — architecture enables expansion.

Category 4 score: 0 out of 4

FINAL PKO VERDICT

Score: 4 / 18 → 22% → OPPOSE Auto‑Oppose Triggers: YES (all four)

The TOTAL Screen Time Act is not a parental‑control bill. It is a federal identity architecture bill disguised as a parental‑control bill.

Under the PKO framework, it fails because it:

  • requires identity binding

  • requires cross‑device enforcement

  • requires identity‑conditioned access

  • creates an interoperability ecosystem

  • expands surveillance architecture

  • shifts control from parents to vendors and federal agencies

PKO position: OPPOSE.