Minnesota 2025-2026 Regular Session

Minnesota House Bill HF4511

Introduced
3/23/26  

Caption

Minnesota Age-Appropriate Design Code Act created, obligations placed on certain businesses regarding children's consumer information, and attorney general enforcement provided.

Summary

HF4511 would create the Minnesota Age-Appropriate Design Code Act, a consumer privacy law focused on online products that are reasonably likely to be accessed by children. The bill requires covered businesses to design products with children’s best interests in mind and to prioritize children’s privacy, safety, and well-being over commercial interests when those interests conflict. It defines “child” as anyone under 18 and sets out age ranges businesses should consider when designing online services. The bill imposes a series of obligations on qualifying businesses, including conducting and maintaining data protection impact assessments for covered online products, updating those assessments when product changes create new risks, and providing them to the attorney general on request. It also requires high-privacy default settings for children, clear and age-appropriate privacy disclosures, and accessible tools for children or parents to exercise privacy rights and report concerns. The bill prohibits certain practices for child users, including profiling by default unless narrow conditions are met, collecting unnecessary personal data, using specific geolocation data by default, using dark patterns, and allowing non-parental monitoring without notice. HF4511 applies to businesses operating in Minnesota that meet specified size or data-processing thresholds, such as annual revenue over $25 million, large-scale data collection or sharing, or deriving most revenue from selling personal data. It excludes certain categories of data and entities, including HIPAA-covered health information, clinical trial data, and data subject to the Gramm-Leach-Bliley Act. Enforcement would rest exclusively with the attorney general, who could seek injunctions and civil penalties of up to $2,500 per affected child for negligent violations and up to $7,500 per affected child for intentional violations. The bill also classifies attorney general-held impact assessments as nonpublic or private data and preserves attorney-client privilege and work product protections. The overall sentiment in the available record appears neutral to supportive, but there is no committee transcript or vote history provided to show debate or opposition. The bill’s structure suggests a child-protection and privacy-focused approach that would likely appeal to advocates for stronger online safeguards, while also imposing compliance obligations on businesses that collect or process children’s data. Because no recorded discussion or votes are included, there is no documented evidence here of specific support, criticism, or amendments. Notable points of contention, based on the bill text itself, would likely center on the scope of covered businesses, the breadth of the “best interests of children” standard, and the operational burden of required impact assessments and default privacy settings. Businesses may also object to restrictions on profiling, geolocation, and design features that increase engagement, while supporters would likely emphasize the bill’s privacy protections and limits on manipulative design. The bill expressly avoids creating a private right of action and says it should not be read to require age-gating or censorship of third-party content, which appears intended to address some legal and free-expression concerns.

Impact

The bill would add a new chapter to Minnesota Statutes establishing a statewide age-appropriate design code for online products likely to be accessed by children, while also amending the state’s data practices law to classify attorney general-held data protection impact assessments as nonpublic/private data. It would create new compliance duties for covered businesses, new prohibitions on certain data practices involving children, and exclusive attorney general enforcement authority with civil penalties and injunctive relief. The measure would affect online platforms, apps, and other digital services meeting the bill’s revenue or data-processing thresholds, while carving out several categories of regulated health, clinical, and financial data.

Sentiment

No committee transcripts or vote history were provided, so the record does not show formal debate or roll-call sentiment. Based on the bill’s text and caption, the measure appears to be framed as a child privacy and online safety bill, which generally suggests support from privacy and child-protection advocates. At the same time, the bill would impose significant compliance obligations on businesses, so industry stakeholders would likely scrutinize it closely even though no specific opposition is documented in the materials provided.

Contention

The main likely points of contention are the bill’s broad definition of covered online products and the requirement that businesses act in the “best interests of children,” a standard that could be seen as flexible but also uncertain. Businesses may object to mandatory impact assessments, high-privacy defaults, limits on profiling and geolocation, and restrictions on engagement features such as autoplay and notifications. Supporters would likely focus on preventing harm, manipulative design, and excessive data collection. The bill tries to reduce controversy by excluding certain regulated data, limiting enforcement to the attorney general, preserving privilege, and stating that it does not require age-gating, censorship of third-party content, or a private right of action.

Companion Bills

MN SF4574

Similar To Minnesota Age-Appropriate Design Code Act establishment

Similar Bills

No similar bills found.