HB 1650 creates a new “Age-Appropriate Design Code Act” in RSA 359-C aimed at regulating how online businesses collect, use, and disclose personal data of minors. It applies to covered businesses that operate in New Hampshire, generate most of their revenue from online services, and offer products or features reasonably likely to be accessed by minors. The bill defines a wide set of terms, including personal data, profiling, algorithmic recommendation systems, age assurance, and social media platform, and it excludes certain entities and activities such as government operations, HIPAA-covered information, specified research, journalism entities, and financial institutions subject to federal banking privacy law.
The bill imposes a duty of care on covered businesses processing a covered minor’s data, requiring that their data practices and product design not result in reasonably foreseeable emotional distress, compulsive use, or discrimination. It also requires default privacy settings at the highest level for minors, limits adult interaction and location sharing, restricts push notifications, requires transparency about recommendation systems and data practices, and prohibits collection, sale, sharing, or retention of minor data that is not necessary for the service the minor is actively using. The bill further restricts algorithmic recommendation practices, limits age-assurance data use and retention, and directs the attorney general to adopt rules on prohibited design practices, age-assurance methods, and enforcement.
The bill would amend state law by adding a new subdivision to RSA 359-C and by making violations an unfair or deceptive act in trade or commerce under RSA 358-A:2. It also authorizes attorney general rulemaking and enforcement tools, including civil investigations, civil actions, and assurances of discontinuance. The act is scheduled to take effect on January 1, 2027, giving businesses and the attorney general time to prepare implementing rules and compliance systems.
Overall sentiment appears generally supportive of child online privacy and safety protections, based on the bill’s structure and policy goals, though no committee transcript or recorded vote is available in the provided materials to show direct debate or opposition. The fiscal note suggests the bill could create indeterminable costs for the state and local governments, mainly through possible judicial and correctional impacts tied to enforcement, but it does not identify any revenue effect. Likely points of contention include the breadth of the covered-business definition, the operational burden of default privacy settings and transparency disclosures, the limits on recommendation algorithms and data collection, and the attorney general’s broad rulemaking authority over age assurance and design practices.
HB 1650 would add a new consumer-privacy regulatory framework to RSA 359-C focused specifically on minors’ online data and platform design. It would affect online businesses that meet the bill’s coverage criteria by restricting data collection, retention, sharing, profiling, recommendation systems, and certain social-media features for covered minors, while also imposing transparency and age-assurance requirements. Violations would be treated as unfair or deceptive trade practices under RSA 358-A:2, expanding potential enforcement exposure under state consumer-protection law and giving the attorney general rulemaking and civil enforcement authority.
The bill’s policy direction is strongly protective of minors’ privacy, safety, and autonomy online, and the text reflects a clear legislative intent to curb data-driven design practices that may encourage compulsive use or expose minors to harm. Because no committee transcript or vote record is provided, there is no direct evidence of floor or committee sentiment; however, the bill’s detailed safeguards and enforcement provisions suggest a serious, affirmative regulatory approach rather than a symbolic measure. The fiscal note also indicates the state anticipates possible enforcement-related costs, but no revenue impact.
The most likely areas of contention are the scope and compliance burden of the bill. Covered businesses may object to the broad definition of covered business, the requirement to default minors to the highest privacy settings, the limits on algorithmic recommendation systems, and the restrictions on collecting or retaining data not strictly necessary for a service. Another likely point of debate is the age-assurance framework, which requires privacy-protective methods and gives the attorney general substantial discretion to define acceptable techniques and appeal procedures. Privacy advocates may support these provisions, while industry stakeholders may argue they are costly, technically difficult, or overbroad, especially for platforms that serve mixed-age audiences.