Requires that any covered entity that develops/provides online services, products, or features that children are reasonably likely to access shall consider the best interest of children when designing/developing such online service, product, or feature.
H5830 creates a new chapter in Rhode Island commercial law called the Age-Appropriate Design Code. It applies to certain for-profit entities operating in Rhode Island that collect personal data, meet specified revenue or data-volume thresholds, or derive a substantial share of revenue from selling personal data. For covered entities, the bill imposes a duty to use reasonable care to avoid heightened risks of harm to children when an online service, product, or feature is reasonably likely to be accessed by children or is known to be used by children.
The bill requires covered entities to conduct and maintain data protection impact assessments for child-accessible online services, update those assessments after material changes, and provide them to the attorney general upon request. It also requires high-privacy default settings for known children, age-appropriate privacy disclosures, and accessible tools for children and parents to exercise privacy rights and report concerns. The bill prohibits a range of practices involving known children, including unnecessary data processing, default profiling, unnecessary precise geolocation collection, dark patterns, and hidden monitoring or tracking without notice to the child.
The bill would add a new set of privacy and design obligations to Rhode Island law for qualifying online businesses and platforms, while carving out certain health information, clinical trial data, and entities already governed by federal health privacy rules. It also states that compliance with the state’s existing child-sensitive data law does not create additional obligations under this chapter. Enforcement authority is assigned to the attorney general, who may seek injunctions and civil penalties of up to $2,500 per affected child for negligent violations and $7,500 per affected child for intentional violations, with no private right of action. The act would take effect January 1, 2026.
Based on the bill text and caption, the measure appears to be framed as a child-safety and privacy protection bill, with a clear policy goal of requiring online services to consider children’s best interests in product design. The introduction by a bipartisan group of representatives suggests at least some cross-party interest in the issue. No committee transcript or vote record is provided, so there is no recorded debate or formal vote sentiment to assess beyond the bill’s protective, regulatory orientation.
The main points of potential contention are the scope and compliance burden on covered entities, especially online platforms and businesses that collect or process large amounts of personal data. The bill’s requirements for impact assessments, high-privacy defaults, limits on profiling and geolocation, and restrictions on design features such as autoplay, rewards, and notifications could be viewed by industry as costly or difficult to implement. Another likely point of debate is the attorney general’s enforcement authority and the per-child civil penalties, though the bill also includes a 90-day cure period for substantial compliance and expressly excludes a private right of action. Because no hearing transcript or vote history is available, these are inferred policy tensions rather than documented objections.