An act relating to an age-appropriate design code
H.210 creates the Vermont Age-Appropriate Design Code Act, a new set of privacy and design rules for online services, products, and features that are reasonably likely to be accessed by minors. The bill defines a covered business broadly and imposes special duties when that business processes a covered minor’s data. It establishes a minimum duty of care requiring businesses to avoid foreseeable emotional distress, compulsive use, and discrimination against minors, and it directs businesses to configure default privacy settings at the highest level of protection for minors.
The bill also limits how covered businesses may collect, use, retain, share, and recommend content based on minors’ personal data. It restricts push notifications during overnight hours, limits profiling and algorithmic recommendation practices, requires prominent transparency disclosures about data use and recommendation systems, and provides minors with a tool to request account deletion or unpublishing. The bill further regulates age-assurance methods by requiring data minimization, deletion of age-verification data after use, an appeal process for age designations, and Attorney General rulemaking to identify acceptable age-assurance practices and additional protections.
If enacted, H.210 would add a new subchapter to Title 9 governing online privacy and design practices for minors, effectively creating a Vermont-specific child and teen online safety regime. It would give the Attorney General rulemaking authority and enforcement power, and violations would be treated as unfair and deceptive acts in commerce under existing consumer protection law. The bill would affect social media platforms and other online services likely to be accessed by minors, while carving out certain entities and activities such as government functions, HIPAA-covered information, some research, and journalism entities.
The bill’s overall posture is strongly protective of children’s privacy, safety, and autonomy online. Even without recorded committee testimony or votes in the provided materials, the text and broad sponsorship suggest a reform-oriented, consumer-protection approach aimed at limiting manipulative design and data practices. The bill also reflects an effort to balance protection with access, as it repeatedly states that minors should not be prevented from viewing media or exercising existing rights and freedoms.
The main points of potential contention are the breadth of the covered-business definition, the operational burden of default privacy settings and transparency disclosures, and the restrictions on algorithmic recommendation systems and data collection. Businesses may object to the limits on profiling, push notifications, and age-assurance requirements, especially where compliance costs or technical feasibility are concerns. Another likely area of debate is the Attorney General’s authority to define prohibited design practices and age-assurance methods by rule, which could be viewed as giving regulators substantial discretion over evolving online product design.