惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Hugging Face - Blog
Hugging Face - Blog
腾讯CDC
阮一峰的网络日志
阮一峰的网络日志
博客园_首页
Last Week in AI
Last Week in AI
月光博客
月光博客
D
DataBreaches.Net
WordPress大学
WordPress大学
雷峰网
雷峰网
酷 壳 – CoolShell
酷 壳 – CoolShell
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园 - 叶小钗
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
U
Unit 42
Recent Announcements
Recent Announcements
宝玉的分享
宝玉的分享
MyScale Blog
MyScale Blog
C
Check Point Blog
F
Fortinet All Blogs
B
Blog
小众软件
小众软件
Vercel News
Vercel News
罗磊的独立博客
有赞技术团队
有赞技术团队

Future of Privacy Forum

Updating the Delaware Personal Data Privacy Act: The “First State” Becomes the Latest to Get a Privacy Refresh FPF at the Singapore Data Festival 2026: Agentic AI, Biometrics, and the Future of Digital Trust in APAC Clean-Up on Aisle Three: New Jersey Becomes Third State to Regulate Data-Driven Pricing This Year - Future of Privacy Forum CADA: An (E)U-turn on AI regulation FPF and Leading Companies Release Risk Assessment Framework and Updated Best Practices for AI in Hiring & Employment FPF Statement on the Senior Chatbot Protection Bill - Future of Privacy Forum The AI Act implementation timeline: What changes under the AI Omnibus? FPF Submits Comments to Inform Colorado Automated Decision-Making Technology and Chatbot Rulemaking Processes - Future of Privacy Forum FPF Releases New Issue Brief on U.S. “Data Broker” Regulatory Landscape New Survey: Privacy Concerns Are A Top Barrier to AgeTech Adoption Among Older Adults New Survey: Privacy Concerns Are A Top Barrier to AgeTech Adoption Among Older Adults Navigating Cross-Border Data Transfers in the ASEAN Region: An Analysis of Developments from 2023 to 2026 FPF Submits Comments to Inform California Children’s Social Media Protections Rulemaking Process Mandating “Evidence-Based” Suicide Detection in Chatbots Data Brokers & Beyond: Navigating New Jersey’s Data Broker & “Data Collector” Registration Law - Future of Privacy Forum FPF Hosts Frontiers Workshop on Privacy, AI, and Emerging Infrastructure FPF’s 2026 DC Privacy Forum: Leading Voices in AI, Privacy and Emerging Technology Understanding Data Embassies and Corridors Perseverance Pays Off for Vermont Privacy Efforts Future of Privacy Forum Announces 2026 Career Achievement Award Recipients - Future of Privacy Forum Future of Privacy Forum Releases Comprehensive Report On Algorithmic Personalization in Youth Online Experiences Frontier AI Goes Federal: How the Great American AI Act Compares to State Laws Privacy Becomes You, Bayou State: A Look at the Louisiana Data Privacy Act Comparing Enacted App Store Accountability Acts - Future of Privacy Forum No Silver Bullet, But a Silver Lining? PETs and International Data Transfers Career Choice in the AI Age: What Next for Privacy and Data Professionals? FPF Releases Practitioner Guides on Privacy Enhancing Technologies for Education Stakeholders SB 5 in Five: What to Know About Connecticut’s New AI Law Third Time’s the Charm: Connecticut Enacts Annual Privacy Update - Future of Privacy Forum Colorado Revises Its AI Act: What Changed and Why
A New Design Code Takes Root in the Garden State
https://www.facebook.com/FutureofPrivacy · 2026-08-13 · via Future of Privacy Forum

Policy Counsel for U.S. Legislation

On August 11, New Jersey became the newest state to enact a design code law aimed at minor online safety after Governor Sherrill signed A4015, the “New Jersey Age-Appropriate Design Code” (NJAADC). The new law is among the broadest in the country, most closely resembling a blend of the design codes enacted in South Carolina and Nebraska. For example, this law has broad applicability thresholds; relies on strong protective default settings; broadly prohibits dark patterns in online services; restricts personalized recommendation practices and certain design features; and mandates mechanisms for minors to report harms in online services. This law takes effect on September 1, 2027 and includes a private right of action (PRA). This blog post covers the NJAADC’s scope, mandatory safeguards, prohibited practices, reporting mechanisms, and enforcement.

Scope & Key Definitions

Applicability: The NJAADC regulates covered online services, defined as any entity providing an online service in the state that is both reasonably likely to be accessed by a child or minor and meets one of the following annual thresholds: (1) gross revenue in excess of $25M, or (2) processes personal data of 25,000 or more consumers or households. This definition includes any person that controls a legal entity that meets this definition and shares common branding with the legal entity. (§ 3)

While design code frameworks generally draw from the California Consumer Privacy Act (CCPA) by applying to entities that collect and control personal data and meet specified revenue or processing thresholds, the NJAADC departs from the CCPA and earlier AADC models by extending coverage beyond for-profit businesses to any legal entity that owns, operates, controls, or provides an online service and meets the statutory thresholds. Nebraska and South Carolina likewise expand scope to potentially cover non-profits and other non-commercial entities. The NJAADC has a lower data processing threshold than all other design codes—requiring processing of just 25,000 consumers or households in the state.

Exemptions: This bill includes entity-level exemptions for government entities (but only “in the ordinary course of its operation”); direct messaging services or products; telecommunications services; broadband internet access services; and email services. The bill also includes data-level exemptions for data subject to GLBA; certain health records, patient identifying information, and research data; protected health information under HIPAA; and information falling under human subjects protections by the FDA. (§§ 3 & 15)

Key Definitions: The NJAADC aligns knowledge standard definitions with other recently enacted design code laws but diverges in its approach to defining age thresholds. Similar to other laws, the NJAADC defines both actual knowledge (the threshold used to determine whether a covered online service provider knew a user was a minor) and “reasonably likely to be accessed by minors” (the standard applied to determine whether a covered online service provider is within the law’s scope). Actual knowledge is defined similarly to Nebraska’s AADC as all information and inferences the covered online service holds relating to an individual’s age—such as self-identified age or any age attributed to the individual for any purpose, including marketing, advertising, or product development. Notably, age classifications used for marketing take precedence over self-declared age. The “reasonably likely to be accessed by minors” standard is defined most comparably to Vermont’s AADC, and relies on three factors—

  1. The service, product, or feature is directed to children, as defined by COPPA and its implementing rules;
  2. The service, product or feature is determined, based on competent and reliable evidence regarding audience composition, to be routinely accessed by an audience that is composed of at least 2% of individuals aged 2-17; or
  3. The covered online service knew or should have known that at least 2% of the audience includes individuals aged 2-17, provided that, in making this assessment, the business shall not collect or process any personal data that is not reasonably necessary to provide an online service, product, or feature. (§ 3)

While other design code laws typically apply protections to a single age category of minors under 18, the NJAADC adopts a two-tiered age threshold, distinguishing “child,” defined as anyone under the age of 13, from “minor,” defined as anyone between 13 and 17. A covered child or minor is one whom the covered online service has actual knowledge to be a child or minor. Although the bill creates separate “children” and “minors” definitions, none of the obligations apply differently between the two age tiers. Accordingly, this divergence likely has little practical impact on how companies implement these requirements compared to other laws as it is currently written, but future amendments could introduce opportunity for substantive divergences if scoped to only one of the two defined age categories. (§ 3)

Mandatory Safeguards

Like many recent design code laws—including those in South Carolina, Nebraska, and Vermont, the NJAADC requires covered online service providers to configure certain default safety settings for covered children and minors. These settings focus on controlling personalized content recommendations, preventing unwanted contact between minors and unknown adults, and adding friction to certain design features. These settings and features can be adjusted by a covered child/minor or their parent. Key mandatory safeguards include:

  • Algorithmic recommendation systems must have a “prominent and accessible” user interface allowing covered children/minors to indicate content recommendation preferences and access, review, and change personal data used to provide algorithmic recommendations. (§ 10(a) & (b))
  • For covered online service providers that use algorithmic recommendation systems to prioritize content or contacts between users, the systems may not display the existence of a covered child’s/minor’s account, created or posted media, or allow direct messaging between a covered child/minor and an unknown adult unless the covered child, minor, or their parent “expressly and unambiguously” allows such conduct.
  • Covered online service providers are prohibited from displaying a covered child’s/minor’s geolocation information or connected users;
  • Covered online service providers need to disable search engine indexing of covered children’s/minor’s accounts and interaction counts (e.g., comments, reactions, and reshares); and
  • Covered online service providers need to provide a block option preventing specific users from accessing, interacting with, or communicating with a covered child’s or minor’s account.

Covered online service providers are barred from providing a single setting that makes multiple default settings less protective, or prompting a covered child/minor to disable settings unless it is necessary to provide a service or feature “expressly and unambiguously” requested by the covered child/minor or their parent. (§ 4(a)-(c))

Prohibited Practices

In addition to requiring certain default safeguards, the NJAADC also restricts covered online services from engaging in certain practices related to children’s and minors’ personal data and service design—including through purpose limitations, compulsive design restrictions, limits on data use for algorithmic recommendations, data retention caps, notification restrictions, advertising prohibitions, and dark pattern prohibitions. 

  • Purpose Limitation: A covered online service may not use a covered child’s/minor’s personal data for any purpose beyond that for which it was collected. There is no consent alternative for this. (§ 7(a)(1))
  • Compulsive Design Limits: The covered online service provider must take reasonable steps to ensure that any use of the covered child’s/minor’s personal data and design of covered design features (e.g., infinite scroll, autoplay) do not result in compulsive use. (§ 12(a))
  • Algorithmic Recommendation Limits: A covered online service may not use a covered child’s/minor’s personal data for content recommendations unless the prioritization is based on: user settings, a search query, parent-selected settings, a user’s age or age flag, age-appropriate content policies, or a covered child’s/minor’s “express and unambiguous” request to receive certain content. (§ 7(a)(2))
  • Data Minimization & Retention: The NJAADC includes substantive data minimization requirements, permitting covered online service providers to process or retain only the minimum amount of data necessary to provide the specific features of an online service with which the covered child/minor is “actively and knowingly engaged.” (§ 7 (b))
  • Notification Curfew: Covered online service providers must disable notifications for covered child/minor notifications by default, and, if enabled, may not send notifications during late night hours (i.e., 10pm-6am) or during the school day when school is in session (i.e., 8am-4pm). (§ 6(a) & (b))
  • Advertising Restrictions: Covered online service providers may not target covered children/minors with advertisements involving narcotic drugs, tobacco products, gambling, or alcohol. (§ 6(c))
  • “Dark Patterns” Prohibitions: Similar to other design code laws, such as Nebraska’s and South Carolina’s, covered online service providers would be broadly prohibited from using “dark patterns” in regard to a covered child/minor. While these requirements are usually tied to business data practices in other laws, like Maryland’s AADC and comprehensive privacy laws, the dark patterns prohibition under this bill is framed in context of the online service as a whole. (§ 6(d))

Reporting & Unpublishing Mechanisms

The NJAADC would require covered online service providers to establish two mechanisms for covered children/minors to use for reporting and account deletion. First, covered online service providers must provide a “prominent and accessible” reporting mechanism for covered children, minors, and their parents to report harms experienced on the online service. Second, covered online service providers must establish an “unpublishing” mechanism that allows covered children/minors to quickly delete their account in fewer steps than it took to create it. This unpublishing tool mirrors the nearly identical requirement established in the Connecticut Data Privacy Act (CTDPA) in its 2023 amendments. (§§ 5 & 9)

Enforcement & Rulemaking

The law includes robust enforcement mechanisms and rulemaking. On enforcement, the NJAADC is enforceable in two ways—first, as a violation of the Consumer Fraud Act (which includes a PRA). Second, the bill also establishes its own PRA through which lawsuits may be brought by either the Attorney General or a parent on behalf of an injured child or minor. For any negligent or greater violations, a court would be authorized to award: 

  1. $5k per violation or treble damages (whichever is greater);
  2. Punitive damages for reckless and knowing violations; 
  3. Injunctive relief;
  4. Declaratory relief;
  5. Attorney’s fees; and
  6. Litigation costs. (§ 14(a)-(c))

On rulemaking, the Attorney General’s office has broad authority to promulgate rules necessary to guide implementation of these provisions. Additionally, the Commissioner of Health has narrow rulemaking authority to provide guidance on criteria establishing “compulsive use.” New Jersey is the third state to provide agencies with such authority—there is ongoing rulemaking on this topic under Vermont’s AADC and Colorado already approved regulations for implementing the heightened minor protections within the Colorado Privacy Act (CPA). (§ 13)

Conclusion

New Jersey’s approach to age-appropriate design code frameworks changes the model’s formula from a data protection to safety-by design focus, distinguishing it from the regulatory approach central to earlier models. Early-enacted age-appropriate design codes, like those in California and Maryland, revolved around a duty of loyalty to act in the best interests of children, default privacy settings, child data processing restrictions, and data protection impact assessments (DPIAs) primarily evaluating whether data management practices would result in children being subject to harm. The NJAADC’s emphasis on product and service design, personalization practices, and default safeguards governing minors’ platform interactions—alongside core data protections—reflects a broader regulatory shift within U.S. age-appropriate design code frameworks toward a distinct protective-by-design approach. This shift, similarly observed in South Carolina’s law, merits consideration as an emerging framework in its own right. 

As age-appropriate design codes continue to coalesce around this new protective-by-design approach, it remains to be seen whether they will continue to face the same constitutional scrutiny that the earlier privacy-by-design frameworks faced. For example, California’s and Maryland’s laws were quickly subject to constitutional challenges that are still ongoing at the time of writing. South Carolina’s law was also challenged in February 2026, and it could prove to be a bellwether for this new protective-by-design model. As states continue to experiment with legal frameworks centered on regulating platform design, continued state adoption of broad protective-by-design frameworks looks likely to continue into the 2027 legislative session.