














Policy Counsel for U.S. Legislation
On August 11, New Jersey became the newest state to enact a design code law aimed at minor online safety after Governor Sherrill signed A4015, the “New Jersey Age-Appropriate Design Code” (NJAADC). The new law is among the broadest in the country, most closely resembling a blend of the design codes enacted in South Carolina and Nebraska. For example, this law has broad applicability thresholds; relies on strong protective default settings; broadly prohibits dark patterns in online services; restricts personalized recommendation practices and certain design features; and mandates mechanisms for minors to report harms in online services. This law takes effect on September 1, 2027 and includes a private right of action (PRA). This blog post covers the NJAADC’s scope, mandatory safeguards, prohibited practices, reporting mechanisms, and enforcement.
Applicability: The NJAADC regulates covered online services, defined as any entity providing an online service in the state that is both reasonably likely to be accessed by a child or minor and meets one of the following annual thresholds: (1) gross revenue in excess of $25M, or (2) processes personal data of 25,000 or more consumers or households. This definition includes any person that controls a legal entity that meets this definition and shares common branding with the legal entity. (§ 3)
While design code frameworks generally draw from the California Consumer Privacy Act (CCPA) by applying to entities that collect and control personal data and meet specified revenue or processing thresholds, the NJAADC departs from the CCPA and earlier AADC models by extending coverage beyond for-profit businesses to any legal entity that owns, operates, controls, or provides an online service and meets the statutory thresholds. Nebraska and South Carolina likewise expand scope to potentially cover non-profits and other non-commercial entities. The NJAADC has a lower data processing threshold than all other design codes—requiring processing of just 25,000 consumers or households in the state.
Exemptions: This bill includes entity-level exemptions for government entities (but only “in the ordinary course of its operation”); direct messaging services or products; telecommunications services; broadband internet access services; and email services. The bill also includes data-level exemptions for data subject to GLBA; certain health records, patient identifying information, and research data; protected health information under HIPAA; and information falling under human subjects protections by the FDA. (§§ 3 & 15)
Key Definitions: The NJAADC aligns knowledge standard definitions with other recently enacted design code laws but diverges in its approach to defining age thresholds. Similar to other laws, the NJAADC defines both actual knowledge (the threshold used to determine whether a covered online service provider knew a user was a minor) and “reasonably likely to be accessed by minors” (the standard applied to determine whether a covered online service provider is within the law’s scope). Actual knowledge is defined similarly to Nebraska’s AADC as all information and inferences the covered online service holds relating to an individual’s age—such as self-identified age or any age attributed to the individual for any purpose, including marketing, advertising, or product development. Notably, age classifications used for marketing take precedence over self-declared age. The “reasonably likely to be accessed by minors” standard is defined most comparably to Vermont’s AADC, and relies on three factors—
While other design code laws typically apply protections to a single age category of minors under 18, the NJAADC adopts a two-tiered age threshold, distinguishing “child,” defined as anyone under the age of 13, from “minor,” defined as anyone between 13 and 17. A covered child or minor is one whom the covered online service has actual knowledge to be a child or minor. Although the bill creates separate “children” and “minors” definitions, none of the obligations apply differently between the two age tiers. Accordingly, this divergence likely has little practical impact on how companies implement these requirements compared to other laws as it is currently written, but future amendments could introduce opportunity for substantive divergences if scoped to only one of the two defined age categories. (§ 3)
Like many recent design code laws—including those in South Carolina, Nebraska, and Vermont, the NJAADC requires covered online service providers to configure certain default safety settings for covered children and minors. These settings focus on controlling personalized content recommendations, preventing unwanted contact between minors and unknown adults, and adding friction to certain design features. These settings and features can be adjusted by a covered child/minor or their parent. Key mandatory safeguards include:
Covered online service providers are barred from providing a single setting that makes multiple default settings less protective, or prompting a covered child/minor to disable settings unless it is necessary to provide a service or feature “expressly and unambiguously” requested by the covered child/minor or their parent. (§ 4(a)-(c))
In addition to requiring certain default safeguards, the NJAADC also restricts covered online services from engaging in certain practices related to children’s and minors’ personal data and service design—including through purpose limitations, compulsive design restrictions, limits on data use for algorithmic recommendations, data retention caps, notification restrictions, advertising prohibitions, and dark pattern prohibitions.
The NJAADC would require covered online service providers to establish two mechanisms for covered children/minors to use for reporting and account deletion. First, covered online service providers must provide a “prominent and accessible” reporting mechanism for covered children, minors, and their parents to report harms experienced on the online service. Second, covered online service providers must establish an “unpublishing” mechanism that allows covered children/minors to quickly delete their account in fewer steps than it took to create it. This unpublishing tool mirrors the nearly identical requirement established in the Connecticut Data Privacy Act (CTDPA) in its 2023 amendments. (§§ 5 & 9)
The law includes robust enforcement mechanisms and rulemaking. On enforcement, the NJAADC is enforceable in two ways—first, as a violation of the Consumer Fraud Act (which includes a PRA). Second, the bill also establishes its own PRA through which lawsuits may be brought by either the Attorney General or a parent on behalf of an injured child or minor. For any negligent or greater violations, a court would be authorized to award:
On rulemaking, the Attorney General’s office has broad authority to promulgate rules necessary to guide implementation of these provisions. Additionally, the Commissioner of Health has narrow rulemaking authority to provide guidance on criteria establishing “compulsive use.” New Jersey is the third state to provide agencies with such authority—there is ongoing rulemaking on this topic under Vermont’s AADC and Colorado already approved regulations for implementing the heightened minor protections within the Colorado Privacy Act (CPA). (§ 13)
New Jersey’s approach to age-appropriate design code frameworks changes the model’s formula from a data protection to safety-by design focus, distinguishing it from the regulatory approach central to earlier models. Early-enacted age-appropriate design codes, like those in California and Maryland, revolved around a duty of loyalty to act in the best interests of children, default privacy settings, child data processing restrictions, and data protection impact assessments (DPIAs) primarily evaluating whether data management practices would result in children being subject to harm. The NJAADC’s emphasis on product and service design, personalization practices, and default safeguards governing minors’ platform interactions—alongside core data protections—reflects a broader regulatory shift within U.S. age-appropriate design code frameworks toward a distinct protective-by-design approach. This shift, similarly observed in South Carolina’s law, merits consideration as an emerging framework in its own right.
As age-appropriate design codes continue to coalesce around this new protective-by-design approach, it remains to be seen whether they will continue to face the same constitutional scrutiny that the earlier privacy-by-design frameworks faced. For example, California’s and Maryland’s laws were quickly subject to constitutional challenges that are still ongoing at the time of writing. South Carolina’s law was also challenged in February 2026, and it could prove to be a bellwether for this new protective-by-design model. As states continue to experiment with legal frameworks centered on regulating platform design, continued state adoption of broad protective-by-design frameworks looks likely to continue into the 2027 legislative session.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。