State Comprehensive Privacy Laws

Vermont's Age-Appropriate Design Code: What Act 63 Requires of Online Services From January 1, 2027

Compliance date January 1, 2027 Vermont Age-Appropriate Design Code Act (9 V.S.A. §§ 2449a to 2449j) takes effect Applies to: Covered businesses as defined in 9 V.S.A. § 2449a(10)

Key Takeaways

  • Act 63 (S.69) adds subchapter 6 to chapter 62 of Title 9, §§ 2449a through 2449j, effective January 1, 2027; its two rulemaking provisions took effect July 1, 2025
  • A covered business must, among five cumulative conditions, earn a majority of its annual revenue from online services and offer a product reasonably likely to be accessed by minors, including under a 2% audience test
  • Most protections attach to a covered minor: a consumer the business actually knows is under 18, or labels as one using age assurance methods set by Attorney General rule
  • The Act sets high-privacy defaults for minors, bars push notifications to covered minors between midnight and 6 a.m., and confines personalized feeds to express requests, settings and searches
  • Violations are unfair and deceptive acts under 9 V.S.A. § 2453 enforced by the Attorney General; no court challenge to Act 63 was located for this post

Two Start Dates in One Act

S.69, "An act relating to an age-appropriate design code," was sponsored by Senator Wendy Harrison and signed by the Governor on June 12, 2025, according to the Vermont General Assembly's bill page, and became Act 63. Section 1 of the act as enacted adds "9 V.S.A. chapter 62, subchapter 6," titled the Vermont Age-Appropriate Design Code Act. It is a subchapter of an existing chapter rather than a chapter of its own: the Legislature's chapter 62 index lists §§ 2449a through 2449j, each marked "[Effective January 1, 2027]."

Section 2 of the act splits its commencement. The act takes effect January 1, 2027, "except that this section (effective dates) and, in Sec. 1, 9 V.S.A. § 2449f(b) and 9 V.S.A. § 2449g(b) (rulemaking authority) shall take effect on July 1, 2025." Both of those subsections direct the Attorney General to adopt rules "on or before January 1, 2027."

The Attorney General's rulemaking page states that proposed rules for the two sections have been published, lists public hearings on September 9, September 21 and September 23, 2026, and sets a comment deadline of October 2, 2026. It describes the law and any adopted rules as taking effect on January 1, 2027.

Five Conditions and a 2% Audience Share

Section 2449a(10) defines a covered business as a legal entity, or an affiliate of one, that meets all five of these conditions:

  1. it conducts business in Vermont
  2. it generates a majority of its annual revenue from online services
  3. its online products, services or features are "reasonably likely to be accessed by a minor"
  4. it collects consumers' personal data or has it collected on its behalf by a processor
  5. alone or jointly with others, it determines the purposes and means of processing consumers' personal data

"Reasonably likely to be accessed" is defined in § 2449a(26) by four alternative indicators: the service is directed to children as COPPA and the Federal Trade Commission's rules define that phrase; competent and reliable evidence about audience composition shows it is routinely accessed by an audience at least 2% of which is minors aged two through 17; internal company research shows the same 2% share; or the business "knew or should have known" that at least 2% of its audience falls in that age range. The last indicator carries a proviso that in making the assessment the business "shall not collect or process any personal data that is not reasonably necessary" to provide a service with which a minor is actively and knowingly engaged.

A "minor" is anyone under 18, and a "consumer" is a Vermont resident, excluding an individual whose dealings with the business occur solely in a commercial or employment role. Most duties run to a "covered minor," which § 2449a(12) defines as a consumer the business "actually knows is a minor or labels as a minor pursuant to age assurance methods in rules adopted by the Attorney General." A "known adult" is defined the same way in reverse, and several of the default settings are framed around contact with known adult users.

Section 2449b excludes government entities acting in the ordinary course, HIPAA protected health information handled by covered entities and business associates, information used for public health activities or regulated human subjects research, an entity whose primary purpose is journalism and whose workforce is mostly journalists, and financial institutions subject to Title V of the Gramm-Leach-Bliley Act.

A Duty of Care Defined by Three Outcomes

Section 2449c provides that a covered business that processes a covered minor's data "in any capacity owes a minimum duty of care to the covered minor." The duty is defined by result: the use of the minor's personal data and the design of the online service, product or feature "will not result in" reasonably foreseeable emotional distress as defined in 13 V.S.A. § 1061(2), reasonably foreseeable compulsive use, or discrimination based on race, ethnicity, sex, disability, sexual orientation, gender identity, gender expression, religion or national origin.

"Compulsive use" is itself defined in § 2449a(8) as repetitive use that "materially disrupts one or more major life activities of a minor, including sleeping, eating, learning, reading, concentrating, communicating, or working." Two limits follow. Section 2449c(c) provides that "[t]he content of the media viewed by a covered minor shall not establish emotional distress, compulsive use, or discrimination," and § 2449c(d) provides that nothing in the section requires a business to prevent a covered minor from accessing any piece or category of media.

Defaults, Deletion and Notifications

Section 2449d(a)(1) requires every default privacy setting offered to a covered minor to be configured "to the highest level of privacy," and names eight defaults. On a social media platform, the minor's account and posted media are hidden from known adult users, known adults cannot like or comment on the minor's media, and direct messaging with known adults is off, in each case unless the minor "expressly and unambiguously" allows a specific known adult. The minor's location is not displayed to other users, the minor's connections are not displayed, search engine indexing of the profile is disabled, and push notifications are not sent.

Section 2449d(a)(2) prohibits offering a single setting that makes all the defaults less protective at once, and prohibits prompting a minor to lower privacy settings unless the change is strictly necessary for a feature the minor has expressly and unambiguously requested. Section 2449d(b) requires a prominent, accessible and responsive tool for a covered minor to unpublish or delete a social media account, with the request honored within 15 days of receipt.

What the Code Prohibits Outright

Section 2449f(a) lists five prohibitions:

  • collecting, selling, sharing or retaining a covered minor's personal data "that is not necessary to provide an online service, product, or feature with which the covered minor is actively and knowingly engaged"
  • using previously collected personal data of a covered minor for a purpose other than the one it was collected for, unless necessary to comply with the chapter
  • permitting anyone, "including a parent or guardian," to monitor a covered minor's online activity or track the minor's location without a conspicuous signal to the minor while it happens
  • using a covered minor's personal data to select, recommend or prioritize media, unless the data is the minor's express request for a specific account, category or similar media, user-selected privacy or accessibility settings, or a search query used only to answer that search
  • sending push notifications to a covered minor between 12:00 midnight and 6:00 a.m.

The Act contains no dark patterns clause of its own. Instead, § 2449f(b) directs the Attorney General to adopt rules prohibiting data processing or design practices that, "in the opinion of the Attorney General, lead to compulsive use or subvert or impair user autonomy, decision making, or choice," and to review those rules at least every two years.

Recommendation Systems and Age Assurance Data

Section 2449e requires a covered business to publish, prominently and clearly, the purpose of each algorithmic recommendation system it uses, the inputs each system relies on and how each input is measured, uses minors' personal data, influences the recommendation and is weighted against the others, and a feature-by-feature description of the personal data collected and used, any transfer to processors or third parties with their identity and purpose, and how long the data is retained.

Section 2449g(a) limits what may be done with data gathered to establish age. Businesses and processors collect only data "strictly necessary for age assurance," delete it immediately once the determination is made apart from the resulting age range, do not use it for another purpose or combine it with other personal data, disclose it only to processors, and offer a process for appealing an age determination. The rules the Attorney General must adopt under § 2449g(b) are to "prioritize user privacy and accessibility over the accuracy of age assurance methods," while weighing the size and resources of businesses, cost and effectiveness, user experience, transparency, and the use of previously collected data, interoperable methods and multiple options.

Enforcement, and the Cross-Reference in Vermont's 2026 Privacy Act

Under § 2449h, a covered business or processor that violates the subchapter or its rules "commits an unfair and deceptive act in commerce in violation of section 2453," and the Attorney General holds the rulemaking, civil investigation, civil action and assurance of discontinuance powers of chapter 63. Section 2449i provides that the subchapter is not to be read to impose liability inconsistent with 47 U.S.C. § 230, or to prevent a covered minor from deliberately or independently searching for or requesting media.

Vermont's comprehensive privacy statute, Act 145 of 2026, points back to the code. Its § 2415e(a)(9) requires a controller that is a covered business, where the consumer is a covered minor, to comply with the Vermont Age-Appropriate Design Code Act, and § 2415e(a)(4)(C) requires a controller with actual knowledge, or that willfully disregards, that a consumer is a child to process that child's sensitive data in accordance with COPPA and, where applicable, § 2449f.

Set Beside California's Code and the Ninth Circuit's Two Rulings

California's Age-Appropriate Design Code Act, Cal. Civ. Code §§ 1798.99.28 to 1798.99.40, has been litigated since 2022. In NetChoice, LLC v. Bonta, 113 F.4th 1101 (9th Cir. 2024), filed August 16, 2024, the Ninth Circuit affirmed the preliminary injunction as to California's requirement that businesses prepare Data Protection Impact Assessment reports addressing whether children could be exposed to harmful or potentially harmful material, and vacated the rest. Act 63 contains no comparable report requirement; the only assessment its text mentions is the audience-share determination in § 2449a(26)(D).

In a second opinion filed March 12, 2026 in No. 25-2366, the same panel vacated the district court's injunction of the entire statute, holding that NetChoice had not carried its burden on a facial challenge to the coverage definition, and vacated the injunction of the age estimation requirement for similar reasons. It affirmed the injunction of the data use restrictions in § 1798.99.31(b)(1) to (4) and the dark patterns restriction in § 1798.99.31(b)(7) on vagueness grounds. The panel's objection was to undefined standards: use of a child's data that is "materially detrimental" to a child's "physical health, mental health, or well-being," and exceptions for practices a business can show are "in the best interests of children." The range of qualifying harms, it wrote, spans "everything from financial exploitation to sleep loss, distraction, or hurt feelings."

The Vermont text differs on those points in ways that can be read from the statutes themselves. Act 63 does not use the terms "materially detrimental," "well-being" or "best interests." Its minimization clause in § 2449f(a)(1) tracks California's "not necessary to provide an online service, product, or feature" wording, but has no best-interests exception. Its duty of care relies on a statutory definition of compulsive use and a cross-referenced definition of emotional distress, and its counterpart to a dark patterns rule is delegated to Attorney General rulemaking rather than written into the statute. None of this has been tested in court. A search of federal court records for the District of Vermont carried out for this post found no lawsuit challenging Act 63, and this post does not predict how such a challenge would be decided.

Background

For the underlying law rather than this development: Vermont privacy law, Technology & SaaS privacy law.

Frequently Asked Questions

When does Vermont's Age-Appropriate Design Code take effect?
January 1, 2027 for the substantive duties. Section 2 of Act 63 brought the Attorney General's rulemaking provisions in §§ 2449f(b) and 2449g(b) into effect on July 1, 2025, and both require rules on or before January 1, 2027.
Is the Vermont code in chapter 62A of Title 9?
No. Act 63 adds subchapter 6 to chapter 62 of Title 9, and the Legislature's statute index lists the provisions as 9 V.S.A. §§ 2449a through 2449j within chapter 62.
What makes a service 'reasonably likely to be accessed' by minors under Act 63?
Any one of four indicators in § 2449a(26): the service is directed to children under COPPA; reliable audience evidence shows at least 2% of its audience is aged two through 17; internal research shows the same; or the business knew or should have known that at least 2% of its audience falls in that range.
Can a parent monitor a teenager on a service covered by Act 63?
Section 2449f(a)(3) bars a covered business from permitting any individual, including a parent or guardian, to monitor a covered minor's online activity or track the minor's location without providing a conspicuous signal to the minor that monitoring or tracking is taking place.
What rules is the Vermont Attorney General writing under the code?
Rules under § 2449f(b) prohibiting processing or design practices that in the Attorney General's opinion lead to compulsive use or subvert user autonomy, and rules under § 2449g(b) on age assurance methods, appeals of age designations and protections for age assurance data. Comments on the proposed rules are due by October 2, 2026.
Who enforces Vermont's Age-Appropriate Design Code?
The Attorney General. Section 2449h makes a violation an unfair and deceptive act in commerce under 9 V.S.A. § 2453 and gives the Attorney General the investigation, civil action and assurance of discontinuance powers of chapter 63.

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.