Vermont's Age-Appropriate Design Code: What Act 63 Requires of Online Services From January 1, 2027
Key Takeaways
- Act 63 (S.69) adds subchapter 6 to chapter 62 of Title 9, §§ 2449a through 2449j, effective January 1, 2027; its two rulemaking provisions took effect July 1, 2025
- A covered business must, among five cumulative conditions, earn a majority of its annual revenue from online services and offer a product reasonably likely to be accessed by minors, including under a 2% audience test
- Most protections attach to a covered minor: a consumer the business actually knows is under 18, or labels as one using age assurance methods set by Attorney General rule
- The Act sets high-privacy defaults for minors, bars push notifications to covered minors between midnight and 6 a.m., and confines personalized feeds to express requests, settings and searches
- Violations are unfair and deceptive acts under 9 V.S.A. § 2453 enforced by the Attorney General; no court challenge to Act 63 was located for this post
Two Start Dates in One Act
S.69, "An act relating to an age-appropriate design code," was sponsored by Senator Wendy Harrison and signed by the Governor on June 12, 2025, according to the Vermont General Assembly's bill page, and became Act 63. Section 1 of the act as enacted adds "9 V.S.A. chapter 62, subchapter 6," titled the Vermont Age-Appropriate Design Code Act. It is a subchapter of an existing chapter rather than a chapter of its own: the Legislature's chapter 62 index lists §§ 2449a through 2449j, each marked "[Effective January 1, 2027]."
Section 2 of the act splits its commencement. The act takes effect January 1, 2027, "except that this section (effective dates) and, in Sec. 1, 9 V.S.A. § 2449f(b) and 9 V.S.A. § 2449g(b) (rulemaking authority) shall take effect on July 1, 2025." Both of those subsections direct the Attorney General to adopt rules "on or before January 1, 2027."
The Attorney General's rulemaking page states that proposed rules for the two sections have been published, lists public hearings on September 9, September 21 and September 23, 2026, and sets a comment deadline of October 2, 2026. It describes the law and any adopted rules as taking effect on January 1, 2027.
Five Conditions and a 2% Audience Share
Section 2449a(10) defines a covered business as a legal entity, or an affiliate of one, that meets all five of these conditions:
- it conducts business in Vermont
- it generates a majority of its annual revenue from online services
- its online products, services or features are "reasonably likely to be accessed by a minor"
- it collects consumers' personal data or has it collected on its behalf by a processor
- alone or jointly with others, it determines the purposes and means of processing consumers' personal data
"Reasonably likely to be accessed" is defined in § 2449a(26) by four alternative indicators: the service is directed to children as COPPA and the Federal Trade Commission's rules define that phrase; competent and reliable evidence about audience composition shows it is routinely accessed by an audience at least 2% of which is minors aged two through 17; internal company research shows the same 2% share; or the business "knew or should have known" that at least 2% of its audience falls in that age range. The last indicator carries a proviso that in making the assessment the business "shall not collect or process any personal data that is not reasonably necessary" to provide a service with which a minor is actively and knowingly engaged.
A "minor" is anyone under 18, and a "consumer" is a Vermont resident, excluding an individual whose dealings with the business occur solely in a commercial or employment role. Most duties run to a "covered minor," which § 2449a(12) defines as a consumer the business "actually knows is a minor or labels as a minor pursuant to age assurance methods in rules adopted by the Attorney General." A "known adult" is defined the same way in reverse, and several of the default settings are framed around contact with known adult users.
Section 2449b excludes government entities acting in the ordinary course, HIPAA protected health information handled by covered entities and business associates, information used for public health activities or regulated human subjects research, an entity whose primary purpose is journalism and whose workforce is mostly journalists, and financial institutions subject to Title V of the Gramm-Leach-Bliley Act.
A Duty of Care Defined by Three Outcomes
Section 2449c provides that a covered business that processes a covered minor's data "in any capacity owes a minimum duty of care to the covered minor." The duty is defined by result: the use of the minor's personal data and the design of the online service, product or feature "will not result in" reasonably foreseeable emotional distress as defined in 13 V.S.A. § 1061(2), reasonably foreseeable compulsive use, or discrimination based on race, ethnicity, sex, disability, sexual orientation, gender identity, gender expression, religion or national origin.
"Compulsive use" is itself defined in § 2449a(8) as repetitive use that "materially disrupts one or more major life activities of a minor, including sleeping, eating, learning, reading, concentrating, communicating, or working." Two limits follow. Section 2449c(c) provides that "[t]he content of the media viewed by a covered minor shall not establish emotional distress, compulsive use, or discrimination," and § 2449c(d) provides that nothing in the section requires a business to prevent a covered minor from accessing any piece or category of media.
Defaults, Deletion and Notifications
Section 2449d(a)(1) requires every default privacy setting offered to a covered minor to be configured "to the highest level of privacy," and names eight defaults. On a social media platform, the minor's account and posted media are hidden from known adult users, known adults cannot like or comment on the minor's media, and direct messaging with known adults is off, in each case unless the minor "expressly and unambiguously" allows a specific known adult. The minor's location is not displayed to other users, the minor's connections are not displayed, search engine indexing of the profile is disabled, and push notifications are not sent.
Section 2449d(a)(2) prohibits offering a single setting that makes all the defaults less protective at once, and prohibits prompting a minor to lower privacy settings unless the change is strictly necessary for a feature the minor has expressly and unambiguously requested. Section 2449d(b) requires a prominent, accessible and responsive tool for a covered minor to unpublish or delete a social media account, with the request honored within 15 days of receipt.
What the Code Prohibits Outright
Section 2449f(a) lists five prohibitions:
- collecting, selling, sharing or retaining a covered minor's personal data "that is not necessary to provide an online service, product, or feature with which the covered minor is actively and knowingly engaged"
- using previously collected personal data of a covered minor for a purpose other than the one it was collected for, unless necessary to comply with the chapter
- permitting anyone, "including a parent or guardian," to monitor a covered minor's online activity or track the minor's location without a conspicuous signal to the minor while it happens
- using a covered minor's personal data to select, recommend or prioritize media, unless the data is the minor's express request for a specific account, category or similar media, user-selected privacy or accessibility settings, or a search query used only to answer that search
- sending push notifications to a covered minor between 12:00 midnight and 6:00 a.m.
The Act contains no dark patterns clause of its own. Instead, § 2449f(b) directs the Attorney General to adopt rules prohibiting data processing or design practices that, "in the opinion of the Attorney General, lead to compulsive use or subvert or impair user autonomy, decision making, or choice," and to review those rules at least every two years.
Recommendation Systems and Age Assurance Data
Section 2449e requires a covered business to publish, prominently and clearly, the purpose of each algorithmic recommendation system it uses, the inputs each system relies on and how each input is measured, uses minors' personal data, influences the recommendation and is weighted against the others, and a feature-by-feature description of the personal data collected and used, any transfer to processors or third parties with their identity and purpose, and how long the data is retained.
Section 2449g(a) limits what may be done with data gathered to establish age. Businesses and processors collect only data "strictly necessary for age assurance," delete it immediately once the determination is made apart from the resulting age range, do not use it for another purpose or combine it with other personal data, disclose it only to processors, and offer a process for appealing an age determination. The rules the Attorney General must adopt under § 2449g(b) are to "prioritize user privacy and accessibility over the accuracy of age assurance methods," while weighing the size and resources of businesses, cost and effectiveness, user experience, transparency, and the use of previously collected data, interoperable methods and multiple options.
Enforcement, and the Cross-Reference in Vermont's 2026 Privacy Act
Under § 2449h, a covered business or processor that violates the subchapter or its rules "commits an unfair and deceptive act in commerce in violation of section 2453," and the Attorney General holds the rulemaking, civil investigation, civil action and assurance of discontinuance powers of chapter 63. Section 2449i provides that the subchapter is not to be read to impose liability inconsistent with 47 U.S.C. § 230, or to prevent a covered minor from deliberately or independently searching for or requesting media.
Vermont's comprehensive privacy statute, Act 145 of 2026, points back to the code. Its § 2415e(a)(9) requires a controller that is a covered business, where the consumer is a covered minor, to comply with the Vermont Age-Appropriate Design Code Act, and § 2415e(a)(4)(C) requires a controller with actual knowledge, or that willfully disregards, that a consumer is a child to process that child's sensitive data in accordance with COPPA and, where applicable, § 2449f.
Set Beside California's Code and the Ninth Circuit's Two Rulings
California's Age-Appropriate Design Code Act, Cal. Civ. Code §§ 1798.99.28 to 1798.99.40, has been litigated since 2022. In NetChoice, LLC v. Bonta, 113 F.4th 1101 (9th Cir. 2024), filed August 16, 2024, the Ninth Circuit affirmed the preliminary injunction as to California's requirement that businesses prepare Data Protection Impact Assessment reports addressing whether children could be exposed to harmful or potentially harmful material, and vacated the rest. Act 63 contains no comparable report requirement; the only assessment its text mentions is the audience-share determination in § 2449a(26)(D).
In a second opinion filed March 12, 2026 in No. 25-2366, the same panel vacated the district court's injunction of the entire statute, holding that NetChoice had not carried its burden on a facial challenge to the coverage definition, and vacated the injunction of the age estimation requirement for similar reasons. It affirmed the injunction of the data use restrictions in § 1798.99.31(b)(1) to (4) and the dark patterns restriction in § 1798.99.31(b)(7) on vagueness grounds. The panel's objection was to undefined standards: use of a child's data that is "materially detrimental" to a child's "physical health, mental health, or well-being," and exceptions for practices a business can show are "in the best interests of children." The range of qualifying harms, it wrote, spans "everything from financial exploitation to sleep loss, distraction, or hurt feelings."
The Vermont text differs on those points in ways that can be read from the statutes themselves. Act 63 does not use the terms "materially detrimental," "well-being" or "best interests." Its minimization clause in § 2449f(a)(1) tracks California's "not necessary to provide an online service, product, or feature" wording, but has no best-interests exception. Its duty of care relies on a statutory definition of compulsive use and a cross-referenced definition of emotional distress, and its counterpart to a dark patterns rule is delegated to Attorney General rulemaking rather than written into the statute. None of this has been tested in court. A search of federal court records for the District of Vermont carried out for this post found no lawsuit challenging Act 63, and this post does not predict how such a challenge would be decided.
Background
For the underlying law rather than this development: Vermont privacy law, Technology & SaaS privacy law.
Frequently Asked Questions
When does Vermont's Age-Appropriate Design Code take effect?
Is the Vermont code in chapter 62A of Title 9?
What makes a service 'reasonably likely to be accessed' by minors under Act 63?
Can a parent monitor a teenager on a service covered by Act 63?
What rules is the Vermont Attorney General writing under the code?
Who enforces Vermont's Age-Appropriate Design Code?
Sources
Everything above is reported from these documents. Follow them to verify.
- Vermont General Assembly, S.69 (Act 63), bill status (June 12, 2025) statute
- Act No. 63 (2025), An act relating to an age-appropriate design code, as enacted (June 12, 2025) statute
- Vermont Statutes Online, Title 9, Chapter 62 index (September 14, 2026) statute
- 9 V.S.A. § 2449a, Definitions (September 14, 2026) statute
- 9 V.S.A. § 2449c, Minimum duty of care (September 14, 2026) statute
- Office of the Vermont Attorney General, Vermont Age-Appropriate Design Code Rulemaking (September 14, 2026) agency guidance
- Act No. 145 (2026), An act relating to consumer data privacy and online surveillance, as enacted (June 16, 2026) statute
- NetChoice, LLC v. Bonta, No. 23-2969 (9th Cir. Aug. 16, 2024), 113 F.4th 1101 (August 16, 2024) court opinion
- NetChoice, LLC v. Bonta, No. 25-2366 (9th Cir. Mar. 12, 2026) (March 12, 2026) court opinion
Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.