Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Kids Code topic

No spam. Unsubscribe anytime.

Vermont committee reviews 'Kids Code' bill that would require online platforms to set stronger defaults for minors

3417476 · May 21, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Rick Segal, Legislative Counsel, walked the Vermont House Committee on Commerce & Economic Development through draft language of S.69, the Vermont Age Appropriate Design Code Act — commonly called the "Kids Code" — during a May 20, 2025 committee meeting.

Rick Segal, Legislative Counsel, walked the Vermont House Committee on Commerce & Economic Development through draft language of S.69, the Vermont Age Appropriate Design Code Act — commonly called the "Kids Code" — during a May 20, 2025 committee meeting. The committee did not vote on the bill.

The bill would apply to defined "covered businesses" and, in some provisions, to processors that handle personal data. "The bill only applies to covered businesses and processors," Segal said, describing limits in the draft intended to narrow which entities must comply. Committee members discussed definitions, exclusions, rulemaking timelines and enforcement authority.

Committee members said the bill aims to limit design features and data practices that could cause "reasonably foreseeable emotional distress" or compulsive use by covered minors and to restrict collection, sale, sharing and retention of minors' personal data beyond what is strictly necessary to provide a service the minor is "actively and knowingly engaged" with. Among the draft's required protections are default privacy settings for covered minors, a prominent tool to request account deletion with a 15-day compliance window, and prohibitions on certain targeted recommendations and push notifications between midnight and 6 a.m.

The draft defines a covered minor as an individual under 18 that a covered business "actually knows" is a minor or that the business "labels as a minor pursuant to age assurance methods and rules adopted by the Attorney General." The committee heard that the Attorney General (AG) would develop rules describing "commercially reasonable and technically feasible" age-assurance methods, and that the AG must review and update rules periodically.

The bill sets a statutory effective date of July 1, 2026 for most provisions and directs the AG to begin rulemaking; a separate provision requires the AG to adopt age-assurance rules "on or before July 1, 2027." Segal said the AG's rulemaking authority is broad and likely to include two rule packages: one addressing prohibited design practices and data protections and a second focused on age-assurance methods and privacy protections for age-assurance data.

Committee members raised legal and practical concerns. Several members referenced court challenges to similar laws in other states and the need to avoid First Amendment issues when the law touches content access. Members also pressed for clarity about whether exclusions in the draft — which currently list government entities, HIPAA-covered health records, certain public-health data, journalistic entities as defined in statute, and financial institutions subject to the Gramm-Leach-Bliley Act — are appropriate or too broad. One member asked whether the journalism exclusion originated as a local request; Segal said he would check the record.

Members discussed operational details in the draft: a threshold for when a service is "reasonably likely to be accessed" by minors (the draft uses a 2 percent audience-composition threshold), requirements that default settings be the most private option for covered minors (for example, hiding an account or content from all known adult users unless a minor "expressly and unambiguously" permits a named adult to view it), restrictions against a single control that would make all privacy protections less protective at once, and transparency requirements describing the purpose of algorithmic recommendation systems and inputs that influence recommendations to minors.

On enforcement, Segal said violations would be treated as unfair or deceptive acts under the Vermont Consumer Protection Act, giving the AG authority to investigate and, where appropriate, bring actions. Committee members discussed whether the AG has funding or statutory authority to perform examinations or investigations at the AG's expense and whether examination-like authorities are needed in the statute.

As next steps, the committee did not vote on the draft. Members asked the AG's office to appear at an upcoming meeting to explain how rulemaking and enforcement would operate in practice; Segal said the committee planned to invite "Todd" from the AG's office to a session the following day. The committee also expects to review a new amendment prepared by stakeholders at its next meeting.

The discussion combined statutory drafting detail (definitions, prohibitions, effective dates) with policy questions about constitutional risk, administrative burden on the Attorney General, and operational impacts on businesses that develop online products used by minors.