Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Age Appropriate Design topic

No spam. Unsubscribe anytime.

Vermont committee reviews amended S.69 narrowing data rules for minors, setting rulemaking deadlines

3159400 · May 1, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The Vermont House Committee on Commerce and Economic Development reviewed draft 1.3 of S.69 on April 30, hearing a line-by-line presentation from legislative counsel about changes to an age-appropriate design code for online services used by minors.

The Vermont House Committee on Commerce and Economic Development reviewed draft 1.3 of S.69 on April 30, hearing a line-by-line presentation from legislative counsel about changes to an age-appropriate design code for online services used by minors. Rich Stable of the Office of Legislative Council walked members through additions, deletions and wording changes in the bill and explained how the revisions reflect legal and implementation concerns.

The committee heard that the bill now defines an "age range"—"either an interval with an upper and lower age limit or a label indicating age above or below a specific age"—to give covered businesses flexibility when determining whether a user is a covered minor. "This definition comes in later in the bill talking about how companies can determine the age of their users, and this bill allows companies to create these age ranges," Rich Stable said.

The change matters because it affects what personal data companies may collect and retain while doing "age assurance." The draft removes several previously defined categories the drafters labeled "sensitive data," including neural data and precise geolocation, and deletes a separate "controller" definition found in the Senate-passed version. The processor definition was broadened to include processors handling data for other processors or for federal, state, tribal, or local entities.

Committee members were told the deletions and tightening of definitions were largely driven by legal strategy: to narrow the bill’s scope and reduce potential vulnerabilities to court challenges. Stable described many edits as aiming to "sustain a court action" by avoiding overly broad categories that recent litigation has called into question.

Other notable revisions in draft 1.3: it removes a prior exclusion that would have exempted entities processing data for fewer than certain user thresholds and with low revenue (thresholds previously set at 25,000 or 50,000 consumers and $1,000,000 annual revenue); it adds "religion" to a list of protected characteristics in the statute’s nondiscrimination provisions; it requires default privacy settings to be configured at the highest level for covered minors; and it changes transparency requirements for algorithmic recommendation systems from "detailed descriptions" to statements of the system’s purpose and its inputs.

The draft also narrows what counts as "publicly available information," removing an inference-based definition that would have treated deductions from multiple public sources as revealing sensitive data. Stable said the change reflected experience with recent state privacy bills and litigation, and that removing the inference language caused a cascade of deletions for related defined terms.

On operational specifics for covered businesses, the bill preserves an age-assurance framework with these safeguards: collect only personal data strictly necessary for age assurance; promptly delete data gathered for age assurance except for the user’s determined age range; do not combine age-assurance data with other personal data (except the age-range determination); limit disclosure of age-assurance data to processors; and provide an appeal process for users to challenge age determinations. The committee discussed a limitation on push notifications to covered minors between midnight and 6 a.m.; a committee member raised concern that the window might still allow a minor to receive a late-night notification at 11:50 p.m.

The bill sets an effective date of July 1, 2026, and includes two related rulemaking timelines: the Attorney General is directed to adopt rules identifying commercially reasonable methods for age assurance on or before July 1, 2027; a separate rulemaking tied to prohibitions on design practices that create compulsive use is intended to start earlier (committee staff indicated a July 1, 2025 start so the AG can begin rulemaking before the act’s effective date).

Committee members were told the changes reflect both legal caution prompted by litigation in other states and feedback from the committee itself, which questioned prior exemptions and broad definitions. The committee did not take a formal vote on S.69 at the April 30 meeting; staff said the committee will take testimony on other bills and continue deliberations in subsequent sessions.

Ending: Committee staff identified next steps including circulating the redraft for review, soliciting AG input, and taking public testimony in coming meetings. Members also noted separate upcoming committee work on related privacy bills and a schedule to review implementation logistics with the Attorney General and other stakeholders.