News

Vermont Attorney General’s Office Seeks Public Comments on Age-Appropriate Design Code Rules

By  |  

On June 12, 2025, Governor Phil Scott signed the Vermont Age-Appropriate Design Code Act (the “Act”) into law.  The Act, which goes into effect on January 1, 2027, imposes obligations on certain businesses that provide online services to minors.  These obligations parallel portions of the recent settlement between Meta Platforms, Inc. and a coalition of State Attorneys General, including limiting the collection of minors’ data, configuring certain default privacy settings, and publishing a privacy policy with specific provisions targeted towards informing minors and their parents of minors’ data privacy rights.  Failure to comply with the Act constitutes a violation of Vermont’s Consumer Protection Act.  9 V.S.A. § 2449h.

On August 12, 2026, the Vermont Attorney General’s Office (the “AGO”) published two proposed rules (each a “Rule” and collectively, the “Rules”) regarding the implementation of Sections 2449g and 2449f of the Act.  Section 2449g outlines prohibited data and design practices.  Section 2449f sets forth required practices for estimating or confirming a user’s age.

The AGO is seeking public feedback on the proposed rules and is holding a series of public hearings in September for stakeholders to weigh in before the rules are finalized.  Members of the public may also submit feedback via an online form.  All comments are due on or before October 2, 2026.

To Whom Does the Act Apply?

The Act applies to “covered businesses.”  A covered business is an entity:

  • that conducts business in Vermont;
  • that generates a majority of its revenue from online services;
  • whose online product or services are reasonably likely to be accessed by a minor;
  • that collects consumers’ personal data or has data collected on its behalf; and
  • that determines the purposes and means of processing consumers’ personal data.  Id. at § 2449a(10).

Key Definitions

Under the Act, an online service is “reasonably likely to be accessed by a minor” if it is directed to children, or if the business knows (or has evidence showing) that at least 2% of its users are between the ages of 2 and 17.  Id. at § 2449a(26).

“Covered minor” means a Vermont resident whom “a covered business actually knows is a minor or labels as a minor pursuant to its age assurance methods.”  Id. at § 2449a(12).  A “minor” is an individual under the age of 18.  Id. at § 2449a(19).

“Personal data” refers to any information that can be reasonably connected to a specific person or device. Id. at § 2449a(21)(A).

Proposed Rule Pursuant to 9 V.S.A. § 2449f

Generally, the Proposed Rule the AGO has promulgated pursuant to 9 V.S.A. § 2449f (“Rule 2449f”) prohibits covered businesses from creating or using data processing or design practices that “create a reasonably foreseeable heightened risk of harm to a covered minor.”  These practices include using features that are designed to increase engagement without user input or designs that remove stopping cues.  When evaluating whether a risk was foreseeable, the AGO may consider “all relevant facts and circumstances,” including internal company processes, research and development, and industry knowledge.  Under Rule 2449f, a “heightened risk of harm” means a risk of hindering a minor’s autonomy and control over when and how the minor engages with the online service.  Rule 2449f also states that businesses may only collect a covered minor’s personal data if such data is “strictly required to provide a specific feature” clearly requested by the minor.  Covered businesses must only retain minors’ data as long as is necessary to provide the service for which it was collected and may not use the data for any other purpose than the purpose for which it was collected.  Rule 2449f explicitly prohibits using personal data to improve algorithms that recommend other content or features and to infer behavioral traits.  For more information, the full text of Rule 2449f can be found here.

Proposed Rule Pursuant to 9 V.S.A. § 2449g

The Proposed Rule the AGO has promulgated pursuant to 9 V.S.A. § 2449g (“Rule 2449g”) regulates the collection of data that is used to determine a user’s age.  Businesses must implement an age assurance process for any online service that is “reasonably likely to be accessed by covered minors.”  Businesses must utilize the least intrusive means for confirming a user’s age that produces reasonably accurate results.  Under Rule 2449g, businesses are obligated to regularly evaluate the accuracy of their age assurance methods.  Businesses must limit the collection of personal data to what is “strictly necessary” to determine whether a user is a minor, and must delete the data as soon as possible after the determination is made.  Prior to deploying an age assurance method, businesses must document how they settled on that method.  The assessment must include, among other things, an evaluation of less intrusive alternatives and an evaluation of accuracy and error rates.  If a business fails to meet the documentation and assessment requirements, it will be presumed to be non-compliant.

Next Steps

Stakeholders should review the two proposed Rules and provide feedback to the AGO by attending a public hearing or filling out the online form.  In order to come into compliance with the Act by January 1, 2027, businesses should determine whether the Act applies to them, and if so, implement internal processes to ensure minors’ data is managed and protected in accordance with the Act.

Please contact Catherine A. Burke (cburke@gravelshea.com) or Eleanor B. Moody (emoody@gravelshea.com) at Gravel & Shea PC if you have questions or would like assistance.