On August 11, 2026, New Jersey Governor Mikie Sherrill's signed the New Jersey Kids Code Act (Assembly Bill 4015) (“the Act”). The Act imposes a range of privacy-by-default and safety-by-design obligations on online service providers whose services are reasonably likely to be accessed by minors. New Jersey joins a growing list of states - including California, Maryland, Nebraska and Vermont - that have adopted age-appropriate design code legislation, modeled, in part, on the United Kingdom's Age Appropriate Design Code.
The Act takes effect on the first day of the 13th month following enactment, giving covered businesses slightly more than a year to build a compliance program.
Who Is Covered?
The Act applies to any “covered online service provider,” meaning a business that:
- owns, operates, or controls an online service (or derives the majority of its revenue from online services);
- conducts business in New Jersey;
- has an online service that is reasonably likely to be accessed by a child (those under 13) or minor (those 13 and over but under 18); and
- either (1) has annual gross revenue exceeding $25 million (to be adjusted to reflect the percentage change in the Consumer Price Index every two years beginning January 2029), or (2) annually processes the personal data of at least 25,000 consumers or households.
An “online service” is any service, product or feature provided over the Internet that collects, uses, stores, discloses, analyzes, deletes or modifies the personal data of consumers. An online service is “reasonably likely to be accessed” by a covered child or covered minor if the services are:
- “website[s] or online service[s] directed to children” as defined by COPPA;
- determined to have at least 2% of its audience routinely accessing the service comprised of individuals between two and 17 years of age; or
- known, or should have been known, by the covered online service provider to have at least 2% of its audience include individuals two to 17 years of age.
In making the latter assessment, the covered online service provider must not collect or process any personal data not reasonably necessary to provide an online service with which a covered child or covered minor is actively and knowingly engaged.
Businesses and online services that solely provide direct messaging services or products are excluded, as are telecommunications services, broadband internet access services, email services and the sale, delivery or use of a physical device product.
The Act exempts data governed by GLBA, HIPAA, HITECH and certain human-subjects research frameworks.
What Does the Act Require?
The Act's substantive requirements focus on default settings and design practices facing users the provider has actual knowledge are a covered child or covered minor.
An online covered service provider must:
- configure default privacy settings to the most privacy-protective option, including:
- restricting covered adult users (i.e., an individual the covered online service provider has actual knowledge is an adult) from viewing the content of, or media created or posted by, a covered child or covered minor's account, unless: (1) the adult is the child’s or minor’s parent; or (2) the covered child or covered minor unambiguously allowed the covered adult to view their account or chose to make the account public;
- prohibiting direct messaging between a covered child or covered minor and a covered adult unless: (1) the adult is the child’s or minor’s parent; or (2) the covered child or covered minor unambiguously allowed direct messaging;
- prohibiting the display of a covered child’s or covered minor’s location to other users unless the covered child or covered minor has expressly and unambiguously chosen to share their location with a specific user;
- disabling search engine indexing of covered children’s and covered minors’ accounts; and
- disabling all interaction counts (i.e., comments, reactions or reshares) and offering settings to enable or disable specific types of interaction metrics;
- offer individual, accessible privacy settings to a covered child or covered minor that provides the option to block specific users from, at a minimum: (1) accessing or interacting with their media; and/or (2) communicating with them through any means offered by the covered online service provider, including direct messaging;
- establish a prominent and accessible user interface to enable a covered child, covered minor, and parent of a covered child or covered minor to report harms experienced on the online service;
- provide a prominent and accessible mechanism for a covered child or covered minor to request that their account be unpublished or permanently deleted;
- This mechanism cannot take more steps than is required to create an account on the online service; and
- The covered online service provider has 10 business days from submission of such request to unpublish the account and 45 calendar days from submission to permanently delete it;
- if using an algorithmic recommendation system, establish a prominent and accessible user interface to enable a covered child, covered minor and parent of a covered child or covered minor to: (1) communicate preferences about which types of media are to be recommended or blocked; and (2) access, review and make changes to any personal data the covered online service provider uses to determine the output;
- provide a prominent and constant real-time signal to a covered child or covered minor when precise geolocation information is being collected or used; and
- take all reasonable steps to ensure that the covered online service provider’s use of a covered child’s or covered minor’s personal data and the design of a covered design feature do not result in compulsive use.
- restricting covered adult users (i.e., an individual the covered online service provider has actual knowledge is an adult) from viewing the content of, or media created or posted by, a covered child or covered minor's account, unless: (1) the adult is the child’s or minor’s parent; or (2) the covered child or covered minor unambiguously allowed the covered adult to view their account or chose to make the account public;
A covered online service provider is prohibited from, among other things:
- offering a single setting that makes multiple default privacy settings less protective at once;
- prompting any covered child or covered minor to lower their privacy settings, unless the change is necessary to access a service or feature that a covered child, covered minor or parent of a covered child has expressly and unambiguously requested;
- sending notifications to any covered child or covered minor by default or sending notifications to a covered child or covered minor between 10:00 p.m. and 6:00 a.m. and, on a weekday between Labor Day and Memorial Day, between 8:00 a.m. and 4:00 p.m.;
- targeting, or allowing an advertiser to target, an advertisement to a covered child or covered minor for narcotic drugs, tobacco products, gambling or alcohol;
- using dark patterns in regard to a covered child or covered minor; or
- using the personal data of a covered child or covered minor for any reason other than the reason for which the personal data was collected, including to verify the user’s age or select, recommend or prioritize media using an algorithmic recommendation system unless certain circumstances are met.
How Will the Act Be Enforced?
A violation of the Act is deemed an unlawful practice under the New Jersey Consumer Fraud Act, giving the Attorney General authority to investigate and bring civil actions.
The Act also creates a private right of action. A covered child or covered minor injured by a violation, or the Attorney General or a parent acting on the child or minor's behalf, may bring a civil action for any negligent or greater violation of the Act, a court may award a prevailing plaintiffs, as appropriate: $5,000 per violation or treble damages (whichever is greater), punitive damages for reckless or knowing violations, injunctive or declaratory relief, and attorneys' fees and costs.
Search
Recent Posts
Categories
- Behavioral Advertising
- Centre for Information Policy Leadership
- Children’s Privacy
- Cyber Insurance
- Cybersecurity
- Enforcement
- European Union
- Events
- FCRA
- Financial Privacy
- General
- Health Privacy
- Identity Theft
- Information Security
- International
- Marketing
- Multimedia Resources
- Online Privacy
- Security Breach
- U.S. Federal Law
- U.S. State Law
- Workplace Privacy
Tags
- Aaron P. Simpson
- Accountability
- Adequacy
- Advertisement
- Advertising
- Age Appropriate Design Code
- Age Verification
- Alabama
- American Privacy Rights Act
- Anna Pateraki
- Anonymization
- Anti-terrorism
- APEC
- Apple Inc.
- Argentina
- Arkansas
- Article 29 Working Party
- Artificial Intelligence (AI)
- Attorney General
- Audit
- Australia
- Austria
- Automated Decisionmaking
- Baltimore
- Bankruptcy
- Belgium
- Biden Administration
- Big Data
- Binding Corporate Rules
- Biometric Data
- Blockchain
- Bojana Bellamy
- Brazil
- Brexit
- British Columbia
- Brittany Bacon
- Brussels
- Business Associate Agreement
- BYOD
- California
- CalPrivacy
- CAN-SPAM
- Canada
- Cayman Islands
- CCPA
- CCTV
- Centre for Information Policy Leadership (CIPL)
- Chatbot
- Children’s Online Privacy Protection Act (COPPA)
- Chile
- China
- Chinese Taipei
- Christopher Graham
- CIPA
- Class Action
- Clinical Trial
- Cloud
- Cloud Computing
- CNIL
- Colombia
- Colorado
- Committee on Foreign Investment in the United States
- Commodity Futures Trading Commission
- Compliance
- Computer Fraud and Abuse Act
- Congress
- Connecticut
- Consent
- Consent Order
- Consumer Protection
- Consumer Rights
- Cookies
- COPPA
- Coronavirus/COVID-19
- Council of Europe
- Council of the European Union
- Court of Justice of the European Union
- CPPA
- CPRA
- Credit Monitoring
- Credit Report
- Criminal Law
- Critical Infrastructure
- Croatia
- Cross-Border Data Flow
- Cross-Border Data Transfer
- Cyber Attack
- Cybersecurity
- Cybersecurity and Infrastructure Security Agency
- Data Breach
- Data Brokers
- Data Controller
- Data Localization
- Data Minimization
- Data Privacy Framework
- Data Processor
- Data Protection Act
- Data Protection Authority
- Data Protection Impact Assessment
- Data Protection Officer
- Data Security
- Data Transfer
- David Dumont
- David Vladeck
- Deceptive Trade Practices
- Delaware
- Denmark
- Department of Commerce
- Department of Defense
- Department of Health and Human Services
- Department of Homeland Security (DHS)
- Department of Justice
- Department of the Treasury
- Design
- Digital Markets Act
- District of Columbia
- Do Not Call
- Do Not Track
- Dobbs
- Dodd-Frank Act
- DORA
- DPIA
- E-Privacy
- E-Privacy Directive
- Ecuador
- Ed Tech
- Edith Ramirez
- Electronic Communications Privacy Act
- Electronic Privacy Information Center
- Electronic Protected Health Information
- Elizabeth Denham
- Employee Monitoring
- Encryption
- ENISA
- EU Data Protection Directive
- EU General Data Protection Regulation (GDPR)
- EU Member States
- European Commission
- European Data Protection Board
- European Data Protection Supervisor
- European Parliament
- European Union
- Facial Recognition Technology
- FACTA
- Fair Credit Reporting Act
- Fair Information Practice Principles
- Federal Aviation Administration
- Federal Bureau of Investigation
- Federal Communications Commission
- Federal Data Protection Act
- Federal Trade Commission
- FERC
- Financial Data
- FinTech
- Florida
- Food and Drug Administration
- Foreign Intelligence Surveillance Act
- France
- Franchise
- Fred Cate
- Freedom of Information Act
- Freedom of Speech
- Fundamental Rights
- GDPR
- Genetic Data
- Geofencing
- Geolocation
- Geolocation Data
- Georgia
- Germany
- Global Privacy Assembly
- Global Privacy Enforcement Network
- Gramm Leach Bliley Act
- Grok
- Hacker
- Hawaii
- Health Data
- HIPAA
- HITECH Act
- Hong Kong
- House of Representatives
- Hungary
- Illinois
- India
- Indiana
- Indonesia
- Information Commissioners Office
- Information Sharing
- Insurance Provider
- Internal Revenue Service
- International Association of Privacy Professionals
- International Commissioners Office
- Internet
- Internet of Things
- Iowa
- IP Address
- Ireland
- Israel
- Italy
- Jacob Kohnstamm
- Japan
- Jason Beach
- Jay Rockefeller
- Jenna Rode
- Jennifer Stoddart
- Jersey
- Jessica Rich
- John Delionado
- John Edwards
- Kentucky
- Korea
- Large Language Model
- Latin America
- Laura Leonard
- Law Enforcement
- Lawrence Strickling
- Legislation
- Liability
- Lisa Sotto
- Litigation
- Location-Based Services
- London
- Louisiana
- Madrid Resolution
- Maine
- Malaysia
- Maryland
- Massachusetts
- Meta
- Mexico
- Michigan
- Microsoft
- Minnesota
- Missouri
- Mobile
- Mobile App
- Mobile Device
- Montana
- Morocco
- MySpace
- Natascha Gerlach
- National Institute of Standards and Technology
- National Labor Relations Board
- National Science and Technology Council
- National Security
- National Security Agency
- National Telecommunications and Information Administration
- Nebraska
- NEDPA
- Netherlands
- Nevada
- New Hampshire
- New Jersey
- New Mexico
- New York
- New Zealand
- Nigeria
- Ninth Circuit
- North Carolina
- North Dakota
- North Korea
- Norway
- Obama Administration
- OCPA
- OECD
- Office for Civil Rights (OCR)
- Office of Foreign Assets Control
- Ohio
- Oklahoma
- Online Behavioral Advertising
- Online Privacy
- Opt-In Consent
- Opt-Out
- Oregon
- Outsourcing
- Pakistan
- Parental Consent
- Payment Card
- PCI DSS
- Penalty
- Pennsylvania
- Personal Data
- Personal Health Information
- Personal Information
- Personally Identifiable Information
- Peru
- Philippines
- Poland
- PRISM
- Privacy
- Privacy and Information Security Law
- Privacy By Design
- Privacy Notice
- Privacy Policy
- Privacy Rights
- Privacy Rule
- Privacy Shield
- Profiling
- Protected Health Information
- Purpose Limitation
- Ransomware
- Record Retention
- Red Flags Rule
- Rhode Island
- Richard Thomas
- Right to Be Forgotten
- Right to Privacy
- Risk Assessment
- Risk-Based Approach
- ROSCA
- Rosemary Jay
- Russia
- Safe Harbor
- Salesforce
- Sanctions
- Schrems
- Scott Kimpel
- SECURE Data Act
- Securities and Exchange Commission
- Security Rule
- Senate
- Sensitive Data
- Serbia
- Service Provider
- Singapore
- Smart Grid
- Smart Metering
- Social Media
- Social Security Number
- South Africa
- South Carolina
- South Dakota
- South Korea
- Spain
- Spyware
- Standard Contractual Clauses
- State Attorneys General
- Steven Haas
- Stick With Security Series
- Stored Communications Act
- Student Data
- Supreme Court
- Surveillance
- Surveillance Pricing
- Sweden
- Switzerland
- Taiwan
- Targeted Advertising
- Telecommunications
- Telemarketing
- Telephone Consumer Protection Act
- Tennessee
- Terry McAuliffe
- Texas
- Text Message
- Thailand
- Transparency
- Transportation Security Administration
- Trump Administration
- United Arab Emirates
- United Kingdom
- United States
- Unmanned Aircraft Systems
- Uruguay
- Utah
- Vermont
- Video Privacy Protection Act
- Video Surveillance
- Virginia
- Viviane Reding
- Washington
- Whistleblowing
- Wireless Network
- Wiretap
- ZIP Code