FPF Submits Comments to Inform Vermont Age-Appropriate Design Code Act Rulemaking Process
Co-authored by Carisma De Anda, Youth Policy Research Contractor
On October 2, the Future of Privacy Forum (FPF) submitted comments in response to the Vermont Office of the Attorney General’s (the Office’s) rulemaking process for the Vermont Age-Appropriate Design Code (S 69). While a handful of states have signed Age-Appropriate Design Codes into law, Vermont is the first state to propose draft rules and engage stakeholders on implementation guidance under this framework. FPF’s comments seek to ensure that Vermont’s regulations adequately clarify compliance ambiguities while supporting interoperability with existing privacy frameworks.
In June 2025, Vermont enacted its Age-Appropriate Design Code Act. The framework establishes a minimum duty of care for businesses whose digital products and services are reasonably likely to be used by minors, requires high default privacy settings, mandates disclosure of algorithmic recommendation systems, provides a data minimization standard pertaining to minors who are “actively and knowingly engaged” with a service, and provides businesses with the option to implement age assurance to identify minor users. The Vermont Attorney General’s Office launched a formal rulemaking in July 2026 to provide guidance on (1) data processing and design practice prohibitions that lead to “compulsive use” or “impair user autonomy, decision making, or choice,” and (2) “commercially reasonable and technically feasible” age assurance methods, appropriate review processes for age appeals, and additional privacy protections for age assurance data. The law and the adopted rules will take effect on January 1, 2027.
FPF offered seven recommendations related to prohibited data and design practices, personalization and compulsive use, and age assurance for the Office’s consideration:
- Clarify that certain administrative and technical functions are “necessary to provide a service”;
- Align secondary use requirements with existing privacy laws;
- Clarify rules and restrictions related to online service personalization to preserve necessary or beneficial practices;
- Clarify rules on compulsive use by providing metrics for what constitutes unacceptable engagement;
- Clarify that graduated escalation is a factor for businesses to consider when selecting appropriate methods under the rule;
- Define clear technical thresholds or standards to assess what constitutes a “material risk of misclassification”; and
- Consult comparable state agency rulemaking processes for age assurance when considering adjustments or clarifications to the proposed rule.