A New Design Code Takes Root in the Garden State
On August 11, New Jersey became the newest state to enact a design code law aimed at minor online safety after Governor Sherrill signed A4015, the “New Jersey Age-Appropriate Design Code” (NJAADC). The new law is among the broadest in the country, most closely resembling a blend of the design codes enacted in South Carolina and Nebraska. For example, this law has broad applicability thresholds; relies on strong protective default settings; broadly prohibits dark patterns in online services; restricts personalized recommendation practices and certain design features; and mandates mechanisms for minors to report harms in online services. This law takes effect on September 1, 2027 and includes a private right of action (PRA). This blog post covers the NJAADC’s scope, mandatory safeguards, prohibited practices, reporting mechanisms, and enforcement.
Scope & Key Definitions
Applicability: The NJAADC regulates covered online services, defined as any entity providing an online service in the state that is both reasonably likely to be accessed by a child or minor and meets one of the following annual thresholds: (1) gross revenue in excess of $25M, or (2) processes personal data of 25,000 or more consumers or households. This definition includes any person that controls a legal entity that meets this definition and shares common branding with the legal entity. (§ 3)
While design code frameworks generally draw from the California Consumer Privacy Act (CCPA) by applying to entities that collect and control personal data and meet specified revenue or processing thresholds, the NJAADC departs from the CCPA and earlier AADC models by extending coverage beyond for-profit businesses to any legal entity that owns, operates, controls, or provides an online service and meets the statutory thresholds. Nebraska and South Carolina likewise expand scope to potentially cover non-profits and other non-commercial entities. The NJAADC has a lower data processing threshold than all other design codes—requiring processing of just 25,000 consumers or households in the state.
Exemptions: This bill includes entity-level exemptions for government entities (but only “in the ordinary course of its operation”); direct messaging services or products; telecommunications services; broadband internet access services; and email services. The bill also includes data-level exemptions for data subject to GLBA; certain health records, patient identifying information, and research data; protected health information under HIPAA; and information falling under human subjects protections by the FDA. (§§ 3 & 15)
Key Definitions: The NJAADC aligns knowledge standard definitions with other recently enacted design code laws but diverges in its approach to defining age thresholds. Similar to other laws, the NJAADC defines both actual knowledge (the threshold used to determine whether a covered online service provider knew a user was a minor) and “reasonably likely to be accessed by minors” (the standard applied to determine whether a covered online service provider is within the law’s scope). Actual knowledge is defined similarly to Nebraska’s AADC as all information and inferences the covered online service holds relating to an individual’s age—such as self-identified age or any age attributed to the individual for any purpose, including marketing, advertising, or product development. Notably, age classifications used for marketing take precedence over self-declared age. The “reasonably likely to be accessed by minors” standard is defined most comparably to Vermont’s AADC, and relies on three factors—
- The service, product, or feature is directed to children, as defined by COPPA and its implementing rules;
- The service, product or feature is determined, based on competent and reliable evidence regarding audience composition, to be routinely accessed by an audience that is composed of at least 2% of individuals aged 2-17; or
- The covered online service knew or should have known that at least 2% of the audience includes individuals aged 2-17, provided that, in making this assessment, the business shall not collect or process any personal data that is not reasonably necessary to provide an online service, product, or feature. (§ 3)
While other design code laws typically apply protections to a single age category of minors under 18, the NJAADC adopts a two-tiered age threshold, distinguishing “child,” defined as anyone under the age of 13, from “minor,” defined as anyone between 13 and 17. A covered child or minor is one whom the covered online service has actual knowledge to be a child or minor. Although the bill creates separate “children” and “minors” definitions, none of the obligations apply differently between the two age tiers. Accordingly, this divergence likely has little practical impact on how companies implement these requirements compared to other laws as it is currently written, but future amendments could introduce opportunity for substantive divergences if scoped to only one of the two defined age categories. (§ 3)
Mandatory Safeguards
Like many recent design code laws—including those in South Carolina, Nebraska, and Vermont, the NJAADC requires covered online service providers to configure certain default safety settings for covered children and minors. These settings focus on controlling personalized content recommendations, preventing unwanted contact between minors and unknown adults, and adding friction to certain design features. These settings and features can be adjusted by a covered child/minor or their parent. Key mandatory safeguards include:
- Algorithmic recommendation systems must have a “prominent and accessible” user interface allowing covered children/minors to indicate content recommendation preferences and access, review, and change personal data used to provide algorithmic recommendations. (§ 10(a) & (b))
- For covered online service providers that use algorithmic recommendation systems to prioritize content or contacts between users, the systems may not display the existence of a covered child’s/minor’s account, created or posted media, or allow direct messaging between a covered child/minor and an unknown adult unless the covered child, minor, or their parent “expressly and unambiguously” allows such conduct.
- Covered online service providers are prohibited from displaying a covered child’s/minor’s geolocation information or connected users;
- Covered online service providers need to disable search engine indexing of covered children’s/minor’s accounts and interaction counts (e.g., comments, reactions, and reshares); and
- Covered online service providers need to provide a block option preventing specific users from accessing, interacting with, or communicating with a covered child’s or minor’s account.
Covered online service providers are barred from providing a single setting that makes multiple default settings less protective, or prompting a covered child/minor to disable settings unless it is necessary to provide a service or feature “expressly and unambiguously” requested by the covered child/minor or their parent. (§ 4(a)-(c))
Prohibited Practices
In addition to requiring certain default safeguards, the NJAADC also restricts covered online services from engaging in certain practices related to children’s and minors’ personal data and service design—including through purpose limitations, compulsive design restrictions, limits on data use for algorithmic recommendations, data retention caps, notification restrictions, advertising prohibitions, and dark pattern prohibitions.
- Purpose Limitation: A covered online service may not use a covered child’s/minor’s personal data for any purpose beyond that for which it was collected. There is no consent alternative for this. (§ 7(a)(1))
- Compulsive Design Limits: The covered online service provider must take reasonable steps to ensure that any use of the covered child’s/minor’s personal data and design of covered design features (e.g., infinite scroll, autoplay) do not result in compulsive use. (§ 12(a))
- Algorithmic Recommendation Limits: A covered online service may not use a covered child’s/minor’s personal data for content recommendations unless the prioritization is based on: user settings, a search query, parent-selected settings, a user’s age or age flag, age-appropriate content policies, or a covered child’s/minor’s “express and unambiguous” request to receive certain content. (§ 7(a)(2))
- Data Minimization & Retention: The NJAADC includes substantive data minimization requirements, permitting covered online service providers to process or retain only the minimum amount of data necessary to provide the specific features of an online service with which the covered child/minor is “actively and knowingly engaged.” (§ 7 (b))
- Notification Curfew: Covered online service providers must disable notifications for covered child/minor notifications by default, and, if enabled, may not send notifications during late night hours (i.e., 10pm-6am) or during the school day when school is in session (i.e., 8am-4pm). (§ 6(a) & (b))
- Advertising Restrictions: Covered online service providers may not target covered children/minors with advertisements involving narcotic drugs, tobacco products, gambling, or alcohol. (§ 6(c))
- “Dark Patterns” Prohibitions: Similar to other design code laws, such as Nebraska’s and South Carolina’s, covered online service providers would be broadly prohibited from using “dark patterns” in regard to a covered child/minor. While these requirements are usually tied to business data practices in other laws, like Maryland’s AADC and comprehensive privacy laws, the dark patterns prohibition under this bill is framed in context of the online service as a whole. (§ 6(d))
Reporting & Unpublishing Mechanisms
The NJAADC would require covered online service providers to establish two mechanisms for covered children/minors to use for reporting and account deletion. First, covered online service providers must provide a “prominent and accessible” reporting mechanism for covered children, minors, and their parents to report harms experienced on the online service. Second, covered online service providers must establish an “unpublishing” mechanism that allows covered children/minors to quickly delete their account in fewer steps than it took to create it. This unpublishing tool mirrors the nearly identical requirement established in the Connecticut Data Privacy Act (CTDPA) in its 2023 amendments. (§§ 5 & 9)
Enforcement & Rulemaking
The law includes robust enforcement mechanisms and rulemaking. On enforcement, the NJAADC is enforceable in two ways—first, as a violation of the Consumer Fraud Act (which includes a PRA). Second, the bill also establishes its own PRA through which lawsuits may be brought by either the Attorney General or a parent on behalf of an injured child or minor. For any negligent or greater violations, a court would be authorized to award:
- $5k per violation or treble damages (whichever is greater);
- Punitive damages for reckless and knowing violations;
- Injunctive relief;
- Declaratory relief;
- Attorney’s fees; and
- Litigation costs. (§ 14(a)-(c))
On rulemaking, the Attorney General’s office has broad authority to promulgate rules necessary to guide implementation of these provisions. Additionally, the Commissioner of Health has narrow rulemaking authority to provide guidance on criteria establishing “compulsive use.” New Jersey is the third state to provide agencies with such authority—there is ongoing rulemaking on this topic under Vermont’s AADC and Colorado already approved regulations for implementing the heightened minor protections within the Colorado Privacy Act (CPA). (§ 13)
Conclusion
New Jersey’s approach to age-appropriate design code frameworks changes the model’s formula from a data protection to safety-by design focus, distinguishing it from the regulatory approach central to earlier models. Early-enacted age-appropriate design codes, like those in California and Maryland, revolved around a duty of loyalty to act in the best interests of children, default privacy settings, child data processing restrictions, and data protection impact assessments (DPIAs) primarily evaluating whether data management practices would result in children being subject to harm. The NJAADC’s emphasis on product and service design, personalization practices, and default safeguards governing minors’ platform interactions—alongside core data protections—reflects a broader regulatory shift within U.S. age-appropriate design code frameworks toward a distinct protective-by-design approach. This shift, similarly observed in South Carolina’s law, merits consideration as an emerging framework in its own right.
As age-appropriate design codes continue to coalesce around this new protective-by-design approach, it remains to be seen whether they will continue to face the same constitutional scrutiny that the earlier privacy-by-design frameworks faced. For example, California’s and Maryland’s laws were quickly subject to constitutional challenges that are still ongoing at the time of writing. South Carolina’s law was also challenged in February 2026, and it could prove to be a bellwether for this new protective-by-design model. As states continue to experiment with legal frameworks centered on regulating platform design, continued state adoption of broad protective-by-design frameworks looks likely to continue into the 2027 legislative session.