1 | 1 | | BILL AS INTRODUCED H.210 |
---|
2 | 2 | | 2025 Page 1 of 24 |
---|
3 | 3 | | |
---|
4 | 4 | | |
---|
5 | 5 | | VT LEG #378939 v.1 |
---|
6 | 6 | | H.210 1 |
---|
7 | 7 | | Introduced by Representatives Priestley of Bradford, Marcotte of Coventry, 2 |
---|
8 | 8 | | Arsenault of Williston, Austin of Colchester, Berbeco of 3 |
---|
9 | 9 | | Winooski, Bos-Lun of Westminster, Bosch of Clarendon, 4 |
---|
10 | 10 | | Boutin of Barre City, Boyden of Cambridge, Brown of 5 |
---|
11 | 11 | | Richmond, Burke of Brattleboro, Burrows of West Windsor, 6 |
---|
12 | 12 | | Campbell of St. Johnsbury, Carris-Duncan of Whitingham, 7 |
---|
13 | 13 | | Casey of Montpelier, Chapin of East Montpelier, Cina of 8 |
---|
14 | 14 | | Burlington, Cole of Hartford, Cordes of Bristol, Donahue of 9 |
---|
15 | 15 | | Northfield, Duke of Burlington, Eastes of Guilford, Goldman of 10 |
---|
16 | 16 | | Rockingham, Graning of Jericho, Greer of Bennington, Harple 11 |
---|
17 | 17 | | of Glover, Headrick of Burlington, Holcombe of Norwich, 12 |
---|
18 | 18 | | Krasnow of South Burlington, Lalley of Shelburne, Lipsky of 13 |
---|
19 | 19 | | Stowe, Masland of Thetford, McCann of Montpelier, McGill of 14 |
---|
20 | 20 | | Bridport, Micklus of Milton, Mihaly of Calais, Minier of South 15 |
---|
21 | 21 | | Burlington, Mrowicki of Putney, Nugent of South Burlington, 16 |
---|
22 | 22 | | O’Brien of Tunbridge, Ode of Burlington, Olson of Starksboro, 17 |
---|
23 | 23 | | Pezzo of Colchester, Pouech of Hinesburg, Rachelson of 18 |
---|
24 | 24 | | Burlington, Satcowitz of Randolph, Sibilia of Dover, Stevens of 19 |
---|
25 | 25 | | Waterbury, Surprenant of Barnard, Tomlinson of Winooski, 20 BILL AS INTRODUCED H.210 |
---|
26 | 26 | | 2025 Page 2 of 24 |
---|
27 | 27 | | |
---|
28 | 28 | | |
---|
29 | 29 | | VT LEG #378939 v.1 |
---|
30 | 30 | | Torre of Moretown, Waszazak of Barre City, and White of 1 |
---|
31 | 31 | | Bethel 2 |
---|
32 | 32 | | Referred to Committee on 3 |
---|
33 | 33 | | Date: 4 |
---|
34 | 34 | | Subject: Commerce and trade; protection of personal information; privacy of 5 |
---|
35 | 35 | | minors 6 |
---|
36 | 36 | | Statement of purpose of bill as introduced: This bill proposes to require that 7 |
---|
37 | 37 | | any covered business that develops and provides online services, products, or 8 |
---|
38 | 38 | | features that children are reasonably likely to access must not use abusive or 9 |
---|
39 | 39 | | privacy-invasive design features on children. 10 |
---|
40 | 40 | | An act relating to an age-appropriate design code 11 |
---|
41 | 41 | | It is hereby enacted by the General Assembly of the State of Vermont: 12 |
---|
42 | 42 | | Sec. 1. 9 V.S.A. chapter 62, subchapter 6 is added to read: 13 |
---|
43 | 43 | | Subchapter 6. Vermont Age-Appropriate Design Code Act 14 |
---|
44 | 44 | | § 2449a. DEFINITIONS 15 |
---|
45 | 45 | | As used in this subchapter: 16 |
---|
46 | 46 | | (1)(A) “Affiliate” means a legal entity that shares common branding 17 |
---|
47 | 47 | | with another legal entity or controls, is controlled by, or is under common 18 |
---|
48 | 48 | | control with another legal entity. 19 BILL AS INTRODUCED H.210 |
---|
49 | 49 | | 2025 Page 3 of 24 |
---|
50 | 50 | | |
---|
51 | 51 | | |
---|
52 | 52 | | VT LEG #378939 v.1 |
---|
53 | 53 | | (B) As used in subdivision (A) of this subdivision (1), “control” or 1 |
---|
54 | 54 | | “controlled” means: 2 |
---|
55 | 55 | | (i) ownership of, or the power to vote, more than 50 percent of the 3 |
---|
56 | 56 | | outstanding shares of any class of voting security of a company; 4 |
---|
57 | 57 | | (ii) control in any manner over the election of a majority of the 5 |
---|
58 | 58 | | directors or of individuals exercising similar functions; or 6 |
---|
59 | 59 | | (iii) the power to exercise controlling influence over the 7 |
---|
60 | 60 | | management of a company. 8 |
---|
61 | 61 | | (2) “Age assurance” encompasses a range of methods used to determine, 9 |
---|
62 | 62 | | estimate, or communicate the age or an age range of an online user. 10 |
---|
63 | 63 | | (3) “Algorithmic recommendation system” means a system that uses an 11 |
---|
64 | 64 | | algorithm to select, filter, and arrange media on a covered business’s website 12 |
---|
65 | 65 | | for the purpose of selecting, recommending, or prioritizing media for a user. 13 |
---|
66 | 66 | | (4)(A) “Biometric data” means data generated from the technological 14 |
---|
67 | 67 | | processing of an individual’s unique biological, physical, or physiological 15 |
---|
68 | 68 | | characteristics that allow or confirm the unique identification of the consumer, 16 |
---|
69 | 69 | | including: 17 |
---|
70 | 70 | | (i) iris or retina scans; 18 |
---|
71 | 71 | | (ii) fingerprints; 19 |
---|
72 | 72 | | (iii) facial or hand mapping, geometry, or templates; 20 |
---|
73 | 73 | | (iv) vein patterns; 21 BILL AS INTRODUCED H.210 |
---|
74 | 74 | | 2025 Page 4 of 24 |
---|
75 | 75 | | |
---|
76 | 76 | | |
---|
77 | 77 | | VT LEG #378939 v.1 |
---|
78 | 78 | | (v) voice prints or vocal biomarkers; and 1 |
---|
79 | 79 | | (vi) gait or personally identifying physical movement or patterns. 2 |
---|
80 | 80 | | (B) “Biometric data” does not include: 3 |
---|
81 | 81 | | (i) a digital or physical photograph; 4 |
---|
82 | 82 | | (ii) an audio or video recording; or 5 |
---|
83 | 83 | | (iii) any data generated from a digital or physical photograph, or 6 |
---|
84 | 84 | | an audio or video recording, unless such data is generated to identify a specific 7 |
---|
85 | 85 | | individual. 8 |
---|
86 | 86 | | (5) “Business associate” has the same meaning as in HIPAA. 9 |
---|
87 | 87 | | (6) “Collect” means buying, renting, gathering, obtaining, receiving, or 10 |
---|
88 | 88 | | accessing any personal data by any means. This includes receiving data from 11 |
---|
89 | 89 | | the consumer, either actively or passively, or by observing the consumer’s 12 |
---|
90 | 90 | | behavior. 13 |
---|
91 | 91 | | (7) “Compulsive use” means the repetitive use of a covered business’s 14 |
---|
92 | 92 | | service that materially disrupts one or more major life activities of a minor, 15 |
---|
93 | 93 | | including sleeping, eating, learning, reading, concentrating, communicating, or 16 |
---|
94 | 94 | | working. 17 |
---|
95 | 95 | | (8)(A) “Consumer” means an individual who is a resident of the State. 18 |
---|
96 | 96 | | (B) “Consumer” does not include an individual acting in a 19 |
---|
97 | 97 | | commercial or employment context or as an employee, owner, director, officer, 20 |
---|
98 | 98 | | or contractor of a company, partnership, sole proprietorship, nonprofit, or 21 BILL AS INTRODUCED H.210 |
---|
99 | 99 | | 2025 Page 5 of 24 |
---|
100 | 100 | | |
---|
101 | 101 | | |
---|
102 | 102 | | VT LEG #378939 v.1 |
---|
103 | 103 | | government agency whose communications or transactions with the covered 1 |
---|
104 | 104 | | business occur solely within the context of that individual’s role with the 2 |
---|
105 | 105 | | company, partnership, sole proprietorship, nonprofit, or government agency. 3 |
---|
106 | 106 | | (9) “Consumer health data” means any personal data that a controller 4 |
---|
107 | 107 | | uses to identify a consumer’s physical or mental health condition or diagnosis, 5 |
---|
108 | 108 | | including gender-affirming health data and reproductive or sexual health data. 6 |
---|
109 | 109 | | (10) “Controller” means a person who, alone or jointly with others, 7 |
---|
110 | 110 | | determines the purpose and means of processing personal data. 8 |
---|
111 | 111 | | (11) “Covered business” means a sole proprietorship, partnership, 9 |
---|
112 | 112 | | limited liability company, corporation, association, other legal entity, or an 10 |
---|
113 | 113 | | affiliate thereof, that conducts business in this State and whose online products, 11 |
---|
114 | 114 | | services, or features are reasonably likely to be accessed by a minor and that: 12 |
---|
115 | 115 | | (A) collects consumers’ personal data or has consumers’ personal 13 |
---|
116 | 116 | | data collected on its behalf by a processor; and 14 |
---|
117 | 117 | | (B) alone or jointly with others determines the purposes and means of 15 |
---|
118 | 118 | | the processing of consumers personal data. 16 |
---|
119 | 119 | | (12) “Covered entity” has the same meaning as in HIPAA. 17 |
---|
120 | 120 | | (13) “Covered minor” is a consumer who a covered business actually 18 |
---|
121 | 121 | | knows is a minor or labels as a minor pursuant to age assurance methods in 19 |
---|
122 | 122 | | rules adopted by the Attorney General. 20 BILL AS INTRODUCED H.210 |
---|
123 | 123 | | 2025 Page 6 of 24 |
---|
124 | 124 | | |
---|
125 | 125 | | |
---|
126 | 126 | | VT LEG #378939 v.1 |
---|
127 | 127 | | (14) “Default” means a preselected option adopted by the covered 1 |
---|
128 | 128 | | business for the online service, product, or feature. 2 |
---|
129 | 129 | | (15) “De-identified data” means data that does not identify and cannot 3 |
---|
130 | 130 | | reasonably be used to infer information about, or otherwise be linked to, an 4 |
---|
131 | 131 | | identified or identifiable individual, or a device linked to the individual, if the 5 |
---|
132 | 132 | | covered business that possesses the data: 6 |
---|
133 | 133 | | (A)(i) takes reasonable measures to ensure that the data cannot be 7 |
---|
134 | 134 | | used to reidentify an identified or identifiable individual or be associated with 8 |
---|
135 | 135 | | an individual or device that identifies or is linked or reasonably linkable to an 9 |
---|
136 | 136 | | individual or household; and 10 |
---|
137 | 137 | | (ii) for purposes of this subdivision (A), “reasonable measures” 11 |
---|
138 | 138 | | shall include the de-identification requirements set forth under 45 C.F.R. 12 |
---|
139 | 139 | | § 164.514 (other requirements relating to uses and disclosures of protected 13 |
---|
140 | 140 | | health information); 14 |
---|
141 | 141 | | (B) publicly commits to process the data only in a de-identified 15 |
---|
142 | 142 | | fashion and not attempt to reidentify the data; and 16 |
---|
143 | 143 | | (C) contractually obligates any recipients of the data to comply with 17 |
---|
144 | 144 | | all provisions of this subchapter. 18 |
---|
145 | 145 | | (16) “Derived data” means data that is created by the derivation of 19 |
---|
146 | 146 | | information, data, assumptions, correlations, inferences, predictions, or 20 BILL AS INTRODUCED H.210 |
---|
147 | 147 | | 2025 Page 7 of 24 |
---|
148 | 148 | | |
---|
149 | 149 | | |
---|
150 | 150 | | VT LEG #378939 v.1 |
---|
151 | 151 | | conclusions from facts, evidence, or another source of information or data 1 |
---|
152 | 152 | | about a minor or a minor’s device. 2 |
---|
153 | 153 | | (17) “Genetic data” means any data, regardless of its format, that results 3 |
---|
154 | 154 | | from the analysis of a biological sample of an individual, or from another 4 |
---|
155 | 155 | | source enabling equivalent information to be obtained, and concerns genetic 5 |
---|
156 | 156 | | material, including deoxyribonucleic acids (DNA), ribonucleic acids (RNA), 6 |
---|
157 | 157 | | genes, chromosomes, alleles, genomes, alterations or modifications to DNA or 7 |
---|
158 | 158 | | RNA, single nucleotide polymorphisms (SNPs), epigenetic markers, 8 |
---|
159 | 159 | | uninterpreted data that results from analysis of the biological sample or other 9 |
---|
160 | 160 | | source, and any information extrapolated, derived, or inferred therefrom. 10 |
---|
161 | 161 | | (18) “Identified or identifiable individual” means an individual who can 11 |
---|
162 | 162 | | be readily identified, directly or indirectly, including by reference to an 12 |
---|
163 | 163 | | identifier such as a name, an identification number, specific geolocation data, 13 |
---|
164 | 164 | | or an online identifier. 14 |
---|
165 | 165 | | (19) “Known adult” is a consumer who a covered business actually 15 |
---|
166 | 166 | | knows is an adult or labels as an adult pursuant to age assurance methods in 16 |
---|
167 | 167 | | rules adopted by the Attorney General. 17 |
---|
168 | 168 | | (20) “Minor” means an individual under 18 years of age who is a 18 |
---|
169 | 169 | | resident of the State. 19 |
---|
170 | 170 | | (21) “Neural data” means information that is collected through 20 |
---|
171 | 171 | | biosensors and that could be processed to infer or predict mental states. 21 BILL AS INTRODUCED H.210 |
---|
172 | 172 | | 2025 Page 8 of 24 |
---|
173 | 173 | | |
---|
174 | 174 | | |
---|
175 | 175 | | VT LEG #378939 v.1 |
---|
176 | 176 | | (22) “Online service, product, or feature” means a digital product that is 1 |
---|
177 | 177 | | accessible to the public via the internet, including a website or application, and 2 |
---|
178 | 178 | | does not mean any of the following: 3 |
---|
179 | 179 | | (A) telecommunications service, as defined in 47 U.S.C. § 153; 4 |
---|
180 | 180 | | (B) a broadband internet access service as defined in 47 C.F.R. 5 |
---|
181 | 181 | | § 54.400; or 6 |
---|
182 | 182 | | (C) the sale, delivery, or use of a physical product. 7 |
---|
183 | 183 | | (23)(A) “Personal data” means any information, including derived data 8 |
---|
184 | 184 | | and unique identifiers, that is linked or reasonably linkable to an identified or 9 |
---|
185 | 185 | | identifiable individual or to a device that identifies, is linked to, or is 10 |
---|
186 | 186 | | reasonably linkable to one or more identified or identifiable individuals in a 11 |
---|
187 | 187 | | household. 12 |
---|
188 | 188 | | (B) Personal data does not include de-identified data or publicly 13 |
---|
189 | 189 | | available information. 14 |
---|
190 | 190 | | (24)(A) “Precise geolocation data” means information derived from 15 |
---|
191 | 191 | | technology that reveals the past or present physical location of a consumer or 16 |
---|
192 | 192 | | device that identifies or is linked or reasonably linkable to one or more 17 |
---|
193 | 193 | | consumers with precision and accuracy within a radius of 1,850 feet. 18 |
---|
194 | 194 | | (B) “Precise geolocation data” does not include: 19 |
---|
195 | 195 | | (i) the content of communications; 20 BILL AS INTRODUCED H.210 |
---|
196 | 196 | | 2025 Page 9 of 24 |
---|
197 | 197 | | |
---|
198 | 198 | | |
---|
199 | 199 | | VT LEG #378939 v.1 |
---|
200 | 200 | | (ii) data generated by or connected to an advanced utility metering 1 |
---|
201 | 201 | | infrastructure system; 2 |
---|
202 | 202 | | (iii) a photograph, or metadata associated with a photograph or 3 |
---|
203 | 203 | | video, that cannot be linked to an individual; or 4 |
---|
204 | 204 | | (iv) data generated by equipment used by a utility company. 5 |
---|
205 | 205 | | (25) “Process” or “processing” means any operation or set of operations 6 |
---|
206 | 206 | | performed, whether by manual or automated means, on personal data or on sets 7 |
---|
207 | 207 | | of personal data, such as the collection, use, storage, disclosure, analysis, 8 |
---|
208 | 208 | | deletion, modification, or otherwise handling of personal data. 9 |
---|
209 | 209 | | (26) “Processor” means a person who processes personal data on behalf 10 |
---|
210 | 210 | | of a covered business. 11 |
---|
211 | 211 | | (27) “Profiling” means any form of automated processing performed on 12 |
---|
212 | 212 | | personal data to evaluate, analyze, or predict personal aspects related to an 13 |
---|
213 | 213 | | identified or identifiable individual’s economic situation, health, personal 14 |
---|
214 | 214 | | preferences, interests, reliability, behavior, location, or movements. 15 |
---|
215 | 215 | | (28)(A) “Publicly available information” means information that: 16 |
---|
216 | 216 | | (i) is made available through federal, state, or local government 17 |
---|
217 | 217 | | records; or 18 |
---|
218 | 218 | | (ii) a controller has a reasonable basis to believe that the consumer 19 |
---|
219 | 219 | | has lawfully made available to the general public. 20 |
---|
220 | 220 | | (B) “Publicly available information” does not include: 21 BILL AS INTRODUCED H.210 |
---|
221 | 221 | | 2025 Page 10 of 24 |
---|
222 | 222 | | |
---|
223 | 223 | | |
---|
224 | 224 | | VT LEG #378939 v.1 |
---|
225 | 225 | | (i) biometric data collected by a business about a consumer 1 |
---|
226 | 226 | | without the consumer’s knowledge; 2 |
---|
227 | 227 | | (ii) information that is collated and combined to create a consumer 3 |
---|
228 | 228 | | profile that is made available to a user of a publicly available website either in 4 |
---|
229 | 229 | | exchange for payment or free of charge; 5 |
---|
230 | 230 | | (iii) information that is made available for sale; 6 |
---|
231 | 231 | | (iv) an inference that is generated from the information described 7 |
---|
232 | 232 | | in subdivision (ii) or (iii) of this subdivision (28)(B); 8 |
---|
233 | 233 | | (v) any obscene visual depiction, as defined in 18 U.S.C. § 1460; 9 |
---|
234 | 234 | | (vi) any inference made exclusively from multiple independent 10 |
---|
235 | 235 | | sources of publicly available information that reveals sensitive data with 11 |
---|
236 | 236 | | respect to a consumer; 12 |
---|
237 | 237 | | (vii) personal data that is created through the combination of 13 |
---|
238 | 238 | | personal data with publicly available information; 14 |
---|
239 | 239 | | (viii) genetic data, unless otherwise made publicly available by the 15 |
---|
240 | 240 | | consumer to whom the information pertains; 16 |
---|
241 | 241 | | (ix) information provided by a consumer on a website or online 17 |
---|
242 | 242 | | service made available to all members of the public, for free or for a fee, where 18 |
---|
243 | 243 | | the consumer has maintained a reasonable expectation of privacy in the 19 |
---|
244 | 244 | | information, such as by restricting the information to a specific audience; or 20 BILL AS INTRODUCED H.210 |
---|
245 | 245 | | 2025 Page 11 of 24 |
---|
246 | 246 | | |
---|
247 | 247 | | |
---|
248 | 248 | | VT LEG #378939 v.1 |
---|
249 | 249 | | (x) intimate images, authentic or computer-generated, known to be 1 |
---|
250 | 250 | | nonconsensual. 2 |
---|
251 | 251 | | (29) “Reasonably likely to be accessed” means an online service, 3 |
---|
252 | 252 | | product, or feature that is reasonably likely to be accessed by a covered minor 4 |
---|
253 | 253 | | based on any of the following indicators: 5 |
---|
254 | 254 | | (A) the online service, product, or feature is directed to children, as 6 |
---|
255 | 255 | | defined by the Children’s Online Privacy Protection Act, 15 U.S.C. §§ 6501–7 |
---|
256 | 256 | | 6506 and the Federal Trade Commission rules implementing that Act; 8 |
---|
257 | 257 | | (B) the online service, product, or feature is determined, based on 9 |
---|
258 | 258 | | competent and reliable evidence regarding audience composition, to be 10 |
---|
259 | 259 | | routinely accessed by an audience that is composed of at least two percent 11 |
---|
260 | 260 | | minors two through 17 years of age; 12 |
---|
261 | 261 | | (C) the online service, product, or feature contains advertisements 13 |
---|
262 | 262 | | marketed to minors; 14 |
---|
263 | 263 | | (D) the audience of the online service, product, or feature is 15 |
---|
264 | 264 | | determined, based on internal company research, to be composed of at least 16 |
---|
265 | 265 | | two percent minors two through 17 years of age; or 17 |
---|
266 | 266 | | (E) the covered business knew or should have known that at least two 18 |
---|
267 | 267 | | percent of the audience of the online service, product, or feature includes 19 |
---|
268 | 268 | | minors two through 17 years of age, provided that, in making this assessment, 20 |
---|
269 | 269 | | the business shall not collect or process any personal data that is not reasonably 21 BILL AS INTRODUCED H.210 |
---|
270 | 270 | | 2025 Page 12 of 24 |
---|
271 | 271 | | |
---|
272 | 272 | | |
---|
273 | 273 | | VT LEG #378939 v.1 |
---|
274 | 274 | | necessary to provide an online service, product, or feature with which a minor 1 |
---|
275 | 275 | | is actively and knowingly engaged. 2 |
---|
276 | 276 | | (30) “Sensitive data” means personal data that: 3 |
---|
277 | 277 | | (A) reveals a consumer’s government-issued identifier, such as a 4 |
---|
278 | 278 | | Social Security number, passport number, state identification card, or driver’s 5 |
---|
279 | 279 | | license number, that is not required by law to be publicly displayed; 6 |
---|
280 | 280 | | (B) reveals a consumer’s racial or ethnic origin; national origin; 7 |
---|
281 | 281 | | citizenship or immigration status; religious or philosophical beliefs; a mental 8 |
---|
282 | 282 | | or physical health condition, diagnosis, disability or treatment; status as 9 |
---|
283 | 283 | | pregnant; income level or indebtedness; or union membership; 10 |
---|
284 | 284 | | (C) reveals a consumer’s sexual orientation, sex life, sexuality, or 11 |
---|
285 | 285 | | status as transgender or nonbinary; 12 |
---|
286 | 286 | | (D) reveals a consumer’s status as a victim of a crime; 13 |
---|
287 | 287 | | (E) is a consumer’s tax return and account number, financial account 14 |
---|
288 | 288 | | log-in, financial account, debit card number, or credit card number in 15 |
---|
289 | 289 | | combination with any required security or access code, password, or 16 |
---|
290 | 290 | | credentials allowing access to an account; 17 |
---|
291 | 291 | | (F) is consumer health data; 18 |
---|
292 | 292 | | (G) is collected and analyzed concerning consumer health data that 19 |
---|
293 | 293 | | describes or reveals a past, present, or future mental or physical health 20 |
---|
294 | 294 | | condition, treatment, disability, or diagnosis, including pregnancy, to the extent 21 BILL AS INTRODUCED H.210 |
---|
295 | 295 | | 2025 Page 13 of 24 |
---|
296 | 296 | | |
---|
297 | 297 | | |
---|
298 | 298 | | VT LEG #378939 v.1 |
---|
299 | 299 | | the personal data is used by the controller for a purpose other than to identify a 1 |
---|
300 | 300 | | specific consumer’s physical or mental health condition or diagnosis; 2 |
---|
301 | 301 | | (H) is biometric or genetic data; 3 |
---|
302 | 302 | | (I) is collected from a covered minor; 4 |
---|
303 | 303 | | (J) is precise geolocation data; 5 |
---|
304 | 304 | | (K) are keystrokes; 6 |
---|
305 | 305 | | (L) is driving behavior; or 7 |
---|
306 | 306 | | (M) is neural data. 8 |
---|
307 | 307 | | (31)(A) “Social media platform” means a public or semipublic internet-9 |
---|
308 | 308 | | based service or application that is primarily intended to connect and allow a 10 |
---|
309 | 309 | | user to socially interact within such service or application and enables a user 11 |
---|
310 | 310 | | to: 12 |
---|
311 | 311 | | (i) construct a public or semipublic profile for the purposes of 13 |
---|
312 | 312 | | signing into and using such service or application; 14 |
---|
313 | 313 | | (ii) populate a public list of other users with whom the user shares 15 |
---|
314 | 314 | | a social connection within such service or application; or 16 |
---|
315 | 315 | | (iii) create or post content that is viewable by other users, 17 |
---|
316 | 316 | | including content on message boards and in chat rooms, and that presents the 18 |
---|
317 | 317 | | user with content generated by other users. 19 |
---|
318 | 318 | | (B) “Social media platform” does not mean a public or semipublic 20 |
---|
319 | 319 | | internet-based service or application that: 21 BILL AS INTRODUCED H.210 |
---|
320 | 320 | | 2025 Page 14 of 24 |
---|
321 | 321 | | |
---|
322 | 322 | | |
---|
323 | 323 | | VT LEG #378939 v.1 |
---|
324 | 324 | | (i) exclusively provides email or direct messaging services; 1 |
---|
325 | 325 | | (ii) primarily consists of news, sports, entertainment, interactive 2 |
---|
326 | 326 | | video games, electronic commerce, or content that is preselected by the 3 |
---|
327 | 327 | | provider for which any interactive functionality is incidental to, directly related 4 |
---|
328 | 328 | | to, or dependent on the provision of such content; or 5 |
---|
329 | 329 | | (iii) is used by and under the direction of an educational entity, 6 |
---|
330 | 330 | | including a learning management system or a student engagement program. 7 |
---|
331 | 331 | | (32) “Third party” means a natural or legal person, public authority, 8 |
---|
332 | 332 | | agency, or body other than the covered minor or the covered business. 9 |
---|
333 | 333 | | § 2449b. EXCLUSIONS 10 |
---|
334 | 334 | | This subchapter does not apply to: 11 |
---|
335 | 335 | | (1) a federal, state, tribal, or local government entity in the ordinary 12 |
---|
336 | 336 | | course of its operation; 13 |
---|
337 | 337 | | (2) protected health information that a covered entity or business 14 |
---|
338 | 338 | | associate processes in accordance with, or documents that a covered entity or 15 |
---|
339 | 339 | | business associate creates for the purpose of complying with, HIPAA; 16 |
---|
340 | 340 | | (3) information used only for public health activities and purposes 17 |
---|
341 | 341 | | described in 45 C.F.R. § 164.512; 18 |
---|
342 | 342 | | (4) information that identifies a consumer in connection with: 19 |
---|
343 | 343 | | (A) activities that are subject to the Federal Policy for the Protection 20 |
---|
344 | 344 | | of Human Subjects as set forth in 45 C.F.R. Part 46; 21 BILL AS INTRODUCED H.210 |
---|
345 | 345 | | 2025 Page 15 of 24 |
---|
346 | 346 | | |
---|
347 | 347 | | |
---|
348 | 348 | | VT LEG #378939 v.1 |
---|
349 | 349 | | (B) research on human subjects undertaken in accordance with good 1 |
---|
350 | 350 | | clinical practice guidelines issued by the International Council for 2 |
---|
351 | 351 | | Harmonisation of Technical Requirements for Pharmaceuticals for Human 3 |
---|
352 | 352 | | Use; 4 |
---|
353 | 353 | | (C) activities that are subject to the protections provided in 21 C.F.R. 5 |
---|
354 | 354 | | Part 50 and 21 C.F.R. Part 56; or 6 |
---|
355 | 355 | | (D) research conducted in accordance with the requirements set forth 7 |
---|
356 | 356 | | in subdivisions (A)–(C) of this subdivision (4) or otherwise in accordance with 8 |
---|
357 | 357 | | State or federal law; and 9 |
---|
358 | 358 | | (5) an entity whose primary purpose is journalism as defined in 10 |
---|
359 | 359 | | 12 V.S.A. § 1615(a)(2) and that has a majority of its workforce consisting of 11 |
---|
360 | 360 | | individuals engaging in journalism. 12 |
---|
361 | 361 | | § 2449c. MINIMUM DUTY OF CARE 13 |
---|
362 | 362 | | (a) A covered business that processes a covered minor’s data in any 14 |
---|
363 | 363 | | capacity owes a minimum duty of care to the covered minor. 15 |
---|
364 | 364 | | (b) As used in this subchapter, “a minimum duty of care” means the use of 16 |
---|
365 | 365 | | the personal data of a covered minor and the design of an online service, 17 |
---|
366 | 366 | | product, or feature will not result in: 18 |
---|
367 | 367 | | (1) reasonably foreseeable emotional distress as defined in 13 V.S.A. 19 |
---|
368 | 368 | | § 1061(2) to a covered minor; 20 BILL AS INTRODUCED H.210 |
---|
369 | 369 | | 2025 Page 16 of 24 |
---|
370 | 370 | | |
---|
371 | 371 | | |
---|
372 | 372 | | VT LEG #378939 v.1 |
---|
373 | 373 | | (2) reasonably foreseeable compulsive use of the online service, 1 |
---|
374 | 374 | | product, or feature by a covered minor; or 2 |
---|
375 | 375 | | (3) discrimination against a covered minor based upon race, ethnicity, 3 |
---|
376 | 376 | | sex, disability, sexual orientation, gender identity, gender expression, or 4 |
---|
377 | 377 | | national origin. 5 |
---|
378 | 378 | | (c) The content of the media viewed by a covered minor shall not establish 6 |
---|
379 | 379 | | emotional distress or compulsive use as those terms are used in subsection (b) 7 |
---|
380 | 380 | | of this section. 8 |
---|
381 | 381 | | (d) Nothing in this section shall be construed to require a covered business 9 |
---|
382 | 382 | | to prevent or preclude a covered minor from accessing or viewing any piece of 10 |
---|
383 | 383 | | media or category of media. 11 |
---|
384 | 384 | | § 2449d. REQUIRED DEFAULT PRIVACY SETTINGS AND TOOLS 12 |
---|
385 | 385 | | (a) Default privacy settings. 13 |
---|
386 | 386 | | (1) A covered business shall configure all default privacy settings 14 |
---|
387 | 387 | | provided to a covered minor through the online service, product, or feature to 15 |
---|
388 | 388 | | the highest level of privacy, including the following default settings: 16 |
---|
389 | 389 | | (A) not displaying the existence of the covered minor’s social media 17 |
---|
390 | 390 | | account to any known adult user unless the covered minor has expressly and 18 |
---|
391 | 391 | | unambiguously allowed a specific known adult user to view their account or 19 |
---|
392 | 392 | | has expressly and unambiguously chosen to make their account’s existence 20 |
---|
393 | 393 | | public; 21 BILL AS INTRODUCED H.210 |
---|
394 | 394 | | 2025 Page 17 of 24 |
---|
395 | 395 | | |
---|
396 | 396 | | |
---|
397 | 397 | | VT LEG #378939 v.1 |
---|
398 | 398 | | (B) not displaying media created or posted by the covered minor on 1 |
---|
399 | 399 | | a social media platform to any known adult user unless the covered minor has 2 |
---|
400 | 400 | | expressly and unambiguously allowed a specific known adult user to view their 3 |
---|
401 | 401 | | media or has expressly and unambiguously chosen to make their media 4 |
---|
402 | 402 | | publicly available; 5 |
---|
403 | 403 | | (C) not permitting any known adult users to like, comment on, or 6 |
---|
404 | 404 | | otherwise provide feedback on the covered minor’s media on a social media 7 |
---|
405 | 405 | | platform unless the covered minor has expressly and unambiguously allowed a 8 |
---|
406 | 406 | | specific known adult user to do so; 9 |
---|
407 | 407 | | (D) not permitting direct messaging on a social media platform 10 |
---|
408 | 408 | | between the covered minor and any known adult user unless the covered minor 11 |
---|
409 | 409 | | has expressly and unambiguously decided to allow direct messaging with a 12 |
---|
410 | 410 | | specific known adult user; 13 |
---|
411 | 411 | | (E) not displaying the covered minor’s location to other users, unless 14 |
---|
412 | 412 | | the covered minor expressly and unambiguously shares their location with a 15 |
---|
413 | 413 | | specific user; 16 |
---|
414 | 414 | | (F) not displaying the users connected to the covered minor on a 17 |
---|
415 | 415 | | social media platform unless the covered minor expressly and unambiguously 18 |
---|
416 | 416 | | chooses to share the information with a specific user; 19 |
---|
417 | 417 | | (G) disabling search engine indexing of the covered minor’s account 20 |
---|
418 | 418 | | profile; and 21 BILL AS INTRODUCED H.210 |
---|
419 | 419 | | 2025 Page 18 of 24 |
---|
420 | 420 | | |
---|
421 | 421 | | |
---|
422 | 422 | | VT LEG #378939 v.1 |
---|
423 | 423 | | (H) not sending push notifications to the covered minors. 1 |
---|
424 | 424 | | (2) A covered business shall not: 2 |
---|
425 | 425 | | (A) provide a covered minor with a single setting that makes all of 3 |
---|
426 | 426 | | the default privacy settings less protective at once; or 4 |
---|
427 | 427 | | (B) request or prompt a covered minor to make their privacy settings 5 |
---|
428 | 428 | | less protective, unless the change is strictly necessary for the covered minor to 6 |
---|
429 | 429 | | access a service or feature they have expressly and unambiguously requested. 7 |
---|
430 | 430 | | (b) Timely deletion of account. A covered business shall: 8 |
---|
431 | 431 | | (1) provide a prominent, accessible, and responsive tool to allow a 9 |
---|
432 | 432 | | covered minor to request the covered minor’s social media account be 10 |
---|
433 | 433 | | unpublished or deleted; and 11 |
---|
434 | 434 | | (2) honor that request not later than 15 days after a covered business 12 |
---|
435 | 435 | | receives the request. 13 |
---|
436 | 436 | | § 2449e. TRANSPARENCY 14 |
---|
437 | 437 | | (a) A covered business shall prominently and clearly provide on their 15 |
---|
438 | 438 | | website or mobile application: 16 |
---|
439 | 439 | | (1) the covered business’ privacy information, terms of service, policies, 17 |
---|
440 | 440 | | and community standards; 18 |
---|
441 | 441 | | (2) detailed descriptions of each algorithmic recommendation system in 19 |
---|
442 | 442 | | use by the covered business, including the factors used by the algorithmic 20 |
---|
443 | 443 | | recommendation system and how each factor: 21 BILL AS INTRODUCED H.210 |
---|
444 | 444 | | 2025 Page 19 of 24 |
---|
445 | 445 | | |
---|
446 | 446 | | |
---|
447 | 447 | | VT LEG #378939 v.1 |
---|
448 | 448 | | (A) is measured or determined; 1 |
---|
449 | 449 | | (B) uses the personal data of covered minors; 2 |
---|
450 | 450 | | (C) influences the recommendation issued by the system; and 3 |
---|
451 | 451 | | (D) is weighed relative to the other factors listed in this subdivision 4 |
---|
452 | 452 | | (2); and 5 |
---|
453 | 453 | | (3) descriptions, for every feature of the service that uses the personal 6 |
---|
454 | 454 | | data of covered minors, of: 7 |
---|
455 | 455 | | (A) the purpose of the service feature; 8 |
---|
456 | 456 | | (B) the personal data collected by the service feature; 9 |
---|
457 | 457 | | (C) the personal data used by the service feature; 10 |
---|
458 | 458 | | (D) how the personal data is used by the service feature; 11 |
---|
459 | 459 | | (E) any personal data transferred to or shared with a processor or 12 |
---|
460 | 460 | | third party by the service feature, the identity of the processor or third party, 13 |
---|
461 | 461 | | and the purpose of the transfer or sharing; and 14 |
---|
462 | 462 | | (F) how long the personal data is retained. 15 |
---|
463 | 463 | | § 2449f. PROHIBITED DATA AND DESIGN PRACTICES 16 |
---|
464 | 464 | | (a) Data privacy. A covered business shall not: 17 |
---|
465 | 465 | | (1) collect, sell, share, or retain any personal data of a covered minor 18 |
---|
466 | 466 | | that is not necessary to provide an online service, product, or feature with 19 |
---|
467 | 467 | | which the covered minor is actively and knowingly engaged; 20 BILL AS INTRODUCED H.210 |
---|
468 | 468 | | 2025 Page 20 of 24 |
---|
469 | 469 | | |
---|
470 | 470 | | |
---|
471 | 471 | | VT LEG #378939 v.1 |
---|
472 | 472 | | (2) use previously collected personal data of a covered minor for any 1 |
---|
473 | 473 | | purpose other than a purpose for which the personal data was collected, unless 2 |
---|
474 | 474 | | necessary to comply with any obligation under this chapter; 3 |
---|
475 | 475 | | (3) permit any consumer, including a parent or guardian of a covered 4 |
---|
476 | 476 | | minor, to monitor the online activity of a covered minor or to track the location 5 |
---|
477 | 477 | | of the covered minor without providing a conspicuous signal to the covered 6 |
---|
478 | 478 | | minor when the covered minor is being monitored or tracked; 7 |
---|
479 | 479 | | (4) use the personal data of a covered minor to select, recommend, or 8 |
---|
480 | 480 | | prioritize media for the covered minor, unless the personal data is: 9 |
---|
481 | 481 | | (A) the covered minor’s express and unambiguous request to receive: 10 |
---|
482 | 482 | | (i) media from a specific account, feed, or user, or to receive more 11 |
---|
483 | 483 | | or less media from that account, feed, or user; 12 |
---|
484 | 484 | | (ii) a specific category of media, such as “cat videos” or “breaking 13 |
---|
485 | 485 | | news,” or to see more or less of that category of media; or 14 |
---|
486 | 486 | | (iii) more or less media with similar characteristics as the media 15 |
---|
487 | 487 | | they are currently viewing; 16 |
---|
488 | 488 | | (B) user-selected privacy or accessibility settings; or 17 |
---|
489 | 489 | | (C) a search query, as long as the search query is only used to select 18 |
---|
490 | 490 | | and prioritize media in response to the search; or 19 |
---|
491 | 491 | | (5) send push notifications to a covered minor between 12:00 a.m. and 20 |
---|
492 | 492 | | 6:00 a.m. 21 BILL AS INTRODUCED H.210 |
---|
493 | 493 | | 2025 Page 21 of 24 |
---|
494 | 494 | | |
---|
495 | 495 | | |
---|
496 | 496 | | VT LEG #378939 v.1 |
---|
497 | 497 | | (b) Rulemaking. The Attorney General shall have the authority to adopt 1 |
---|
498 | 498 | | rules pursuant to this subchapter that prohibits data processing or design 2 |
---|
499 | 499 | | practices of a covered business that, in the opinion of the Attorney General, 3 |
---|
500 | 500 | | lead to compulsive use or subvert or impair user autonomy, decision making, 4 |
---|
501 | 501 | | or choice during the use of an online service, product, or feature of the covered 5 |
---|
502 | 502 | | business. The Attorney General shall, at least once every two years, review 6 |
---|
503 | 503 | | and update these rules as necessary to keep pace with emerging technology. 7 |
---|
504 | 504 | | § 2449g. AGE ASSURANCE PRIVACY 8 |
---|
505 | 505 | | (a) Privacy protections for age assurance data. Covered businesses and 9 |
---|
506 | 506 | | processors shall: 10 |
---|
507 | 507 | | (1) only collect personal data of a user that is strictly necessary for age 11 |
---|
508 | 508 | | assurance; 12 |
---|
509 | 509 | | (2) immediately upon determining whether a user is a covered minor, 13 |
---|
510 | 510 | | delete any personal data collected of that user for age assurance, except 14 |
---|
511 | 511 | | whether the user is or is not determined to be a covered minor; 15 |
---|
512 | 512 | | (3) not use any personal data of a user collected for age assurance for 16 |
---|
513 | 513 | | any other purpose; 17 |
---|
514 | 514 | | (4) not combine personal data of a user collected for age assurance with 18 |
---|
515 | 515 | | any other personal data of the user, except whether the user is or is not 19 |
---|
516 | 516 | | determined to be a covered minor; and 20 BILL AS INTRODUCED H.210 |
---|
517 | 517 | | 2025 Page 22 of 24 |
---|
518 | 518 | | |
---|
519 | 519 | | |
---|
520 | 520 | | VT LEG #378939 v.1 |
---|
521 | 521 | | (5) implement a review process to allow users to appeal their age 1 |
---|
522 | 522 | | designation. 2 |
---|
523 | 523 | | (b) Rulemaking. 3 |
---|
524 | 524 | | (1) Subject to subdivision (2) of this subsection, the Attorney General 4 |
---|
525 | 525 | | shall, on or before July 1, 2027, adopt rules identifying commercially 5 |
---|
526 | 526 | | reasonable and technically feasible methods for covered businesses and 6 |
---|
527 | 527 | | processors to determine if a user is a covered minor, describing appropriate 7 |
---|
528 | 528 | | review processes for users appealing their age designations, and providing any 8 |
---|
529 | 529 | | additional privacy protections for age assurance data. The Attorney General 9 |
---|
530 | 530 | | shall periodically review and update these rules as necessary to keep pace with 10 |
---|
531 | 531 | | emerging technology. 11 |
---|
532 | 532 | | (2) In adopting these rules, the Attorney General shall: 12 |
---|
533 | 533 | | (A) prioritize user privacy and accessibility over the accuracy of age 13 |
---|
534 | 534 | | assurance methods; and 14 |
---|
535 | 535 | | (B) consider: 15 |
---|
536 | 536 | | (i) the size, financial resources, and technical capabilities of 16 |
---|
537 | 537 | | covered businesses and processors; 17 |
---|
538 | 538 | | (ii) the costs and effectiveness of available age assurance methods; 18 |
---|
539 | 539 | | (iii) the impact of age assurance methods on users’ safety, utility, 19 |
---|
540 | 540 | | and experience; 20 BILL AS INTRODUCED H.210 |
---|
541 | 541 | | 2025 Page 23 of 24 |
---|
542 | 542 | | |
---|
543 | 543 | | |
---|
544 | 544 | | VT LEG #378939 v.1 |
---|
545 | 545 | | (iv) whether and to what extent transparency measures would 1 |
---|
546 | 546 | | increase consumer trust in an age assurance method; and 2 |
---|
547 | 547 | | (v) the efficacy of requiring covered businesses and processors to: 3 |
---|
548 | 548 | | (I) use previously collected data to determine user age; 4 |
---|
549 | 549 | | (II) adopt interoperable age assurance methods; and 5 |
---|
550 | 550 | | (III) provide users with multiple options for age assurance. 6 |
---|
551 | 551 | | § 2449h. ENFORCEMENT 7 |
---|
552 | 552 | | (a) A covered business or processor that violates this subchapter or rules 8 |
---|
553 | 553 | | adopted pursuant to this subchapter commits an unfair and deceptive act in 9 |
---|
554 | 554 | | commerce in violation of section 2453 of this title. 10 |
---|
555 | 555 | | (b) The Attorney General shall have the same authority under this 11 |
---|
556 | 556 | | subchapter to make rules, conduct civil investigations, bring civil actions, 12 |
---|
557 | 557 | | and enter into assurances of discontinuance as provided under chapter 63 of 13 |
---|
558 | 558 | | this title. 14 |
---|
559 | 559 | | § 2449i. LIMITATIONS 15 |
---|
560 | 560 | | Nothing in this subchapter shall be interpreted or construed to: 16 |
---|
561 | 561 | | (1) impose liability in a manner that is inconsistent with 47 U.S.C. 17 |
---|
562 | 562 | | § 230; or 18 |
---|
563 | 563 | | (2) prevent or preclude any covered minor from deliberately or 19 |
---|
564 | 564 | | independently searching for, or specifically requesting, any media. 20 BILL AS INTRODUCED H.210 |
---|
565 | 565 | | 2025 Page 24 of 24 |
---|
566 | 566 | | |
---|
567 | 567 | | |
---|
568 | 568 | | VT LEG #378939 v.1 |
---|
569 | 569 | | § 2449j. RIGHTS AND FREEDOMS OF COVERED MINORS 1 |
---|
570 | 570 | | It is the intent of the General Assembly that nothing in this act may be 2 |
---|
571 | 571 | | construed to infringe on the existing rights and freedoms of covered minors or 3 |
---|
572 | 572 | | be construed to discriminate against the covered minors based on race, 4 |
---|
573 | 573 | | ethnicity, sex, disability, sexual orientation, gender identity, gender expression, 5 |
---|
574 | 574 | | or national origin. 6 |
---|
575 | 575 | | Sec. 2. EFFECTIVE DATE 7 |
---|
576 | 576 | | This act shall take effect on July 1, 2026. 8 |
---|