"New Jersey Kids Code Act"; adopts New Jersey Age-Appropriate Design Code and requires certain online service providers to implement certain measures concerning minors' use of online service.*
What changed between versions
The protected population is now split into two categories: 'child' (under 13) and 'minor' (13-17). Previously only 'minors' (under 18) were covered. Many obligations now apply to both groups, with some differences (e.g., parent exceptions for algorithmic recommendation services).
The data-processing threshold for a 'covered online service provider' was lowered from 50,000 consumers or households to 25,000, expanding the number of companies subject to the law. A new requirement was added that the provider's online services must be 'reasonably likely to be accessed by a minor.' The 98% adult-user exemption was removed.
The bill no longer amends P.L.2023, c.266 (the NJ Consumer Privacy Act). The amendment to Section 9 of that law (controller duties including data protection assessments) was removed entirely. The bill now supplements Title 56 of the Revised Statutes directly.
New definition of 'compulsive use' (repetitive, difficult-to-stop usage that materially disrupts major life activities) and 'algorithmic recommendation system' (with exclusions for basic search functionality). These create the basis for new design-feature restrictions and transparency requirements.
'Actual knowledge' was expanded to include 'age flags' and 'a commercially-reasonable and technically-feasible age assurance mechanism,' broadening when a provider is deemed to know a user's age. A new definition of 'reasonably likely to be accessed' establishes specific criteria including the 2% audience threshold for ages 2-17.
'Covered design feature' was redefined to focus on features with an associated risk of resulting compulsive use rather than merely features designed to increase engagement. 'Intermittent variable reward schedules' were added as a covered design feature. 'Quantification of engagement' (visible like/comment counts) was removed from the list but interaction counts are now disabled by default under privacy settings.
New Section 10 requires covered online service providers that use algorithmic recommendation systems to provide a user interface enabling children, minors, and parents to communicate preferences about media types and to access, review, and change the personal data used in recommendations. Providers must ensure recommendations are informed by these communicated preferences.
Default privacy settings now require disabling all interaction counts (comments, reactions, reshares) by default, with settings to enable specific types or all at once. For services using algorithmic recommendation systems, parents are now explicitly allowed to view their child's account, media, and messaging.
New prohibition on sending notifications to covered children or minors by default (Section 6a). Previously there was no such blanket prohibition, only time-of-day restrictions.
The geolocation disclosure requirement was strengthened from an 'obvious sign' to a 'prominent and constant real-time signal' and expanded to cover situations where online activity is being monitored by any individual, including parents.
Age verification data retention period was reduced from 60 days to 15 days after use. Account deletion deadline was changed from 15 days to 10 business days, and the mechanism must require the same number or fewer steps than account creation.
The annual public report requirement (original Section 13), which required covered online service providers to publish a detailed report prepared by an independent third-party auditor covering design features, data practices, algorithm use, and percentile time-spent data, was removed from the visible portion of the substitute.