Last updated: 2026-10-02
Governor Mikie Sherrill signed the New Jersey Kids Code Act (A4015/S3413) on August 11, 2026; the bill history records it as P.L.2026, c.73. The act is New Jersey's age-appropriate design code: default privacy settings, data limits and design rules for online services that display account-holder content and that children and teens are reasonably likely to access. It takes effect on September 1, 2027.
The synopsis calls it the "New Jersey Kids Code Act"; section 1 of the enacted text gives the short title "New Jersey Age-Appropriate Design Code". The Senate amended the bill and both houses passed it on June 30, 2026: 36-4 in the Senate and 73-5 on Assembly concurrence. The enacted text is the Third Reprint of the Assembly Committee Substitute, "as amended by the Senate on June 30, 2026". The governor signed two companion bills the same day: A4014 establishes a Social Media Research Center and S3412 directs it to study warning labels.
When does the New Jersey Kids Code Act take effect?
September 1, 2027. Section 17 says the act takes effect "on the first day of the 13th month following the date of enactment". Enactment was in August 2026, so September 2026 is month one and September 2027 month 13. The Future of Privacy Forum (FPF) analysis gives the same date. The Attorney General may adopt implementing rules, and the Commissioner of Health may add criteria for "compulsive use" (section 13).
Who must comply with the New Jersey Kids Code?
A "covered online service provider" (section 3) is any legal entity that provides an online service, conducts business in New Jersey, has online services "reasonably likely to be accessed by a child or minor", and either has annual gross revenue above $25,000,000 or "annually processes the personal data of not less than 25,000 consumers or households". Affiliates under common control and common branding are included. Entities that solely provide a direct messaging service are excluded. The act applies to conduct "that occurs in whole or in part in New Jersey" and to "each online service" a provider offers (section 16).
The Senate's June 30 floor amendment narrowed "online service". The enacted definition covers a service or product that "(1) is accessible to the public via the Internet; (2) displays content that is generated by one or more account holders; (3) has an account holder in this State; and (4) allows account holders to interact with content associated with other individual account holders as a central feature of the service." The deleted text, bracketed in the Third Reprint, covered "any service, product, or feature provided over the Internet that collects, uses, stores, discloses, analyzes, deletes, or modifies the personal data of consumers", including "a website or application". The definition joins the four elements with "and", so each is required. FPF's scope summary omits the account-holder content test.
A "child" is under 13 and a "minor" is 13 to 17. A service is "reasonably likely to be accessed" if it is directed to children under COPPA, or if "at least two percent of the audience" is aged two through 17, either on "competent and reliable evidence regarding audience composition" or because the provider "knew or should have known" it (section 3).
What counts as actual knowledge of a user's age?
The duties apply to a "covered child" or "covered minor", meaning a user the provider has actual knowledge is under 18. Section 3 defines actual knowledge as "all information known to and inferences made by the covered online service provider relating to the age of an individual", including "any age the covered online service provider has attributed or associated with the individual for any purpose, including marketing, advertising, or product development." Where the provider's own classification for marketing, advertising or engagement conflicts with the declared age, the provider "shall disregard the declared age".
Under that definition, an age range the provider attributes to a user for ad targeting is part of its actual knowledge. Section 8 adds that a provider is not required to collect personal data to comply, and that data collected for age verification must be deleted within 15 days of verifying the user's age.
What does the New Jersey Kids Code require?
| Duty | Section | Enacted text |
|---|---|---|
| Default privacy settings | 4(a) | Configure all defaults for a covered child or minor "to the highest level of privacy" |
| Location display | 4(a)(2) | Prohibit display of the user's location to other users unless the user chooses to share it with a specific user |
| Connections and indexing | 4(a)(3)–(4) | Do not display connected users; disable search engine indexing of the account |
| Notifications | 6(a)–(b) | Off by default; none from 10:00 p.m. to 6:00 a.m., and none from 8:00 a.m. to 4:00 p.m. on weekdays between Labor Day and Memorial Day |
| Advertising | 6(c) | No ads targeted at a covered child or minor for narcotic drugs, tobacco products, gambling or alcohol |
| Dark patterns | 6(d) | None used in regard to a covered child or minor |
| Purpose limit | 7(a)(1) | No use of personal data "for any reason other than the reason for which the personal data was collected" |
| Data minimization | 7(b) | Process or retain only "the minimum amount" needed for "the specific features of the online service with which the covered child or covered minor has knowingly engaged" |
| Account deletion | 9 | Unpublish within 10 business days; permanently delete within 45 calendar days of the request |
| Location and monitoring signal | 11 | A "prominent and constant real-time signal" while "precise geolocation information is being collected or used" or the user's activity is monitored |
| Compulsive use | 12(a) | Take "all reasonable steps" so that data use and design features such as infinite scroll and autoplay "do not result in compulsive use" |
Source: the enacted text, ACS for A4015, Third Reprint. "Precise geolocation data" is defined in section 3 with a 1,750-foot radius; section 11 uses the phrase "precise geolocation information".
FPF's summary describes the data minimization duty with the phrase "actively and knowingly engaged". Section 7(b) reads "knowingly engaged"; "actively and knowingly engaged" is in the section 3 audience test.
Who can sue under the New Jersey Kids Code, and for what?
A violation is an unlawful practice under New Jersey's Consumer Fraud Act, and the Attorney General has the same investigative and enforcement powers as under that act (section 14(a)–(b)). Section 14(c) adds a civil action: a covered child or minor "injured by a violation" may sue, and the Attorney General or a parent may sue on the child's behalf. For "any negligent or greater violation", a court may award "$5,000 per violation or treble damages, whichever is greater", punitive damages for reckless or knowing violations, injunctive and declaratory relief, and attorney's fees and costs.
Section 14(d) provides that any violation of sections 4 through 12 "as to any covered child or covered minor shall constitute an injury to that covered child or covered minor". Section 14 sets no notice or cure step before an action. Section 16 states the act is not to be construed to impose liability inconsistent with 47 U.S.C. § 230 or the First Amendment.
NetChoice, a trade association, filed testimony opposing A4015 with the Assembly Budget Committee on June 28, 2026, arguing that the bill "effectively requires that social media companies perform age-verification for every user". A search of CourtListener's federal docket index on October 2, 2026 returned no challenge to the act filed since August 1, 2026; the search covers only federal dockets in that index.
Related: the COPPA Rule amendments and the April 22, 2026 compliance date, the app store age signal laws that send an age range to apps, and the Fifth Circuit ruling on the Texas SCOPE Act.
What does an app scan show for the Kids Code?
Three provisions turn on data an app handles: the actual-knowledge definition (age inferences used for advertising), the section 7(b) minimization duty, and the section 11 signal for precise geolocation collection or use. Each applies only to a service inside the section 3 scope, account-holder content test included, and only to users the provider knows are under 18.
When I scan an app, the report lists the ad, analytics and location SDKs found in the binary, the permissions the app declares (fine location, notifications) and the consent flow on first launch. It also lists the network traffic recorded on a test device: which host received coordinates, age or birth-year fields, audience or interest segments and device identifiers, and whether each request was sent before or after consent. Every static finding cites its file and line; every traffic finding cites its capture. SDK presence in a binary shows the code is in the build; only a capture shows the data was sent. The tester sets the test account's age, so a capture shows what the app sends for that profile; a provider's actual knowledge of a real user's age is a fact in the provider's own records. The methodology page covers what a scan checks and its limits.
I run these investigations for lawyers and for researchers working with lawyers, on one app or a list of apps in bulk. Sign up for a CanITrustThat account to run your own research, let us run an investigation for you, or browse the scanned apps.