Washington, D.C. – The Computer & Communications Industry Association testified on proposed rules implementing the Age-Appropriate Design Code. CCIA warned that provisions exceed the scope of Act 63, create significant compliance uncertainty, and could introduce new privacy concerns for minors and adults.
CCIA supports efforts to protect children online and promote their privacy, safety, and well-being. However, the Association is urging the Attorney General to revise the proposed rules to ensure they remain consistent with Act 63, provide clear and workable standards for businesses, and preserve beneficial uses of data that serve minors’ interests.
CCIA highlighted several provisions that could create uncertainty for covered businesses. The proposed rules would apply when a business “knows or has reason to know” that a user is a covered minor. This language expands beyond the statute’s standard of actual knowledge or identification through approved age-assurance methods. CCIA cautioned that this vague and subjective threshold could encourage businesses to adopt age-verification practices that require the collection of additional information from users of all ages, which would undermine privacy rather than protect it.
The association also raised concerns that the proposed rules extend beyond Act 63’s authorization to regulate practices that lead to compulsive use or impair user autonomy, decision-making, or choice. Provisions addressing any service used by a covered minor could create broad and unpredictable obligations that are not clearly grounded in the statute. CCIA further urges the Attorney General to reconsider restrictions on behavioral data and inferred preferences that could limit lawful, beneficial content recommendations and conflict with permissions established under Act 63.
CCIA encourages the Attorney General to pursue a targeted, privacy-conscious approach that protects minors without imposing unnecessary data-collection requirements, restricting beneficial online services, or creating unclear obligations for businesses. The Association recommends aligning the proposed rules with Act 63 and established legal frameworks while ensuring that covered businesses have clear guidance for compliance.
The following statement can be attributed to Kyle Sepe, State Policy Manager, Northeast Region at CCIA:
“Protecting children online is a priority, as is privacy. Vermont’s proposed rules raise serious concerns about privacy, statutory authority, and how businesses can comply with the law. Protecting young people should not come at the expense of the privacy of all users or the beneficial uses of technology and data. We urge the Attorney General to revise the proposed rules to align with Act 63, provide greater protections and set clear standards for businesses.”