SB 495: "Age-Appropriate Design Code Act"; enact
Last action February 12, 2026 · Senate Read and Referred
Senate Bill 495 would create Georgia's 'Age-Appropriate Design Code Act,' setting new rules for online platforms that limit data collection, algorithmic feeds, and design features aimed at minors, with enforcement by the Attorney General.
The summaries below were written by an AI model (claude-sonnet-5) from the text of the bill and are not part of it. Quote the text, not the summary. The stored text is the Introduced version, the latest LegiScan holds.
In plain language
Georgia law currently has no specific rules governing how websites and apps design their products and handle data for users under 18. This bill would add a new article to Georgia's trade practices code (O.C.G.A. Title 10, Chapter 1) creating the Age-Appropriate Design Code Act. The bill defines 'covered entities' as profit-driven online businesses likely to be accessed by minors, and bars them from certain high-risk data practices, like collecting unnecessary personal data, letting adults be recommended to connect with minors, sending push notifications to minors overnight, or using design features meant to cause compulsive use. It requires risk assessments before design changes, independent audits, strong default privacy settings for minors, easy account deletion tools, and public disclosure of data practices. Small businesses under certain revenue and data thresholds are exempted. Violations would be enforced as unfair or deceptive practices under Georgia's Fair Business Practices Act, by both the Attorney General and private lawsuits. Rulemaking could begin once the Governor signs the bill, but most requirements would take effect January 1, 2027.
What the bill does
- Creates a new legal category of 'covered entity' for profit-seeking online businesses whose products are reasonably likely to be used by minors, and applies new duties to them.
- Bans specific high-risk practices such as collecting unnecessary personal data, using minors' data for undisclosed algorithmic recommendations, and sending push notifications to minors between midnight and 6 a.m.
- Requires covered entities to assess the risk of compulsive use before launching or changing a design, document findings for ten years, and submit records to an independent auditor annually.
- Sets strict default privacy and safety settings for minors, including disabling location sharing, disabling search indexing, and preventing adults from being algorithmically matched with minors.
- Requires covered entities to let minors (or their parents) request deletion of their data within 15 days and to publicly post details about their data practices, feeds, and algorithms.
- Makes violations enforceable as unfair or deceptive trade practices under the Fair Business Practices Act, allowing Attorney General action and private lawsuits with damages of at least $5,000 per violation or actual damages, whichever is greater.
Who it affects
The bill affects for-profit online companies (websites and apps) whose services are likely to be used by people under 18, especially social media and content platforms, as well as their processors and independent auditors. It also affects minors and their parents or guardians, who gain new privacy tools and data deletion rights, and the Attorney General's office, which gains new enforcement and rulemaking duties.
Why it matters
If enacted, Georgia teenagers and children using covered online platforms would get stronger default privacy settings, limits on late-night notifications, and easier ways to delete their data or block other users. Companies would face new compliance costs, audits, and potential lawsuits or fines if they fail to follow the rules, while journalism outlets, financial institutions, and small businesses under set revenue thresholds are exempt.
Key provisions
- Section 1 (O.C.G.A. § 10-1-971) defines key terms including 'minor,' 'covered entity,' 'algorithmic feed,' and 'compulsive use,' setting the scope of who and what the law covers.
- Section 1 (§ 10-1-972) lists banned high-risk data practices and design features, such as unnecessary data collection, undisclosed use of personal data in feeds, and design meant to cause compulsive use, unless a verified adult explicitly requests them.
- Section 1 (§ 10-1-973) requires risk assessments before deploying or changing designs, documentation retained for ten years, and independent annual audits of compliance records; exempts small businesses under $25 million average revenue or 50,000 users.
- Section 1 (§ 10-1-974) mandates strict default privacy settings for minors, including disabling location sharing, interaction counts, and adult-to-minor connection recommendations.
- Section 1 (§ 10-1-975) requires public disclosure of privacy policies, algorithmic feed purposes, and data usage details for features affecting minors.
- Section 1 (§ 10-1-976) sets rules for age-assurance data collection, requiring deletion of age-verification data once age status is determined and an appeals process for age determinations.
- Section 1 (§ 10-1-977) makes violations enforceable under the Fair Business Practices Act, allowing Attorney General enforcement and private lawsuits with damages of $5,000 per violation, punitive damages up to $50,000 or triple damages, and attorney's fees.
- Section 3 sets the effective date: rulemaking authority begins once the Governor signs the bill, while most substantive requirements take effect January 1, 2027.
From the bill
“A covered entity shall not engage in or use any of the following high-risk data practices or design features”
“A covered entity that has violated a provision of this article shall be liable for damages of $5,000 per violation, as adjusted annually to reflect an increase in the Consumer Price Index, or actual damages, whichever is greater”
“Do not use an algorithmic recommendation system to recommend to adult consumers that they connect to a minor as a friend, follower, or contact on an online service”
Status timeline
- Senate Read and Referred (Senate)
- Senate Hopper (Senate)
Sponsors
- Sally Harrell (D, SD-040)
- Shawn Still (R, SD-048)
- Ed Setzler (R, SD-037)
- Bo Hatchett (R, SD-050)
- Marty Harbin (R, SD-016)
- Carden Summers (R, SD-013)
- Frank Ginn (R, SD-047)
- Ricky Williams (R, SD-025)
- Lee Anderson (R, SD-024)
- Elena Parent (D, SD-044)
- Harold Jones (D, SD-022)
- Ben Watson (R, SD-001)
- Clint Dixon (R, SD-045)
- Nikki Merritt (D, SD-009)
- Nan Orrock (D, SD-036)
- Russ Goodman (R, SD-008)
- Nabilah Islam Parkes (D, SD-007)
- Josh McLaurin (D, SD-014)
- Max Burns (R, SD-023)
- Blake Tillery (R, SD-019)
- Brian Strickland (R, SD-042)
- Chuck Payne (R, SD-054)
- Mike Hodges (R, SD-003)
- Billy Hickman (R, SD-004)
- Chuck Hufstetler (R, SD-052)
- Sonya Halpern (D, SD-039)
- Jason T. Dickerson (R, SD-021)
- Kenya Wicks (D, SD-034)
- Gail Davenport (D, SD-017)
- Tonya Anderson (D, SD-043)
- Jaha Howard (D, SD-035)
- Sam Watson (R, SD-011)
- Freddie Sims (D, SD-012)
- RaShaun Kemp (D, SD-038)
- Kim Jackson (D, SD-041)
- Ed Harbison (D, SD-015)
- Randal Mangham (D, SD-055)
- Drew Echols (R, SD-049)
- Derek Mallow (D, SD-002)
- Donzella James (D, SD-028)
Topics
- online privacy
- children's online safety
- social media regulation
- data protection law
- consumer protection