SB495: SB495 "Age-Appropriate Design Code Act"; enact
Last action February 12, 2026 · Senate Read and Referred
A Georgia Senate bill would create an 'Age-Appropriate Design Code Act' requiring online services likely used by minors to limit data collection, turn off risky design features like autoplay and late-night notifications, and give kids privacy defaults and deletion rights.
In plain language
Georgia law does not currently set special design and data rules for online products used by children and teens. Senate Bill 495 would add a new article to Georgia's consumer protection code creating the Age-Appropriate Design Code Act. It applies to 'covered entities': companies that make most of their money from online products, whose services are reasonably likely to be used by minors, and that collect personal data. These companies would be barred from collecting more personal data than needed, using addictive design features such as autoplay, infinite scroll, or variable reward schedules on minors, and sending push notifications to minors overnight. They must assess new designs for compulsive-use risk, set the strictest privacy defaults for minors, let minors delete their data within 15 days of a request, and publicly disclose how their algorithms and data practices work. The Attorney General would enforce the law under the Fair Business Practices Act, with private lawsuits also allowed. Small businesses under certain revenue and data thresholds are exempt. Rulemaking could begin once the Governor signs the bill, but most requirements take effect January 1, 2027.
What the bill does
- Bars covered entities from collecting, selling, or retaining minors' personal data beyond what is needed for the service the minor is actively using.
- Prohibits specific 'high-risk' design features aimed at minors, including autoplay videos, infinite scroll, variable reward schedules, and push notifications between midnight and 6 a.m.
- Requires covered entities to assess new or changed designs for the risk of causing 'compulsive use' in minors and use a lower-risk alternative design by default when one exists.
- Requires the strictest privacy settings by default for minors, including disabling location sharing, search indexing, and algorithm-driven adult-to-minor contact recommendations.
- Gives minors (or their parents) the right to request deletion of their data and profile within 15 days, and requires public disclosure of privacy policies and how algorithmic feeds use personal data.
- Lets the Attorney General enforce violations as unfair or deceptive practices and lets individuals sue for damages, including punitive damages of at least $50,000 per case.
Who it affects
The bill affects companies operating websites, apps, or online services likely to be accessed by minors and that rely on advertising or data-driven business models, along with their processors and affiliates. It also directly affects Georgia minors and their parents, who gain new privacy defaults, disclosure rights, and data-deletion tools, while small businesses under set revenue and data thresholds are exempt.
Why it matters
If enacted, apps and websites used by Georgia kids and teens would have to turn off features like autoplay, infinite scroll, and overnight notifications by default, disclose how their algorithms use children's data, and let minors or parents demand data be deleted within 15 days, changing how these platforms operate for young Georgia users.
Key provisions
- Section 1 (O.C.G.A. § 10-1-971) defines who counts as a 'covered entity,' 'minor,' and other key terms, including a 2 percent minor-audience threshold for determining whether a service is 'reasonably likely to be accessed' by minors.
- O.C.G.A. § 10-1-972 lists banned high-risk data practices and design features, such as unnecessary data collection, algorithmic feeds using non-consented personal data, and overnight push notifications.
- O.C.G.A. § 10-1-973 requires risk assessments before deploying new designs, ten years of documentation retention, and annual independent audits, but exempts small businesses meeting specific revenue and data-volume limits.
- O.C.G.A. § 10-1-974 sets required default privacy and safety settings for minors, including disabling interaction counts, location sharing, and adult contact recommendations, plus tools to block other users.
- O.C.G.A. § 10-1-975 requires public disclosure of privacy policies, algorithmic feed purposes, and how personal data feeds into recommendation systems.
- O.C.G.A. § 10-1-977 makes violations enforceable under the Fair Business Practices Act by the Attorney General and through private lawsuits, with damages of $5,000 per violation or actual damages, plus punitive damages of $50,000 or three times combined damages, whichever is greater.
- O.C.G.A. § 10-1-979 exempts government entities, HIPAA-covered health information, certain research activities, journalism organizations, and Gramm-Leach-Bliley financial institutions from the article.
- Section 3 makes the law effective upon the Governor's signature for rulemaking purposes, with all other requirements effective January 1, 2027.
Status timeline
- Senate Read and Referred (Senate)
- Senate Hopper (Senate)
Sponsors
- Sally Harrell (D, SD-040)
- Shawn Still (R, SD-048)
- Ed Setzler (R, SD-037)
- Bo Hatchett (R, SD-050)
- Marty Harbin (R, SD-016)
- Carden Summers (R, SD-013)
- Frank Ginn (R, SD-047)
- Ricky Williams (R, SD-025)
- Lee Anderson (R, SD-024)
- Elena Parent (D, SD-044)
- Harold Jones (D, SD-022)
- Ben Watson (R, SD-001)
- Clint Dixon (R, SD-045)
- Nikki Merritt (D, SD-009)
- Nan Orrock (D, SD-036)
- Russ Goodman (R, SD-008)
- Nabilah Islam Parkes (D, SD-007)
- Josh McLaurin (D, SD-014)
- Max Burns (R, SD-023)
- Blake Tillery (R, SD-019)
- Brian Strickland (R, SD-042)
- Chuck Payne (R, SD-054)
- Mike Hodges (R, SD-003)
- Billy Hickman (R, SD-004)
- Chuck Hufstetler (R, SD-052)
- Sonya Halpern (D, SD-039)
- Jason T. Dickerson (R, SD-021)
- Kenya Wicks (D, SD-034)
- Gail Davenport (D, SD-017)
- Tonya Anderson (D, SD-043)
- Jaha Howard (D, SD-035)
- Sam Watson (R, SD-011)
- Freddie Sims (D, SD-012)
- RaShaun Kemp (D, SD-038)
- Kim Jackson (D, SD-041)
- Ed Harbison (D, SD-015)
- Randal Mangham (D, SD-055)
- Drew Echols (R, SD-049)
- Derek Mallow (D, SD-002)
- Donzella James (D, SD-028)
Topics
- child online safety
- data privacy
- social media regulation
- consumer protection
- algorithmic design