On August 11, 2026, Governor Mikie Sherrill signed Assembly Bill 4015, the New Jersey Kids Code Act, into law as P.L.2026, c.73, supplementing Title 56 of the Revised Statutes. It was signed alongside A4014 (a Social Media Research Center funded with $500,000 in the FY2027 budget) and S3412 (a warning-labels efficacy study) as a three-bill kids’ online safety package. The Act takes effect on the first day of the 13th month following enactment — September 1, 2027.

Read as a list of obligations, it is the fifth American age-appropriate design code, and a conventional one: highest-available default privacy settings, data minimization, a ban on targeted advertising to minors, restrictions on engagement-driving design features. California got there first in 2022; Maryland, Vermont, and Nebraska followed. If you have done that work, most of the New Jersey product requirements are a delta, not a rebuild.

That reading misses the point of the statute. The operative provision is Section 14(c), and it does something no prior US design code does: it gives the children themselves a cause of action, with statutory damages of $5,000 per violation or treble damages, whichever is greater, plus punitive damages for reckless or knowing violations, injunctive and declaratory relief, and attorney’s fees and litigation costs. There is no cure period. And Section 14(d) provides that “any violation of sections 4 through 12 … as to any covered child or covered minor shall constitute an injury to that covered child or covered minor” — a legislative answer to the standing question that has been the largest obstacle to children’s privacy class actions.

The design work is the same as everywhere else. The exposure is not. This article is about that asymmetry, and what a product organization should do with the runway that remains.

What the Act Actually Says

Precision first, because most of the trade coverage has compressed the thresholds and the damages formula in ways that matter.

Who is covered. A “covered online service provider” must (1) own, operate, control, or provide an online service, (2) conduct business in this State, (3) offer a service reasonably likely to be accessed by a child or minor, and (4) meet either of two thresholds: annual gross revenue in excess of $25,000,000, or annual processing of the personal data of not less than 25,000 consumers or households. It is disjunctive — “or,” not “and.” The enacted text lowered that count: the bill as introduced set it at 50,000, and the Assembly Committee Substitute halved it. From January 1, 2029, Treasury adjusts the revenue figure for CPI biennially. The consumer-count clause is not expressly limited to New Jersey residents — the nexus comes separately from “conducts business in this State” — so treat 25,000 as a national count until regulations say otherwise.

“Reasonably likely to be accessed” carries a quantitative floor: a service qualifies where at least two percent of its audience is routinely composed of individuals two through 17 years of age, along with services directed to children under COPPA. Two percent is a very low bar. A general-audience service with a million users needs 20,000 minors to be inside the statute.

Two age tiers. A “child” is under 13; a “minor” is 13 through 17. Obligations attach where the provider has actual knowledge — defined expansively as “all information known to and inferences made” relating to an individual’s age. This is not the COPPA actual-knowledge standard as platforms have traditionally litigated it. Inferences count: if your ad stack has classified a user into an age bracket for monetization, you have knowledge for compliance purposes, and the discovery request that surfaces it writes itself.

Section 4 — defaults. All default privacy settings for a covered child or minor must be set to the highest protection available: account existence not displayed to known adults absent express permission (or a parent), adult–minor direct messaging disabled, precise location hidden, search indexing disabled, interaction counts off. Providers may not offer a single control lowering multiple protections at once, and may not prompt a minor to weaken settings.

Section 6 — the notification curfew. Notifications to covered children and minors are off by default, and even where enabled may not be sent between 10:00 p.m. and 6:00 a.m., or on a weekday between Labor Day and Memorial Day, between 8:00 a.m. and 4:00 p.m.

Section 7 — data. Providers may “only process or retain the minimum amount” of a minor’s personal data necessary for the specific features the minor knowingly engaged with, may not repurpose it, may not facilitate targeted advertising to a covered minor, and may not advertise narcotics, tobacco, gambling, or alcohol to them. Section 8(b) requires that data collected to verify age be used for no other purpose and deleted within 15 days.

Section 12 — compulsive use. Providers must take “all reasonable steps” to prevent compulsive use arising from data practices or design features, and dark patterns are prohibited. The covered-design-feature catalogue reaches infinite scroll, autoplay, engagement counts, streaks and badges, notification clustering, virtual currencies, and ephemerality used to manufacture urgency.

Section 14 — enforcement, both barrels. A violation is an unlawful practice under the New Jersey Consumer Fraud Act, N.J.S.A. 56:8-1 et seq., giving the Attorney General civil investigative demand, civil action, and assurance-of-discontinuance authority — and the standalone private right of action in 14(c), exercisable by the child or minor, by a parent on their behalf, or by the Attorney General.

Why the Private Right of Action Changes the Risk Model Entirely

Every prior American design code — California’s AB 2273, Maryland’s Kids Code, Vermont’s and Nebraska’s statutes — routes through a single public enforcer, an architecture with three properties that quietly cap exposure. Enforcement is discretionary: an AG office with fixed headcount picks a handful of large, visible targets a year. It is negotiated: the output is an assurance of discontinuance with a penalty bearing no arithmetic relationship to the number of affected users. And it is usually preceded by a cure period — California’s AADCA gave 90 days’ written notice, converting most first-instance non-compliance into a free fix.

New Jersey removes all three properties at once. There is no cure period. There is no discretion, because the enforcer is anyone with a minor and a contingency-fee lawyer. And the remedy is not a negotiated figure; it is arithmetic.

Do the arithmetic. New Jersey has roughly two million residents under 18. Suppose a platform has 300,000 New Jersey users it has actual knowledge — including by inference — are minors, and its notification service sends one re-engagement campaign at 9:00 p.m. Pacific, which is midnight Eastern. On the plain text, that is a notification sent to a covered minor inside the prohibited window, 300,000 times. At $5,000 per violation, the statutory floor is $1.5 billion for one misconfigured cron job. Treble damages apply where greater; punitive damages on recklessness or knowledge; fees on top.

That number is not a prediction — courts have tools for absurd aggregate awards, and how “per violation” is counted here is unsettled and will be the central fight in the first wave of cases. It illustrates a structural point: once statutory damages are multiplied by userbase, every operational defect becomes a bet-the-company event, and the settlement value of a claim no longer depends on proving anyone was harmed. Section 14(d) makes that explicit by deeming violation to be injury.

The precedent for how this reshapes a market is Illinois’s Biometric Information Privacy Act, which passed in 2008 and lay largely dormant for a decade. Then the Illinois Supreme Court held in Rosenbach v. Six Flags (2019) that a plaintiff need not plead harm beyond the statutory violation to be “aggrieved,” and in Cothron v. White Castle (2023) that a separate claim accrues on each scan. Applied to a $1,000/$5,000 per-violation schedule, those rulings produced the Facebook $650 million and Google $100 million settlements, a specialist plaintiffs’ bar, biometric exclusions in cyber policies, and eventually a 2024 amendment limiting recovery to one violation per person per modality, because the aggregate math had become untenable.

New Jersey begins where BIPA arrived after fifteen years of litigation: a per-violation figure at BIPA’s reckless tier, a legislated injury element, fee-shifting, and no cure. Firms were publishing client alerts on the private right of action within hours of the signing — marketing for an intake pipeline being built now, twelve months before the statute is enforceable. It is the same shift from regulator-led to plaintiff-led enforcement we examined around the New York SAFE for Kids Act final rules — except New York kept enforcement with the Attorney General, and New Jersey did not.

The First Amendment Question, Honestly Assessed

Any competent analysis has to address the possibility that significant parts of this statute never take effect. Some provisions look considerably more defensible than others, and the thirteen-month runway is long enough for a challenge to be filed and preliminarily resolved before September 1, 2027.

The controlling reference point is NetChoice v. Bonta. The Northern District of California enjoined the AADCA in its entirety in September 2023. In August 2024, the Ninth Circuit affirmed the injunction as to the data protection impact assessment requirement — reasoning that compelling a service to assess and mitigate the risk of minors encountering “harmful” content deputizes private companies as censors and compels speech — while vacating the balance and remanding. On March 12, 2026, a Ninth Circuit panel issued its second opinion, narrowing the injunction but leaving most challenged provisions blocked: NetChoice had not met the demanding facial standard as to the Act’s coverage definition or age estimation provision, but the court found the data use restrictions and dark patterns prohibition likely unconstitutionally vague. NetChoice separately challenged South Carolina’s protective-by-design statute in February 2026 — the closer analogue to New Jersey’s model.

Sorting A4015 against that record:

More defensible. Default privacy settings, the ban on prompting minors to weaken protections, the 15-day deletion rule for age-assurance data, purpose limitation, and the targeted-advertising prohibition are conduct regulations applied to data handling. They do not turn on what content a service carries and do not require the provider to judge whether speech is harmful. Notably, the New Jersey drafters omitted the DPIA obligation that sank California’s statute — the single most important structural difference between A4015 and AB 2273, and one that reads as deliberate.

More vulnerable. The compulsive use duty and the dark patterns prohibition are most exposed, and the March 2026 vagueness holding on California’s parallel clause is a direct warning. “All reasonable steps to prevent compulsive use” is a standard, not a rule; the covered-design-feature list reaches infinite scroll and autoplay, which are also mechanisms for delivering expressive content; and a challenger will argue that regulating how content is sequenced regulates the editorial function Moody v. NetChoice (2024) confirmed is protected. The notification curfew sits in between: as a time, place, and manner restriction on a provider’s own outbound messaging it has a real defense, but it restricts speech delivery directly and will be tested.

What follows practically. Build the defensible tier first — defaults, minimization, age-assurance hygiene, advertising restrictions — because four other design codes, the UK Children’s Code, and the DSA require that work regardless of what happens to A4015 in court. Sequence compulsive-design remediation second, and keep those decisions documented and reversible so a narrowed injunction does not strand a year of engineering. Litigation posture is not a reason to defer the common work; it is a reason to order it.

The Age Assurance Circularity

“Highest available privacy settings by default for known minors” requires knowing who is a minor. The Act’s expansive “actual knowledge” definition creates a genuine trap: a service that avoids formal age collection but infers age for ad targeting has knowledge anyway, and inherits the obligations without the ability to apply them accurately.

The circularity is worth stating plainly: protecting children’s data more rigorously requires collecting more data about children. Facial age estimation processes biometrics; document verification processes government ID; behavioural inference processes usage history. Every method that improves accuracy increases the sensitivity of what is held, and the most accurate methods create exactly the biometric and identity-document repositories that produce catastrophic breaches.

New Jersey’s partial answer is Section 8(b), and it is a hard engineering constraint: it rules out retaining an ID image “for audit purposes,” rules out feeding verification selfies into a training pipeline, and requires a deletion job with evidence. The defensible architecture is to estimate at the lowest assurance level that fits the risk, prefer signals you already hold over new collection, use third-party attestation returning an over/under boolean rather than an identity, store the derived age band rather than the underlying evidence, and instrument deletion so you can prove the 15-day clock was met. This is the same tension running through the state age-verification patchwork; New Jersey does not resolve it, it just prices failure differently.

The Notification Curfew Is an Engineering Problem, Not a Policy Problem

The curfew reads like a one-line requirement and decomposes into five.

Whose clock? The statute gives wall-clock hours without naming a reference zone. The safe implementation is the minor’s local time, not server time and not registration region — which means holding a reliable timezone per minor account and handling travel, VPNs, and stale device settings.

What counts as a notification? Push notifications clearly. Then in-app badges, SMS, email digests, tag alerts, transactional messages, security alerts, two-factor codes — the statute carves out none of these on its face. Classify every outbound message type as engagement or non-engagement, suppress the former in the window, document the reasoning for anything you keep sending, and escalate ambiguous categories to counsel rather than to a product manager.

Which weekdays? “A weekday between Labor Day and Memorial Day” is a fixed seasonal band, not a school calendar — it captures winter break, spring break, and every public holiday inside the band. Simpler than a district-by-district calendar, and it is what the text says.

Queue behaviour. A suppressed notification must be dropped or deferred, not queued for a 6:01 a.m. burst — a batch arriving the instant the window closes reads badly in a deposition and arguably implicates the compulsive-use duty.

Third parties and evidence. Marketing platforms schedule by campaign time, not recipient time. Enforce the curfew at a single chokepoint every sender must call, and log the suppression decisions, not just the sends — with no cure period, retrospective proof is itself a control.

Stacking New Jersey Against What You Already Owe

New Jersey is one row in a matrix, and treating it in isolation produces duplicated work.

COPPA and the amended Rule. The FTC’s amended COPPA Rule reached full compliance on April 22, 2026, adding separate verifiable parental consent for third-party disclosure, a written children’s data retention policy barring indefinite retention, and expanded security program requirements. COPPA is the under-13 floor; New Jersey extends the same instincts to 17 and adds the remedy COPPA never had. Our COPPA amended Rule deadline guide covers that baseline.

The New Jersey Data Privacy Act, effective January 2025, already requires consent to process the data of consumers aged 13 to 16 for targeted advertising, sale, or profiling, plus data protection assessments whose artefacts are reusable inputs to A4015 readiness.

Other state design codes — California, Maryland, Vermont, Nebraska, South Carolina — supply overlapping default and minimization requirements at varying levels of litigation risk. The UK Age Appropriate Design Code, enforceable since September 2021, is the most mature implementation guidance in existence; the ICO’s enforcement work, including its children’s data findings against Reddit, previews what regulators actually inspect. And DSA Article 28 requires platforms accessible to minors to take proportionate measures ensuring a high level of privacy, safety and security, and bans advertising based on profiling using minors’ data.

The synthesis: the design work is largely common; the enforcement exposure is not. One privacy-by-default architecture, one age-signal service, one notification suppression chokepoint, and one minimization policy satisfy most of this matrix. Build them once, jurisdiction-parameterised. Then treat New Jersey as the jurisdiction where a defect in any of them is priced at $5,000 a head.

Working Backward From September 1, 2027

  • By October 2026 — scope. Do you clear either threshold? Does two percent or more of your audience fall in the 2–17 band? Answer from your own analytics and write the memo: the finding is discoverable, and an out-of-scope decision needs contemporaneous support.
  • By December 2026 — age-signal inventory. Catalogue every place in the stack that holds or infers an age signal, including the ad tech classifications that constitute “actual knowledge.” Decide whether your strategy is to improve age assurance or to reduce inference. Both are viable; drifting between them is not.
  • By February 2027 — defaults and the notification chokepoint. Ship the suppression service and timezone model first; longest lead time, crispest liability.
  • By April 2027 — data controls. Purpose-limit minor data, disable targeted advertising to covered minors, implement the 15-day age-assurance deletion job with logged evidence.
  • By June 2027 — compulsive-design review, informed by wherever the litigation stands. Assess covered design features against the statutory list and record what you deliberately deferred pending judicial clarity — a reasoned deferral is a very different posture from silence.
  • By August 2027 — evidence readiness. Log retention aligned to the limitations period, an internal audit of defaults on freshly created minor accounts, vendor amendments pushing curfew and minimization terms to every outbound-messaging processor, and written notice to your insurer — per-violation statutory damages are exactly the exposure carriers begin excluding once they understand it.

Conclusion

The New Jersey Kids Code Act is not a novel set of product requirements. Nearly everything in Sections 4 through 12 exists somewhere else, and a service that has genuinely implemented the UK Children’s Code and DSA Article 28 is most of the way to the substantive obligations. What is novel is Section 14: a legislature looked at seven years of AG-enforced design codes — discretionary, negotiated, cure-periodded, slow — concluded that the enforcement model rather than the standards was the binding constraint, and borrowed the mechanism that unambiguously changed corporate behaviour in a different domain, BIPA, to point at children’s product design.

Whether the courts let all of it stand is unknown, and nobody should be selling a prediction. But the litigation risk falls unevenly, and the provisions most likely to survive — defaults, minimization, age-assurance hygiene, advertising restrictions — are the ones you already owe four other jurisdictions. The constitutional uncertainty is a reason to sequence the work, not to defer it.

The organisations that will find September 1, 2027 uneventful are the ones that spend the next twelve months building a single age-signal service, a single notification chokepoint, and a single minimization policy, and can produce logs proving all three worked. Everyone else will discover that “we were going to fix that next quarter” is not a defense under a statute with no cure period, and that the arithmetic runs against the userbase they spent a decade growing.

Sources: New Jersey A4015, third reprint (bill text), Office of the Governor — Governor Sherrill Signs Kids’ Online Safety Package, Hunton — New Jersey Enacts the Kids Code Act with Privacy-by-Default and Safety-by-Design Obligations, Future of Privacy Forum — A New Design Code Takes Root in the Garden State, Cooley — NetChoice v. Bonta: Ninth Circuit Narrows Injunction Against California’s Age-Appropriate Design Code Act, Holland & Knight — Ninth Circuit Issues Mixed Ruling on California Age-Appropriate Design Code Act

This article is provided for informational purposes only and does not constitute legal advice.