More

    South Carolina Enforces Stricter Age-Appropriate Design: Audits, Parental Controls, and Employee Accountability

    Understanding the South Carolina Age Appropriate Design Code Act

    The newly enacted South Carolina Age Appropriate Design Code Act represents a significant development in the landscape of digital privacy laws not just within the state but also across the United States. As organizations scramble to comply, this innovative legislation introduces robust measures aimed at protecting the privacy of minors online, a demographic often vulnerable to data exploitation.

    Key Features of the Act

    Immediate Effectiveness

    One distinguishing aspect of the Act is its immediate implementation upon enactment in February 2026. In contrast to other states that provide a grace period for compliance, South Carolina has mandated that the first audit reports be submitted to the Attorney General by July 1, 2026. This swift enforcement strategy signals a serious commitment to safeguarding minors and emphasizes the urgency for organizations to adapt quickly.

    Scope of the Act: Who is Affected?

    The Act applies to what are termed "covered online services." These include legal entities that meet certain thresholds, notably:

    1. Revenue Requirements: Organizations with annual gross revenue exceeding $25 million.
    2. Data Processing Volumes: Those that buy, sell, or share personal data of 50,000 or more individuals, households, or devices.
    3. Data-Driven Revenue: Enterprises deriving at least 50% of their annual revenue from selling or sharing personal data.

    Beyond these thresholds, the Act also requires organizations to assess whether their online services are “reasonably likely to be accessed by minors.” This determination includes having actual knowledge that a user is under 18 or specifically targeting children under 13, aligning with the Children’s Online Privacy Protection Act (COPPA).

    Independent Compliance Audits

    One of the Act’s notable features is its mandate for annual independent audits. The law requires that these audits be conducted by a third-party professional and addresses how effectively the entity has designed online features intended for minors.

    The audit report submission deadline aligns with the annual date—July 1—consistent with the enforcement timeline. Reports must include details such as:

    • Implementation of required controls for protecting minors.
    • Notifications received from parents or guardians regarding perceived harms.
    • Descriptions of algorithms recommending content to minors.

    The public availability of these audit reports on the Attorney General’s website emphasizes transparency, making compliance a public matter that can invite scrutiny from various stakeholders.

    Default User Controls for Minors

    One of the Act’s essential elements centers around robust user controls. It obliges covered entities to offer tools for all users—not just adults—to manage their online experiences.

    For minors, the Act establishes several stringent default settings, ensuring heightened privacy protections, including:

    • Disabling features not necessary for the online service.
    • Restricting social connectivity options.
    • Turning off personalized recommendation systems by default.

    This proactive design ethos focuses on preserving the online experiences of minors from potential risks associated with excessive data collection and targeted advertising.

    Prohibitions on Targeted Advertising and Profiling

    A critical aspect of the Act is its prohibition against targeted advertising aimed at minors. This means that businesses cannot engage in practices that individually target advertising toward users under 18, providing yet another layer of protection to this vulnerable demographic.

    Moreover, profiling minors—gathering insights or making assumptions about their behavior—is similarly restricted, featuring narrow exceptions. If a minor actively engages with a service where profiling is necessary, organizations may proceed cautiously under specific conditions.

    Parental Controls and Harm Reporting Mechanisms

    Understanding that parents play a crucial role in managing their children’s online activity, the Act mandates powerful parental controls. These controls are detailed and robust:

    • Parents can manage privacy settings.
    • Restrictions can be placed on purchases.
    • Monitoring tools to track usage time are required.

    Additionally, there must be mechanisms for notifying entities about potential harms experienced by minors using their platforms, ensuring accountability and swift corrective action.

    Transparency and Data Minimization

    In terms of transparency, covered entities must provide:

    • Clear, user-friendly descriptions of data collection practices and privacy protections.
    • Instructions for using parental controls and settings.

    The Act also vigorously enforces data minimization principles, ensuring organizations collect only the data necessary for specific user interactions. This focus on restraint contrasts with the more lenient approaches present in many other jurisdictions.

    Aggressive Penalties and Enforcement

    Enforcement under the Act is robust, with the South Carolina Attorney General wielding exclusive authority to impose penalties. Notably, the legislation introduces significant repercussions for non-compliance, including:

    • Potential personal liability for company officers and employees for willful violations.
    • Treble damages for financial losses incurred from breaches of the Act.

    This strong enforcement mechanism reflects a clear intent to prioritize the protection of minors in the digital space.

    Preparing for Compliance

    Entities engaged in providing online services within South Carolina need to act swiftly. Key steps to prepare for compliance include:

    • Mapping data collected about minors.
    • Conducting assessments of current practices against the Act’s requirements.
    • Designing and operating effective parental control systems.
    • Establishing mechanisms for reporting and documenting harm.

    Engaging an independent auditor to prepare for the mandatory compliance reports is also advisable.

    As organizations navigate this complex new landscape, the South Carolina Age Appropriate Design Code Act may indeed shape how data privacy rights evolve across the country, holding entities accountable for their engagement with younger users.

    Latest articles

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    Popular