Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Vercel restricts its Sites and Services to users age 16 and older, states it does not knowingly collect personal information from individuals under 16, and commits to removing such information if discovered.
This analysis describes what Vercel AI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The stated minimum age of 16 aligns with GDPR's default age of digital consent in many EU member states and exceeds COPPA's US minimum of 13; this provision creates a compliance boundary relevant to any Customer deploying Vercel-hosted services accessible to minors.
The updated policy establishes a new mechanism for resolving privacy disputes related to Data Privacy Framework transfers. Users in the EU, UK, and EEA who have unresolved privacy complaints can now submit them to VeraSafe for independent review, which will be conducted free of charge. Additionally, the policy introduces an explicit Right to Restriction, permitting users to request that Vercel limit processing of their personal information or restrict further disclosures in certain instances, particularly for sensitive information. You can file a complaint with VeraSafe by submitting required information at https://www.verasafe.com/privacy-services/dispute-resolution/submit-dispute/.
View change record →The agreement establishes that Vercel's Services are not available to individuals under age 16, and that any personal information collected from individuals under 16 without verification will be removed upon discovery; parents or guardians may contact Vercel directly to report a minor's data.
Cross-platform context
See how other platforms handle Minimum Age Requirement of 16 and similar clauses.
Compare across platforms →Monitoring
Vercel AI has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"The Sites and Services are not directed or intended for use by individuals under the age of 16. To use Vercel's Sites and Services, you must be old enough to consent to the processing of your information in your jurisdiction. We do not knowingly collect personal information from anyone under the age of 16. If you are a parent or guardian and you become aware that your child has provided us with personal information, please contact us. If we become aware that we have collected personal information from anyone under the age of 16 without verification or parental consent, we take steps to remove such information.Excerpt from Vercel AI's SDK Privacy
(1) REGULATORY LANDSCAPE: COPPA in the United States requires verifiable parental consent before collecting personal information from children under 13; Vercel's stated minimum of 16 sets a higher threshold. GDPR Article 8 establishes a default minimum age of 16 for digital services consent, with member states permitted to lower this to 13; the 16-year minimum in this Notice aligns with the GDPR default. UK Children's Code (Age Appropriate Design Code) may impose additional requirements for services likely to be accessed by users under 18. (2) GOVERNANCE EXPOSURE: Low for Vercel directly, given the 16-year minimum and stated removal commitment. Medium for Customers deploying consumer-facing applications on Vercel's infrastructure that may be accessed by minors, as Customer responsibility for end user compliance is separately established in this Notice. (3) JURISDICTION FLAGS: EU member states that have exercised the option to lower the GDPR Article 8 minimum below 16 present a potential gap between Vercel's stated minimum and applicable law for users in those jurisdictions. UK Children's Code exposure depends on whether Vercel's own sites are likely to be accessed by under-18 users. (4) CONTRACT AND VENDOR IMPLICATIONS: Customers operating consumer-facing services with potential minor user populations should confirm that their own age verification mechanisms are adequate and that Vercel's infrastructure does not create a gap in their minor data protection compliance. (5) COMPLIANCE CONSIDERATIONS: Legal teams should confirm that Vercel's age verification or restriction mechanisms are operationally implemented on relevant site properties and that the stated commitment to remove minor data is supported by documented internal procedures.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
The stated minimum age of 16 aligns with GDPR's default age of digital consent in many EU member states and exceeds COPPA's US minimum of 13; this provision creates a compliance boundary relevant to any Customer deploying Vercel-hosted services accessible to minors.
The agreement establishes that Vercel's Services are not available to individuals under age 16, and that any personal information collected from individuals under 16 without verification will be removed upon discovery; parents or guardians may contact Vercel directly to report a minor's data.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Vercel AI.