Skip to main content
Category: Privacy Principles

Children's Privacy

Also known as: Children's Online Privacy, Kids' Privacy
Simply put

Children's privacy refers to the special legal protections that apply when websites and online services collect personal information from children. In the United States, the main federal law addressing this area is the Children's Online Privacy Protection Act (COPPA), which is designed to give parents control over what information is collected from their children online. These protections generally recognize that children may not fully understand the consequences of sharing their personal information.

Formal definition

Children's privacy is a domain of data protection concerned with regulatory obligations governing the collection, use, and disclosure of personal information relating to children. In the U.S. federal context, the Children's Online Privacy Protection Act (COPPA) and its implementing Children's Online Privacy Protection Rule impose requirements on operators of websites or online services that are directed to children under 13 years of age, generally including obligations to obtain verifiable parental consent and to give parents control over information collected from their children. COPPA is a U.S. federal instrument enforced by the Federal Trade Commission; its scope, age thresholds, and specific obligations are not necessarily equivalent to children's privacy provisions in other regimes, and treatment of minors differs across jurisdictions (for example, under the EU GDPR and the UK GDPR, which set their own conditions for children's consent and are not addressed by COPPA). This entry defines the concept and scope of children's privacy; it does not detail specific consent verification mechanics, applicable age thresholds across all regimes, state-level laws, retention rules, or enforcement penalties, and no single consent or compliance mechanism should be treated as guaranteeing compliance in a given context.

Why it matters

Children's privacy carries heightened stakes because children may not fully understand the consequences of sharing personal information, and regulators have responded by imposing obligations that go beyond those applying to adults. In the United States, the Children's Online Privacy Protection Act (COPPA) reflects a policy judgment that parents, rather than children, should exercise control over what information online services collect from kids under 13. For operators of websites and online services, this means that a business model or feature that is unremarkable when directed at adults can trigger a distinct set of legal requirements when a service is directed to children.

The compliance burden here is not interchangeable across jurisdictions, which is a frequent source of error. COPPA is a U.S. federal instrument enforced by the Federal Trade Commission, and its age threshold and specific obligations are not equivalent to the children's provisions found in other regimes such as the EU GDPR or the UK GDPR, which set their own conditions for children's consent. Organizations operating across borders cannot assume that satisfying one framework satisfies another, and treatment of minors differs meaningfully across jurisdictions.

The practical relevance has grown as more of children's social and educational lives move online. As services expand their reach to younger users, the question of whether a service is directed to children, and therefore whether children's privacy obligations attach, becomes a live and consequential determination rather than an edge case. Misjudging that scope can expose an operator to enforcement, but no single consent or compliance mechanism should be treated as guaranteeing compliance in a given context.

Who it's relevant to

Operators of services directed to children
Businesses running websites or online services that are directed to children under 13 in the U.S. are the primary parties on whom COPPA imposes obligations, generally including obtaining verifiable parental consent and giving parents control over information collected from their children. Whether a service is 'directed to children' is itself a determination that shapes whether these obligations attach.
Privacy and compliance professionals
Data protection officers, privacy counsel, and compliance leads need to identify when children's privacy provisions are triggered and to avoid treating regimes as interchangeable. COPPA is not equivalent to the children's provisions of the EU GDPR or UK GDPR, and organizations operating across jurisdictions must assess each applicable framework on its own terms.
Product and engineering teams
Teams designing features, data collection flows, and consent mechanisms for services that may reach younger users must understand that features benign for adult audiences can trigger distinct legal requirements. They should note that no single consent mechanism should be treated as guaranteeing compliance, and that verification mechanics and age thresholds must be determined against the applicable law.
Parents and guardians
COPPA is designed to give parents control over what information is collected from their children online, reflecting the recognition that children may not fully understand the consequences of sharing their personal information. Parents are the party to whom control and consent rights are generally directed under the U.S. framework.

Inside Children's Privacy

Age thresholds for consent
Regimes set age boundaries below which processing generally requires a parent or guardian to consent or authorize on the child's behalf. The EU GDPR sets a default digital-services consent age with a range within which member states may set their own lower threshold, so the applicable age varies by jurisdiction. Practitioners should confirm the specific threshold for each market rather than assuming a single universal age.
Parental or guardian involvement
Where a child cannot provide valid consent, a lawful basis often depends on obtaining and, in some regimes, making reasonable efforts to verify parental or guardian authorization. The mechanism and rigor of verification differ across instruments and are not standardized globally.
Special protective status of children as data subjects
Several frameworks treat children as meriting specific protection because they may be less aware of the risks, consequences, and their rights regarding processing. This status can heighten expectations around transparency, marketing restrictions, and risk assessment, but the exact obligations depend on the governing instrument.
Transparency addressed to children
Where services are directed at or likely to be used by children, notices and information about processing are generally expected to be presented in clear, age-appropriate language so the intended audience can understand it.
Sector- and regime-specific rules
Children's privacy is governed by different instruments depending on jurisdiction and context, and treatment is not interchangeable across them. Terms, ages, and obligations that apply under one regime should not be assumed to apply under another.

Common questions

Answers to the questions practitioners most commonly ask about Children's Privacy.

Is parental consent always the required lawful basis for processing children's personal data?
No. Parental or guardian consent is one mechanism that applies in specific contexts, but it should not be conflated with a universal requirement. Under the EU GDPR and UK GDPR, verifiable parental consent is generally tied to the offer of information society services directly to children below a specified age threshold, and consent is only one of several lawful bases for processing. Other lawful bases may apply depending on the processing context, and treatment differs across regimes such as the CCPA and CPRA in the United States, which frame protections for minors differently. The appropriate basis depends on jurisdiction, the nature of the service, and the specific processing activity. This answer does not address the precise age thresholds, which vary by jurisdiction and may be set within a permitted range.
Does applying pseudonymization or encryption to a child's data remove it from children's privacy obligations?
No. Pseudonymization is reversible and the resulting data generally remains personal data, so it stays within scope of applicable protections. Encryption and tokenization are security controls that protect confidentiality but do not render data non-personal. A child's data that has been pseudonymized, encrypted, or tokenized typically continues to attract children's privacy obligations. Only irreversible anonymization would generally move data out of scope for most data protection regimes, and achieving genuine irreversibility is difficult in practice. These techniques are security and risk-reduction measures, not a means of exemption from the accountability and lawful basis requirements that apply to children's data.
How should an organization determine whether its service is directed at or likely to be accessed by children?
This is generally assessed by examining factors such as the nature and content of the service, marketing and presentation, any age-related terms, and available evidence about the actual audience. Some regimes distinguish between services directed at children and services likely to be accessed by children, and the applicable analysis differs by jurisdiction. The assessment should be documented as part of demonstrable accountability rather than asserted informally. This answer does not cover the specific criteria used by any individual regulator, which should be consulted directly for the relevant jurisdiction.
What role does age assurance or age verification play in a compliance program for children's data?
Age assurance or verification is typically used to determine whether a user falls within an age group that triggers additional protections or a parental consent requirement. The chosen method should generally be proportionate to the risks of the processing, and it can itself involve collecting personal data, which must be justified and minimized. No single verification mechanism guarantees compliance; the appropriateness depends on context, jurisdiction, and implementation. Organizations should document the rationale for the method selected as part of accountability. This answer does not endorse or specify particular technical verification products or thresholds.
When is a data protection impact assessment appropriate for processing involving children?
A data protection impact assessment is not automatically mandatory for all processing, but processing of children's data is commonly treated as a factor that raises risk and may make an assessment appropriate or required, particularly where large-scale, profiling, or high-risk processing is involved. The determination should follow the criteria set out in the applicable regime and any regulator guidance. Where conducted, the assessment should be documented to support demonstrable accountability. This answer does not enumerate the specific triggers, which differ by jurisdiction and should be assessed against the governing instrument.
How can an organization demonstrate accountability for its handling of children's data?
Accountability under governance and data protection frameworks generally requires demonstrable evidence rather than stated intent. In practice this can include documented policies on children's data, records of the lawful basis relied upon, evidence of any consent mechanisms and their verification, documented age assurance decisions, and any risk assessments performed. These records fall on the data controller, which bears primary accountability, while any processor handling the data acts on the controller's documented instructions. This is a governance and documentation matter distinct from the security controls protecting the data. This answer does not address retention schedules, cross-border transfer mechanics, or enforcement penalties, which are governed separately.

Common misconceptions

There is a single global age of consent for children's data.
Age thresholds differ by jurisdiction and instrument. The EU GDPR permits member states to set a threshold within a defined range, and other regimes set their own ages, so practitioners must determine the applicable threshold per market rather than relying on one number.
Parental consent alone guarantees that processing of a child's data is compliant.
Consent is only one lawful basis and, even where parental authorization is obtained, compliance still depends on satisfying other applicable requirements such as transparency, purpose limitation, and the specific conditions of the governing regime. No single consent mechanism guarantees compliance across contexts.
If a service is not explicitly marketed to children, children's privacy rules do not apply.
Protective obligations can attach where a service is directed at or likely to be accessed by children, not only where it is expressly marketed to them. Whether the rules apply depends on the actual and anticipated audience and the applicable instrument.

Best practices

Identify the specific children's privacy instrument(s) applicable to each jurisdiction and market you operate in, and confirm the relevant age threshold rather than assuming a single universal age.
Assess whether your service is directed at or likely to be accessed by children, and document the basis for that assessment as demonstrable evidence rather than stated intent.
Where processing relies on parental or guardian authorization, define and record the verification approach appropriate to the governing regime, recognizing that required rigor varies.
Provide transparency information in clear, age-appropriate language where children are the intended or likely audience.
Treat the applicable consent age and verification method as regime-specific, and avoid porting requirements from one instrument to another without confirming they apply.
Maintain documented evidence of the lawful basis, age-assurance decisions, and any parental authorization to support accountability, since compliance depends on context and implementation and cannot be assured by any single control.