General legal information, published for everyone. It does not apply the law to anyone’s particular situation and is not legal advice. Laws change and differ by place; check the primary sources below.
Quick summary
- Children’s privacy on apps is governed by a mix of privacy, consumer-protection, education, and online-safety laws.
- The rules often depend on the child’s age, the type of information collected, whether the app is used through a school, and where the child lives.
- Posting or sharing a child’s information can also create harassment, safety, or reputation problems.
What it means
Children’s privacy on apps is governed by a mix of privacy, consumer-protection, education, and online-safety laws. The rules often depend on the child’s age, the type of information collected, whether the app is used through a school, and where the child lives. Posting or sharing a child’s information can also create harassment, safety, or reputation problems.
How the law works
How the law usually works
An app may collect information such as a child’s name, age, photographs, voice recordings, location, contacts, messages, device identifiers, browsing activity, and inferred interests. Privacy laws commonly require the app to explain what it collects, why it collects it, how long it keeps it, and who receives it.
Many laws also require:
- Collection to be limited to what is reasonably needed for the service.
- Reasonable security against unauthorized access.
- Clear privacy notices written in language children and parents can understand.
- Limits on targeted advertising, profiling, or sharing.
- A way to access, correct, or delete information.
- Special treatment where the service knows, or should reasonably know, that a user is a child.
In the United States, the federal Children’s Online Privacy Protection Act (COPPA) generally applies to online services directed to children under 13, or services that knowingly collect personal information from children under 13. It commonly requires notice to parents, verifiable parental consent in covered situations, parental access and deletion rights, data minimization, and reasonable security. COPPA does not provide a complete privacy framework for teenagers, so state laws and other federal laws may matter.
A school or school district can create additional issues. Information held by an educational institution may be covered by the Family Educational Rights and Privacy Act (FERPA) in the United States, while information processed by a private app may be covered by a separate privacy law or contract. A school’s approval of an app does not necessarily mean that every form of collection or advertising is lawful.
In England and Wales, the UK General Data Protection Regulation and the Data Protection Act 2018 apply to personal data. The Information Commissioner’s Children’s Code sets expectations for online services likely to be accessed by children. It emphasizes the child’s best interests, high privacy settings by default, data minimization, safety, and limits on profiling and geolocation. For online services relying on consent, UK data-protection law generally treats a child as able to provide consent at age 13, although other legal questions can arise below or above that age.
In Canada, the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and provincial privacy laws may apply. Meaningful consent, reasonable purposes, safeguards, access, and correction are common themes. A parent’s involvement may be relevant, but the law does not always treat parental consent as automatically necessary or sufficient; the child’s age, maturity, and the nature of the information can matter.
In Australia, the Privacy Act 1988 and its Australian Privacy Principles may apply to an app or organization. Australia does not use one universal statutory age at which a child can consent to every privacy decision. Capacity depends on the circumstances and the child’s understanding. The Office of the Australian Information Commissioner expects organizations to take children’s vulnerability and comprehension into account.
Privacy law is not always a complete remedy for harmful posts. Sharing private information, impersonation, threats, or repeated unwanted contact may involve separate harassment, criminal, civil, or online-safety rules. Defamation generally concerns publication of material that harms reputation and is usually subject to different tests and deadlines.
Common processes
- Review the app and account settings. People commonly examine the privacy notice, permissions, advertising settings, linked accounts, location access, public-profile settings, and direct-message controls. They may turn off unnecessary permissions and avoid entering information that is not needed.
- Ask the app or school what information is held. A written request may seek the categories of information collected, the purposes, recipients, retention period, source of the information, and whether automated profiling is used. A parent may make the request, but the organization may need to verify identity or consider the child’s own privacy rights.
- Request correction or deletion. People commonly ask the organization to correct inaccurate information, close the account, delete content, stop targeted advertising, or withdraw consent where the law provides that right. Deletion may not remove information already copied by others, preserved for legal reasons, or held in backups.
- Preserve evidence of harmful conduct. Screenshots, account names, URLs, dates, messages, and records of reports can help show what happened. Evidence is usually stored without reposting the harmful material. If threats, exploitation, or immediate danger are involved, emergency services should be contacted first.
- Use the app’s reporting and safety process. Platforms commonly have processes for impersonation, sexual exploitation, doxxing, threats, bullying, and unauthorized accounts. Reports should identify the child’s age where relevant and explain the specific safety or privacy concern.
- Complain to a regulator or school authority. If the response is inadequate, people commonly complain to the relevant privacy regulator, education authority, consumer-protection agency, or online-safety regulator. The complaint usually includes the original request, the organization’s response, and supporting evidence.
- Consider legal proceedings. Depending on the facts, possible routes can include a privacy complaint, a data-protection claim, a defamation claim, an injunction, or a claim involving misuse of private information. The available remedies differ substantially by country and state.
Deadlines and time limits
Privacy-request deadlines vary. UK GDPR requests are commonly answered within one month, subject to permitted extensions for complex requests. PIPEDA commonly uses a 30-day response period, with limited extensions. Australian privacy law generally requires access requests to be handled within a reasonable period rather than using one universal fixed period. COPPA requires covered operators to provide parental access or deletion mechanisms, but the practical timing can depend on the request and the operator’s procedures.
Complaints to regulators may have their own filing periods or expectations that you first complain to the organization. Defamation deadlines are often short: England and Wales commonly use a one-year limitation period; many United States jurisdictions use roughly one to three years; Canadian and Australian periods vary by province, territory, or state and may commonly be about one to three years. These are only typical ranges. The applicable deadline should be confirmed with the court or a licensed attorney where you live.
Documents that usually matter
Useful documents commonly include:
- The app’s privacy notice, terms, age rules, and consent screens.
- Screenshots of settings, profiles, posts, messages, and permissions.
- Account records, usernames, URLs, dates, and device information.
- Copies of requests for access, correction, deletion, or consent withdrawal.
- The organization’s replies and records of telephone calls.
- School contracts, notices to parents, acceptable-use policies, and technology policies.
- Evidence of financial loss, emotional harm, threats, or safety concerns.
- Records showing whether information was shared publicly, sold, used for advertising, or provided to another service.
How it differs by jurisdiction
- United States: COPPA focuses mainly on children under 13 and covered online services. State privacy laws can protect teenagers and may provide opt-out or consent rights for sale, sharing, targeted advertising, or profiling. California is a prominent example, but its rules are not the same as every other state.
- England and Wales: UK GDPR rights and the Children’s Code apply broadly to personal data and child-accessible services. The child’s best interests and privacy by default are important considerations. Scotland and Northern Ireland use the same UK-wide data-protection framework but have different legal systems for some court and child-law matters.
- Canada: Federal and provincial rules can overlap. Quebec, Alberta, and British Columbia have important provincial privacy regimes, while other situations may primarily involve PIPEDA. The child’s maturity and the sensitivity of the information can affect consent questions.
- Australia: The Privacy Act and Australian Privacy Principles apply nationally, but state and territory education, health, child-protection, and surveillance laws may also matter. The eSafety framework can be relevant to serious online abuse, image-based abuse, and cyberbullying.
- Schools and public bodies: Public-sector and education records can be governed by separate laws from those applying to private apps. The location of the school, the app company, and the child may all affect which rules apply.
When people consult a lawyer
A licensed lawyer may be useful when an app refuses a significant access or deletion request, a child’s sensitive information has been exposed, a school has shared information without clear authority, or a dispute involves threats, sexual material, doxxing, impersonation, or serious reputational harm.
Legal advice is especially important before filing a defamation or privacy lawsuit, agreeing to a settlement, signing a school or platform release, or making a public accusation. Urgent advice may be needed where evidence could disappear, a limitation period is close, or an injunction might be considered.
Primary sources
- StatuteUnited States: Children’s Online Privacy Protection Act, 15 U.S.C. §§ 6501–6506, andUnited States (federal)
Links go to official or widely used free sources. Check that a source is current before relying on it. Browse all sources →
- Last updated
- Sep 26, 2026
- Jurisdiction
- General — United States, England & Wales, Canada, Australia
- Written by
- House Legal editorial (AI-generated, earlier format)