Key privacy considerations for minors: Navigating a rapidly evolving landscape

This Insight was prepared with the assistance of Summer Student Zoë Goetz.
The protection of children’s personal information has become one of the defining regulatory priorities of 2026. From amendments to longstanding federal frameworks in the United States to the development of a dedicated Children’s Privacy Code here in Canada, organizations that collect or process minors’ data face an increasingly complex web of obligations. Whether you operate an online platform, develop connected products or simply maintain a website accessible to young users, understanding these key considerations for minors should be considered an essential component of your overall privacy program.
Why minors require heightened protection
Children and teens interact with digital services differently than adults. They may not fully appreciate the consequences of consenting to data collection, and they are particularly vulnerable to manipulative design features, targeted advertising and exploitation. Legislators and regulators worldwide have responded with frameworks rooted in the principle that the best interests of the child must be a primary consideration whenever their personal information is at stake.
High-profile incidents involving online exploitation, exposure to harmful content and addictive platform design have spurred public demand for stronger safeguards – and policymakers have answered. We previously canvassed these issues in an earlier Insight, and the compliance expectations have continued to expand since.
The Canadian context: A Children’s Privacy Code on the horizon
In Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) does not currently contain specific provisions for children’s privacy. However, the Office of the Privacy Commissioner (OPC) has made this a national priority.
Between May and August 2025, the OPC ran an exploratory consultation on the development of a dedicated Children’s Privacy Code, receiving 37 submissions and hosting four roundtable discussions – including one directly with youth. In May 2026, the OPC published formal age assurance guidance and released findings from this consultation, signalling a shift from a purely principles-based approach to a structured, code-based framework more closely aligned with the UK’s Age Appropriate Design Code (Children’s Code).
Key themes emerging from the Canadian consultation include:
- Best interests of the child as the overarching standard for data handling decisions
- Privacy by default, including high default privacy settings for services accessible to minors
- Restrictions on deceptive design patterns that nudge children into sharing unnecessary personal information
- Limitations on disclosures to third parties, supported by contractual and technical measures
- Tiered applicability, distinguishing between services directed at children and mixed-audience services likely to be accessed by children
The anticipated reform of PIPEDA itself is expected to address children’s personal information specifically and introduce potentially significant penalties for non-compliance. We discuss the Federal government’s proposed overhaul in detail in our Insight, Implications of Canada’s proposed privacy overhaul Bill C-36 for organizations.
Consent and age thresholds: A patchwork of requirements
One of the most complex aspects of minors’ privacy compliance is navigating inconsistent age thresholds and consent requirements across jurisdictions.
In the United States, the Children’s Online Privacy Protection Act (COPPA) remains the foundational Federal law, requiring verifiable parental consent before collecting personal information from children under 13. The FTC’s April 2025 amendments to the COPPA Rule added new obligations, including mandatory written information security programmes and data retention policies. Enforcement has intensified, with more than a dozen public COPPA actions in the past two years, some resulting in multimillion-dollar settlements. Some state-level laws are expanding these protections beyond the under-13 threshold.
In Canada, the OPC treats users under 13 as unable to provide independent consent, while the proposed code envisions a broader framework for all minors.
Under the UK General Data Protection Regulation (GDPR), the age of digital consent is set at 13, and the UK’s Children’s Code applies to all information society services likely to be accessed by users under 18.
Age-appropriate design: Beyond notice and consent
A critical trend in minors’ privacy regulation is the move away from reliance on notice-and-consent alone, toward obligations centered on how digital products are designed.
Age-appropriate design codes such as the UK’s Children’s Code, generally require:
- High privacy by default for child users
- Data minimization, collecting only what is strictly necessary
- Restrictions on profiling and targeted advertising directed at minors
- Prohibition of nudge techniques that encourage children to weaken privacy settings
- Geolocation services switched off by default
- Mandatory data protection impact assessments before launching services likely to be accessed by children
In February 2026, the UK ICO fined Reddit £14.47 million for failing to protect children’s privacy – a clear signal that these obligations carry real enforcement consequences.
Age assurance and verification
Regulators are increasingly expecting organizations to implement age assurance mechanisms rather than relying on self-declaration. In February 2026, the FTC issued a policy statement encouraging robust age-verification technologies, pledging not to bring COPPA enforcement actions against operators that collect personal information solely to verify users’ ages, provided strict safeguards are followed.
In Canada, the OPC published formal age assurance guidance in May 2026 for both website operators and age assurance developers.
The challenge for organizations lies in implementing age estimation or verification without itself creating privacy risks – particularly the risk of collecting more personal information than necessary in the process.
Practical steps for organizations
Given this rapidly evolving landscape, organizations processing or potentially processing minors’ data should consider the following:
- Audit your user base – Determine whether your services are directed at children or whether children are reasonably likely to access them, even if they are not the primary audience.
- Implement privacy by default – Apply the most protective privacy settings automatically for users who may be minors. Do not rely on children to opt into protections.
- Minimize data collection – Collect only what is strictly necessary for service delivery. Avoid retaining biometric identifiers, precise geolocation or persistent tracking identifiers for child accounts.
- Adopt robust age assurance – Move beyond simple checkbox self-declaration and implement proportionate age estimation or verification measures, while ensuring those measures are themselves privacy-protective.
- Review consent workflows – Ensure verifiable parental consent mechanisms are in place where required and maintain auditable records of when and how consent was obtained.
- Conduct child-focused privacy impact assessments (PIAs) – Before launching new products, features or services likely to be accessed by minors, carry out PIAs that specifically address risks to children.
- Eliminate dark patterns – Audit your interfaces for deceptive design patterns that may pressure minors into sharing unnecessary data or weakening their privacy settings.
- Monitor regulatory developments – With the OPC’s Children’s Privacy Code in development, PIPEDA reform anticipated and new State and Provincial laws emerging regularly, maintaining an active regulatory monitoring program is critical.
Looking ahead
The protection of children’s privacy is no longer a niche compliance concern – it is a national and international priority backed by escalating enforcement. In Canada, the forthcoming Children’s Privacy Code and expected PIPEDA reforms will likely impose structured obligations that go well beyond the current principles-based approach. Globally, the direction of travel is clear: Default protections, safety-by-design and meaningful accountability for how organizations handle minors’ personal information.
Children’s privacy is also converging with online safety regulation. On June 10, 2026, the federal government introduced Bill C-34, the Safe Social Media Act, which would enact the Digital Safety Act and establish a Digital Safety Commission of Canada, imposing duties on operators of regulated social media services, chatbot services and other regulated online services with the express purpose of promoting the safety of persons in Canada, particularly children, and protecting children’s physical and mental health. Bill C-34 and Bill C-36 are designed to work together, and organizations serving young users will need to plan for both. Watch for our forthcoming Insight on what the Safe Social Media Act would mean for organizations.
Organizations that proactively embed child-centric privacy protections into their products and operations today will be better positioned to meet tomorrow’s regulatory expectations – and to maintain the trust of the families they serve.
Our Privacy, Data Protection and Cybersecurity team will continue to monitor and provide updates on the ongoing changes to the privacy landscape. Whether you’re looking to better manage cyber-risk, comply with privacy legislation, protect your intellectual property, or launch a new digital transformation initiative – we are here to help.
Note: This article is of a general nature only and is not exhaustive of all possible legal rights or remedies. In addition, laws may change over time and should be interpreted only in the context of particular circumstances such that these materials are not intended to be relied upon or taken as legal advice or opinion. Readers should consult a legal professional for specific advice in any particular situation.




