← Policy & Global Updates
Draft privacy code, age assurance & children’s dataAustralia

Children’s privacy should not be the price of age appropriate protection

Australia’s privacy regulator consulted on a draft Children’s Online Privacy Code under the Privacy Act 1988. The draft would apply to social media, relevant electronic services and designated Internet services that are likely to be accessed by children, including many applications, games and websites.

01

What it could improve

The draft Code would translate general privacy principles into clearer requirements for services handling children’s personal information. It addresses the best interests of children, age assurance, consent, transparency, marketing, access and correction, and permanent deletion. This could make privacy part of age appropriate design rather than a notice children are expected to understand after data collection has already begun.

02

What remains unresolved

Age appropriate protection requires some services to understand a user’s age or developmental context. The unresolved challenge is how to provide that context without turning every service into a separate identity checkpoint.

  • Services need clear limits on what age assurance data may be collected, retained, reused, combined or disclosed.
  • A child may face repeated checks across platforms, games and websites, creating inconsistent outcomes and unnecessary exposure of documents, facial data or behavioural signals.
  • Consent should not legitimise harmful design or excessive data collection, particularly when children have limited practical choice.
  • A right to deletion needs to cover copies, inferred profiles and data shared with third parties, subject to lawful and proportionate exceptions.
  • Children need accessible explanations, correction routes and support when an age decision is wrong.
  • Privacy rules must address cross-service tracking and prevent a reusable assurance signal from becoming a persistent identifier.
03

The Child-Friendly Internet perspective

The draft Code aligns with the Child-Friendly Internet view that privacy and protection must be designed together. A trusted assurance mechanism could confirm only the relevant age or developmental band and provide a short-lived, purpose-limited signal to a participating service. The service could then apply its safeguards without receiving the child’s name, identity document or complete date of birth.

  • Collect the minimum information needed for the specific protective response.
  • Separate proof of eligibility from identity and prevent signals from being linked across services.
  • Require services to change recommendations, contact settings, commercial practices and wellbeing features when child context is recognised.
  • Give children and families practical ways to challenge errors and exercise deletion, access and correction rights.
  • Test whether privacy protections work across accounts, devices, signed-out use and shared-device situations.
?

The central question

Can online services recognise the child context they need while collecting less identity data and preventing tracking across services?