Privacy and Data

Most conversations about kids’ online privacy start from fear of a stranger getting hold of information. That risk is real, but it’s not the main one. The main one is quieter: by the time a child is old enough to have an opinion about their own privacy, a great deal of it has already been decided for them, by an app, a school, or a parent, without anyone involved doing anything a person would call wrong. Privacy here isn’t primarily about danger. It’s about what’s owed to a child’s future self: the right to define their own story before someone else has already written a large part of it.

Where the data actually comes from

Three sources feed most of this, mostly invisible to a child and often to a parent, too.

Apps and platforms the child uses directly. “Free” almost always means data is the actual payment. Even large, well-resourced companies get this wrong: the FTC settled with Disney for $10 million in 2025 over collecting data from children on YouTube without parental notice, and with game developer Cognosphere for $20 million the same year for continuing to collect children’s data after learning specific users were minors.

Canada’s privacy regulator doesn’t have that power: PIPEDA gives the Office of the Privacy Commissioner no authority to levy fines like these. But in September 2025, the federal Commissioner and his Quebec, B.C., and Alberta counterparts found TikTok’s safeguards against under-13 use, and against using children’s data for ad targeting, “inadequate,” after finding roughly 17% of children aged 6 to 12 in Quebec already had accounts despite the platform’s 14-plus minimum age; the outcome was negotiated commitments from TikTok, not a financial penalty. If it happens at that scale to companies this size, it’s safe to assume it happens, unnoticed, at smaller ones.

School-assigned EdTech tools, which a family doesn’t get to opt out of the way they might a social media account. A 2022 industry benchmark found 96% of American school apps shared student data with third parties, mostly advertisers and analytics firms, and newer research puts the share of American school apps collecting data beyond what they disclose at roughly half.

A global picture from Human Rights Watch, examining EdTech products endorsed by 49 governments across every populated continent, found a similar pattern: 89% of the products it assessed monitored or could monitor children, mostly without meaningful consent, and more than 140 of them sent children’s data to a combined 196 advertising-technology companies. The FTC has stated that a school authorizing a tool doesn’t exempt the company from children’s privacy law; Canada has no equivalent child-specific rule under PIPEDA yet, though a bill before Parliament, Bill C-36, would add real penalty powers and treat children’s data as sensitive by default if it passes.

Parents themselves, through “sharenting.” A 2010 study across ten countries found this varied widely by country: as high as 92% of children under two already had some digital footprint in the United States, roughly 84% in Canada, and 73% on average across the European countries surveyed, all created entirely by a parent’s own posts before the child could have any say.

That data is now over fifteen years old and due for an update, but the core issue researchers keep raising hasn’t changed: the issue isn’t the posting itself but consent. A child too young to talk can’t agree to what’s being shared about them, and it follows them regardless.

What actually helps, in practice

  • Treat a “free” app your child wants to join the way you’d treat a form you’re signing on their behalf, because that’s what it is. A few minutes checking what data it collects and who it’s shared with is worth more than any setting you’ll adjust afterward.
  • Ask the school directly what tools are required and whether they’ve been vetted, especially for anything used regularly. You’re within your rights to ask: the FTC’s position in the U.S. is that school approval doesn’t excuse a vendor from the law, and in Canada, PIPEDA’s obligations apply to a vendor regardless of who authorized the tool, even though Canadian enforcement currently looks different in practice.
  • Make sharenting a family decision, not a unilateral one, as soon as a child can weigh in. A short, explicit family media agreement, what gets posted, what doesn’t, that a child can object to something after the fact, does real work here and is something researchers specifically point to as effective.
  • Treat data as durable, not disposable. A photo, a school-app record, a chatbot transcript doesn’t expire when the phase it captured does. The habit worth building isn’t paranoia; it’s the pause of asking “does this need to exist, indefinitely, attached to my child’s name,” before it’s created.

That closes the practical ground this guide set out to cover: attention, social platforms, AI tools, and now data. Underneath all four is the same question the first page opened with: not just what are we protecting our kids from, but who are we helping them become, and what are we, ourselves, teaching them a person’s information and attention are worth.

Sources