This week we hosted an online webinar in the form of a panel discussion with experts from digital rights, medtech, gaming and privacy consulting. The topic was something that is often kept under the radar by the authorities enforcing data protection: the protection of children's personal data.
As privacy professionals, we are well aware that privacy regulations put enhanced emphasis on the protection required when processing children's personal data, but we also acknowledge the many challenges and misunderstandings that come with it. And since the objective of privacy regulation is not to make life harder for companies, but to make life easier for data subjects, we wanted to open a conversation around the key issues and stumbling blocks in processing children's data.
We held the webinar on Wednesday 23 September and made the recording available to all registered participants. If you would also like to watch the webinar but were not able to register or attend, feel free to reach out to webinar@whitelabelconsultancy.com, and we will happily send you the recording. Otherwise, please enjoy the read below, which summarises the key points of reflection and takeaways shared by the speakers during the session.
Key takeaways
1. The risk is not the data itself, but what it could be used for
Children are rights holders in their own right, but they find themselves navigating digital services built on an enormous imbalance of power and information, without yet having the maturity or the tools to handle it.
From a privacy standpoint, the issue goes far beyond someone learning a child's name or birthday. Data is used to infer interests, vulnerabilities, even emotional states, and then to shape what children see, what they are nudged to buy, and how automated systems classify them.
Gaming is a very concrete example. Game data is often used both to run the game and to judge how likely a player is to spend money. For children, these two uses should be kept strictly apart. Data needed to keep the game fair and secure is one thing; data used to keep a child playing longer or spending more is another. That is why, for children's accounts, profiling should be switched off by default.
2. You can't protect a child you haven't identified
Protecting children starts with knowing that you are dealing with one. During the session, we used the Reddit case to show what can go wrong when this step is missed. In February 2026, the UK Information Commissioner’s Office (ICO) fined Reddit £14.47 million for failing to protect children's personal data. Reddit's Terms of Service said that children under 13 were not allowed on the platform, but nothing was in place to enforce that rule, and many children under 13 were using it anyway. The ICO found that Reddit had no lawful basis for processing these children's data: it relied on consent, but it had no way of collecting parental consent for them.
What we found most interesting was what came next. Reddit introduced an age check based on self-declaration, where users simply confirmed that they were over 13. As the panel noted, this puts the whole burden on the child, and the ICO agreed it was easy to get around, since any child can simply say they are older. Reddit's answer was that collecting more data to verify age would go against privacy principles. This is a real dilemma that many companies face, and it sparked one of the most useful parts of the discussion: how do you check age reliably without collecting more data than you need?
Unfortunately, there is no one-size-fits-all answer. The EDPB calls for a proportionate approach using the most privacy-friendly methods available, such as a digital wallet on the user's phone that only tells the platform “over 13” or “under 13.” The platform learns nothing more, but the proof is far more reliable.
3. Consent, and even age checks, are only part of the answer
It is tempting to see parental consent as the solution to everything, but a parent clicking “I agree” does not make excessive data collection or manipulative design lawful. All the usual GDPR rules still apply, and in many cases consent is not even the legal basis being relied on.
The same goes for age verification. One of the most interesting challenges raised during the session was that checking someone's age is not the same as protecting them. Before asking how to verify age, companies should ask whether they need to know it at all. Many safeguards, like limiting profiling, collecting less data, removing addictive design and restricting contact from strangers, can simply be applied to everyone. Where an age check is truly needed, it should collect the minimum, stay separate from the rest of the account, and never be reused for anything else. And turning 16 or 18 should not suddenly make harmful design acceptable.
4. The child is still the person whose data it is
Once a parent gives consent, it is easy to forget the child. But the child remains the data subject, and they should keep a real say. In practice, this means testing with children whether they understand what is being agreed, and doing so at different ages. It means giving them settings they can manage themselves, such as whether their voice is recorded or whether others can see them. A helpful principle is that a child cannot agree to more than their parent did, but they can take parts of it back.
Two observations came with this. Parental consent should not turn into a tool for monitoring children, and respecting a child's maturity should not become an excuse to profile them in order to judge how mature they are. Finally, a child can only use their rights if they understand them, so privacy notices should be written for the people who will actually read them.
5. Children grow up and systems need to be ready for it
When a child reaches the age to decide for themselves, they should be able to confirm, change or withdraw what their parent agreed to, and be told that they can. For companies, this raises practical questions. Which activities actually rely on consent? What happens if a young patient does not give new consent, and could it affect their care? Should parents lose access to certain records? And coming of age is rarely only a privacy matter: new terms of use, health insurance or bank account rules may change at the same time.
This gets even harder across borders, because the age of digital consent differs from country to country. The practical answer is flexibility: on process, with different rules for each country's age threshold, applied across the whole product and not just the app. None of this can be solved at the last minute. It needs legal, clinical and support teams involved early, ideally when the product is first designed.
A final thought
If there is one thing we would like readers to take away, it is that protecting children's data means keeping two questions in mind at the same time:
- What are we doing to keep children safe from the risks of our processing?
- And what are we doing to make sure they still have a say over their own data, even when a parent is involved?
The first is about safety, the second is about autonomy, and good practice needs both.