Privacy in Practice · 2026-08-11 · 46 min
Key moments - from our scoring
Substance score
68 / 100
Five dimensions, 20 points each
Children's privacy requires a fundamentally different approach than adult privacy because the traditional notice-and-consent model breaks down when dealing with minors. Hailyn Ying from Roblox explains that children lack the developmental capacity to understand data consequences, face power imbalances with persuasive design patterns, and face distinct harms like identity development exposure and location tracking that differ from adult risks. The regulatory landscape is fragmented globally - COPPA sets the U.S. federal baseline at 13 but states now range from 13-18; GDPR defaults to 16 (down to 13 in some EU states); Brazil's Digital Eka covers under-18s; South Korea's PIPA sets 14 with penalties up to 10% of global turnover. Rather than relying on child consent, modern frameworks shift to parental authorization, privacy-by-design defaults, and age assurance mechanisms. These span three categories: age verification (ID documents, payment instruments), age estimation (facial analysis via AI), and self-declaration. Each approach presents trade-offs between accuracy, privacy, friction, and equity.
Children may in some jurisdictions be able to agree to terms and conditions or download an app, but this is distinct from legal consent to process their personal data. Depending on the country and the child's age, parental authorization may be required for data processing even if the child can technically register for a service.
Age assurance is an umbrella term for any process or technology to determine if a user is above or below an age threshold. The three main methods are verification (ID documents or payment instrument), estimation (facial age analysis via AI), and self-declaration (user stating their age at sign-up).
Following Coupang's data breach in 2023 that affected the entire adult population of South Korea, President Moon Jae-in determined the existing penalties were insufficient, leading to the increase in maximum fines under PIPA.
Modern children's privacy laws increasingly include privacy-by-design defaults, data minimization requirements, enhanced parental disclosures, strict security obligations, and restrictions on profiling and targeted advertising - shifting compliance burdens from parents to service providers.
Facial age estimation analyzes physical characteristics like bone structure, skin texture, and face shape through AI to estimate an age range; it has improved accuracy but shows inconsistent performance across demographics, raising bias and fairness concerns.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode delivers consistent, substantive information about children's privacy law across multiple jurisdictions and technologies. However, it often stays at a high level (regulatory overview, age assurance categories) rather than drilling into surprising operational trade-offs or lesser-known implementation details. The discussion of vendor risk, bias in age estimation, and the tension between age verification and COPPA is solid, but relatively predictable for an audience already familiar with privacy frameworks.
Children's privacy isn't just a legal, uh, or compliance problem anymore. It's legal, it's product, it's engineering, it's safety, it's policy.
the age estimation models and these other models have shown disparate performance across race, skin tone and even gender, meaning that the system is more likely to misclassify certain populations.
The episode covers familiar regulatory terrain (COPPA, GDPR, age verification methods) with competent synthesis but limited contrarian insight. The observation about threat actors timing attacks during summer vacations when gaming platform use peaks is novel and well-observed. However, most frameworks and concerns (consent problems, cross-functional alignment, privacy by design) are standard in privacy discourse. The FTC February 2024 policy statement is timely but explained rather than critically examined.
It's also summer vacations and water breaks, because that's when the kids are home, when school is out and the use of platforms spikes dramatically. The threat actors know the risk surface is larger.
the old model of assuming users are adults and building for adults and adding child protections to the ones that you identify as children, if you even admit that you have children in the first place on your service doesn't really work anymore
Hailyn Ying is well-positioned: Director of Privacy and Security Legal at Roblox, a major children-facing platform, with prior experience at PayPal handling M&A and security privacy. She speaks with operational authority about real implementation challenges Roblox faces. However, she is primarily a legal counsel rather than a product, engineering, or executive operator who built a children's product from scratch or scaled one. Her perspective is informed but somewhat counsel-centric.
Helen is currently the Director and Head of Privacy and Security Legal at Roblox, where she leads the team responsible for privacy and cybersecurity legal matters across one of the world's largest online platforms for user generated content.
children's privacy is genuinely one of my favorite topics to talk about. There's always something new happening.
The episode provides good concrete examples: named countries (Brazil, Korea, UK, EU), specific fines (Instagram €405M, Reddit £14M+), company cases (Apitor, Hyperbear, YouTube, Google, Disney), and identified regulations (COPPA, GDPR, LGPD, Digital EKA, PIPA). However, it lacks specific metrics on accuracy rates of age estimation technologies, concrete breach timelines, or quantified costs of age assurance implementation. Numbers are present but selective; the discussion remains largely illustrative rather than deeply data-driven on operational impacts.
There was a big fine against Instagram, 405 million euros couple of years ago.
the UK ICO issued a fine, just over 14 million pounds for Reddit's unlawful processing of children's personal information.
The hosts ask clear, structured questions and allow the guest space to answer substantively. Follow-ups are present but often move to new topics rather than probe deeper into tensions or push back on assumptions. The hosts occasionally make clarifying interventions (e.g., noting the distinction between consent to use an app vs. consent to data processing) which is valuable. However, there is little genuine disagreement, challenge to the guest's framing, or exploration of edge cases where the guest's recommendations might break down. The tone is collaborative rather than interrogative.
I want to come back to the US and talk about one of those very specific tensions, which is COPPA and sort of, you know the point that you can't collect any information.
if you are using some kind of age assurance process and you realize that you have been collecting data of children under the age of 13. What do you do? What are your options?
Computed from the transcript - who did the talking, and the words that came up most.
Children’s privacy requires more than adapting privacy rules for younger users. Children may not fully understand the consequences of sharing personal information, may lack the legal capacity to consent to certain processing, and can be more susceptible to persuasive design features. At the same time, the age at which someone is legally treated as a child varies across jurisdictions and processing activities. Hailun Ying, Head of Privacy and Security, Legal at Roblox, joins Kellie du Preez and Danie Strachan to examine this fragmented legal landscape. The conversation covers COPPA in the U.S., the EU and the UK GDPR, age-appropriate design codes, Brazil’s LGPD and ECA Digital, and South Korea’s PIPA. They also explore the practical challenges of age assurance, including age verification, age estimation, and self-declaration. Technologies involving government-issued identification, facial age estimation, liveness checks, and other methods may help businesses assess users’ ages, but they can also create risks involving biometrics, vendor security, data retention, demographic bias, and user trust.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Children's privacy isn't just a legal, uh, or compliance problem anymore. It's legal, it's product, it's engineering, it's safety, it's policy. And when you're dealing with that many cross functional teams, it really requires a lot of alignment and understanding that it's more than just a legal requirement. And it sometimes needs to be a fundamental shift organizationally to be on the same page now that we're in a very different era of handling children's data and building products for and children M
Speaker B: welcome to Privacy in Practice, the podcast where we bring you the latest insights, practical solutions and real world stories from the world of data protection and privacy. I'm Kelly Dupree.
Speaker C: And I'm Dani Strachan. Privacy in Practice is brought to you by verisafe, your trusted partner in privacy and data protection. In this podcast we dig into the challenges and opportunities in privacy compliance, from navigating complex regulations to building a sustainable privacy program that works for your business, not against it.
Speaker B: So let's jump in and get practical with privacy. Today we are going to do our best to dive into the stormy, murky waters of children's privacy, and we have an excellent guest to do it with. We are very, very excited to welcome Hailyn Ying of Roblox to the podcast.
Speaker C: Helen is currently the Director and Head of Privacy and Security Legal at Roblox, where she leads the team responsible for privacy and cybersecurity legal matters across one of the world's largest online platforms for user generated content. Heylin's whole career has focused on data privacy, including at PayPal, where she specialized in privacy matters relating to mergers and acquisitions, product development, and security incidents.
Speaker B: With Heylin's expert assistance, we'll explore one of the most challenging and rapidly evolving areas of privacy law, children's privacy. We'll try to give an overview and orientation to the laws and issues around the world, unpack the growing focus on age assurance and age appropriate design, and examine the practical challenges organizations face when dealing with a rapidly changing regulatory and technological landscape.
Speaker C: Quick Disclaimer the views and opinions expressed on this podcast episode are those of the speakers and do not necessarily reflect the views or positions of any entities they represent. And without further ado, welcome Helen. It's a pleasure to have you here.
Speaker A: Thank you so much for having me. Uh, children's privacy is genuinely one of my favorite topics to talk about. There's always something new happening, so this could not be more timely.
Speaker C: And isn't that the great thing with privacy? It's always relevant it's ever changing. And lots of people have children or interact with children, or work at companies that have users, and those users might be children. So I'm so glad that we finally have an opportunity on this podcast to speak specifically about children's privacy, noting though that this is a high level discussion of children's privacy, there isn't enough time within today's podcast to really unpack everything in details. Having said that, Helen, why children's privacy different from standard privacy? If there is a difference, Most people
Speaker A: might think children are just, you know, a younger, uh, version of adults and you can treat children's privacy the same way and they might have heard something about a cutoff of 13, but it's actually a lot more complicated than that. And it's not really a recent thing that children's privacy is an area of interest either. The law has always recognized the difference between well before the Internet was widely available. But when we talk about standard or modern day privacy, you think about laws like GDPR and ccpa and the foundational assumption is that you're dealing with a capable adult who can read a privacy notice, understand what they're agreeing to, and make an informed choice. The whole notice and transparency and consent model is really built on that assumption. And with children, that model almost breaks down immediately. First, developmentally kids, especially younger kids, don't really understand how important their personal information is and the downstream impacts of sharing personal information or what it really means to even agree to something. Second, there is a real power imbalance here because the issues are different for adults and minors, and platforms are trying to be engaging and be appealing to both adults and minors. But children are arguably a lot more susceptible to those persuasive design patterns, the streaks, the likes, the reward bonuses, the continuous scrolling features that are out there. And laws are increasingly calling this out here directly. Potential harms are different in kind and severity. We're talking about harm to developing identity, exposure to inappropriate content, bad targeting by threat actors or bad actors, and the kind of data profiling that can actually follow a child into adulthood with data breaches or anything that exposes a child's location or daily patterns, anything like that, and it wouldn't be the same for an adult. So when children's privacy laws are getting drafted nowadays, they're starting to include these structural protections that go well beyond just notice and consent.
Speaker B: I think that's fantastic. Kaylin and I want to pick up on something you said at the beginning of your answer where you mentioned 13 for our, uh, non American listeners. That's the age of a child in capa. Right. Which is the US federal law that, as you say, predates gdpr, ccpa, all that stuff. But now in all of these laws and frameworks and all the things that are coming out around children, it's kind of hard to say what is a child. So what is a child?
Speaker A: You'd think that this would be an easy question, but it's actually one of the more complicated ones in this space because like you mentioned us, 13. But it's no longer just 13, it's 18 in some states, it's 16 in others. In the EU we have anything that ranges from 13 to 16. In the UK we have under 18. In APAC, we have some that are under 16, some that are 14. In LATAM we have under 13, we have under 12, under 18. So essentially there's no good answer and it's a patchwork and there's no common
Speaker B: baseline which, you know, to be fair, makes sense. Right, to the point you were saying. I mean, if at, ah, base what we're talking about is somebody's ability to give consent, ability to understand what they're interacting with and how it might be impacting them and how susceptible they are to it, and then to your point again about the data breaches and the impact and the location patterns, it kind of does make a difference whether someone's 17 or whether they're 11. So it makes sense that these different laws are going to have different approaches, but doesn't make it easy for companies in compliance.
Speaker C: Another philosophical question. Let's talk about consent within the context of children's privacy. So when we talk about standard privacy, if there's such a thing, consent often comes up. There are some situations where an organization must get consent to process some type of personal data and then you get the consent from the data subject and you carry on and you do the processing basically in some situations. But when it comes to a child, can a child even give consent to the processing of their personal data? How do we handle consent when it comes to a child?
Speaker A: Well, from the digital age of consent under privacy law perspective, a child can't actually provide consent legally. The concept of consent in privacy law borrows from contract law, where you're binding consent and it requires capacity or the, uh, ability to understand what you're agreeing to and the consequences of that agreement. A lot of legal standards don't grant that capacity to minors or children. However, it's defined whatever age under 18 that the country has elected for this specific type of processing and the contract signed by a child or created by a child through the agreement process is generally voidable. And a child's consent to data processing really has the same structural problem as in contract law. So what does the law actually require? Different frameworks have taken different approaches. Some laws allow you to rely on verifiable parental consent. Others allow for parental authorization, which is really a similar concept as verifiable parental consent. And more recently, there's been a shift toward privacy by design and default off settings. What I think we're seeing more is taking the burden off of parents and putting it onto parents companies offering the products and services that are made available to children.
Speaker C: And I think it's important also that people realize there is a difference between consent for the processing of a child's data versus just consent to use an app or to sign up for a service. Because there are some situations where children might under some law be able to agree to terms and conditions or download an app and register a profile for themselves, but that doesn't mean that they are now also giving consent to the processing of their personal data. While they might sometimes in some countries have, depending on their age, the ability to agree to terms and conditions and sign up for something, there might be situations certainly in some countries where the parent must give the consent. I can think of a number of countries where whether it's practical or not, the law says if someone is under 18, you cannot process their personal data without the parents authorization. Some of those laws might have been written in the infancy of the digital age. Whether that's still practical these days is a very big open question. So if you're in the U.S. you probably know about Coppa, but let's chat a little bit about the laws that regulate children's privacy across the globe. Obviously we're not going to cover each and every country, but call out some examples or some big or popular regions.
Speaker A: So I'll start with the US from federal and then go into states and then maybe you guys can cover some of the international countries as well because there's so much happening everywhere when it comes to children's data. But at the federal level in the US the anchor is obviously coppa, Children's Online Privacy Protection Act. It came into effect in the late 1990s, was first amended in 2013, and then, uh, again in 2024. And the latest amendment was actually finalized last year and went into effect last year. That update added a really important new requirements such as separate consent for third party sharing, strict data minimization, and disclosure of retention periods. Expanded definition of personal information, enhanced parental notices, new security obligations, and a lot more. And it was really focused on granting the parents and rights and what information needs to be shared with parents. The FTC has been increasingly active in enforcement, especially in this space. We've seen a lot of big cases in recent years, including against companies like YouTube and Google, Disney, and they've given a lot of clear guidance that they're very invested in children's privacy. So we should expect more in the upcoming years as well. And at the state level in the US there isn't a COPPA equivalent, but state AGs also have the ability to bring a COP account. And oftentimes when you see that there is a COP account, regardless whether it's at the state level or the federal level, there's actually an additional unfair and deceptive count to cover the teen age range as well. And a lot of these new privacy laws, statewide at least, they are making amendments to cover up to the age 18, or they're even coming up with different laws to cover children of, uh, various age ranges as well.
Speaker C: And then on the other side of the Atlantic, we have the EU and UK gdpr. Uh, I always like referring to the actual text of the gdpr. Often organizations and people forget that the GDPR isn't just the concept. It's actually written down and you have to go and read it and see what it says. And it's interesting because recital 38 specifically recognizes that children may be less aware of the risks, consequences and safeguards involved in the processing of their personal data. And therefore it merits additional protection. So it sets the scene at the beginning of the gdpr. And then there are situations where you do need parental consent. So Article 8 of the GDPR says where you have to rely on consent as a lawful basis for processing of personal data, you actually need to obtain parental consent in order to go ahead. And then it sets thresholds. So the default threshold under The GDPR is 16, although some member states can lower it to 13. In the UK, the threshold threshold is 13, but that's not where the story ends. So if you are processing personal information of children in the EU or the uk, still have to check is the processing fair? And you obviously have to think about the context there. You're dealing with children's information transparency. Is your privacy notice understandable to children? That's a whole episode on its own. Uh, but it's a real challenge for organizations. And is a transparency appropriate for children? And, um, then obviously you have to be very careful when it comes to Processing activities like profiling, targeted advertising, automated decision making. When you are dealing with children's data, and if you want to rely on legitimate interests, you have to be very careful when using that balancing test where children are involved. And then in the uk, there's actually the children's code to try and make it more practical to take some of these concepts and translate them into product design expectations. I just took a quick look at some fines. So there have been fines relating to children's data, uh, in the EU and in the UK. So there was a big fine against Instagram, 405 million euros couple of years ago. That fine was imposed by the Irish Data Protection Commission and that was because users between age of 13 and 17 had their profiles set to public by default and they could also switch their profiles to business accounts and then their phone numbers and email addresses were publicly displayed. So big issues that Instagram had to fix and they subsequently worked on those. They've also been fined against TikTok. And then as recent as February this year there was enforcement action in the UK against Reddit. UK ICO issued a fine, just over 14 million pounds for Reddit's unlawful processing of children's personal information. They didn't have any adequate, well, according to the regulator, didn't have adequate age assurance measures and allowed children under 13 to create accounts even though it they said that their service isn't aimed at or available to children. Children under the age of 13 could create accounts on the Reddit platform. Kelly, talking about age and appropriate things,
Speaker B: I was just going to say, picking up on two things you said and you know, as we said at the beginning, this has just got to be an orientation. There's so much information in this space. If you're trying to wrap your head around this as something, somebody in house or trying to help clients navigate this, I think you should just assume something applies and then go figure out where your potential kids are located and then figure out, you know, what to deal with. But just to flag that, you also have, in addition to the law, you also have these age appropriate design codes, some of which are sort of supported by the law, some of which are sort of being challenged. But you've got one in the uk, as Dani sort of alluded to, you've got one in California, there's a draft one in Australia that's supposed to be finalized by December. Comments on that just closed. So that's another thing to think about. And then you also got to think about sector specific stuff. So, uh, this has made a lot of news Headlines, but the social media bans, for example. So anyway, there's more than just, well, it's the eu, it's the gdpr, or it's the uk, it's the UK gdpr. There's a lot of other pieces to kind of consider internationally.
Speaker A: I think two other countries come to mind right now as being really notable. Brazil is definitely at the top of my list. The LGPD, the privacy law, has been around since 2021 and the reason why it's moved to the top of my list, notable countries in the children's space is because Digital Eka, which is an online safety and privacy law for children and minors under the age of 18. And it just came into effect in March of this year. The funny part is the enforcing regulator is actually the anpd. And yes, that's the same ANPD that regulates lgpd. So now they have two focuses, private privacy and children. And before they were vocal about children being, uh, a top priority and now they actually have two split priorities with their one scoping specifically children and the other being privacy. And the overlap is naturally going to be children's privacy. And the other country is Korea and their pipa, which is their version of the privacy law. And so something that's different right off the bat is the age of consent is 14 and, oh, you need to have consent of a legal representative before any kind of processing is done. For someone under the age of 14, yes, that's not unheard of. But what is new and raises the risk and eyebrows is that they're now actually going to be Moving from a 3% of global turnover Maximum fine to up to 10% of global turnover maximum fine. And this came about after Coupang had a data breach last year, and then the President of South Korea essentially said this was unacceptable because it essentially reached the entire adult population of South Korea and they decided to increase the maximum potential fine. And also the pipc, which is the regulator for pipa, have indicated that they're interested in children's data. And now a lot of companies that operate in South Korea are double triple checking their privacy practices if they have children using their services, just because of the incredible amount of fines that are potentially at stake right now.
Speaker B: I want to jump quickly to what we do now about this. So let's say you've done your homework and you've figured out kind of what laws might be in effect or what design codes might be in effect. You've read them, you've thought about them, maybe you're fighting through one topic we are not going to get into today because we do not have time. But then there's sort of some practical things that might raise this topic. Like for example, the Google Play Store or the Apple App Store suddenly has a whole bunch of information that they're either requesting or giving you or something that's messing with your structure of compliance. So we're going to sidestep that issue. But just point is these issues are coming up right in a variety of different contexts or ways. And I want to talk about then what you do with that. And a lot of these laws either require or you may want to consider in order to consider how to comply or whether to comply or whether you have to comply with these laws. The concept of age assurance. So you might hear age gating, you might hear age verification, you might hear a couple different things. But I want to cone in on this kind of term of age assurance is sort of a umbrella term. Can you tell us a little bit about it, Haylyn? What is it? I mean, is it an umbrella term? Kind of. How does this show up in some of the different laws?
Speaker A: Yeah, age assurance is definitely the umbrella term because it broadly refers to any kind of process or tech used to determine or estimate whether a user is above or below a certain age threshold or is in a certain age. So kind of to the age gating point you were talking about. And within that, there's really three recognized forms of age assurance. There's verification, estimation and self declaration. So let's start with age verification. The most common method is really ID document. So a user uploads or captures a photo of a government issued id, a driver's license, a passport, national ID card. And then a service provider uses a combination of automated document authentication because they have a database somewhere and is often paired with a liveness check to confirm the document is real and belongs to the person presenting it. And it would show that they are over a, uh, relevant age threshold. And the challenge here is really obvious because not everyone has a government ID and children oftentimes don't. And requiring that level of identification has a lot of friction involved as well, and privacy concerns and equity issues for users who don't have these qualifying documents. Another age verification method is payment instrument verification, with the idea being that if a credit card is associated with the account, the cardholder is probably an adult. And this was actually one of the original COPPA approved methods for verifying parental consent way back in 1998. And it's still used, but it's not exactly perfect. Right. There's Plenty of adults who give children access to payment instruments. Like children might have their own credit card or, you know, parents just hand a child their credit card sometimes if they want to make a purchase somewhere. On the age estimation side, it's the most technological, sophisticated current method. And right now it's facial age estimation. So you take a live selfie or a short video or photo. Usually the liveness component really matters to just prevent someone from taking a photo. And that can be done by like you have to say a word when you're being recorded, or you're taking photos with a light flashing and they're taking different angles of your face, something like that. And then AI model analyzes the physical characteristics associated with the age. So things like bone structure, skin texture and face shape, that kind of thing, to estimate a probable age range. But it's not biometrics, right? They're not doing a, uh, facial geometry map of someone's face to identify who they are, but just kind of looking at facial features to understand their rough estimate age. And the accuracy has actually gotten remarkably good for most demographics, but it's not uniform across all demographics, which raises important bias and fairness concerns. Another thing I learned recently was that there's technology where you can scan your hand in front of a camera and it can accurately estimate your age from that as well. There's also more nascent methods, more along the lines of like behavioral age estimation, where patterns of how someone uses an app might be indicative age or network level signals or a combination of signals added together form some probabilistic age range. These ideas are more or less mature and they're still being researched. And then just one last quick ad, the self declaration piece is pretty self explanatory, but just to kind of be comprehensive. It's when a user provides their age at sign up during an age gate or they click a box to confirm that they're over the age of 18.
Speaker B: So yeah, that's amazing. And I think it's a complicated area right now. I mean, there's so many startups and so many companies, there's so many options of these potential technologies to try to solve this problem. How do you get just enough information to accurately give you information, but not so much information that suddenly, you know, you're, as you said, processing biometrics or processing some kind of a sensitive piece of information about a child, or you are, you know, violating some other privacy principles using AI in a way that might be problematic or something along those lines. So it's a very complicated space. And the Fact that so many different regulators have different perspectives on this or haven't opined on this, or have opined on this makes it even harder I think for many companies to navigate. And I, uh, want to come back to the US and talk about one of those very specific tensions, which is COPPA and sort of, you know the point that you can't collect any information, even if it's not sensitive, of a child without parental consent under 13. But on the other hand you don't know whether you need parental consent until you have some information about the person who's seeking to use your service. So there was a interesting FTC policy statement in February that at least tried to throw some companies a lifeline on this point. Can you talk us through that one, Haylin?
Speaker A: Yeah. So the tension is real and actually has genuinely been a legal and practical problem for the industry. You're caught in what feels like a catch 22. Coppa says you can't collect personal information from a child without parental consent or for specific exceptions. Right? There's internal operations exception, there's like a safety exception, things like that. But to figure out whether someone is a child and uh, you essentially would need parental consent because you're collecting things like their face or potentially their id and that selfie or that document scan or even that birth date submitted as part of the verification flow are considered personal information in some cases. So how do you get the consent that you need to do the verification that tells you whether you need consent? That flow doesn't quite make sense. And so the FTC luckily came out and said earlier this year and it's their attempt at uh, creating a workable path for the industry. And the statement says that the FTC will exercise enforcement discretion AKA it won't bring a COPPA action for the collection of personal information as part of an age assurance process if certain conditions are met. And the first condition is that the service is not primarily directed to children under coppa's definition. And this distinction really matters because there is a category of services that are on their face at least made for children, thinking of like a uh, children's educational app or kids entertainment platform that markets itself as specifically for children and not for adults or the general audience doesn't use it at all. And the FTC is not giving that category a pass here. The non enforcement policy essentially is directed at services with a general audience that includes children, not the services whose primary audience is children. The second condition that's really notable is that the uh, personal information collected for age assurance has to be used only for the purpose of age assurance. Which makes sense, right? So if you're collecting a selfie to determine whether someone's over the age of 13, you can't then use that selfie for marketing. And you can't retain it beyond what's necessary for the verification purpose. And you can't share it in ways that go beyond the age assurance purpose or age verification purpose. The FTC is essentially saying here, we'll give you the room to do the verification, but you can't bootstrap an age assurance flow into an excuse to collect and monetize biometric or identity data of a child. And the thing to note is that this policy statement is not part of COPPA yet. And because it's not part of COPPA yet, the states technically don't have to follow it, but they have historically been aligned with the FTC when bringing actions against companies. And the message here is really clear. The FTC is interested in removing guardrails for the industry to do more when it comes to determining who is a child. And they've also specifically said that this policy statement is temporary. They've indicated that they intend to initiate a COPPA rulemaking specifically on age verification to make this permanent. So we should watch the space to see what happens and how quickly that can happen.
Speaker B: I want to jump in here quickly and just note this is one area where, you know, sometimes as a privacy lawyer or sometimes as a lawyer, right? You think, okay, I've read the law, I know what the law says. But there are so many places where in this specific area of the law, technical knowledge, technical understanding, specifics around, like, implementation steps, like, you can use this kind of technology, but not this kind of technology. You need to have a skillset that's not simply the ability to read and understand regulations. One thing we didn't talk about a lot earlier is with these age design codes, for example, like, often the GDPR will say things like, you need adequate or appropriate technical and organizational measures, but the design code, they'll have more specifics and almost more like, yeah, details and actions. Whereas a law might have more like principles and outcomes that it's looking for. And so just flagging that again in this broader orientation discussion for people, that it's not just that you need to understand the law, you also might need to understand what your technological options are and actually how they work.
Speaker C: Yeah, I mean, talking about options, sometimes you might be faced with really difficult options. And I wanted to ask you, in a situation where you are using some kind of age assurance process and you realize that you have been collecting data of children under the age of 13. What do you do? What are your options? What is the best solution if there is a solution? If you find yourself in that kind of situation?
Speaker A: Yeah. So this is actually one of those moments where the law is pretty clear and has been indicative through a lot of enforcement actions from the FTC and from other regulators. But under caba, if you've discovered that you've been collecting personal information from a child under the age of 13 without verifiable parental consent and you weren't relying on relevant exceptions, you only have two options. Delete the data or get parental consent and then continue. So the FTC's guidance, including this policy statement, is that deletion should actually happen pretty quickly. We're talking days, not weeks, and certainly not months or years. There's been real FTC scrutiny on companies that have maintained children's data beyond what's necessary while waiting to see whether a parent shows up to provide consent. And that lag is, uh, a problem that they've called out and have fined companies for. And the alternative was if you want to maintain a relationship with that user and allowing them to continue on the platform, you pretty much have to go through the full verifiable parental consent process relatively quickly. The verification method has to be an FTC approved method to authorize the continued collection of that child's data.
Speaker B: I know we said we weren't going to deep dive, but I do feel like this area of like age assurance and the technologies around age assurance and the process of age assurance is a very important one right now because it's evolving quickly, the technology is evolving quickly. The rules are kind of changing, I think, and they're splitting in different areas. What do you see as some of those challenges that when companies are trying to experiment with some of these age assurance options, these rapidly evolving. The hand one sounds really cool. Like, you know, what should they be thinking about? Like, what are some of the challenges that they need to consider that maybe are perhaps outside of the four walls of the child privacy law?
Speaker A: Yeah. So I think the first thing is whatever technology you choose to use is going to interact with a bunch of other legal regimes, some of which have their own requirements or restrictions. And I think the most prominent space is probably the biometric issue. Right. In Illinois, there's the Biometric Information Privacy act, or bipa. It has really strict requirements on the collection, the use, the storage, the destruction of biometric identifiers and information. It has requirements on specific disclosures that need to be made. And it also has a private action, which makes it a very fun space. BIPA litigation has produced some of the largest class action settlements in privacy law in the US. I think there was a company that settled something for close to $100 million. Settled, not a, uh, regulatory fine. And if you're deploying ID verification at scale to users who are or may be in Illinois, BITPA compliance is really not optional at this point and definitely not trivial. Washington and Texas have their own biometric laws. The EU GDPR treats biometric data as sensitive data under Article 9, where there's explicit consent and you can't rely on other legal bases that may be available in other circumstances, like performance of a contract or legitimate interest. So your age assurance solution really has to comply with coppa, but also all these other requirements coming out because you're dealing with biometric information. The second is vendor risk and security. And this one isn't one that always gets enough attention in abstract legal discussions about age assurance. When you're implementing age assurance, you're almost certainly relying on a third party vendor to do the actual verification or estimation, or you just have a company that does everything. That could be a possibility too. But that vendor is now processing some of the most sensitive data that exists. It's government ID information, it's biometric data and it's potentially linked to children. Your diligence on that vendor, your contractual obligations, your ability to audit their security practices and their data retention, your response plan if there is a breach. All of that matters enormously. If a vendor who holds your age verification data has a breach, you're accountable to your users and to regulators. Because anything that involves a breach and children is going to raise awareness for a regulator and could result in some door knocks and some questions. And if the data is government identification of images of, uh, people who turn out to be minors, the harm and the scrutiny are going to be increased significantly as well. The third thing is probably the accuracy and bias issue. That's in a lot of the models that briefly touched on earlier. But these AI models that power the facial age estimation or even the mapping of an ID to a selfie aren't actually created equal across all demographic groups. The age estimation models and these other models have shown disparate performance across race, skin tone and even gender, meaning that the system is more likely to misclassify certain populations. And if your age estimation technology or your verification technology is systematically less accurate through it for certain groups, you might either be under blocking access for minors, those groups which could be a safety failure or over blocking access for adults from those groups as well, which is a discrimination concern. And regulators are starting to ask questions about this as well. It's an issue that they're really thinking about deeply because they realize this technology has improved and a lot more companies are starting to use this technology. It's more widely available. And these issues should really factor into which vendors you use and what accuracy threshold you said. One bonus challenge, if we have time for it, is there's more things that we need to worry about beyond the legal requirements. There's also the user distrust issue, uh, here as well. Users in different jurisdictions react differently to collection of biometric data or facial image collection in general. And you have to deal with the cultural differences, you have to deal with the concerns around over data collection. You might have to deal with loss of users. And so none of these are legal risks, but there are PR risks and they're business risks. And honestly, notable and real risks in general that could have immediate impacts versus the legal impacts that could be longer tail.
Speaker B: I think that's a really good one as well as the bias point. I mean, I think in general, I think it, gosh, it just gets harder and harder each day to be a privacy lawyer, guys, doesn't it? But I think those are important points.
Speaker C: So it's interesting because age assurance is trying to solve a privacy problem, but, uh, it definitely can create a new privacy problem for you if you're using a vendor that doesn't have its privacy house in order. And that's why it's so important to do proper vendor due diligence. Look at your vendor, look at their cybersecurity posture and their certifications and on what they're doing with the data. So are they storing the data? Are they retaining the data for how long Are they retaining it? Are they using the data for their own purposes, which could create real problems? Are they sharing it? What are they doing? And making sure that if you are onboarding a vendor to try and solve this privacy problem, that you aren't creating a new challenge for yourself. And I think it's just wider than using vendors that provide age assurance solutions. Organizations should also think about any other third party that they might have involved in a situation where children's privacy is at stake. I actually looked for some examples and I found two FTC settlements that involved situations where businesses aimed at children had third parties involved and where they got into trouble. So one is Apitor, a robot toy company. They had a companion app, and that companion app had a third party SDK which allowed a third party in China to constantly monitor the children's precise geolocation data. Uh, quite a scary thing if your child has a toy and there's an app that goes with the toy and that toys app tells someone in China the whole time where the child is located. So they got into trouble in there to pay a civil penalty. And another company was Hyper Beard. They did children's apps and they allowed third party ad networks to collect persistent identifiers for behavioral advertising without parental knowledge or consent. The interesting thing with Hyperbio is also that they had a disclaimer saying, these games aren't meant for children, but the games involved in the settlement, it's described as cartoon characters that were super cute and silly. So obviously those were aimed at children and they were dogs and cats and bunnies. So you can't just get away from things by putting some kind of disclaimer on saying this is not for children. If it's very clear that what you've designed is for children. But it's important if you have third, uh, parties in your ecosystem to vet them as well. It's not just only your age assurance service providers, but also just look at any other role player and making sure that what they're doing is above board and that you've checked. They might.
Speaker B: I just want to point out, Dani, that I also am, um, fond of, you know, super cute cartoon bunnies and puppies. You never know. You never know.
Speaker C: I suppose we all are, but in most cases I think children would love them.
Speaker B: There's so many things to talk about. I know we were trying to keep this kind of to an overview. Just quickly pulling out one small thing you said too, that we didn't touch in great deal up until about is a lot of these laws, particularly the age design codes, deal with advertising. So we've been focused on what are the laws and then how do you tell if someone is a child and then make sure that you have good security practices. Kind of as far as we've kind of gotten in some of this basic ecosystem, but there is a lot of detail in a lot of these regulations, design codes, whatnot that have other implications. It's not like once you've got it, you can just use it however you want. Advertising in particular is a topic to keep an eye out for. I know, Halen. That's something we've gotten a chance to work with you guys on and that's been like a fun one to kind of consider across the world too. I think that's one that is an important thing to keep in the back of your head, because once you know that someone is a kid, even if you've got parental consent, you may still have other things that you can't do with their data. And I think those kind of, again, technical design points is something that people should be keeping an eye out for.
Speaker A: The US Space is getting more and more interesting when it comes to advertising in children in general. There's repeated bills, the, uh, COPPA 2.0s essentially, that have come out, talk increasing the agency for advertising for children from 13 to 16. And different states are coming out with the requirements for how you can target children. And then in combination with the age assurance or app store accountability acts. This is definitely a space that, uh, you should talk to some lawyers about to get more information on if you'd like to learn more about it.
Speaker B: There's a lot going on right now, exactly as you say. All these things are important to kind of keep top of mind. All right, I think we've done a pretty good job of an overview. What do we think, guys? Uh, do we feel like people know what to look for now, at least as a starting point?
Speaker A: I think people know enough to be scared.
Speaker C: Yeah.
Speaker B: Which is probably good, Sam, but good. That's awesome. Helen, you. You shared something kind of funny as we were talking, kind of prepping for this, and it was sort of about just, like, all the ways these sorts of issues can show up in unexpected ways. Do you want to share your kind of funny moment?
Speaker A: Yeah. So I, uh, think we were talking about how incidents lead to regulators finding out about things. And then when we're talking about the timing of incidents. And so the running joke in cybersecurity is that breaches always happen on a Friday afternoon before a holiday weekend when your team is at, like, minimum staffing. And that's genuinely true. The threat actors know when people aren't watching. But in the gaming industry specifically, the timing pattern we actually see is really like, on top of the Friday stuff. It's also summer vacations and water breaks, because that's when the kids are home, when school is out and the use of platforms spikes dramatically. The threat actors know the risk surface is larger with more users on the platform. But also it's when the kids are unoccupied and have more time to dig into things and test vulnerabilities. So a lot of kids are now in the white hat hacker, um, group, and they're able to, like, go and find these issues and bugs to report in the first place too.
Speaker B: I think. It's funny, they're old enough to be white hat hackers, but maybe not old enough to give consent.
Speaker C: Some practical tips for listeners. So we work with roadblocks and we've come up with solutions for you. But just generally, if you are at a business and it seems that your business is aimed, um, at children or children are using your services, what three things would you recommend they focus on to try and address this really complicated topic?
Speaker A: I'll keep it to my top three. I'd probably say know your user base, understand where your users are located, know the rough demographics of your users, understand how good your age data is, because without looking at the information you already have, you can't really tell what your real requirements that you'll have to follow are. Next, I'd probably say treat privacy for children as a, uh, default because at this point there are so many laws out there requiring privacy by design and high privacy by default for children that you really have to build that into the product if you know you're going to have young users. And the old model of assuming users are adults and building for adults and adding child protections to the ones that you identify as children, if you even admit that you have children in the first place on your service doesn't really work anymore in the modern age. And having a platform or default settings are, um, where the default settings are the most privacy protective and additional features require an additional steps to enable will put you in a much better place in the long run to be in compliance with all these new laws and then finally educate and collaborating cross functionally. Children's privacy isn't just a legal or compliance problem anymore. It's legal, it's product, it's engineering, it's safety, it's policy and it's trust problems. And it's all these problems all together at the same time. And when you're dealing with that many cross functional teams, it really requires a lot of alignment and understanding that it's more than just a legal requirement. And it sometimes needs to be a fundamental shift organizationally to be on the same page now that we're in a very different era of handling children's data and building products for children.
Speaker B: I love that last point. That's a very good top three list. But I think that last point in particular is a really good takeaway.
Speaker C: And you know what, it feels to me like in every podcast we come to this, but the importance of data mapping, because if you don't know whose information you're processing, how are you going to manage it. I always say that, but it's the same issue with children's data. I've had more than one practical example where clients just carry on as if it's not relevant to them. And then when you start unpacking what data they process and why they process it, someone at some stage says, oh, we are doing this, and you just open Pandora's box there. So it's so important to understand what data you're processing. And if there is children's data involved, could your services potentially be used by children? Could they potentially be aimed at children and then finding solutions for that problem that you've then uncovered?
Speaker A: I think the final thought I have is regulators are really trying to move fast and protect children as technology moves even faster. And so even though the law hasn't caught up yet, building for the law will set you up for legal compliance, but building for the ethical doing things right by your user base will usually take you farther and put you in a space that you're not just playing catch up with competitors and regulators at the same time.
Speaker B: Excellent point, and I think a really good way to end it. It's a fun time to be alive in the world of privacy compliance, and it's not boring. Well, thank you so much for giving up so much of your time to talk to us. I know you said at the beginning this is one of your favorite topics that was so apparent. It was so fun to talk to you about it and to get to hear your passion, but also all your experience and your and your thoughts, even if we only could go 2 millimeters deep. So thank you very much for your time.
Speaker A: Thank you for giving me the excuse to talk more about children's privacy. And I hope you guys had as much fun with this conversation as I did.
Speaker C: We definitely sure did. Thanks so much. It was a pleasure. Thanks, Hayden.
Speaker A: Thank you.
Speaker B: That's it for today's episode of Privacy in Practice, brought to you by VeraSafe. We hope today's insights help you navigate privacy challenges with confidence and clarity.
Speaker C: If you enjoyed today's conversation, be sure to subscribe so you don't miss out on future episodes, and we'd love to hear from you, share your thoughts, questions, or suggestions for future topics. Send us an email to podcasterisafe.com and
Speaker B: to learn more about VeraSafe's data protection and privacy services, you can Visit us@verasafe.com until next time.
Speaker C: Best of luck in approaching your privacy challenges in a practical way.
Speaker B: See you then.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.