Everyday Privacy

How to Protect Your Kids' Privacy Online

By the RedactZero Team · August 7, 2026 · 8 min read

The short version

Children build a data trail long before they can consent to one, through apps, games, school records, and the household address on a parent's public listing. Federal law covers less than most parents assume: COPPA protects children under 13 and stops there. The two highest-value moves are free and take under an hour: freeze your child's credit at all three bureaus, and opt out of directory information at their school. After that, shrink your own data-broker footprint, because that is what points strangers at your household.

How a child's data ends up in the same databases as yours

Kids generate records almost from birth: school enrollment, sports leagues, medical billing, apps and games, and the address that sits on their parents' public record. None of it requires the child to agree to anything. By the time a kid reaches high school there is a durable trail that marketers, data brokers, and identity thieves can all reach.

Some of that trail is sold outright. A Fordham Law School Center on Law and Information Policy study, "Transparency and the Marketplace for Student Data," documented that student lists are commercially available for purchase on the basis of ethnicity, affluence, religion, lifestyle, awkwardness, and even a perceived or predicted need for family planning services. The researchers also found an overall lack of transparency in that marketplace, and no law squarely governing it.

The rest of the trail is inherited. People-search sites build household profiles from public records and list relatives, associates, and past and present addresses. A child rarely gets their own profile, but a parent's profile is a map to the family.

What COPPA protects, and where it stops

The Children's Online Privacy Protection Rule requires sites and services directed to children under 13, and operators with actual knowledge they are collecting from a child, to notify parents about what they collect and to obtain verifiable parental consent first. It also gives parents the right to require an operator to delete their child's information.

That is real protection, and it has a hard ceiling: 13. The federal consent rules do not follow your child into their teenage years, which is exactly when social platforms, group chats, and location-sharing enter the picture. Congress has been trying to close that gap. The Senate passed a version of COPPA 2.0, which would extend protections to teens under 18, in March 2026, and the House passed the broader KIDS Act on June 29, 2026. Neither has become law.

Worth watching for anyone who follows the broker industry: the KIDS Act as passed by the House includes a "Data Broker Disclosures" section that would require brokers who knowingly sell minors' personal data to register with the FTC, in a public searchable registry.

What changed in the rules for 2026

The FTC finalized the first substantial COPPA overhaul since 2013. The amended Rule took effect June 23, 2025, and regulated companies had until April 22, 2026 to come into full compliance, so 2026 is the first year the new obligations actually bite. Three changes matter most to parents.

Separately, on February 25, 2026, the FTC issued a policy statement saying it will not bring COPPA enforcement actions against general-audience and mixed-audience services that collect data solely to verify a user's age, provided they meet conditions including using it for nothing else, deleting it promptly, and giving clear notice. Expect to see more age checks as a result.

What enforcement actually looks like

Parents often ask whether any of this is enforced. It is, and the penalties are large enough to be worth knowing about, because they tell you where the real leaks are: game platforms, voice assistants, and video. Each of these cases came down to a company collecting from kids without telling parents first.

CompanyYearPenaltyWhat the FTC alleged
Epic Games (Fortnite)2022$275 millionCollected personal information from under-13 players without parental notice or consent; voice and text chat on by default
Amazon (Alexa)2023$25 millionKept children's voice recordings indefinitely and failed to fully honor parents' deletion requests
Microsoft (Xbox)2023$20 millionCollected information from children signing up for Xbox without parental consent, and retained it illegally
Disney2025$10 millionFailed to label kid-directed YouTube uploads "Made for Kids," enabling data collection and targeted ads

Source: Federal Trade Commission press releases for each action. The Epic penalty was the COPPA portion of a $520 million total and, per the FTC, the largest penalty ever obtained for violating an FTC rule.

The pattern is consistent: default settings and quiet retention, not dramatic hacks. That is also why parental controls alone do not solve this. The data was collected in the ordinary course of the child using the product.

School records: the opt-out most parents never see

Under FERPA, schools may release what they designate as "directory information" to third parties without asking you first. That category can include your child's name, address, telephone listing, date and place of birth, participation in officially recognized activities and sports, and dates of attendance. It is a lot more than most parents picture.

The protection is an opt-out, not an opt-in. The school has to give public notice of what it treats as directory information, of your right to restrict disclosure, and of the window you have to say no in writing. That notice usually arrives in the back-to-school paperwork and gets signed without being read.

Do this: find your district's annual FERPA notice, then submit a written request restricting directory information disclosure. Ask specifically about name, address, and phone. And when a school asks for your child's Social Security number, the FTC suggests asking why they need it, how they will protect it, whether a different identifier will do, and whether the last four digits are enough.

Freeze your child's credit first

If you do only one thing from this article, do this one. A child's Social Security number is attractive to thieves precisely because it is clean and nobody checks it for years. The FTC's guidance is direct: if your child is under 16, request a free credit freeze to make it harder for someone to open new accounts in their name.

The freeze stays in place until you tell the bureaus to remove it. The process for a minor differs from an adult freeze, and there is no single form, so you have to go to each bureau separately: Equifax, Experian, and TransUnion. Minors who are 16 or 17 may request and remove a freeze themselves.

Have your documents ready. Bureaus typically want a copy of your government-issued ID, proof of your address such as a utility bill, your child's birth certificate, and your child's Social Security card. Legal guardians who are not the parent will need paperwork proving guardianship.

Warning signs your child's identity is being used

Child identity theft is quiet by design. Nobody is checking a nine-year-old's credit, so the fraud can run for a decade before it surfaces, often when the child applies for a first job, a student loan, or an apartment. The FTC lists specific signals that mean someone is using your child's information.

You do not have to wait for a signal. Contact the three bureaus and ask for a manual search of your child's Social Security number. A child under 18 generally will not have a credit report, so the existence of one is itself the alarm. If something turns up, report it at IdentityTheft.gov, close the fraudulent accounts in writing, and freeze the report. Our guide to the early signs of identity theft covers the adult version of the same checklist.

Your exposure is your child's exposure

Here is the part parents tend to miss. Your child is unlikely to have their own people-search profile, but yours lists your address, your phone numbers, and your relatives. Anyone who wants to find where a specific child lives starts with the parent, and that search is free and takes seconds.

So shrinking your own footprint is a child-safety measure, not just a personal one. Every major people-search site has a free opt-out, and we publish step-by-step opt-out guides for the big ones. Start with the sites that rank for your name, and expect to re-check every few months, because listings commonly reappear within three to six months as brokers re-ingest public records.

The same logic applies to what you post. Birthday posts, first-day-of-school photos with the school name visible, sports schedules, and location tags assemble into the same profile a broker would build, only faster and with pictures. You do not have to stop posting. Lock the audience down, strip identifying detail from captions, and think of the school name and street as the two things worth withholding.

A one-evening plan

None of this needs a weekend. If you have about an hour, work through it in this order, because each step reduces more risk than the one after it. Everything here is free.

  1. Freeze each child's credit at Equifax, Experian, and TransUnion, and ask for a manual Social Security number search while you are there.
  2. Opt out of directory information in writing at your child's school, and ask what identifier they use instead of a Social Security number.
  3. Audit the household's apps and games. Delete accounts your kids no longer use, and ask operators to delete the data rather than just uninstalling.
  4. Check your own exposure with a free exposure scan, then opt out of the data brokers that list your household.
  5. Tighten social audiences on the accounts where you post about your children, and turn off location tagging.
  6. Put a reminder in the calendar for three months out to re-check the broker listings that came back.

For the wider version of steps 4 through 6, our guide to shrinking your digital footprint walks through the household audit in more detail.

Start with what is already public about your household

Run a free exposure scan to see which data brokers likely list you, plus any breaches tied to your email. No account, nothing stored.

Run a free exposure scan

Frequently asked questions

At what age does COPPA stop protecting my child?

COPPA applies to children under 13. Once a child turns 13, the federal parental-consent rules no longer apply to them. Congress has been working on an extension: the Senate passed a version of COPPA 2.0 in March 2026 and the House passed the KIDS Act in June 2026, but as of August 2026 neither has become law.

Is freezing my child's credit free?

Yes. The FTC says that if your child is under 16 you can request a free credit freeze, and it stays in place until you tell the credit bureaus to remove it. You have to contact Equifax, Experian and TransUnion separately. Minors who are 16 or 17 may request and remove a freeze themselves.

How do I find out whether my child already has a credit report?

Contact all three credit bureaus and ask for a manual search of your child's Social Security number. A child under 18 generally should not have a credit report at all, so if one exists, treat it as a red flag. Expect to send ID, proof of address, your child's birth certificate and their Social Security card.

Can I remove my child from people-search sites?

Usually the exposure runs through you rather than your child. People-search profiles list relatives, associates and household addresses, so a parent's listing is what points to the family. Opting your own listing out, for free, is the practical way to shrink what a stranger can pull up about your household.

Does my child's school have to ask before sharing their information?

Not for what it designates as directory information, which can include name, address, telephone listing, date and place of birth, participation in activities and sports, and dates of attendance. Under FERPA the school must give public notice of what it designates and of your right to restrict disclosure, and you have to opt out in writing.

Should I give the school my child's Social Security number?

Ask first. The FTC suggests four questions: why do you need it, how will you protect it, can you use a different identifier, and can you use just the last four digits. A Social Security number is the single piece of data that makes child identity theft possible, so it is worth the awkward conversation.

If I delete an app, is my child's data deleted too?

No. Deleting an app removes it from the device but does not delete the account or anything already stored on the company's servers. Under COPPA, parents have the right to require an operator to delete personal information collected from their child, so ask for deletion directly rather than assuming an uninstall did it.

What should I do if I think my child's identity has been stolen?

Contact each company where the fraud happened and ask them to close the account and confirm in writing that your child is not responsible. Ask the three credit bureaus to remove fraudulent accounts, freeze your child's credit report, and report the theft to the FTC at IdentityTheft.gov with as much detail as you can.

Sources: FTC, "How To Protect Your Child From Identity Theft" (consumer.ftc.gov) for credit freezes, warning signs, and Social Security number questions; FTC press releases of January 16, 2025 and February 25, 2026 and the amended COPPA Rule as published in the Federal Register (effective June 23, 2025; compliance date April 22, 2026); FTC press releases in the Epic Games, Amazon Alexa, Microsoft Xbox, and Disney actions; US Department of Education, Protecting Student Privacy, on FERPA directory information; Congressional Research Service Legal Sidebar LSB11465, "The House Passes the KIDS Act," August 3, 2026; Fordham CLIP, "Transparency and the Marketplace for Student Data," June 2018. Data-broker opt-out and relisting behavior reflects how those companies describe their own operations.