
Short answer: The Children's Online Privacy Code is a binding APP code the OAIC is developing under the Privacy and Other Legislation Amendment Act 2024. It is proposed to cover apps, games, websites and other online services likely to be accessed by children, and must be registered by 10 December 2026. Start mapping children's data and consent flows now.
Related guides:
- Australian Privacy Principles for small business
- Privacy by design principles
- How to run a privacy impact assessment
Key takeaways
- The Children's Online Privacy Code will sit on top of the Australian Privacy Principles (APPs) for online services children are likely to use.
- The OAIC released an exposure draft on 31 March 2026 and consulted until 5 June 2026. No final code had been registered when this post was last checked (see the status note under When does the code take effect?).
- The statutory deadline for registration is 10 December 2026. Commencement and any transition period have not been confirmed.
- The draft proposes a "strictly necessary" collection standard, a best interests of the child test, parental consent for under-15s, child-specific privacy policies, a destruction right, and mandatory privacy impact assessments for new services.
- SaaS, EdTech-adjacent and consumer HealthTech teams should inventory children's data and review consent flows now.
What is the Children's Online Privacy Code?
It is a legally binding code, made by the Australian Information Commissioner, that will set out how online services must apply the Australian Privacy Principles to children's personal information.
The Privacy and Other Legislation Amendment Act 2024 received Royal Assent on 10 December 2024 and requires the Office of the Australian Information Commissioner (OAIC) to develop and register the code within 24 months. The same Act added a definition of a child to the Privacy Act 1988: an individual who has not reached 18 years.
The code does not replace the APPs. It narrows and adds to them for a defined group of services. Once registered, failing to comply with it is an interference with privacy under section 13 of the Privacy Act, which brings the OAIC's existing enforcement powers into play, as Allens notes in its analysis of the draft.
You can follow progress on the OAIC's code page.
Who is the code proposed to cover?
The draft is proposed to apply to APP entities that provide a social media service, a relevant electronic service or a designated internet service, where children are likely to access the service, or the service is primarily concerned with children's activities.
These categories are broad. Allens gives examples such as email, chat and online multiplayer gaming services, plus file and photo storage and certain generative AI services. Baker McKenzie points to examples such as early childhood development trackers, family photo sharing apps and online school management systems.
The exposure draft also sets two limits that matter for scoping:
- Health services. The draft clause that extends the code to services primarily concerned with children's activities applies only where the entity is not providing a health service. Summaries such as Allens describe health services as excluded from the code's scope, but the draft wording only limits that one limb. A health provider whose service is likely to be accessed by children may still be in scope, so take advice on how the carve-out applies to your services.
- Carriage service providers within the meaning of the Telecommunications Act 1997 are specified in the draft as entities not bound by the code.
Because the code binds APP entities, businesses that currently sit under the Privacy Act's small business exemption are generally outside it unless they are APP entities for another reason. Our Australian Privacy Principles guide explains how that exemption works.
What this means for different teams:
| Company type | Likely position under the draft |
|---|---|
| B2B SaaS used only by adult staff | Probably out of scope, unless the product is likely to be accessed by children in practice |
| EdTech-adjacent tools (homework, tutoring, school communication, classroom apps) | Likely in scope where students use the service or it concerns their activities |
| Consumer wellness, fitness or parenting apps | Assess carefully. "Likely to be accessed" turns on real-world use |
| Providers of a health service | The proposed carve-out limits only the "primarily concerned with children" limb; services likely to be accessed by children may still be covered |
What does the exposure draft propose?
The table below summarises the main proposals from the OAIC exposure draft and pairs each with a practical action. The final code may differ.
| Proposed obligation (draft) | What it would mean in practice |
|---|---|
| Age assurance: take reasonable steps to ascertain a user's age before collecting personal information, and destroy age-check data as soon as practicable | Choose an age assurance method proportionate to risk, or apply child protections to all users. Delete verification data once checked |
| Privacy by default: by default, collect, use or disclose only what is strictly necessary to provide the service, and give children clear controls | Turn off non-essential tracking, analytics and sharing by default for child users. Build simple in-app privacy controls |
| Best interests of the child: collection, use and disclosure must be consistent with the child's best interests | Add a documented best interests test to product and data reviews |
| Consent age: under the draft, only a child aged at least 15 may consent for themselves. For under-15s, consent must come from a person with parental responsibility, after reasonable steps to confirm that person | Build a parental consent flow that confirms the consenting adult and records who consented and when |
| Quality of consent: consent must be voluntary, informed, current, specific and unambiguous. No bundling, manipulative design or pre-ticked boxes | Audit sign-up and settings screens for dark patterns. Split bundled consents into separate choices |
| Child assent: for under-15s, seek the child's assent for certain handling such as sensitive information and direct marketing | Write age-appropriate assent prompts alongside the parental consent step |
| Child-specific privacy policy and notices: a child-directed version of the APP privacy policy and age-appropriate collection notices | Publish a plain-language, age-appropriate version of your privacy policy, using visuals where helpful |
| Direct marketing: consent required, plus an easy way for a child to opt out | Gate marketing behind consent and add a prominent opt-out |
| Destruction right: under the draft, a child, or a person with parental responsibility for an under-15, can request destruction of specified information, and the entity must destroy it, subject to listed exceptions | Build a deletion workflow that reaches backups and processors, with response timeframes tracked |
| Monitoring notices: notify the child when a parent or another user can monitor their activity or geolocation | Show clear, ongoing indicators whenever monitoring or location sharing is active |
| Privacy impact assessments: the draft requires PIAs before launching, or significantly changing, a service likely to be accessed by children, and a register of PIAs published online | Add a children's PIA gate to your product launch process |
| Training: the draft requires education and training for staff with regular or frequent access to children's data, on engagement and at least annually | Add a children's privacy module to your security awareness program |
The draft also requires entities to review and update their privacy practices, procedures and systems at least annually, a point Gilbert + Tobin also highlights. Treat every item above as proposed until the final code is registered.
How does the code relate to the Australian Privacy Principles?
The code sits on top of the APPs, so in-scope entities would need to comply with both.
For example:
- Collection (APP 3). The APPs generally allow collection that is reasonably necessary for your functions. The draft proposes "strictly necessary" for providing the service, a noticeably tighter test.
- Notice and policy (APPs 1 and 5). The draft proposes a separate child-directed version of your APP privacy policy and age-appropriate collection notices.
- Use and disclosure (APP 6) and direct marketing (APP 7). The draft layers consent and a best interests test on top of the existing rules.
- Deletion. The draft proposes a destruction right that goes further than the APP 11 obligation to destroy or de-identify information you no longer need. Allens notes the draft excludes de-identification as an alternative.
When does the code take effect?
The final code must be registered by 10 December 2026, but the OAIC has not confirmed when it will commence or whether there will be a transition period.
| Milestone | Date | Status |
|---|---|---|
| Privacy and Other Legislation Amendment Act 2024 receives Royal Assent | 10 December 2024 | Done |
| Phase 1 and 2 consultation (children, parents, industry, civil society) | 2025 | Done |
| Exposure draft released and public consultation | 31 March to 5 June 2026 | Done |
| Statutory deadline to register the final code | 10 December 2026 | Pending |
| Commencement and transition | Not yet announced | To be confirmed |
The draft leaves its commencement provision to be drafted, and Gilbert + Tobin notes the OAIC invited submissions on transition. Status (last checked 5 October 2026): the OAIC had not registered a final code. Check the OAIC's code page for the current position before planning around a date.
How does it compare with the UK Children's Code and COPPA?
The Australian draft shares the UK code's "likely to be accessed by children" scope, while US COPPA focuses on younger children.
- UK Age Appropriate Design Code. The ICO's code has 15 standards, applies to information society services likely to be accessed by children, came into force on 2 September 2020 and had a 12-month transition, according to Lewis Silkin. The OAIC's 2025 issues paper said it may provide age range guidance aligned with the UK code.
- US COPPA. The FTC's rule protects children under 13. Amendments published in the Federal Register took effect on 23 June 2025, with most compliance obligations applying from 22 April 2026.
If you already comply with the UK code or COPPA, you have useful building blocks, but expect gaps around the proposed consent age of 15, child assent, destruction requests and the published PIA register.
How should you prepare now?
Start with scoping and a data inventory, then fix the highest-impact flows before the final text lands.
- Decide whether you are in scope. For each service, document the service category and whether children are likely to access it, using signals such as app store ratings and school customers.
- Map children's data. List every field collected from or about children, where it flows, which processors receive it and how long you keep it.
- Apply the strictly necessary test. Flag anything not needed for the core service, such as analytics SDKs, ad identifiers and location data.
- Fix the highest-risk flows first: consent, age assurance and deletion. Then embed a privacy impact assessment step with a children's section into launches.
Readiness checklist
- Scope assessment and children's data map complete
- Non-essential collection switched off by default for child users
- Age assurance approach chosen and documented
- Parental consent flow for under-15s designed and tested
- Child-friendly privacy policy and notices drafted
- Destruction request process covers backups and processors
- Children's PIA step added to product launches, with a register
- Vendor contracts updated for children's data handling
- Staff training and annual review scheduled
Privacy by design principles make these items easier to sustain.
How SecureSlate helps
SecureSlate helps SMBs and HealthTech teams run privacy and security programs. You can track the code's requirements alongside your other frameworks, maintain your privacy policies, record risks in a risk register, manage vendor risk for processors that touch children's data, and store evidence for each control in one place.
Start your free SecureSlate trial
FAQ
Is the Children's Online Privacy Code in force yet?
Not when this post was last checked; see the status note above and the OAIC's code page. It must be registered by 10 December 2026, and commencement and any transition period have not yet been announced.
Are HealthTech companies covered by the code?
The exposure draft limits the "primarily concerned with children's activities" limb where the entity provides a health service, and some law firm summaries describe health services as excluded. A health service likely to be accessed by children may still be in scope, so take advice. Assess any family-facing or community app separately from clinical products.
What age counts as a child?
The 2024 amendments define a child in the Privacy Act as an individual who has not reached 18 years. Under the draft, children 15 and over could consent for themselves, while under-15s would generally need consent from a person with parental responsibility.
Disclaimer (legal note)
This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds