Share this article

Australia’s Children’s Online Privacy Code: Does it impact your business?
Accelerating security solutions for small businesses Tagore offers strategic services to small businesses. | A partnership that can scale Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. | Standing out from competitors Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market. |
Children’s online privacy has become a growing concern worldwide, with governments introducing stricter regulations to strengthen privacy protections in digital products and services. One of these upcoming regulations is Australia’s Children Online Privacy Code, which is being developed under the Privacy Act 1988 and is set to be registered by December 2026.
It may sound like the Code only applies to children’s apps, games, or social media platforms, but that’s not the case. It can impact many online services likely to be accessed by children, so it’s important to understand and prepare for the Code’s requirements before it takes effect.
What is Australia’s Children’s Online Privacy Code?
Australia’s Children’s Online Privacy Code is an Australian Privacy Principles (APP) Code, which establishes how online services likely to be accessed by children must comply with the APPs. The Office of the Australian Information Commissioner (OAIC) is developing it under a statutory direction in the Privacy Act 1988, as amended by the Privacy and Other Legislation Amendment Act 2024. The OAIC is required to register the Code by 10 December 2026.
Unlike many traditional privacy standards, the Code uses a risk-based approach that shifts responsibility away from children and parents. Instead, it requires organisations that collect, use, disclose, and otherwise process data to design their products and services with children’s privacy interests in mind.
Once the Code is finalised, it will be legally binding for in-scope organisations. Violating it will constitute a breach of the Privacy Act 1988 and may result in enforcement actions and civil penalties.
Note: The public consultation for the Code closed on 5 June 2026. The OAIC is currently finalising it ahead of the mandatory registration by 10 December 2026.
{{cta_withimage14="/cta-blocks"}} | GDPR checklist
Who should comply with Australia’s Children’s Online Privacy Code?
A common misconception about the Children’s Privacy Code is that it only relates to traditional “children’s services.” Its scope is actually much broader, extending to APP-entities that meet any of the following criteria:
- They are a provider of an internet carriage service, social media service, relevant electronic service, or designated internet service
- The service is likely to be accessed by children or primarily concerns the activities of children
- The entity is not providing a health service
The OAIC may also specify additional APP entities that must comply with the Code.
Whether an online service is “likely to be accessed by children” is the most important factor in determining if the Code applies. This criterion can be interpreted broadly—as a result, many general products could fall within the Code's scope depending on factors such as intended audience groups, marketing, and usage patterns.
Because the exclusions from the Code are limited, it’s best not to assume your organisation is out of scope without conducting a careful assessment. A service doesn’t have to be designed for children to be covered. The biggest compliance risk isn’t ignoring the Code, but assuming it doesn’t apply after just a cursory scoping exercise. This misconception can affect organisations across a range of industries:
- Gaming and entertainment platforms: Applying an age gate alone may not be sufficient. A game rated for users aged 15+ could still fall within the Code’s scope if younger children are reasonably likely to access it.
- EdTech providers: Counterintuitively, some educational institutions incorrectly assume their existing school-facing compliance posture covers them. However, the Code introduces additional obligations that extend beyond the consent and data-handling practices many providers already have in place.
- Smaller apps and startups: Unlike some privacy laws, the Code doesn’t include a GDPR-style size or revenue threshold. Smaller organisations shouldn’t assume they're out of scope based solely on their scale.
Key takeaway: The Privacy Code’s “likely to be accessed by children” threshold is broad enough to capture almost every consumer-facing website, e-commerce platform, or SaaS product, making it essential to carefully determine if you’re in scope instead of relying on assumptions.
Core requirements of Australia’s Children’s Online Privacy Code
Compliance with Australia’s Children’s Online Privacy Code requires organisations to address several key privacy obligations, most notably:
- Consent architecture
- Best-interests test
- Privacy-by-default
- Mandatory PIAs
- Right to destruction
1. Consent architecture
This obligation revolves around methods to obtain consent using mechanisms that are clear, age-appropriate, and easy to understand. Under the draft Code, children aged 15 and over may provide their own consent, while consent for children under 15 must be obtained from a person with parental responsibility.
For many organisations, implementing these consent requirements depends on proportionate, risk-calibrated age assurance.
As part of the consent infrastructure, start by creating child-friendly privacy notices that pass design, legal, and accessibility review. The notices should explain:
- What information is being collected
- Why the information is collected, used, and disclosed
- How long the information will be retained
- The impact of consenting or not consenting to data collection
- The right to withdraw consent, and how to do it
- How the information will be used (if applicable)
- Who the information will be shared with (if applicable)
For consent to be valid, it must be freely given, informed, current, and presented in a way the individual can understand. You must also provide clear, accessible channels for individuals to withdraw consent at any time.
Many of the provisions are closely aligned with Article 8 of the GDPR, especially the parental consent provisions. This means organisations with GDPR-aligned processes for consent may already have the necessary foundation in place for the Children’s Online Privacy Code.
Bonus read: Learn more about building a website integrated with GDPR-aligned consent processes in our guide.
2. Best-interests test
The best interests test is a foundational principle of the Code. It requires you to ensure that the collection, use, and disclosure of children’s personal information are in their best interests. Where children’s best interests conflict with business objectives, the best interests must take precedence.
This best-interests principle should extend beyond individual decisions and be embedded into product development workflows where privacy has historically had limited influence.
Your records should demonstrate privacy-informed product decisions and serve as evidence of compliance. The resulting documentation should describe how you assessed the impact of data processing on children, what factors you considered during decision-making, and how you balanced those decisions against business objectives.
3. Privacy-by-default
Products and services that children may access should provide the highest privacy settings by default. The draft Code also requires entities to consider dark patterns and deceptive design and prohibits nudging children toward weaker privacy settings. Organisations should not expect children to adjust settings to receive stronger privacy protections.
To meet these requirements, organisations should implement privacy-by-default principles into the design, development, deployment, and ongoing operation of products and services that may be covered by the Code. That way, you don’t have to retrofit privacy features after launch.
In practice, this means implementing measures such as limiting profile visibility, minimising data collection, and restricting data sharing unless there’s a justifiable operational need.
If a product allows users to reduce privacy protections, doing so should require deliberate, informed action. Children should receive clear, age-appropriate information on how their settings will change, what information will be shared, and the impact of the adjustments before they take effect.
4. Mandatory PIAs
Before launching a new activity or service that can be accessed by children or is primarily concerned with their activities, organisations must conduct a privacy impact assessment (PIA).
These assessments should identify privacy risks, assess their impact on children, and document measures to mitigate those risks. The PIA should cover:
- The nature, scope, context, and purpose of handling children’s personal information
- An explanation of why collecting the information is necessary for the service or activity
- An explanation of how data collection is conducted lawfully and fairly
- An evaluation of whether data collection aligns with children's best interests
- The way the entity complies with the Privacy Code
- An assessment of the potential risks posed by the data collection
Conduct the initial PIA early in the development process, with additional assessments at later stages of development or before you change existing services. Maintain PIA registers in real time to avoid reconstructing after the fact. This helps demonstrate compliance with the Privacy Code and serves as a valuable record for future product development and risk assessments.
5. Right to destruction
The Code requires organisations to establish processes that allow children or persons with parental responsibility to request the destruction of the child’s personal information. These mechanisms must be easy to access and supported by procedures for verifying, processing, and responding to requests.
In most cases, organisations must destroy the information upon receiving a deletion request. However, the Code sets out exceptions where the organisation may refuse, including when:
- Destroying the information poses a risk to the safety, health, and life of any individual
- The information relates to existing or anticipated legal processes involving the organisation or the child
- The information is contained in a Commonwealth record
- The Australian law requires the organisation to retain the information
- Destroying the information would be unlawful
After processing a request, the organisation must give written notice of its decision, along with the reasons why.
The Code also establishes different timeframes for responses. Organisations typically have 30 days from receiving the request, although this can be extended to 60 days based on case complexity and the volume of information set to be destroyed. In this case, the organisation must inform the individual of the reason behind the delay.
Destruction procedures should extend across the organisation's ecosystem, including backup locations, third-party databases, and any other areas where the data has been stored, if logically feasible.
{{cta_withimage30="/cta-blocks"}} | SOC 2 Ebook
Which frameworks can help you get compliant faster?
While the Code is unique to Australia, many of its privacy requirements overlap with other privacy frameworks and regulations from around the world. This means organisations with mature compliance programs can leverage existing controls to accelerate adoption of APPs and the Children's Online Privacy Code.
Some of the most closely aligned frameworks include:
The GDPR has the biggest overlap with the Privacy Code, since both strongly emphasise personal data protection through privacy-by-default, clear consent, and impact assessments.
Top GDPR solutions or compliance automation platforms can help you build the foundation for privacy-related frameworks. Vanta is a leading platform that offers automation and framework cross-mappings, which reduce the implementation effort and readiness timeline as you align with Australia's Children's Online Privacy Code.
How Vanta help you align closer with Australia’s Children’s Online Privacy Code
Vanta is the #1 agentic trust platform that helps organisations efficiently manage privacy, security, and compliance programmes. The platform unifies your compliance activities into a single system supported by AI-powered workflows, continuous oversight, and centralised tracking and reporting.
With Vanta, you can align with several privacy frameworks, including SOC 2, HIPAA, ISO 27001, PCI, and GDPR. For example, the GDPR product can support your Privacy Code readiness journey with:
- Pre-built policy templates for standardisation
- A centralised repository for privacy documentation, replacing spreadsheets
- Automated evidence collection through 400+ integrations
- Control mapping to reuse existing control evidence across overlapping privacy requirements
- Integrated risk management that connects privacy assessments to risks, controls, vendors, and frameworks
Vanta’s privacy module streamlines assessment and documentation management with an inventory of up-to-date data and processing records and consistent DPIAs based on risk scoring, which connect back to your chosen privacy standard automatically.
Schedule a custom demo to see how Vanta can help expand your compliance programme.
{{cta_simple19="/cta-blocks"}} | See how GDPR works
Legal disclaimer: Vanta is not a law firm, and this article does not constitute or contain legal advice or create an attorney-client relationship. When determining your obligations and compliance with respect to relevant laws and regulations, you should consult a licensed attorney.





FEATURED VANTA RESOURCE
The ultimate guide to scaling your compliance program
Learn how to scale, manage, and optimize alongside your business goals.










.webp)





.png)



