Children are spending more time online for education, gaming, entertainment, communication and other everyday activities. Behind something as simple as creating an account, joining an online class or playing a game, an organization may collect a considerable amount of personal information.
A child’s name, date of birth, photograph, school information, attendance records, location, voice recordings, learning results and online activity can all become part of a digital record.
For businesses operating websites, mobile applications, educational platforms, gaming services and children’s products, this raises an important question:
What do Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) require when the personal information belongs to a child?
The answer is more nuanced than simply adding a parental-consent checkbox.
PIPEDA does not contain a separate, comprehensive statutory regime specifically dedicated to children’s privacy. Instead, children’s personal information is protected through the Act’s broader requirements concerning meaningful consent, appropriate purposes, limiting collection, use and retention, safeguards, openness and accountability. The Office of the Privacy Commissioner of Canada (OPC) has also issued specific guidance and findings concerning children and young people’s privacy.
Does PIPEDA apply to children’s personal information?
PIPEDA protects personal information rather than creating a separate statutory category called “children’s data.”
Under PIPEDA, personal information generally means information about an identifiable individual. The Act applies to organizations in respect of personal information collected, used or disclosed in the course of commercial activities, subject to its jurisdictional rules and exemptions.
For a children’s service, this can include information collected through:
- children’s websites and mobile applications;
- online games;
- educational and learning platforms;
- sports and activity programmes;
- children’s products and connected devices;
- online registration systems; and
- services where parents provide information about their children.
However, businesses should first determine which Canadian privacy law applies to their activities.
Alberta, British Columbia and Quebec have private-sector privacy legislation that has been deemed substantially similar to PIPEDA. In situations where the provincial legislation applies, PIPEDA may not apply to the same activity. PIPEDA continues to apply in circumstances covered by its federal jurisdiction, including certain federally regulated organizations and certain interprovincial or international commercial activities.
Therefore, an organization should establish its applicable privacy-law requirements before concluding that PIPEDA governs a particular children’s service.
Is parental consent always required?
This is one of the most common questions surrounding children’s privacy in Canada.
PIPEDA does not simply establish a rule that every individual below 18 must obtain parental consent.
Instead, the starting point is meaningful consent.
Section 6.1 of PIPEDA states that consent is valid only if it is reasonable to expect that an individual to whom the organization’s activities are directed would understand the nature, purpose and consequences of the collection, use or disclosure of their personal information.
This becomes particularly important when the individual is a child.
The OPC’s position is that, in all but exceptional circumstances, organizations should obtain consent from a parent or guardian for children under 13, because young children generally cannot understand the consequences of their privacy choices sufficiently to provide meaningful consent themselves.
For older children and youth who are capable of providing meaningful consent, organizations should consider their age and maturity and design the consent process accordingly.
Therefore, businesses should avoid treating age as the only factor.
A better approach is to consider:
- the child’s age and maturity;
- the nature of the information;
- the purpose for which it is being collected;
- how the information will be used or disclosed; and
- the potential consequences for the child.
The important distinction is between a legal requirement expressly written into PIPEDA and the OPC’s interpretation of what meaningful consent requires in the context of children.
What makes children’s consent different?
Consider two situations.
A learning platform may require a child’s name and an account identifier to provide access to an online course. Another application might request photographs, precise location, voice recordings and behavioural information and use that information to build profiles.
The privacy implications are clearly different.
PIPEDA’s consent principle requires individuals to understand what they are agreeing to. The OPC’s guidance states that express consent should generally be obtained where information is sensitive, where collection, use or disclosure falls outside reasonable expectations, or where there is a meaningful residual risk of significant harm.
For children, organizations should therefore avoid relying on privacy notices that are difficult to understand, buried in lengthy terms and conditions or presented through confusing interface designs.
A child—or the parent or guardian providing consent—should be able to understand basic questions such as:
- What information is being collected?
- Why is it needed?
- Who will receive it?
- How will it be used?
- What choices are available?
The ten PIPEDA principles still apply
Children’s privacy is not only a consent issue.
Schedule 1 of PIPEDA contains ten fair information principles:
- Accountability
- Identifying purposes
- Consent
- Limiting collection
- Limiting use, disclosure and retention
- Accuracy
- Safeguards
- Openness
- Individual access
- Challenging compliance
These principles apply when an organization handles children’s personal information in circumstances governed by PIPEDA.
- Collect only what is necessary
- A children’s service should ask:
- Do we actually need this information to provide the service?
- PIPEDA’s limiting-collection principle requires organizations to limit collection of personal information to what is necessary for the identified purposes.
- For example, if an organization needs a child’s name and certain information to register the child for a service, it should consider carefully whether collecting additional information—such as precise location or photographs—is genuinely necessary.
- The fact that technology makes information easy to collect does not, by itself, make the collection appropriate.
- Do not quietly change the purpose
- Information collected for one purpose should not automatically be used for an unrelated purpose.
- For example, information collected to administer an educational service should not automatically become information for unrelated marketing or profiling.
- PIPEDA requires organizations to identify purposes and obtain consent for collection, use and disclosure consistent with those purposes. Where an organization intends to use personal information for a new purpose, fresh consent may be required.
- For children’s information, this distinction is particularly important because the expectations of a child or parent may be very different from the organization’s commercial interests.
- Protect children’s information appropriately
- PIPEDA’s safeguards principle requires organizations to protect personal information using security safeguards appropriate to its sensitivity.
- The Act does not prescribe one particular security technology for every organization. Instead, the safeguards should reflect the nature and sensitivity of the information and the circumstances in which it is held.
For a children’s platform, this may involve consideration of:
- access controls;
- authentication;
- encryption;
- secure software development;
- monitoring;
- employee access;
- security testing; and
- secure destruction.
The risks increase where large volumes of children’s information are concentrated within one platform.
A Real Canadian EdTech Example: CoreFour and Edsby
One useful real-world example comes from an OPC investigation involving CoreFour Inc., the company behind the Edsby educational platform.
Edsby was used as a K–12 learning-management and analytics platform. The OPC investigation involved personal information relating to hundreds of thousands of children in Canada and elsewhere.
The information involved included student names, dates of birth, student identification numbers, photographs, school information, attendance information, medical information such as allergies, assignments, test results and report cards.
The investigation identified several privacy and security issues, including vulnerabilities relating to password requirements for certain parental accounts and access to thumbnail images of student profile pictures. The investigation also considered malware scanning for content uploaded from third-party applications.
The OPC concluded that CoreFour’s safeguards were not adequate in the circumstances investigated and recommended improvements to its information-security framework and privacy management framework, as well as improvements relating to retention and destruction practices and privacy training.
What can businesses learn from this?
The lesson is broader than simply “use stronger passwords.”
When an organization handles children’s information, privacy and security need to be considered across the entire information lifecycle.
A privacy policy by itself does not demonstrate that appropriate safeguards, retention controls, access management and governance are actually operating.
Gaming: privacy does not end when the game begins
Online games can involve considerably more information than a player’s username.
Depending on the service, information may include account information, communications, photographs, location information, device information and other activity associated with the player’s account.
The OPC has specifically addressed privacy considerations for online gaming. Its guidance states that children under 13 generally cannot provide meaningful consent themselves and that gaming services should seek parental consent where they believe a player is under 13.
The OPC has also discussed parental controls relating to children’s access to content, communications with other users and sharing of personal information.
This means that privacy should be considered during product design, rather than being added only after a game has been developed.
Educational technology: a growing privacy concern
Educational technology creates another important area for children’s privacy.
In October 2025, Canada’s federal, provincial and territorial privacy regulators issued a joint resolution concerning the responsible use of educational technologies in classrooms.
The resolution highlighted concerns including excessive collection, profiling and inferences, manipulative design, biometric surveillance, retention and security.
The regulators called for children and youth to receive clear, age-appropriate information about what information is collected, why it is collected, where it is stored and with whom it is shared.
The resolution also called on EdTech providers to collect, use, disclose and retain children’s information only as necessary and proportionate for educational services.
It further addressed secondary uses such as marketing, product improvement and AI training, calling for specific consent from individual users before such uses occur.
It is important to understand the legal status of this development.
The 2025 resolution is not itself a new provision of PIPEDA. It represents a joint position and call to action from Canada’s privacy regulators concerning responsible educational technology.
Businesses should therefore distinguish between statutory requirements under PIPEDA and recommendations or expectations expressed by privacy regulators.
A Real-World Example: Photographs at a Swimming Pool
Children’s privacy concerns are not limited to online platforms.
In a 2025 PIPEDA investigation concerning a privately operated swimming pool, parents were required to agree to photographs and videos of their children being taken and posted on public platforms as a condition of enrolling their children in swimming lessons.
The OPC found this requirement inappropriate because using the photographs and videos for promotional purposes was not necessary to provide the swimming lessons.
The finding considered Principles 4.3.3 and 4.3.6 of Schedule 1 of PIPEDA.
Principle 4.3.3 is particularly relevant because it states that an organization should not make consent to collection, use or disclosure beyond what is necessary for an explicitly specified and legitimate purpose a condition of supplying a product or service.
The practical lesson is important:
Consent to receive a service does not automatically mean consent to every additional use of a child’s personal information.
An organization should distinguish between information required to provide the service and optional processing such as promotional use of photographs.
What happens if children’s information is breached?
Children’s services should also have an effective privacy-breach response process.
Under section 10.1 of PIPEDA, an organization must report a breach of security safeguards to the Privacy Commissioner where it is reasonable to believe that the breach creates a real risk of significant harm to an individual.
Where the reporting threshold is met, affected individuals must also be notified.
The Act requires organizations to consider factors including the sensitivity of the information and the probability that the information will be misused.
Consequently, a business handling children’s information should have a documented process for:
- identifying a privacy breach;
- containing the incident;
- assessing the information involved;
- determining whether there is a real risk of significant harm;
- documenting the assessment;
- reporting to the OPC where required; and
- notifying affected individuals where required.
In the CoreFour investigation, the OPC found that the organization had breach-reporting procedures and maintained a breach register. In relation to the specific vulnerabilities examined, the OPC concluded that the circumstances did not trigger the PIPEDA reporting and notification requirements on the facts of that investigation.
Retention and deletion of children’s information
Another important consideration is how long children’s information remains in an organization’s systems.
PIPEDA’s limiting-use, disclosure and retention principle requires organizations to retain personal information only as long as necessary to fulfil the identified purposes, subject to applicable legal requirements.
Organizations should establish retention and destruction procedures and periodically review whether information is still required.
For children’s platforms, businesses should be able to identify:
- what information has been collected;
- why it was collected;
- where it is stored;
- who can access it;
- how long it is retained;
- when it should be deleted; and
- how deletion is securely performed.
Retention should therefore be treated as part of privacy governance rather than simply a technical storage decision.

A Practical Approach for Businesses
Organizations providing services to children can consider the following approach.
1. Determine the applicable privacy law
Confirm whether PIPEDA applies or whether a substantially similar provincial privacy law governs the activity.
2. Map the information collected
Identify the categories of personal information collected from children and their parents or guardians.
3. Understand the users
Determine the age range of the intended users and consider their ability to understand the privacy implications of the processing.
4. Design an appropriate consent process
For children under 13, consider the OPC’s position that parental or guardian consent should generally be obtained, except in exceptional circumstances.
For older children and youth, consider whether the individual can provide meaningful consent based on their age and maturity.
5. Use clear and age-appropriate information
Explain collection, purposes, disclosures, choices and other relevant privacy information in language that the intended audience can reasonably understand.
6. Minimize collection
Collect only information necessary for identified purposes.
7. Separate essential and optional uses
Do not automatically bundle optional processing—such as promotional photographs or unrelated marketing—with the core service.
8. Implement appropriate safeguards
Apply technical, organizational and administrative safeguards proportionate to the information and risks involved.
9. Establish retention and deletion rules
Determine how long information needs to be retained and securely destroy or delete it when it is no longer required, subject to applicable legal obligations.
10. Maintain accountability
Privacy compliance should be supported through policies, procedures, employee training, contracts, security controls and ongoing review.
Children’s Privacy Is Becoming a Larger Compliance Issue
Children’s privacy continues to receive attention from Canadian privacy regulators.
In 2025, the OPC conducted an exploratory consultation concerning the development of a Canadian Children’s Privacy Code. The consultation considered how organizations should address the unique privacy needs and best interests of children in a digital and data-driven environment.
The OPC has stated that it is developing the Children’s Privacy Code based on feedback received through the consultation.
This should not be confused with an existing statute or an already enacted Canadian Children’s Privacy Code. It is part of the OPC’s ongoing work in this area.
The international regulatory picture is also developing.
The OPC’s 2026 report on the Global Privacy Enforcement Network (GPEN) Children’s Privacy Sweep reported findings from an international review of 876 websites and apps. The review examined areas including age assurance, children’s data collection, protective controls and account deletion.
Educational services represented 23% of the websites and apps examined, while gaming represented 18%.
The sweep also identified concerns involving age-assurance mechanisms, collection of email addresses and geolocation, account deletion and other potentially high-risk practices.
These findings do not mean that every website or application examined was violating PIPEDA. The sweep was an international review conducted by participating privacy authorities, and the findings should be understood in that context.
They nevertheless demonstrate the increasing attention being given to how digital services handle children’s personal information.
Final Takeaway
PIPEDA does not contain one single provision that answers every question about children’s privacy.
Instead, organizations need to consider children’s information through the Act’s broader privacy framework—particularly meaningful consent, appropriate purposes, limiting collection, limiting use and retention, safeguards, openness and accountability.
For businesses operating websites, applications, educational platforms, games and children’s products, the key questions are:
- Are we collecting only the information we actually need?
- Can the child or parent understand why it is being collected?
- Are we obtaining meaningful consent where required?
- Are optional uses separated from the core service?
- Is the information appropriately protected?
- Do we have clear retention and deletion practices?
- Can we demonstrate accountability if the organization is questioned about its privacy practices?
For children’s services, privacy should not begin and end with a parental-consent checkbox.
It should be considered throughout the information lifecycle—from product design and registration, through collection, use, disclosure and security, to retention and eventual deletion.
As children’s use of digital services continues to expand, organizations that understand these requirements and build privacy into their products and processes will be better positioned to meet their responsibilities under Canada’s evolving privacy landscape.
