How to protect your child's data online, from apps and school systems to identity thieves

Data removal. Updated 2026-09-13. About 6 minutes to read.

In the US, freeze your child's credit at all three bureaus now, then set up Family Link or Screen Time and opt out of school directory sharing.

Children's data leaks from four places: the apps and games they use, the school systems that hold their records, the photos and details adults post about them, and identity thieves who prize a clean record nobody checks. A child's Social Security number or identity can be misused for years before anyone notices, usually when they apply for a first loan or job.

The good news is that the most effective protections are free and take an evening. In the US you can freeze a child's credit before anyone uses it. Every major phone and console platform has parental privacy controls. Schools must let you opt out of some sharing. And the law now gives children more protection than adults in several countries.

This guide covers the United States, the United Kingdom and Australia, with the steps first and the legal background after.

Where children's data actually leaks

  • School systems. The PowerSchool breach disclosed in early 2025 exposed student records from school districts across North America, including names, addresses and in some cases medical notes and Social Security numbers.
  • Games, chat and video apps that collect voice, location, contacts and in game purchases, often through an account set up with a false birth date.
  • Parents and relatives posting full names, birthdays, school uniforms, sports club names and location tagged photos.
  • Connected toys, baby monitors and smart speakers with weak default passwords.
  • Breaches at retailers, clinics and sports clubs where a parent registered the child.

Freeze your child's credit in the US before anyone else uses it

Under US law, a parent or guardian can request a free credit freeze for a child under 16 at each of the three credit bureaus. If the child has no credit file, the bureau creates one and freezes it immediately, so nobody can open credit in the child's name until you lift it.

  1. Contact Equifax, Experian and TransUnion separately. Each has a minor freeze process on its website, usually completed by mail or upload.
  2. Send copies of the child's birth certificate and Social Security card, your government issued ID, and proof of your address, as each bureau requests.
  3. While you are in contact, ask each bureau for a manual search on your child's Social Security number to check whether a file already exists. Children should not normally have one.
  4. Store the confirmation letters and any PINs in your password manager. You will need them to lift the freeze when your child is older.

Outside the US there is no equivalent child freeze. In Australia, contact IDCARE on 1800 595 160 if you suspect misuse, and the credit reporting bureaus can place a ban on a file where fraud is suspected. In the UK, credit files for children are rare, so watch for post addressed to your child from lenders.

Turn on the platform controls that already exist

  1. Android and Google accounts: use Google Family Link to create a supervised account for a child under 13, approve app downloads and turn off location sharing with apps that do not need it.
  2. iPhone and iPad: set up Family Sharing, then open Settings, then Screen Time for the child, and use Content and Privacy Restrictions to lock location, contacts, photos and microphone permissions.
  3. Consoles: use the Xbox Family Settings app, PlayStation family management, or the Nintendo Switch Parental Controls app to restrict chat with strangers and require approval for purchases.
  4. Enter your child's real birth date on every account. Lying about age to unlock a service also removes the child protections that platforms are required to apply.
  5. Review each app's privacy settings with your child, rather than for them, so they learn why location and contacts matter.

What the law gives you: COPPA, the UK Children's Code and Australia's age limit

In the US, the Children's Online Privacy Protection Act covers online services aimed at children under 13 and those that know they are collecting data from under 13s. Operators need verifiable parental consent, and you can ask them to show you and delete your child's data. The FTC's amended COPPA Rule took effect on 23 June 2025, with full compliance required by 22 April 2026. It adds biometric identifiers such as face and voice data and government ID numbers to protected information, and requires separate parental consent before a child's data is disclosed to third parties such as advertisers.

In the UK, the ICO's Age Appropriate Design Code, known as the Children's Code, requires online services likely to be used by under 18s to set high privacy by default, switch off geolocation by default, and avoid nudging children to weaken their settings.

In Australia, the social media minimum age law took effect on 10 December 2025. Platforms including Facebook, Instagram, Snapchat, TikTok, X and YouTube must take reasonable steps to stop under 16s holding accounts. Children and parents are not penalised. The OAIC released a draft Children's Online Privacy Code in March 2026 and is due to register the final code by 10 December 2026.

Ask the school what it shares

  1. In the US, ask the school office for its FERPA directory information opt out form. Without it, schools can release a student's name, address, phone number, date of birth and photo to outside parties. Opt outs usually need renewing each school year.
  2. Ask which apps and learning platforms hold your child's data, and whether a data protection agreement is in place with each vendor.
  3. Question requests for your child's Social Security number. Ask why it is needed, how it is protected, and whether another identifier can be used.
  4. When your child leaves a school or stops using a platform, ask in writing for their account and data to be deleted.

If your child's data is exposed

  1. Read the breach notice carefully and note exactly which data types were involved.
  2. In the US, freeze the child's credit at all three bureaus if you have not already, and report misuse at IdentityTheft.gov for a recovery plan.
  3. In Australia, contact IDCARE for free support. In the UK, report fraud to Report Fraud or, in Scotland, Police Scotland on 101.
  4. Change passwords on the affected accounts and on any account that reused the same password.
  5. Warn your child that scammers may use the leaked details to make messages look genuine, and agree that they will check with you before replying to anything that asks for codes or money.

Frequently asked questions

Can I freeze my child's credit if they do not have a credit report yet?

Yes. For a child under 16, the bureau creates a record and immediately freezes it. That is the point: it stops anyone creating a file in your child's name in the first place.

Is it free to freeze a child's credit?

Yes. US federal law requires the three bureaus to place, lift and remove freezes for free, including for children under 16 at a parent's request.

What age does COPPA cover?

COPPA protects children under 13. Teenagers aged 13 to 17 are not covered by COPPA, although several US state privacy laws add protections for teens, and platforms often apply extra defaults for them.

How do I find out if my child's identity has been stolen?

Warning signs include collection calls or bills in your child's name, pre-approved credit offers addressed to them, tax notices saying their number was already used, or a denied benefit. In the US, ask each bureau for a manual search on the child's Social Security number.

Does Australia's social media age limit delete existing accounts?

The law requires platforms to take reasonable steps to prevent under 16s having accounts, which includes finding and deactivating existing accounts, not only blocking new sign ups. Ask the platform how to download your child's photos and messages before an account is removed.

Tools that help

Related guides

Sources