Australia Children's Online Privacy Code

OAIC code required under the 2024 Privacy Act reforms, to be registered by 10 December 2026: applies the Australian Privacy Principles to services likely to be accessed by children, with design, consent and default-setting requirements.

JurisdictionAustralia
CategoryPrivacy & Data Protection
StatusUpcoming
Effective date
Latest development

Analysis

The Children’s Online Privacy Code (COPC) is an APP code under the Privacy Act 1988, mandated by the Privacy and Other Legislation Amendment Act 2024, and must be developed and registered by 10 December 2026 by the OAIC. According to the OAIC, the Code applies to social media services, relevant electronic services and designated internet services likely to be accessed by children, and specifies how these entities must comply with the Australian Privacy Principles (APPs) when handling children’s personal information, including additional requirements on design, consent and default settings.Children's Online Privacy Code – OAIC Privacy for Kids – Children’s Online Privacy Code – OAIC Privacy and Other Legislation Amendment Act 2024 – ATO Privacy and Other Legislation Amendment Bill 2024 – Parliament of Australia


Key Requirements

Below are the main proposed requirements of the Children’s Online Privacy Code, as reflected in the OAIC exposure draft and related materials. Until the Code is formally registered, these are draft obligations, but they are authoritative indicators of the final regime.

  • Applicability to online services likely to be accessed by children
  • Best interests of the child as a central principle
  • Stronger rules for direct marketing and targeted advertising
  • Enhanced rights and controls for children (including deletion)
  • Age‑appropriate, clear privacy notices and policies
  • Stronger consent mechanisms (including parental consent)
  • Application of Australian Privacy Principles (APPs) to children’s data
  • Design and default‑setting obligations (child‑centric design)

Compliance Challenges

While the Code is still being finalised, several common compliance challenges are already evident from OAIC consultations and industry analysis.

  • Determining when a service is “likely to be accessed by children”
  • Implementing robust and reliable age assurance
  • Reconciling advertising‑driven business models with best interests of the child
  • Designing truly age‑appropriate notices and consent flows
  • Operationalising deletion rights and controls for children
  • Real examples and case‑style insights

Implementation Best Practices

Below are practical steps organisations can take to prepare for the Code, anchored in OAIC guidance and industry frameworks.

  • Map services and data flows involving children
  • Embed “best interests of the child” into governance
  • Develop or strengthen age‑assurance mechanisms
  • Redesign consent and privacy notices for children
  • Implement deletion and control mechanisms
  • Align with APPs and existing OAIC privacy‑by‑design guidance
  • Ensure that child‑specific measures

Recent developments

  • — Integrity Institute publication summarising its 2026-06-04 submission to the OAIC on the draft Children’s Online Privacy Code, raising platform governance and enforcement considerations and illustrating civil society reaction to the proposed rules.[14] (source)
  • — Analysis of the exposure draft of the Privacy (Children's Online Privacy) Code 2026, outlining scope, which online service providers are covered, consultation timeline to 2026-06-05, and the requirement to register the final Code by 2026-12-10, alongside new ADM disclosure obligations.[11] (source)
  • — Law firm briefing on the Draft Children’s Online Privacy Code explaining proposed protections, expected material impact on online services used by children, and urging potentially in-scope organisations to participate in the OAIC consultation before 2026-06-05.[12] (source)
  • — OAIC social post promoting the public consultation on the exposure draft of the Children’s Online Privacy Code, inviting stakeholders to participate between 2026-03-31 and 2026-06-05 and to attend a public webinar explaining the draft Code.[8] (source)
  • — News article reporting that the OAIC has published the exposure draft of the Privacy (Children’s Online Privacy) Code 2026, describing new obligations for social media and other online services accessed by children and noting the 60‑day public consultation period ending 2026-06-05 and planned registration on 2026-12-10.[13] (source)
  • — OAIC media release announcing the exposure draft of the Children’s Online Privacy Code, highlighting new rules to prioritise children’s best interests in collection, use and disclosure of their personal information, and opening a 60‑day public consultation running from 2026-03-31 to 2026-06-05 before planned commencement in December 2026.[6] (source)
  • — Regulatory tracking note summarising the OAIC’s consultation on the exposure draft of the Privacy (Children’s Online Privacy) Code 2026, with emphasis on proposed age‑verification requirements and key dates: consultation opened 2026-03-31 and closed 2026-06-05.[5] (source)
  • — OAIC “Privacy for Kids” page presenting the official exposure draft of the Children’s Online Privacy Code and inviting submissions from industry, civil society and other stakeholders as part of the public consultation running to 2026-06-05.[3] (source)
  • — Extended OAIC guide explaining in accessible language how the Children’s Online Privacy Code will protect children’s data online and how children, young people and parents can engage with the consultation on the draft Code.[7] (source)
  • — OAIC register entry for the Children’s Online Privacy Code describing the multi‑phase consultation process, Phase 3 consultations from 2026-03-31 to 2026-06-05, and confirming that the Code must be finalised and registered by 2026-12-10, with commencement on 2026-12-10.[1] (source)

Related regulations

Put it into practice

Browse all regulations · Compliance deadlines · Latest updates