The Office of the Australian Information Commissioner (OAIC) published a long-awaited draft Children’s Online Privacy Code (Code) on Tuesday. Once registered, the Code will set out new rules for the digital domain which aim to uplift online protections for children while promoting and educating children about their privacy rights. The Code is intended to work in tandem with other legislative instruments such as the Social Media Minimum Age scheme, the Online Safety Act 2021 (Cth) and the Unlawful and Age-Restricted Material Codes recently registered by the eSafety Commissioner.
Who does the Code apply to?
The Code will apply to providers of social media services (being online services that enable social interaction between people such as social network platforms and discussion forums), relevant electronic services (being online services that let people communicate with each other such as messaging apps, email services and online games with chat capabilities) and designated internet services (being online services that allow users to access or receive material over the internet such as apps, websites, cloud storage and streaming platforms) where that service is likely to be either accessed by children or primarily concerned with activities of children (with an exclusion applying for health services).
These service provider definitions are central to the Online Safety Act and its Codes and Standards, showing a clear focus on brining regulatory alignment between the privacy and online safety regimes.
What are the key takeaways?
Our key takeaways from the draft Code are:
- The Code is broad in its application and will affect a range of sectors and industries, not just big tech and social media.
- The Code raises the standard for the collection, use and disclosure of children’s personal information, which must now be consistent with the best interests of the child. While this standard has been used in areas like family law, it is new for the privacy space and may require entities to consider factors such as the nature and extent of child exploitation risks and likely impact on the physical, psychological, emotional and cognitive development of the child.
- Entities must implement technical and organisational measures to ensure that, by default, they only collect personal information that is strictly necessary to provide the relevant service. This privacy by default and design concept will require a clear understanding of the entity’s data flows and organisation-wide data handling practices and policies (similar to what is required in relation to data security obligations under APP 11).
- It applies at a service (and not entity) level – if an entity provides multiple services under one business, it will only apply to the service within scope for the Code. This will require entities to ensure that they understand both their customer base and their service offerings to that customer base, and will potentially drive operational complexity.
- The requirements of consent are defined clearly – it must be voluntary, informed, current, specific, unambiguous and can be withdrawn.
- Additionally, consent for the collection, use or disclosure of personal information must be obtained directly (for children 15 years or older) or through a parent or carer (for children under 15 years). If a parent or carer provides consent, then a notice must also be given to the child. Children under 15 years may only give consent if permitted by law or if the child seeks legal or health-related information or support in connection with a parent or carer.
- A form of ‘dual consent’ is needed if personal information of a child under 15 years is used for direct marketing or for a secondary purpose other than that for which it was collected, or if sensitive information is collected. This requires the entity to obtain the assent of the child and consent of the parent or carer. Before contacting the parent or carer, the entity must seek the child’s assent to communicate with that parent or carer. This represents a novel approach and may force entities into a broader rethink of the methods employed for obtaining consent.
- An emphasis on improving transparency will require a review of privacy policies and notices to ensure these are accessible to children and written in clear and age-appropriate language.
- Entities that fail to comply with the Code will be subject to the regulatory and penalty framework under the Privacy Act 1988 (Cth), which includes hefty civil penalties for breaches.
What’s next?
The release of the Code has triggered a public consultation process with the OAIC currently seeking feedback on the draft Code until 5 June 2026. While the final version of the Code must be registered by 10 December 2026 its actual commencement date is still to be confirmed. For advice on the Code or other regulations in the privacy or online safety space, please contact our Digital and IP team:
- Alex Hutchens, Partner
- Belinda Breakspear, Partner
- Melissa Miller, Partner
- Jane Davies, Special Counsel
- Nikhil Ullal, Special Counsel,
or reach out to us here.