28/08/2026

With children spending more time online, amendments to the Privacy Act introduced a requirement for the Office of the Australian Information Commission (OAIC) to develop a Children’s Online Privacy Code to enhance online privacy protections for children (the Code). For the purposes of the Code, a child is an individual under the age of 18.
A draft of the Code has undergone numerous rounds of consultation, and OAIC must finalise it by 10 December 2026. It is expected that the code will commence shortly thereafter.
Does my organisation need to comply?
The Code establishes obligations for online services, such as apps, games, and websites, to safeguard the privacy of children.
Importantly, the Code will apply to all of the following:
- the entity is a provider of a social media service, relevant electronic service (such as SMS or MMS services) or designated internet service (all within the meaning of the Online Safety Act 2021);
- the service is likely to be accessed by children or primarily concern the activities of children; and
- the entity is not providing a health service.
The Code will likely apply to a range of organisations including schools, child care, not-for-profits, sporting clubs and government departments. Some examples of the types of services the Code may apply to include:
- applications that track early childhood development
- family photo sharing applications
- online school management systems that monitor student performance
- internet-connected baby monitors
- messaging or chat services
- online games
- sports club management systems that monitor junior athlete performance or attendance
- social club management systems that monitor members activities and attendance at events
- youth church management systems that communicate study and social events to members
- tutoring platforms
- transport services used by children
- systems that manage housing services or out-of-home care for families and youth
Essentially, ask yourself, does my online service have the potential to be used by children or concern the activities of children? If the answer is yes or you are unsure, it is likely the Code will apply.
Failure to comply with the Code could result in a breach of the Privacy Act, exposing agencies and organisations to potential civil penalties.
Examples of the new draft rules include:
- Online services are required to adopt a ‘privacy by default’ approach which is in the ‘best interest of the child’.
- Collection of children’s personal information must be ‘strictly necessary’ by default.
- Online services must seek permission from the child, parent or carer to use children’s personal information. Including a two-step consent model where children under 15 must assent AND parents must consent to the collection, use or disclosure of the child’s personal information.
- If requested by the child, parent or carer, online services must permanently delete personal information.
- Before launching new or updated services, online services must consider and document how they protect children’s online personal information. This is known as a ‘Privacy Impact Assessment’ (‘PIA’) and must be made publicly available upon completion.
What does my organisation need to do?
Currently, the Code is in draft form and does not yet impose obligations on organisations. Once the Code is finalised, your organisation may need to assess its current practices and implement updates to ensure compliance within a reasonable timeframe.
Are you and your business ready for the Children’s Online Privacy Code? Griffin Legal’s team of privacy experts can assist in reviewing your privacy practices to ensure compliance with the new requirements once the Code is finalised.