What Age Can Children Consent to Data Collection in Australia?

Alex Solo
byAlex Solo12 min read

If your business collects personal information from children, or from users who may be under 18, age and consent are not small details. Founders often make the same mistakes, they copy a generic privacy policy that says anyone can agree to it, they rely on a checkbox without asking whether a child can really understand what they are agreeing to, or they collect extra data for marketing and analytics before working out whether parental consent is needed. This gets especially risky for apps, online platforms, edtech products, gaming businesses, health and wellbeing services, and any brand building a youth audience.

Australian privacy law does not set one simple age that applies in every case. The real question is whether the child has capacity to understand the collection, use and disclosure of their personal information. That makes this a practical business issue, not just a legal theory point. This guide explains what age can children consent to data collection in Australia, when parental consent is likely to be required, and what businesses should do before they launch, onboard users, or change their data practices.

Overview

In Australia, there is no single fixed age at which children can always consent to data collection. The key issue is whether the child has enough maturity and understanding to make an informed decision about the handling of their personal information.

  • Whether your business is covered by the Privacy Act 1988 (Cth), and whether you follow its standards even if not strictly required
  • What kinds of personal information you collect from children, including sensitive information
  • Whether a child using your service can reasonably understand what information is being collected and why
  • When parental or guardian consent is the safer approach
  • How your privacy policy, sign-up flow, and consent wording deal with minors
  • Whether your product design encourages over-collection, profiling, location tracking, or behavioural advertising
  • How you verify age or parental authority where needed
  • What your contracts with developers, platforms, schools, marketing providers, and data processors say about privacy responsibilities

The short answer is that Australian businesses should not assume a child can consent just because they clicked “I agree”. Capacity matters more than a fixed number.

Under Australian privacy principles, consent needs to be voluntary, informed, current, specific, and given by a person with capacity. For children, capacity depends on the individual child and the context. A teenager may be able to understand a simple collection notice for a basic app feature, while a younger child may not. The answer can also change depending on how complex the data practice is.

This is why businesses asking “what age can children consent to data collection” often do not get a clean statutory number in response. Australian law generally takes a capacity-based approach. In practice, many organisations treat under-15s or under-16s more cautiously, but that is a risk-management choice rather than a universal legal rule that solves every scenario.

Why capacity matters

A valid consent is not just a formality. The person giving consent needs to understand the key points, including:

  • What personal information is being collected
  • Why it is being collected
  • Who it may be shared with
  • What happens if they do not agree
  • Whether the information will be used for marketing, profiling, analytics, or location tracking

If a child cannot reasonably understand those points, their consent may not be valid. In that case, a parent or guardian may need to consent on their behalf.

There is no one-size-fits-all age

Businesses sometimes look for a hard rule such as 13, 15, 16, or 18. Australian privacy law does not work that neatly. The age question depends on the circumstances, including the child’s maturity and the complexity and sensitivity of the data collection.

For example, collecting an email address so a teen can create a basic account may raise a different consent question from collecting health details, voice recordings, school performance data, precise location data, or behavioural data used for targeted advertising. The more intrusive or sensitive the collection, the stronger the case for parental involvement and clearer consent processes.

What counts as personal information

The issue is broader than names and email addresses. Personal information can include anything that identifies or could reasonably identify a child. Depending on your product, this may include:

  • Name, date of birth, and contact details
  • Photos, videos, audio recordings, and avatars
  • Device identifiers and IP addresses
  • Location data
  • Usage data and in-app behaviour
  • School, class, or learning progress information
  • Health or wellbeing information
  • Parent or family contact details linked to the child

Some of this information may also be sensitive information. That brings a higher privacy risk and usually requires more careful handling.

What this means for startups and SMEs

If you are building a consumer app, education product, community platform, game, wearable, or online marketplace used by minors, this issue should be dealt with before you spend money on setup or launch a new feature. Your product design, registration flow, terms, privacy disclosures, and supplier contracts should all line up.

This is also relevant if children are not your main target market but are likely to use your service anyway. A general audience platform can still end up collecting data from minors, and that can create legal and reputational risk if the sign-up process was written only for adults.

When This Issue Comes Up

This issue usually appears when a business collects data directly from children online, or when a service is obviously attractive to younger users. It also comes up when founders add analytics, ad tech, or new account features without reconsidering how minors are giving consent.

Apps, platforms and games

If your app or game allows children to create accounts, message others, upload content, or make purchases, you need to think carefully about age, consent, and parental involvement. A simple “tick to accept” flow may not be enough if the privacy explanation is too dense or the user is likely to be too young to understand it.

This is where founders often get caught. They focus on app store release dates and product testing, but not on whether their privacy collection notice and account terms are readable for the actual audience.

Edtech and services connected to schools

Education businesses often collect names, ages, learning records, attendance information, parent details, and sometimes health or support needs. The legal position can differ depending on whether the school is collecting information on behalf of students, whether the provider is acting under a school contract, and whether the student or parent signs up directly.

Before you sign a school agreement, check who is responsible for obtaining consent, who is the main contact for privacy complaints, and whether the service allows any extra data uses beyond delivering the core educational function.

Health, wellbeing and support services

If your business collects health or mental wellbeing information from children, the main risk increases quickly. Sensitive information usually needs a clear lawful basis for collection and more careful consent handling. A young person’s capacity may still be relevant, but the stakes are higher and businesses should be cautious.

Products in this space should avoid broad “all-purpose” consents. Separate disclosures are often better where the service includes different functions, such as treatment support, progress tracking, research, or marketing communications.

Marketing and behavioural tracking

Children’s data should not be treated like ordinary ad inventory. If your website, app, or platform uses pixels, audience profiling, cookies, software development kits, or third-party advertising tools, think about whether those tools are collecting personal information from minors and whether the consent process is meaningful.

Many businesses miss this because the tracking is bundled into tools installed by developers or marketing teams. Your legal review should cover both first-party collection and what third parties receive.

Community features and user-generated content

Forums, social features, leaderboards, photo uploads, and chat tools create extra privacy issues. Children may share more than you expected, and other users may be able to see or infer identifying details.

Before you launch online, review whether your settings default to public sharing, whether moderation is active, and whether children can delete content or close accounts easily.

Offline collection and mixed channels

The issue is not limited to websites and apps. Gyms, tutoring businesses, clinics, holiday programs, retail loyalty programs, and event businesses may collect children’s data through paper forms, QR code sign-ups, kiosks, tablets, or online waivers.

If your staff collect information face to face, they need practical scripts and forms that make it clear when a parent or guardian should provide consent.

Practical Steps And Common Mistakes

The safest approach is to build your collection process around the age and maturity of your likely users, not around a generic adult-style consent screen. Clear drafting, limited data collection, and sensible parent verification usually reduce risk more than adding more legal text.

1. Map exactly what data you collect

You cannot assess children’s consent properly if you have not mapped your data flows. Start with a practical list of what your product collects at account creation, during use, and through third-party tools.

Your data map should include:

  • Information entered by the child
  • Information entered by a parent, teacher, or school
  • Automatically collected technical data
  • Sensitive information
  • Sharing with payment providers, analytics providers, cloud hosts, customer support platforms, and marketing tools

Founders often discover at this stage that the business is collecting much more than the product team realised.

2. Decide whether children are part of your audience

If children are likely users, your documents and user flow should say so clearly. If your service is intended only for adults, your terms and sign-up process should not be ambiguous.

That said, a statement saying “you must be 18+” is not a complete solution if your branding, features, or content are obviously aimed at younger users. Regulators and courts may look past labels to the practical reality.

3. Use age-appropriate notices

A privacy policy written for investors or lawyers will not help a child understand what they are agreeing to. Consider layered notices, shorter summaries at sign-up, and plain language prompts around key permissions.

For example, if your app asks to access location, camera, microphone, or contacts, the explanation should appear at the point of collection and use simple language. The child or parent should not need to hunt through a long document to work out what is happening.

If a child may not have capacity to understand the data practice, parental or guardian consent is usually the safer route. This is especially relevant where the child is younger, the processing is complex, or the information is sensitive.

Think about parental consent where your service involves:

  • Young children using the product independently
  • Sensitive information such as health, disability, or biometric data
  • Public profiles or sharing features
  • Location tracking
  • Behavioural advertising or profiling
  • In-app purchases or ongoing subscriptions

You should also think about how to verify that the person giving consent is actually the parent or guardian. The right method depends on the service and risk level.

5. Avoid over-collection

If you do not need certain information, do not collect it. This sounds obvious, but it is one of the easiest ways to reduce privacy risk.

Common examples of over-collection include asking for full date of birth when an age band would do, collecting precise location when suburb-level information is enough, or enabling broad contact-list access where the feature does not really require it.

6. Align your terms, privacy policy and product design

Your legal documents should match what the product actually does. If your privacy policy says children need parental consent, but the registration flow lets anyone sign up with a single click and no parent touchpoint, the process is inconsistent.

Before you print marketing material or approve a release, check alignment across:

  • App onboarding screens
  • Website forms and checkboxes
  • Terms and conditions
  • Privacy policy and collection notices
  • Parental consent forms or email workflows
  • Customer support scripts
  • Developer documentation and data processing arrangements

7. Review your supplier and platform contracts

If third parties host, analyse, store, or monetise children’s data, your contracts matter. This includes software developers, learning management platforms, cloud services, ad networks, customer support tools, and outsourced operations providers.

Before you sign a contract, confirm who can access the data, where it is stored, how long it is kept, what happens on termination, and whether the supplier can use the data for its own purposes.

8. Train your team

Staff in product, marketing, support and partnerships should know the basics. A good policy will not help if your team tells schools, parents, or users the wrong thing.

Training should cover:

  • When to escalate privacy questions
  • How to identify a minor user issue
  • What staff can and cannot promise about data use
  • How to handle correction, deletion, and access requests
  • What to do if a child signed up without proper consent

Common mistakes businesses make

The most common mistake is assuming age alone answers the question. Capacity, risk, and context all matter.

Other regular mistakes include:

  • Using a generic overseas template that does not match Australian privacy law
  • Collecting children’s information for optional marketing without a clear consent process
  • Relying on long-form terms that children are unlikely to understand
  • Failing to separate essential data collection from optional features
  • Letting third-party tracking tools run without checking what they collect
  • Ignoring school or parent-facing contract terms
  • Keeping children’s data longer than necessary under a data retention policy

If your business is early stage, these issues are easier to fix before scale. Once schools, families, subscribers, or platform partners are involved, a privacy redesign becomes more expensive.

FAQs

No. Australia generally uses a capacity-based approach, so the key issue is whether the child can understand the collection, use and disclosure of their personal information in the relevant context.

No. A parent does not always need to consent. If the child has enough maturity and understanding, they may be able to provide valid consent themselves. If they do not, parental or guardian consent is usually needed.

What if my business is not technically covered by the Privacy Act?

You may still face contractual, platform, reputational, and consumer expectations around privacy. Following Australian privacy law standards is often sensible, especially if children use your product or if you plan company setup and growth.

Not automatically. The answer depends on the arrangement with the school, the kind of information collected, and whether the provider uses the data only to deliver the service or for other purposes as well.

What type of children’s data needs extra caution?

Sensitive information, location data, behavioural tracking, public profile data, and anything shared with third-party marketers or analytics providers generally need closer review and clearer consent processes.

Key Takeaways

  • Australia does not have one fixed age at which children can always consent to data collection, capacity and context are the key issues.
  • Your business should assess what data it collects, how complex the processing is, and whether the child can reasonably understand what they are agreeing to.
  • Parental or guardian consent is often the safer approach for younger users, sensitive information, location tracking, behavioural advertising, and public-sharing features.
  • Privacy policies, collection notices, terms, onboarding flows, and supplier contracts should all match your actual product design and data practices.
  • Early legal review can help avoid expensive fixes after launch, especially for apps, edtech, health, gaming, and online services used by children.

If your business is dealing with what age can children consent to data collection and wants help with privacy policies, consent processes, supplier contracts, and platform terms, you can reach us on 1800 730 617 or team@sprintlaw.com.au for a free, no-obligations chat.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Need legal help?

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.