When the user is a minor, companies need a different approach
Language-learning apps, gaming platforms, social networks, streaming services - across a wide range of digital products, a significant share of users are minors. In most cases, the company behind the product never built a dedicated mechanism to handle users under the age of 18.
The result: personal information is collected from children, sometimes including location, photos, or browsing habits, without a tailored consent mechanism, and without ever asking whether the company's general privacy policy is adequate for such a particularly vulnerable audience.
Israel's Privacy Protection Authority treats information about minors as a category requiring heightened sensitivity, even though Israeli law does not include a dedicated children's privacy statute comparable to those in the United States or the European Union. Technology companies serving an audience that includes minors need to adapt their privacy policy, consent mechanisms, and product design accordingly.
What Israeli law says about children's data
The Privacy Protection Law, 5741-1981, as amended by Amendment 13 (in force since 14.8.2025), is the primary source governing the processing of personal data in Israel, including data concerning minors. The law does not set out a separate definition of "children's data," but information relating to a child - such as age, location, photos, or consumption habits - may qualify as data requiring a heightened level of protection given the data subject's vulnerability.
Amendment 13 expanded the enforcement powers of the Privacy Protection Authority, introduced a data breach notification duty, and established significant administrative fines for violations. The database registration requirement was narrowed, and today applies mainly to public bodies and to "data brokers" above a statutory size threshold - not to ordinary businesses.
In addition, the Privacy Protection Authority's guidance on consent, which entered into force in February 2026, sets a heightened standard for informed consent and requires separate, specific consent for profiling and for direct mailing. When minors are involved, this standard carries additional weight, since a minor's capacity to give informed consent is inherently limited.
Can a minor consent to data processing on their own
The Legal Capacity and Guardianship Law, 5722-1962, provides that a minor - someone under the age of 18 - has limited legal capacity. A legal act performed by a minor may be voidable, and in certain cases requires the consent of a parent or guardian.
Where consent to the processing of personal data is a condition for using a service, companies need to examine whether the minor's own consent is sufficient, or whether parental involvement is required. The more sensitive the data, and the younger the minor, the greater the need for a structured parental consent mechanism - rather than a blanket consent buried in lengthy terms of use.
In practice, digital platforms implement an age-tiered approach: young children require explicit, verified parental consent; teenagers are sometimes permitted a limited form of independent consent, alongside clear, age-appropriate disclosure written for the reader's comprehension level.
Lessons from GDPR and COPPA
The European GDPR provides in Article 8 that consent to information society services offered directly to children requires parental consent, with the relevant age set by each member state within a defined range. The American COPPA statute, aimed at companies operating digital services for children, imposes explicit obligations of verified parental consent, restrictions on data collection, and limitations on targeted advertising.
Israeli companies operating in international markets, or whose product is accessible to users outside Israel, generally need to comply with these frameworks alongside Israeli law. A gap between a relatively lenient domestic regulatory framework and stricter foreign frameworks is a significant source of legal and reputational risk.
Companies targeting minor users are advised to adopt the stricter standard among the relevant frameworks, even where Israeli law alone does not explicitly require it.
What is actually required of a platform serving minors
A platform that is aware that some of its users are minors - or whose product is aimed at that audience - needs to examine several layers:
- A reasonable age-verification mechanism, calibrated to the service's level of risk
- Verified parental consent, where the service is aimed at young children or collects sensitive data
- A privacy notice written in clear, age-appropriate language, in addition to the general policy
- Data minimization - collecting only what is required to operate the service
- Restrictions on profiling and targeted advertising directed at minors
- Restrictions on sharing data with third parties, particularly advertisers
It is important to distinguish between data collection required to operate the service (for example, age for content adaptation) and data collection to enrich a marketing profile. The Privacy Protection Authority's current guidance on consent emphasizes that consent to profiling must be separate and explicit - all the more so when the data subject is a minor.
Biometric data, educational records, and content created by minors
Edtech services, facial recognition apps for parental controls, and platforms that allow children to create and publish content all raise heightened risks. A minor's biometric data, information on academic achievement or classroom behavior, and content the minor themselves created and posted may all qualify as sensitive data requiring enhanced security measures.
Where a service allows children to publish content to the public - photos, videos, or messages - companies should examine content moderation mechanisms, accessible deletion options, and restricted default visibility. Product design that encourages a minor to disclose personal information beyond what is necessary may be considered a dark pattern and expose the company to regulatory risk.
In appropriate cases, it is advisable to conduct a privacy impact assessment for products aimed at minors or that serve them substantially, and to document the reasoning behind the design of protective mechanisms.
What companies should do now
Companies operating a digital service that could be used by minors, even if it was not originally designed for them, should map this as part of their ongoing privacy risk assessment. Practical steps include:
- Assessing whether the service is, in practice, accessible to or aimed at minors
- Updating the privacy policy and terms of use to address minors
- Building an appropriate parental consent mechanism that is documented and auditable
- Separating consents - basic use versus profiling and direct marketing
- Restricting targeted advertising to minors and data sharing with advertising providers
- Assessing whether a privacy impact assessment is warranted
Companies operating in international markets should also review GDPR requirements and equivalent laws in their target jurisdictions, and ensure their consent and protection mechanisms meet the strictest applicable standard.
Protecting children's privacy is not only a regulatory obligation - it is also a core business consideration. Users and parents alike now scrutinize how platforms handle their children's data, and a company that invests in appropriate protective mechanisms builds trust and reduces long-term legal exposure.
The information contained in this article is general in nature and does not constitute legal advice. For advice tailored to the specific circumstances of your company, we invite you to contact our firm.