Services / Children's Online Privacy Code
Children's Online Privacy Code readiness
The test is not whether you market to children. It is whether children could reasonably end up using your service.
Why this catches businesses out
A Children’s Online Privacy Code is due to be registered by 10 December 2026 under the 2024 privacy reforms. It is aimed at services that are likely to be accessed by children, which is a considerably wider net than services aimed at children.
A tutoring business, a sports club booking system, a clinic, a retailer selling to teenagers, a community app: none of these market themselves to children, and all of them may be captured. The obligation does not depend on your intent. It depends on who realistically turns up.
Who should check
- Education, tutoring, coaching and training services.
- Sport, recreation and youth programs that take online bookings.
- Health and allied health practices that see young patients.
- Retail, entertainment and community platforms with any teenage audience.
- Any app or site where a signup form has no meaningful age gate.
What I assess
- Exposure: whether your service is one children could reasonably access, documented with reasoning you can show someone.
- What you collect from young users, and whether any of it is unnecessary.
- Age assurance: what you do now, and what would be proportionate for your risk level.
- Defaults: whether settings that affect privacy start in the protective position.
- Consent: how parental involvement works where it is required.
- Third parties: what your analytics, advertising and embedded tools collect from young users.
- Your privacy notice: whether a young person could actually understand it.
What you get
A written assessment of whether the Code is likely to apply to you and why, the specific safeguards your situation calls for, and a fixed-price quote to implement them. If the Code does not apply to you, I will tell you that, in writing, with the reasoning. That document is worth having on file either way.
The Code text is still being finalised by the OAIC. Assessments reflect the requirements as published at the time of the engagement, and I will tell you where something remains subject to change.
Assessed against: the Children's Online Privacy Code (OAIC)
Common questions
We do not target children. Do we still need to look at this?
Possibly. The threshold is whether your service is likely to be accessed by children, not whether you market to them. If a fifteen-year-old could plausibly sign up, book or buy, it is worth a documented assessment even if the conclusion is that little changes.
Do we have to verify everyone's age?
Not necessarily. What is expected is proportionate to the risk of your service. A low-risk service may need a simple age declaration and sensible defaults. The assessment sets out what is proportionate for your situation rather than applying the strictest possible reading.
What if the Code changes after you assess us?
The report records the requirements as they stood on the date of assessment and flags anything still in flux. Compliance is ongoing, and a point-in-time assessment cannot be a permanent answer.
Related services
Start with a free check
I run a short external diagnostic and send you what I find. No obligation, and no pitch if there is nothing worth fixing.
I assess your systems and documents against published standards, identify where the gaps are, and give you the documentation to show you have addressed them. This is not legal advice.