info@nexoprivacy.com +254 768200243 Mon - Sat | 24 Hours
Home Blog Insights
Insights

CHILDREN’S DATA PRIVACY; RISING GLOBAL ATTENTION

By NexoPrivacy Team · June 24, 2026 · 5 min read

Kenya:

The formal legal interpretation of a child in Kenya under Article 260 of the Constitution is any person who is under the age of 18

With the Adoption of Kenya DPA laws in 2019, several Legal Frameworks were introduced to protect Minors which are found in the Guidance Note for Processing Children's Data

This include

Age of Consent-Individuals under the Age of 18 CANNNOT legally consent on their own for general data Protection

Best Interests of the Child-All Data Processing done on behalf of a minor must be align with the child’s fundamental rights to Freedom, safety and best interest

Marketing and Media-Adverts and promotional use of a child’s information including image and names must be done with the explicit, auditable and informed parental/guardian Consent

No Presumed Permission- Enrollment in a school or participation in an event does not constitute consent to publish a child's photographs, name, or academic results on social media platforms, websites, or billboards.

Exemptions- Certain organizations offering child protection or counseling services exclusively for the benefit of a child may not be required to seek parental consent


USA

The Maryland Kids Code (officially the Age-Appropriate Design Code Act, Legislation - HB0603 - Maryland) is a state law termed the New Era of Childs Online Privacy that was enacted on October 1 ,2024

Under this Law companies offering online products likely to be accessed by Minors under 18 years has to prioritize the minors' privacy and safety over commercial interests



Key Requirements

Data Protection Impact Assessment- organizations are now expected to carry out data protection impact assessments for online products likely to be accessed by children under 18

Profiling by Default-Default profiling of children is prohibited unless an organization can demonstrate a legitimate and compelling reason that the profiling will not adversely affect the child's rights, welfare, or best interests.

Our latest "Topic in Focus" on children's data is now available. Get in touch if you would like a copy.


Australia

Children's Online Privacy Code

In March 2026, Australia's privacy regulator, the Office of the Australian Information Commissioner (OAIC), released the draft Children's Online Privacy Code, which is scheduled to be finalized by December 2026. The Code would strengthen children's privacy rights online by requiring:

  1. Privacy-by-default settings.
  2. Limits on unnecessary data collection.
  3. Stronger consent requirements.
  4. Child-friendly privacy notices.
  5. Additional protections for apps, games, websites, and online services used by children

This is on top of the Online Safety Amendment (Social Media Minimum Age) Act 2024 whose key provision was a minimum of 16 years for certain social media platforms






Europe

Digital Services Act (DSA)

The DSA applies across the EU and requires online platforms to provide a high level of privacy, safety, and security for minors. It prohibits targeted advertising based on profiling of children and requires platforms to assess and mitigate risks to minors.

Key child protection requirements under the DSA

  1. No profiling-based advertising directed at children.
  2. Stronger privacy and safety protections for minors.
  3. Child-friendly terms and conditions.
  4. Measures to prevent exposure to harmful and illegal content.
  5. Enhanced reporting and complaint mechanisms for children.

Major 2026 developments

The European Commission has made child online safety a major priority in 2026 and is advancing:

  1. EU-wide age verification systems.
  2. New guidance on protecting minors under Article 28 of the DSA.
  3. Proposed rules targeting addictive platform design, dark patterns, and manipulative personalization





Get our weekly digest

One email a week, no fluff - only the privacy & compliance signal that matters.

Tags

No tags.

More reading

Related posts.

AI Act vs GDPR: What Every CEO Needs to Know Before Deploying AI in Your Business

AI Act vs GDPR: What Every CEO Needs to Know Before Deploying AI in Your Business

Read
AI Governance for Banks: A Practical Guide to Building Trust, Managing Risk, and Unlocking Innovation

AI Governance for Banks: A Practical Guide to Building Trust, Managing Risk, and Unlocking Innovation

Read
Cloud Storage Compliance for African Companies: GDPR, POPIA, Kenya DPA & Global Privacy Requirements

Cloud Storage Compliance for African Companies: GDPR, POPIA, Kenya DPA & Global Privacy Requirements

Read