Photo by cottonbro studio from Pexels

You found a great new app for your kid, or maybe a SaaS tool your whole family will use. Before you tap "Subscribe," there is a question most people skip: does this service collect data from children, and what exactly does it do with that data? Children's privacy clauses are buried deep inside terms of service, wrapped in legal language that even attentive adults miss. This checklist gives you a concrete, repeatable process to spot those clauses in minutes, no law degree required.

TL;DR

  • Laws like COPPA (U.S.) and GDPR-K (EU) set strict rules for collecting data from children under 13 (or 16 in some EU countries), but many services bury compliance details in dense legal text.
  • Look for five key signals: age-gating language, parental consent mechanisms, data-type disclosures, third-party sharing clauses, and retention/deletion policies.
  • A quick Ctrl+F search for terms like "child," "minor," "parent," "guardian," and "under 13" can surface the most critical paragraphs in seconds.
  • Terms Doctor's 101 automated checks flag children's data collection clauses automatically, saving you from manual scanning.
  • Automated tools help, but they are not legal advice, always read flagged sections yourself before subscribing.
0
Consumer-protection checks in Terms Doctor

Why children's data clauses matter more than you think

person reading legal document laptop
Photo by Mikhail Nilov from Pexels

Children's personal information is uniquely sensitive. Unlike an adult who can weigh the trade-off between convenience and privacy, a seven-year-old cannot meaningfully consent to having their voice recordings, location data, or browsing habits stored on a server halfway around the world. That is exactly why regulators treat children's data differently.

Yet many services that are not explicitly "for kids" still collect data from minors. Think about a family password manager, a homework-help AI tool, or a streaming service with a kids' profile. If the terms of service do not clearly address children's data, that is itself a red flag.

"The notice must describe not only your practices, but also the practices of any others collecting personal information on your site or service, for example, plug-ins or ad networks."
>, Children's Online Privacy Protection Rule: A Six

Key takeaway: If a service can reasonably be used by children, its terms of service should explicitly address how it handles minors' data, silence on the topic is a warning sign, not a comfort.

The five signals to look for in any terms of service

privacy policy on screen
Photo by AS Photography from Pexels

Before you open any terms page, know what you are hunting for. Children's data collection language clusters around five distinct signals:

  1. Age-gating or age-verification language, Phrases like "you must be at least 13 years old," "users under the age of 16," or "we do not knowingly collect information from children." This tells you whether the service even acknowledges minors.
  2. Parental or guardian consent mechanisms, Look for descriptions of how a parent can approve an account, review collected data, or request deletion. COPPA-compliant services must describe a verifiable consent process (email-plus, signed form, credit card verification, etc.).
  3. Data-type disclosures specific to minors, Does the policy list what categories of data are collected from children? Responsible services separate children's data types (name, school, age, device identifiers) from general user data.
  4. Third-party sharing and advertising clauses, COPPA prohibits conditioning a child's participation on disclosing more data than necessary. Check whether the service shares children's data with ad networks, analytics providers, or AI training pipelines.
  5. Retention and deletion policies, How long is children's data kept? Can a parent request deletion at any time? A compliant service will spell out a retention period and a clear deletion procedure.
Terms pages with hidden auto-renewal clauses
0%

Your step-by-step scanning process

Checklist: spot children's data collection clauses before you subscribe process
Figure 1: Checklist: spot children's data collection clauses before you subscribe at a glance.

Follow these steps every time you evaluate a new service. The whole process takes five to ten minutes for a typical terms page.

Step 1, Open the terms and privacy policy side by side

Most services split their legal text into at least two documents: a "Terms of Service" (or "Terms of Use") and a "Privacy Policy." Children's data clauses can appear in either, or in a separate "Children's Privacy" addendum. Open all of them.

Step 2, Use keyword search

Press Ctrl+F (or Cmd+F on Mac) and search for these terms one by one:

  • child
  • children
  • minor
  • under 13 / under 16
  • parent
  • guardian
  • COPPA
  • verifiable consent
  • school (relevant for EdTech tools)
Each hit takes you directly to the paragraph that matters. Read the surrounding sentences for context.

Step 3, Check for a dedicated children's section

Well-structured policies include a clearly labeled section, often titled "Children's Privacy," "Information About Children," or "COPPA Compliance." If the service has no such section and is reasonably likely to be used by minors, treat that as a red flag.

Step 4, Evaluate third-party data sharing

Within any children's section, look for language about sharing data with advertisers, analytics services, or "business partners." Under COPPA, operators must disclose every third party that collects data through their service. Vague language like "we may share information with selected partners" without specifying who those partners are is a concern.

Step 5, Verify deletion rights

Confirm that the policy grants parents the right to review, correct, and delete their child's personal information. If the policy only mentions deletion "upon account termination" but not on parental request, the service may not be fully COPPA-compliant.

Step 6, Run Terms Doctor for an automated second opinion

Install the free Terms Doctor extension for Chrome, Edge, Brave, Opera, or Vivaldi. Navigate to the service's website and let Terms Doctor automatically locate the terms of service. The extension runs 101 consumer-protection checks, including specific flags for children's data collection, forced arbitration, AI training on user data, and auto-renewal traps, and assigns an A-F grade with plain-language explanations. Use the flagged items as a starting point for your manual review.

The complete checklist

Children's Data Collection Clause Checklist

Your progress is saved automatically in your browser.

Common red flags in real-world terms

consumer reading fine print
Photo by Mathias Reding from Pexels

Here are patterns that should make you pause before subscribing:

  • "We do not knowingly collect data from children under 13", and nothing else. This single sentence is the bare minimum. Without details on what happens if a child does sign up, or how the service detects minors, it is essentially a legal disclaimer rather than a protection.
  • No age gate at registration. If anyone can create an account without confirming their age, the service has no practical mechanism to enforce its own policy.
  • Broad data sharing with unnamed third parties. Phrases like "trusted partners" or "affiliates" without a list or link to those partners make it impossible to assess risk.
  • Behavioral advertising enabled for all users. If the privacy policy does not carve out an exception for children's profiles, minors may be subject to the same tracking as adults.
  • No mention of parental deletion rights. COPPA requires operators to honor parental deletion requests. If the policy is silent, the service may not have a process in place.
  • Data retention "for as long as necessary." Without a defined period, children's data could sit on servers indefinitely.
Quick tip: If a service scores a D or F in Terms Doctor and you see children's data flags among the red-flag highlights, think twice before creating a child's account. The extension's plain-language explanations tell you exactly which clauses triggered the warning.

What to do when you find a problem

Spotting a problematic clause does not necessarily mean you must avoid the service entirely. Here is a practical decision tree:

  1. Missing children's section entirely, Email the service's privacy contact (usually listed at the bottom of the privacy policy) and ask how they handle data from users under 13. Document their response.
  2. Vague parental consent language, Ask specifically what verification method they use. If they cannot answer clearly, consider an alternative service.
  3. Third-party sharing without named partners, Request a list of sub-processors or advertising partners. GDPR-compliant services are required to maintain one.
  4. No deletion process, File a formal deletion request citing COPPA (in the U.S.) or GDPR Article 17 (in the EU). If the service does not respond within the legally required timeframe, you can file a complaint with the FTC or your national data protection authority.
  5. Everything checks out, Great. Save a copy of the current terms (or enable Terms Doctor's change tracking) so you will be alerted if the policy changes later.

FAQ

Frequently Asked Questions

It depends on the jurisdiction. In the United States, COPPA sets the threshold at under 13. In the European Union, the GDPR default is 16, but individual member states can lower it to as young as 13. If the service operates globally, look for both thresholds. A well-drafted policy will address both COPPA and GDPR requirements.
Yes. Among its 101 consumer-protection checks, Terms Doctor includes flags for children's data collection language, age-gating requirements, and parental consent mechanisms. When the extension detects these clauses, it highlights them in the report and factors them into the overall A-F grade. Remember that automated checks are not legal advice, always read the flagged sections yourself.
Many general-audience services include a disclaimer that they are not intended for children under 13. Legally, this may reduce the operator's COPPA obligations, but it does not eliminate your responsibility as a parent. If your child will use the service, review the data collection practices as if the service were directed at children. Consider whether the data types collected (location, voice, photos) pose risks for a minor.
Yes. Under COPPA, a parent has the right to request deletion of a child's personal information at any time, regardless of what the terms of service say. Under GDPR, the right to erasure (Article 17) also applies. Send a written request to the service's privacy contact and keep a copy for your records.
Terms of service can change at any time, often with minimal notice. A good practice is to re-check at least once every six months, or whenever you receive a "we've updated our terms" email. Terms Doctor's change-tracking feature can automate this by alerting you when a service modifies its terms, so you do not have to remember to check manually.

Let Terms Doctor do the heavy lifting

Manually scanning every terms page is important but time-consuming. The free Terms Doctor extension for Chrome, Edge, Brave, Opera, and Vivaldi automates the first pass for you. It finds the terms of service on any website, runs 101 consumer-protection checks, including children's data collection, forced arbitration, AI training on user data, and auto-renewal traps, and delivers an A-F grade with plain-language explanations. Install it from the homepage and pair it with the checklist above for a thorough, repeatable review process. Automated checks are a effective starting point, but they are not legal advice, always read flagged clauses yourself before making a decision.

Additional Resources