The right to digital privacy for minors is the most philosophically unstable right in current children's online law. Adults claim privacy against the state, against employers, against other adults. Minors must claim it against three parties simultaneously — the state, the platforms, and their own parents — and the three claims are not coherent. A child's privacy against a platform is something most parents want strengthened. A child's privacy against parents is something most parents want bounded. A child's privacy against the state is something both child and parent share. The statutory regimes pretend this is a single right. It is not. It is at least three rights with overlapping but distinct architectures.
Begin with the developmental claim. Children become increasingly entitled to private mental and social space as they mature. The UN Convention on the Rights of the Child (Article 16) recognizes this. Most national laws gesture at it without specifying ages. Developmental psychology suggests rough thresholds: limited privacy interests around age seven, expanding privacy interests through adolescence, near-adult privacy interests by sixteen or seventeen. The law does not track this gradient. It tends instead toward binary cutoffs (under-13, under-18) that serve administrative convenience and produce strange results — a 17-year-old enjoys less statutory privacy from her parents than a 25-year-old, while enjoying more statutory privacy from advertisers than her 13-year-old brother.
Then consider the surveillance claim. Modern parenting tools — Bark, Aura, Qustodio, Apple Screen Time, Google Family Link, Life360, school-issued monitoring software — produce levels of parental visibility into children's communications and movements that have no historical precedent. The justifications are familiar (safety, mental-health monitoring, drug prevention, homework compliance) and often genuine. The effects are mixed. Several studies (Ghosh, Hartwig, Wisniewski, et al., 2018-2023) find that high-surveillance households produce worse, not better, adolescent outcomes on measures of self-regulation, online safety skill, and disclosure to parents about actual risks. The reason is intuitive: a child who knows she is monitored learns to evade rather than to navigate. Collective parenthood has not yet metabolized this finding. The market is still selling surveillance as parenting.
Then the commercial claim. Children's data has commercial value that grew with the rise of behavioural advertising and grew again with the rise of generative AI training corpora. The legal regimes — COPPA in the US, GDPR-K in the EU, age-appropriate-design codes in the UK and several US states — attempt to constrain commercial exploitation by limiting data collection, requiring parental consent for under-13s, and forbidding behavioural advertising to minors in some jurisdictions. Enforcement has been uneven. FTC penalties against YouTube (2019, $170 million), TikTok (2019, $5.7 million and 2024, ongoing), Epic Games (2022, $275 million), and Amazon (2023, $25 million for Alexa retention of children's voice data) signal increasing seriousness. The aggregate fines remain small relative to the underlying revenue. The architectures of data collection have changed less than the rhetoric suggests.
Then the state claim. Schools, child-protective services, juvenile courts, and law enforcement all routinely access children's digital records. School-district surveillance — particularly through software like Gaggle, GoGuardian, and Securly — flags student communications for review by school staff and sometimes police. The intent is suicide prevention and threat detection; the effect includes disproportionate flagging of LGBTQ students, students of colour, and students discussing trauma. State-actor surveillance of minors operates under Fourth Amendment doctrines (T.L.O., Vernonia, New Jersey v. T.L.O.) that grant schools wide latitude. The 1,000-page manual treats this as the area of children's privacy most likely to harm children most acutely, and least likely to be reformed soon.
For collective parenthood, the practical question is not "should children have digital privacy?" but "from whom, against what, at what ages?" A coherent policy framework would specify, by developmental stage: the data platforms may collect; the surveillance parents may conduct; the records schools may share; the metadata law enforcement may obtain without warrant. No jurisdiction yet has such a framework. Several are drafting one. Parents who participate in those drafts will determine whether the framework is rights-respecting or surveillance-respecting. Both options are on the table.
The deepest collective work is cultural. Privacy is not only a legal right; it is a social practice that adults must model. Parents who post their children's lives on social media from infancy ("sharenting") have made privacy choices on those children's behalf that the children cannot retract. The eight-year-old whose tantrum video has 4 million views did not consent. The fifteen-year-old discovering her medical history is searchable did not consent. The 1,000-page manual treats sharenting as the under-discussed counterpart to platform data collection: parents are also data controllers, and they too should ask before they post.
The right to digital privacy for minors is, in the end, a right to a navigable adolescence — a right to make mistakes that do not become permanent records, to explore identity without algorithmic profiling, to think in writing without those writings becoming training data. It is a right whose violation has consequences that arrive years later, when a college admissions officer, employer, or partner runs a search. The collective task is to write the rules now that allow those years later to be different.