Children's Online Privacy Code 2026
OAIC developing a mandatory children's online privacy code — must be registered by 10 December 2026 (commencement not yet fixed).
Who must comply
APP entities providing social media, relevant electronic or designated internet services likely to be accessed by children (not health service providers).
What triggers it
Online service availability to children.
When due
Code to be registered by 10 December 2026; obligations apply from the commencement date the Code sets (not yet fixed).
Evidence required
Age verification + default privacy + parental consent records.
Max penalty
—
Effective from
10 December 2026
Who must comply with this? The applicability test by industry, business structure and size.
Summary
Privacy and Other Legislation Amendment Act 2024 requires the OAIC to develop a binding Code addressing children's privacy online and register it by 10 December 2026. Consultation ran in three phases from January 2025 to June 2026. Per the OAIC, the Code binds APP entities that provide a social media service, a relevant electronic service or a designated internet service (as defined in the Online Safety Act 2021) that is likely to be accessed by children or is primarily concerned with children's activities — unless the entity is providing a health service. The OAIC may specify additional APP entities. The Code's commencement date is not yet fixed — the Code will set it.
Enforced by
Source legislation
Topics
Related
- CWLTHNotifiable Data Breach (NDB) schemeUnder the NDB scheme, APP entities must notify the OAIC and affected individuals of an eligible data breach likely to cause serious harm — assessed within 30 days.
- CWLTHAPP 3 collection of sensitive informationAPP 3 bars collecting sensitive information — health, race, religion, sexual orientation and more — without consent. What counts as sensitive, the exceptions and penalties.
- CWLTHAutomated decision-making transparency in your privacy policy (APP 1.7–1.9)From 10 December 2026, APP entities that use computer programs to make or substantially assist decisions that significantly affect individuals must say so in their APP privacy policy.
- CWLTHPrepare for the proposed removal of the small business exemptionRemoving the Privacy Act small business exemption (<$3M turnover) is proposed for a future reform tranche — agreed in principle, not yet law.
- CWLTHComply with credit reporting obligations (Part IIIA Privacy Act)Credit providers and CRBs must adhere to the CR Code on collection, use, disclosure, hardship and dispute resolution.
- CWLTHAPP 8 cross-border disclosureBefore disclosing personal information overseas, APP 8 requires reasonable steps so the recipient meets the APPs — unless an exception applies. Steps and exceptions.
Reading
Frequently asked questions
- Who must comply with Children's Online Privacy Code 2026?
- APP entities providing social media, relevant electronic or designated internet services likely to be accessed by children (not health service providers).
- What triggers Children's Online Privacy Code 2026?
- Online service availability to children.
- When is Children's Online Privacy Code 2026 due?
- Code to be registered by 10 December 2026; obligations apply from the commencement date the Code sets (not yet fixed).
- What evidence is required for Children's Online Privacy Code 2026?
- Age verification + default privacy + parental consent records.
Source: https://www.oaic.gov.au/privacy/privacy-registers/privacy-codes/childrens-online-privacy-code. Rules Mate is not a law firm. Always verify against the live regulator source before acting.