Who must comply with Children's Online Privacy Code 2026?
The applicability test for Children's Online Privacy Code 2026 (OAIC), computed across 35 industries, 9 business structures and 6 size bands.
Short answer: Only if
Applies when the business has APP-entity status (turnover > $3M or a s 6D(4) carve-out) and an online service likely to be accessed by children and not a health service. Where the business has APP-entity status (turnover > $3M or a s 6D(4) carve-out) and not a health service and children's data or an approved childcare service or a school, check whether you provide an app, website, game or other online service likely to be accessed by children.
What the obligation is
OAIC developing a mandatory children's online privacy code — must be registered by 10 December 2026 (commencement not yet fixed).
Privacy and Other Legislation Amendment Act 2024 requires the OAIC to develop a binding Code addressing children's privacy online and register it by 10 December 2026. Consultation ran in three phases from January 2025 to June 2026. Per the OAIC, the Code binds APP entities that provide a social media service, a relevant electronic service or a designated internet service (as defined in the Online Safety Act 2021) that is likely to be accessed by children or is primarily concerned with children's activities — unless the entity is providing a health service. The OAIC may specify additional APP entities. The Code's commencement date is not yet fixed — the Code will set it.
The applicability test
Applies when the business has APP-entity status (turnover > $3M or a s 6D(4) carve-out) and an online service likely to be accessed by children and not a health service. Where the business has APP-entity status (turnover > $3M or a s 6D(4) carve-out) and not a health service and children's data or an approved childcare service or a school, check whether you provide an app, website, game or other online service likely to be accessed by children.
How the regulator frames it: APP entities providing social media, relevant electronic or designated internet services likely to be accessed by children (not health service providers).
What triggers it: Online service availability to children.
Jurisdiction: Commonwealth law, so the test is the same in every state and territory.
Which industries are in or out
Outcome across the 35 industries Rules Mate maps (35 of 35: no).
The answer is the same in every industry: no. Industry does not change who must comply.
Business structure and size
Structure does not change the answer across all industries: for every structure the answer is "no".
Size does not change the answer across all industries: at every size band the answer is "no".
Worked examples
Each line is one run of the Rules Mate applicability engine for a single business profile, with the reason the engine gives:
- Pty Ltd company in real estate agents with 6–19 employees, turnover $1M–$3M: does not apply. Requires APP-entity status (turnover > $3M or a s 6D(4) carve-out) and an online service likely to be accessed by children and not a health service.
Answers that bring it into scope
Starting from a small or large professional services company that does not otherwise meet the test, each of these single facts changes the engine's answer:
- The business holds children's personal information: it becomes worth checking, because it applies only if you provide an app, website, game or other online service likely to be accessed by children.
When you need to check further
The engine shows this obligation as "check whether this applies" when a business has APP-entity status (turnover > $3M or a s 6D(4) carve-out) and not a health service and children's data or an approved childcare service or a school. It then applies only if you provide an app, website, game or other online service likely to be accessed by children. That fact is not something Rules Mate can infer from industry, structure or size.
What you must do, and when
- When due
- Code to be registered by 10 December 2026; obligations apply from the commencement date the Code sets (not yet fixed).
- Frequency
- Ongoing
- Evidence to keep
- Age verification + default privacy + parental consent records.
- In force from
- 10 December 2026
- Status
- Upcoming (not yet in force)
- Priority
- High
Penalty for not complying
No maximum penalty is recorded for this obligation in the Rules Mate corpus; check the regulator source below.
Audit or assurance level
Rules Mate has not yet classified the audit or assurance level for this obligation. Any audit, review or certification requirement is set by the regulator source listed below.
Dates in the compliance calendar
Where it sits in the corpus
Rules Mate tracks 20 published obligations tagged "privacy", 3 of them rated critical. For a professional services Pty Ltd company with 6–19 employees operating in every state, 4 of those apply outright. This obligation is rated high priority, and is an ongoing duty.
Regulator, legislation and tools
Regulated by Office of the Australian Information Commissioner.
OAIC: Privacy and freedom of information regulator. Administers the Privacy Act 1988, the Notifiable Data Breaches scheme, and the Australian Privacy Principles.
Privacy Act 1988: Federal privacy Act.
Free tools that help with this obligation:
Questions
- Who must comply with Children's Online Privacy Code 2026?
- Applies when the business has APP-entity status (turnover > $3M or a s 6D(4) carve-out) and an online service likely to be accessed by children and not a health service. Where the business has APP-entity status (turnover > $3M or a s 6D(4) carve-out) and not a health service and children's data or an approved childcare service or a school, check whether you provide an app, website, game or other online service likely to be accessed by children.
- Does Children's Online Privacy Code 2026 apply to sole traders?
- No. Across every industry and every size band, the engine's answer for a sole trader is: no.
- Does Children's Online Privacy Code 2026 apply to businesses with 1–5 employees?
- No (1–5 employees, turnover $100K–$1M).
- When is "Children's Online Privacy Code 2026" due?
- Code to be registered by 10 December 2026; obligations apply from the commencement date the Code sets (not yet fixed).
Related
Sources
Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.