Canadian Privacy
Featured

Children's Privacy Protection in Canada: PIPEDA Rules for Collecting Minor's Data

Children's privacy in Canada: consent for minors under PIPEDA and provincial law, age verification, and what apps and schools must get right.

Canada Compliance AI• Compliance Team
March 3, 2026
Updated September 12, 2026
12 min read
Children Privacy
PIPEDA
Minor Consent
Age Verification

Collecting children's personal information in Canada requires heightened privacy protections. Unlike the US with COPPA, Canada doesn't have a standalone children's privacy law—but PIPEDA and provincial laws impose strict requirements that many businesses overlook.

Canadian Legal Framework for Children's Privacy

PIPEDA's Approach to Minors

PIPEDA doesn't set a specific age threshold for consent. Instead, it uses a "meaningful consent" standard that considers the child's capacity to understand:

  • Under 13: Parent or guardian consent required in virtually all circumstances
  • 13-17: Depends on the sensitivity of data and the minor's understanding
  • 18+: Full independent consent

The Office of the Privacy Commissioner (OPC) has stated that children constitute a "vulnerable population" deserving enhanced protections.

Provincial Variations

ProvinceAge of Consent for DataSpecial Provisions
Quebec (Law 25)14 (civil majority for data)Parental consent under 14; PIA required for children's data
Alberta (PIPA)No fixed ageReasonableness standard
BC (PIPA)No fixed ageReasonableness standard

When Do You Need Parental Consent?

Always Required (Under 13)

  • Account creation on websites or apps
  • Newsletter or marketing subscriptions
  • Social media account registration
  • Collection of photos, videos, or voice recordings
  • Location tracking
  • Behavioral advertising or profiling

Contextual (Ages 13-17)

  • Sensitive personal information (health, financial)
  • Data sharing with third parties
  • Cross-border data transfers
  • Automated decision-making
  • Biometric data collection

Generally Not Required (Ages 13-17)

  • Basic account registration with minimal data
  • Age-appropriate educational content access
  • Parental notification still recommended

Age Verification Requirements

OPC Guidance on Age Verification

The Privacy Commissioner recommends a risk-based approach:

Low-Risk Services:

  • Self-declaration (age gate) may suffice
  • "I am 13 or older" checkbox
  • Date of birth entry

Medium-Risk Services:

  • Credit card verification
  • Email verification through parent
  • Knowledge-based verification

High-Risk Services (Sensitive Data):

  • Government ID verification
  • Parent/guardian identity verification
  • Third-party age verification services

Best Practices for Age Gates

  1. Don't use "What year were you born?" (easily bypassed)
  2. Use neutral date entry without hints
  3. Don't allow repeated attempts with different dates
  4. Log failed attempts (but don't store the child's data)
  5. Implement technical measures, not just honor systems

Privacy Impact Assessments for Children's Data

When a PIA Is Mandatory

Under Quebec Law 25, PIAs are mandatory for:

  • Any new service targeting users under 18
  • Changes to how children's data is collected or used
  • Third-party sharing of children's data
  • Cross-border transfers of children's data

PIA Considerations for Children's Services

  1. Necessity test: Is each data point truly necessary?
  2. Sensitivity assessment: Children's data is inherently more sensitive
  3. Third-party risk: Vendors must also comply with children's privacy standards
  4. Retention limits: Shorter retention periods for children's data
  5. Deletion mechanisms: Easy-to-use data deletion for parents

Sector-Specific Requirements

EdTech and Schools

  • School boards are data controllers; EdTech companies are processors
  • Data Processing Agreements required
  • No advertising based on student data
  • Student data cannot be used for purposes beyond education
  • Parents must be informed of all EdTech tools used

Gaming and Apps

  • In-app purchases require verifiable parental consent
  • Push notifications to minors require parental opt-in
  • Chat features must be monitored or restricted
  • No behavioral advertising to under-13 users
  • Age-appropriate content filtering required

Social Media Platforms

  • Quebec requires age verification for platforms
  • No profiling of minors for advertising purposes
  • Default privacy settings must be maximum for minor accounts
  • Reporting mechanisms for inappropriate content
  • Easy account deletion process

E-Commerce

  • No marketing to children under 13 without parental consent
  • Quebec Consumer Protection Act prohibits advertising to under-13
  • Payment processing requires adult authorization
  • Wishlist and profile features need parental controls

Bill C-27 and the Future of Children's Privacy

Bill C-27 died on the Order Paper when Parliament was prorogued in January 2025; none of its proposals became law, and PIPEDA remains in force. Federal privacy reform was re-introduced as Bill C-36 on June 15, 2026 and is currently at second reading. Its content could change before passage, and it is not yet law (LEGISinfo).


Compliance Checklist for Businesses

Before Collecting Children's Data

  • Determine if your service targets or is likely to be used by minors
  • Implement age verification appropriate to your risk level
  • Create a child-specific privacy notice in plain language
  • Design parental consent mechanisms
  • Conduct a Privacy Impact Assessment

Data Collection Practices

  • Minimize data collection to what's strictly necessary
  • Do not collect sensitive data from minors without parental consent
  • Disable behavioral advertising for minor accounts
  • Set maximum privacy defaults for minor accounts
  • Implement data retention limits (shorter than adult data)

Parental Controls

  • Allow parents to review data collected about their child
  • Enable parents to delete their child's data
  • Provide parental dashboard for managing child's account
  • Send regular privacy summaries to parents
  • Allow parents to revoke consent at any time

Technical Safeguards

  • Encrypt all children's data at rest and in transit
  • Restrict employee access to children's data
  • Separate children's data from adult data in databases
  • Implement enhanced security for children's data stores
  • Regular security audits focused on children's data

Penalties for Children's Privacy Violations

Current Penalties

  • PIPEDA: Offences up to $100,000 (via prosecution; the OPC cannot fine directly)
  • Quebec Law 25: Up to $25,000,000 or 4% global revenue

Aggravating Factors for Children's Privacy

  • Penalties are significantly higher when children are involved
  • Reputational damage is amplified for children's privacy breaches
  • Class action litigation risk is elevated
  • Regulatory scrutiny is more intense

Frequently Asked Questions

Q: Does PIPEDA have a specific "children's privacy" section like COPPA? No. PIPEDA applies the same principles universally but requires "meaningful consent," which means parental consent for young children.

Q: At what age can a child consent to their own data collection in Canada? There's no fixed federal age. The OPC uses 13 as a general guideline, but it depends on the child's maturity and the sensitivity of the data.

Q: Do I need separate privacy policies for children? Best practice is yes—a child-friendly privacy notice written in plain, age-appropriate language.

Q: Can I use children's data for advertising? Generally no for under-13. In Quebec, commercial advertising to children under 13 is prohibited under the Consumer Protection Act.


Canada Compliance AI helps Canadian SMEs work through CASL, PIPEDA and Quebec Law 25: a free two-minute compliance check, readiness scores, a prioritized task plan, a 24-month breach register and an exportable audit log. See what's live and what's planned.

Related Articles:

Found this article helpful?

Share it with your team or save it for later reference.

Related compliance guides

Explore step-by-step guidance for PIPEDA, CASL, and Quebec Law 25.