Australia's Children's Online Privacy Code must be registered by 10 December 2026, and a breach falls under a Privacy Act that now carries fines up to $50 million. The scope reaches any service children can access, not just apps built for kids.
The Take: Australia is about to make "we did not know children used our service" an expensive thing to say. The Children's Online Privacy Code must be registered by 10 December 2026, and a breach falls under the same Privacy Act that now carries fines of up to $50 million. If under-18s can reach your site, this is your problem, not just a big platform's.
The rule: The OAIC has released the draft Children's Online Privacy Code, which must be registered no later than 10 December 2026. It sets requirements on age assurance, data collection and default privacy settings for any online service likely to be accessed by children, assessed service by service rather than by who you think your audience is. Age assurance in particular means a service can no longer treat age as something a user simply ticks a box to confirm.
The fine print: The scope runs wider than apps built for kids. Analysis from law firm Bird & Bird notes the code reaches services primarily concerned with children's activities, from school management systems to internet-connected baby monitors. Once registered, a breach becomes an interference with privacy, which for a company can cost the greater of $50 million, three times the benefit gained or 30% of adjusted turnover.
The date Australia's Children's Online Privacy Code must be registered, after which a breach is a Privacy Act interference
Follow the money: Read the direction of travel. The same reform package already forces social media platforms to keep under-16s off their services or wear penalties near A$49.5 million. Regulators have shifted from protecting the platform to protecting the child. The cost of missing that shift is now written in eight figures.
For Australian operators: Work out honestly whether children can reach your service, because "not intended for kids" is not the test the code applies. Audit what you collect from anyone who might be under 18 and cut anything you cannot defend. Check your age assurance and default settings before December, not after a complaint lands. If a campaign could pull in a teenage audience, make consent and data minimisation the first requirement, not a legal footnote.