Photo by Markus Winkler from Pexels

You signed up for a new project-management tool, an AI writing assistant, or an ed-tech platform your team wants to pilot. Somewhere in the privacy policy there is a section about children's data, and it either says too little or promises too much. If your SaaS product touches users under 13 (or under 16 in the EU), the legal stakes jump dramatically. Understanding the warning signs now saves you from compliance headaches, reputational damage, and potential fines later.

TL;DR

  • Children's data collection is governed by strict laws like COPPA and GDPR, and SaaS providers that ignore them put you at risk too.
  • Vague age-gating language, blanket consent clauses, and missing data-retention limits are the biggest red flags in a privacy policy.
  • Third-party SDKs and ad networks embedded in a SaaS tool can collect children's data without the provider even realizing it.
  • A quick checklist and Terms Doctor's 101 automated checks can surface these issues in seconds instead of hours.
  • Automated checks are helpful but are not legal advice, consult a qualified attorney for binding compliance decisions.
0
Consumer-protection checks in Terms Doctor

Why children's data collection matters for SaaS buyers

person reading legal document laptop
Photo by Mikhail Nilov from Pexels

When you evaluate a SaaS tool, you probably check pricing, uptime SLAs, and integrations. Children's data protection rarely makes the shortlist, until something goes wrong. In the United States, the Children's Online Privacy Protection Act (COPPA) applies to any online service that is "directed to children" or that has "actual knowledge" it collects personal information from children under 13. In the EU, the General Data Protection Regulation (GDPR) sets the bar at 16 (or as low as 13, depending on the member state) and demands verifiable parental consent.

Here is the part many SaaS buyers miss: liability can extend to you as the customer. If you deploy an ed-tech tool in a school district, or if your marketing platform lets minors create accounts, regulators may look at the entire data-processing chain, not just the vendor. A privacy policy that glosses over children's data is therefore your problem, not just the vendor's.

SaaS privacy policies that lack a dedicated children's data section
0%

Key takeaway: A SaaS vendor's failure to address children's data properly is a risk you inherit the moment you integrate their product.

The top red flags in a privacy policy

lawyer reviewing contract
Photo by https://kaboompics.com/ from Pexels

Not every warning sign is obvious. Below are the specific phrases and omissions that should make you pause before signing a contract or clicking "I agree."

1. No mention of children at all

If a SaaS product could reasonably be used by minors, think collaboration tools used in schools, creative platforms, or social features, and the privacy policy contains zero references to children, COPPA, or age restrictions, that is the single biggest red flag. Silence is not compliance.

2. Vague age-gating language

Watch for phrases like "this service is not intended for children" with no follow-up mechanism. A compliant policy explains how the service prevents or detects underage sign-ups (age gates, date-of-birth checks, teacher-managed accounts, etc.). A single disclaimer sentence without enforcement is legally fragile.

3. Blanket consent for data sharing with third parties

A policy that says "we may share information with our partners for business purposes" without carving out children's data is a problem. Under COPPA, operators must obtain verifiable parental consent before sharing a child's personal information with third parties, and the policy must name the categories of third parties involved.

"The notice must describe not only your practices, but also the practices of any others collecting personal information on your site or service, for example, plug-ins or ad networks."
>, Children's Online Privacy Protection Rule: A Six

4. No data-retention or deletion policy for minors

COPPA requires that children's data be retained only as long as necessary to fulfill the purpose for which it was collected. If the privacy policy sets no retention period, or worse, claims the right to keep data "indefinitely", that is a clear violation signal.

5. Behavioral advertising or AI training on user content without age exceptions

Many modern SaaS tools feed user-generated content into machine-learning models. If the policy permits AI training or behavioral advertising on all user data without explicitly excluding children's data, the vendor is likely non-compliant with both COPPA and GDPR.

6. Missing parental-rights section

A compliant policy must tell parents how to review, delete, or refuse further collection of their child's data. If you cannot find this section, the vendor has not done the work.

Quick test: Search the privacy policy for the words "child," "children," "minor," "COPPA," "parental," and "under 13." If none appear and the product could be used by minors, treat that as a critical gap.

How to audit a SaaS privacy policy for children's data risks

Privacy policy warning signs: children's data collection for SaaS users process
Figure 1: Privacy policy warning signs: children's data collection for SaaS users at a glance.

Follow these steps every time you evaluate a new tool that might be accessed by users under 13 (or under 16 in the EU).

  1. Locate the privacy policy. It should be linked from the footer of every page. If it is buried or missing, that alone is a warning sign.
  2. Search for children-specific keywords. Use Ctrl+F for "child," "COPPA," "parental consent," "under 13," "minor," and "age."
  3. Check for a dedicated children's section. A mature privacy policy has a clearly labeled heading, for example, "Children's Privacy" or "Information About Children."
  4. Verify the consent mechanism. The policy should describe how parental consent is obtained (email-plus, signed form, credit-card verification, etc.). A vague "we may collect consent" is not enough.
  5. Review third-party disclosures. Identify every category of third party that receives data. Confirm that children's data is either excluded or that parental consent covers the sharing.
  6. Look for retention and deletion details. There should be a stated retention period and a clear process for parents to request deletion.
  7. Run Terms Doctor's automated scan. Install the free extension, navigate to the SaaS vendor's site, and let Terms Doctor find the ToS and privacy policy automatically. Its 101 consumer-protection checks include flags for missing children's data provisions, forced arbitration, AI training clauses, and more. You will get an A-F grade plus plain-language explanations of every issue found.

Your children's data privacy checklist

Children's Data Privacy Policy Audit

Your progress is saved automatically in your browser.

Real-world scenarios that catch SaaS buyers off guard

consumer reading fine print
Photo by Kampus Production from Pexels

Scenario A, The school pilot. A district IT director signs up for a free tier of a collaboration tool. Teachers invite students. The tool's privacy policy says "not intended for children under 13" but has no age gate. Six months later, a parent files a COPPA complaint. The FTC investigates both the vendor and the district.

Scenario B, The embedded SDK. A SaaS analytics dashboard embeds a third-party tracking pixel that collects device identifiers from all visitors, including minors on a family-shared device. The SaaS vendor's privacy policy never mentions this SDK. Under COPPA, the vendor is still responsible for what third-party code does on its service.

Scenario C, The AI training clause. An AI writing tool states that "all user-generated content may be used to improve our models." A homeschooling parent uses the tool with their 10-year-old. The child's essays, including personal details, are now training data, with no parental consent ever obtained.

These are not hypothetical edge cases. They reflect patterns the FTC and EU data-protection authorities have already pursued in enforcement actions.

What good compliance looks like

A well-drafted children's data section in a SaaS privacy policy will typically include:

  • A clear age threshold with a reference to the applicable law (COPPA, GDPR Article 8, or both).
  • A description of the consent flow, such as "We send a consent form to the parent's email address and do not activate the child's account until the signed form is returned."
  • A limited list of data points collected, often restricted to a username, age range, and content created within the app.
  • An explicit opt-out from advertising and AI training for accounts identified as belonging to minors.
  • A retention schedule, for example: "We delete children's data within 30 days of account closure or parental request."
  • A direct contact method (email, form, or phone number) for parents to exercise their rights.
When you see all of these elements, you can be more confident, though not certain, that the vendor takes children's privacy seriously. Always cross-reference with your own legal counsel for high-stakes deployments.

FAQ

Frequently Asked Questions

Yes, it can. COPPA applies not only to services "directed to children" but also to general-audience services that have "actual knowledge" they are collecting data from users under 13. If your tool allows open registration and a child signs up, you may still be on the hook. The FTC looks at factors like the subject matter, visual content, and whether the service uses animated characters or child-oriented language.
No. A terms-of-use clause that says "you must be 18 to use this service" does not satisfy COPPA or GDPR requirements on its own. Regulators expect active measures, age gates, parental consent mechanisms, and a privacy policy that specifically addresses what happens if a child's data is collected despite the restriction. A passive disclaimer is not a compliance strategy.
Terms Doctor automatically locates the terms of service and privacy policy on any website you visit. It runs 101 consumer-protection checks, including checks for missing children's data provisions, vague age-gating language, and third-party data-sharing without proper disclosures. You get an A-F grade and a plain-language summary of every flagged issue, so you can evaluate a vendor in seconds rather than spending an hour reading legal text. Remember that automated checks are informational and are not legal advice.
First, contact the vendor directly and ask how they handle data from users under 13 (or under 16 in the EU). Document their response. If the answer is unsatisfactory or vague, consider it a material compliance gap. For high-risk deployments, especially in education or healthcare, escalate to your legal team before proceeding. You can also use Terms Doctor's change-tracking feature to monitor whether the vendor updates their policy after your inquiry.
Yes. COPPA (US) sets the age threshold at under 13 and requires verifiable parental consent before collecting, using, or disclosing a child's personal information. The GDPR (EU) sets a default threshold of under 16 for consent to data processing, though individual member states can lower it to 13. The GDPR also imposes broader obligations around data minimization, purpose limitation, and the right to erasure that apply to all data subjects, including children. If your SaaS tool serves users in both regions, the privacy policy must address both frameworks.

Let Terms Doctor do the heavy lifting

Reading a 5,000-word privacy policy line by line is nobody's idea of a good time, especially when you are evaluating multiple vendors in a single quarter. The free Terms Doctor browser extension (available for Chrome, Edge, Brave, Opera, and Vivaldi) automatically finds the privacy policy and terms of service on any site you visit, runs 101 consumer-protection checks, and gives you an instant A-F grade. Children's data provisions, forced arbitration, auto-renewal traps, AI training clauses, it flags them all in plain language so you can make informed decisions fast. Install it from the Terms Doctor homepage and start your next vendor review with confidence. Just remember: automated checks are a effective first step, not a substitute for qualified legal advice.

Additional Resources