Photo by Markus Winkler from Pexels
You signed up for a new project-management tool, an AI writing assistant, or an ed-tech platform your team wants to pilot. Somewhere in the privacy policy there is a section about children's data, and it either says too little or promises too much. If your SaaS product touches users under 13 (or under 16 in the EU), the legal stakes jump dramatically. Understanding the warning signs now saves you from compliance headaches, reputational damage, and potential fines later.
TL;DR
- Children's data collection is governed by strict laws like COPPA and GDPR, and SaaS providers that ignore them put you at risk too.
- Vague age-gating language, blanket consent clauses, and missing data-retention limits are the biggest red flags in a privacy policy.
- Third-party SDKs and ad networks embedded in a SaaS tool can collect children's data without the provider even realizing it.
- A quick checklist and Terms Doctor's 101 automated checks can surface these issues in seconds instead of hours.
- Automated checks are helpful but are not legal advice, consult a qualified attorney for binding compliance decisions.
Why children's data collection matters for SaaS buyers
When you evaluate a SaaS tool, you probably check pricing, uptime SLAs, and integrations. Children's data protection rarely makes the shortlist, until something goes wrong. In the United States, the Children's Online Privacy Protection Act (COPPA) applies to any online service that is "directed to children" or that has "actual knowledge" it collects personal information from children under 13. In the EU, the General Data Protection Regulation (GDPR) sets the bar at 16 (or as low as 13, depending on the member state) and demands verifiable parental consent.
Here is the part many SaaS buyers miss: liability can extend to you as the customer. If you deploy an ed-tech tool in a school district, or if your marketing platform lets minors create accounts, regulators may look at the entire data-processing chain, not just the vendor. A privacy policy that glosses over children's data is therefore your problem, not just the vendor's.
Key takeaway: A SaaS vendor's failure to address children's data properly is a risk you inherit the moment you integrate their product.
The top red flags in a privacy policy
Not every warning sign is obvious. Below are the specific phrases and omissions that should make you pause before signing a contract or clicking "I agree."
1. No mention of children at all
If a SaaS product could reasonably be used by minors, think collaboration tools used in schools, creative platforms, or social features, and the privacy policy contains zero references to children, COPPA, or age restrictions, that is the single biggest red flag. Silence is not compliance.
2. Vague age-gating language
Watch for phrases like "this service is not intended for children" with no follow-up mechanism. A compliant policy explains how the service prevents or detects underage sign-ups (age gates, date-of-birth checks, teacher-managed accounts, etc.). A single disclaimer sentence without enforcement is legally fragile.
3. Blanket consent for data sharing with third parties
A policy that says "we may share information with our partners for business purposes" without carving out children's data is a problem. Under COPPA, operators must obtain verifiable parental consent before sharing a child's personal information with third parties, and the policy must name the categories of third parties involved.
"The notice must describe not only your practices, but also the practices of any others collecting personal information on your site or service, for example, plug-ins or ad networks.">, Children's Online Privacy Protection Rule: A Six
4. No data-retention or deletion policy for minors
COPPA requires that children's data be retained only as long as necessary to fulfill the purpose for which it was collected. If the privacy policy sets no retention period, or worse, claims the right to keep data "indefinitely", that is a clear violation signal.
5. Behavioral advertising or AI training on user content without age exceptions
Many modern SaaS tools feed user-generated content into machine-learning models. If the policy permits AI training or behavioral advertising on all user data without explicitly excluding children's data, the vendor is likely non-compliant with both COPPA and GDPR.
6. Missing parental-rights section
A compliant policy must tell parents how to review, delete, or refuse further collection of their child's data. If you cannot find this section, the vendor has not done the work.
How to audit a SaaS privacy policy for children's data risks
Follow these steps every time you evaluate a new tool that might be accessed by users under 13 (or under 16 in the EU).
- Locate the privacy policy. It should be linked from the footer of every page. If it is buried or missing, that alone is a warning sign.
- Search for children-specific keywords. Use Ctrl+F for "child," "COPPA," "parental consent," "under 13," "minor," and "age."
- Check for a dedicated children's section. A mature privacy policy has a clearly labeled heading, for example, "Children's Privacy" or "Information About Children."
- Verify the consent mechanism. The policy should describe how parental consent is obtained (email-plus, signed form, credit-card verification, etc.). A vague "we may collect consent" is not enough.
- Review third-party disclosures. Identify every category of third party that receives data. Confirm that children's data is either excluded or that parental consent covers the sharing.
- Look for retention and deletion details. There should be a stated retention period and a clear process for parents to request deletion.
- Run Terms Doctor's automated scan. Install the free extension, navigate to the SaaS vendor's site, and let Terms Doctor find the ToS and privacy policy automatically. Its 101 consumer-protection checks include flags for missing children's data provisions, forced arbitration, AI training clauses, and more. You will get an A-F grade plus plain-language explanations of every issue found.
Your children's data privacy checklist
Children's Data Privacy Policy Audit
Your progress is saved automatically in your browser.
Real-world scenarios that catch SaaS buyers off guard
Scenario A, The school pilot. A district IT director signs up for a free tier of a collaboration tool. Teachers invite students. The tool's privacy policy says "not intended for children under 13" but has no age gate. Six months later, a parent files a COPPA complaint. The FTC investigates both the vendor and the district.
Scenario B, The embedded SDK. A SaaS analytics dashboard embeds a third-party tracking pixel that collects device identifiers from all visitors, including minors on a family-shared device. The SaaS vendor's privacy policy never mentions this SDK. Under COPPA, the vendor is still responsible for what third-party code does on its service.
Scenario C, The AI training clause. An AI writing tool states that "all user-generated content may be used to improve our models." A homeschooling parent uses the tool with their 10-year-old. The child's essays, including personal details, are now training data, with no parental consent ever obtained.
These are not hypothetical edge cases. They reflect patterns the FTC and EU data-protection authorities have already pursued in enforcement actions.
What good compliance looks like
A well-drafted children's data section in a SaaS privacy policy will typically include:
- A clear age threshold with a reference to the applicable law (COPPA, GDPR Article 8, or both).
- A description of the consent flow, such as "We send a consent form to the parent's email address and do not activate the child's account until the signed form is returned."
- A limited list of data points collected, often restricted to a username, age range, and content created within the app.
- An explicit opt-out from advertising and AI training for accounts identified as belonging to minors.
- A retention schedule, for example: "We delete children's data within 30 days of account closure or parental request."
- A direct contact method (email, form, or phone number) for parents to exercise their rights.
FAQ
Frequently Asked Questions
Let Terms Doctor do the heavy lifting
Reading a 5,000-word privacy policy line by line is nobody's idea of a good time, especially when you are evaluating multiple vendors in a single quarter. The free Terms Doctor browser extension (available for Chrome, Edge, Brave, Opera, and Vivaldi) automatically finds the privacy policy and terms of service on any site you visit, runs 101 consumer-protection checks, and gives you an instant A-F grade. Children's data provisions, forced arbitration, auto-renewal traps, AI training clauses, it flags them all in plain language so you can make informed decisions fast. Install it from the Terms Doctor homepage and start your next vendor review with confidence. Just remember: automated checks are a effective first step, not a substitute for qualified legal advice.
Additional Resources
- SaaS Privacy Policy Template - To stay compliant with laws like the Children's Online Privacy Protection Act (COPPA), your Privacy Policy should state that your products and ...
- Children's Online Privacy Protection Rule: A Six-Step ... - Your privacy policy must tell parents that the parent can review or delete the child's personal information and refuse to permit further collection or use of ...
- Privacy Policy for a SaaS Business - In the unlikely event that a child registers on your mobile app or website, you may be held liable under the Children's Online Privacy ...
