Privacy in Practice
Children’s Privacy and Age Assurance Across Borders
August 11, 2026
Children’s privacy requires more than applying adult privacy rules to younger users. Age thresholds vary across jurisdictions, children may lack the legal capacity to consent to certain processing, and the methods used to identify young users can introduce additional privacy, security, and compliance risks. Addressing these challenges successfully requires coordinated decisions across legal, compliance, product and design, engineering, and trust and safety teams. Hailun Ying, Head of Privacy and Security, Legal at Roblox, joins Kellie du Preez and Danie Strachan to discuss the global patchwork of children’s privacy laws, the practical challenges of age assurance, and why privacy-protective defaults need to be built into products from the beginning. Hailun also discusses why children’s privacy must be treated as a cross-functional responsibility rather than solely as a legal or compliance matter.

Children’s privacy requires more than adapting privacy rules for younger users. Children may not fully understand the consequences of sharing personal information, may lack the legal capacity to consent to certain processing, and can be more susceptible to persuasive design features. At the same time, the age at which someone is legally treated as a child varies across jurisdictions and processing activities. 

Hailun Ying, Head of Privacy and Security, Legal at Roblox, joins Kellie du Preez and Danie Strachan to examine this fragmented legal landscape. The conversation covers COPPA in the U.S., the EU and the UK GDPR, age-appropriate design codes, Brazil’s LGPD and ECA Digital, and South Korea’s PIPA.

They also explore the practical challenges of age assurance, including age verification, age estimation, and self-declaration. Technologies involving government-issued identification, facial age estimation, liveness checks, and other methods may help businesses assess users’ ages, but they can also create risks involving biometrics, vendor security, data retention, demographic bias, and user trust.

Hailun closes with three practical priorities for businesses: understand the user base, make privacy-protective settings the default for young users, and treat children’s privacy as a shared cross-functional responsibility.

What This Episode Covers:

Hailun Ying is the Head of Privacy and Security, Legal at Roblox, where she leads the team responsible for privacy and cybersecurity legal matters across one of the world’s largest online platforms for user-generated content. Her career has focused on data privacy, including previous work at PayPal involving mergers and acquisitions, product development, and security incidents.

Connect with Hailun Ying here: LinkedIn
Connect with Kellie du Preez here: LinkedIn
Connect with Danie Strachan here: LinkedIn
Follow VeraSafe here: LinkedIn
If you enjoyed this episode, make sure to subscribe, rate, and review it.


Episode Highlights:

The traditional notice-and-consent model assumes that users can understand a privacy notice, assess the consequences of sharing information, and make an informed decision. Children may not have that same capacity and can be more vulnerable to persuasive design patterns and harms that may follow them into adulthood. Modern children’s privacy laws are therefore introducing protections that go beyond transparency and consent.

There is no consistent global definition of a child. The relevant threshold may be 12, 13, 14, 16, or 18 depending on the country, state, legal framework, and processing activity involved. Businesses need to understand where their users are located and which requirements apply rather than relying on a single global age cutoff.

Age assurance is an umbrella term covering several ways of determining whether a user falls above or below an age threshold. Verification may involve government identification or payment instruments, while estimation can use facial features, behavioral signals, or emerging hand-scanning technology. Self-declaration asks users to provide their age directly, but each method comes with different levels of accuracy, friction, and privacy risk.

COPPA may restrict a business from collecting personal information from a child without parental consent. However, determining whether someone is a child can itself require collecting a selfie, an identification document, or date of birth. Hailun explains the FTC’s enforcement approach discussed in the episode and the conditions businesses need to consider when collecting information solely for age-assurance purposes.

An age-assurance tool may implicate laws beyond children’s privacy law. Businesses may also need to consider biometric privacy requirements, vendor security, retention practices, breach response, model accuracy, and demographic bias. A solution intended to reduce one privacy risk can create another if the technology or vendor is not properly assessed.

Hailun recommends starting with the information the business already has. Organizations should understand where their users are located, the likely demographics of the user base, and the quality of their age data. Privacy-protective settings should be the default for young users, and responsibility should be shared across legal, product and design, engineering, trust and safety, policy, and compliance teams.


Episode Resources:


Privacy in Practice is handcrafted by our friends over at: fame.so.

Connect with us at podcast@verasafe.com

This podcast is brought to you by VeraSafe.