Children in the Digital World
Part one — a profile that begins before the child has learned to speak
This is not a metaphor. It is literally what happens. And it is only the beginning of a process that will go on for the next eighteen years — until the child becomes an adult and discovers that everything about them is already known. Long before they themselves decided to tell anything. Today — about how this works. From the very beginning. Step by step.
Sharenting. A word worth knowing
In English a word has appeared. Sharenting — from share and parenting. The practice of parents publishing photographs and information about their children on social networks. The scale of this phenomenon is hard to imagine. A study conducted in the United Kingdom showed that by their fifth birthday the average child is already present in about 1,500 photographs published online. By adulthood — thousands of photographs, hundreds of mentions, a detailed chronicle of life available publicly or semi-publicly. Parents publish out of love. Out of a desire to share joy with loved ones. Out of a desire to preserve memories. This is absolutely understandable and human. But here is what happens to these photographs at the technical level. Every photograph uploaded to a social network passes through computer-vision systems. The algorithm extracts the geometry of the face. The distance between the eyes. The shape of the nose. The contour of the jaw. This is biometric data. It is saved. It is linked to the profile. The child grows — the parents publish new photos. The algorithm tracks the changes. Builds a model of how the face changes with age. By the time the child becomes a teenager — the face-recognition system already has a multi-year history of their biometrics. They never gave consent. They do not know this is happening. They simply grew up — while someone recorded it. French lawyers already warn that when today’s children grow up — some of them may sue their parents for publishing their childhood photographs without consent. In France the right to one’s image is protected by law. Precedents already exist — so far isolated ones. But the direction is set.
YouTube Kids. Safe — it says on the packaging
When Google launched YouTube Kids in 2015 — the idea was right. A separate platform for children. Content vetted. Advertising limited. Parents can relax. The reality turned out to be different. 2019. The US Federal Trade Commission and the Department of Justice filed a suit against Google. The accusation — the unlawful collection of the data of children under 13 without parental consent. A violation of COPPA — the Children’s Online Privacy Protection Act. Google paid a 170-million-dollar fine. At that time — the largest fine in COPPA history. What specifically was happening. YouTube knew that there was a huge number of children on the platform — including on channels clearly aimed at a children’s audience. Cartoons, toys, children’s songs. Advertisers paid a premium to place advertising precisely on these channels — because a children’s audience is valuable. At the same time the platform officially declared that it did not know users’ ages — and therefore bore no responsibility under COPPA. While simultaneously selling advertisers access to a «children’s audience». This is not an error. It is a deliberate construction that allowed earning on children while avoiding responsibility for it. After the fine Google changed its policy. Channels with children’s content now do not show personalised advertising. Data from such channels is not used for targeting. Formally. But here is what remained. YouTube’s algorithm still tracks what a child watches. For how long. What they stop on. What they rewatch. What they skip. This is behavioural data. It is collected. It is used for recommendations — what to show next. The algorithm shapes tastes, interests, content-consumption habits. This is not advertising. This is something more fundamental — the shaping of a personality through management of the information environment.
Games. Where entertainment ends and data collection begins
Roblox. Minecraft. Among Us. Fortnite. If you have school-age children — these names are familiar to you. These are not just games — they are whole worlds in which children spend hours every day. And each of these worlds collects data. Roblox — a separate matter. The platform has more than 200 million registered users. A significant part — children from 6 to 12. Inside the platform there is a virtual economy with real money — parents buy the virtual currency Robux so that the child can acquire game items. What Roblox collects. Username, date of birth, the parent’s email at registration. Time spent in each game. Social connections — who they are friends with, who they play with, who they message. Purchasing behaviour — what they buy, how often, for what sums. Geolocation — via the IP address, accurate to the city. Device and operating system. But something else is more important. Roblox collects behavioural patterns — how the child reacts to different types of content. What arouses their interest. What arouses frustration. How they make decisions in game situations. How prone they are to social interaction versus solo play. This is a psychographic profile. On a child. From the age of six. Fortnite collects analogous data. A study conducted in 2020 showed that Epic Games — the developer of Fortnite — transferred minors’ data to third parties without parental consent. In 2022 the FTC ordered the company to pay a 275-million-dollar fine. At that time — the largest fine related to a violation of children’s privacy in history. 275 million. For children’s data.
Educational platforms. The most unexpected place for surveillance
The school recommends an app. The teacher says you need to register for homework. The parent helps the child create an account. Everything looks official and safe. This is the most unprotected scenario of all. Because when a platform is recommended by the school — parents do not read the privacy policy. Why? The school checked. The school can be trusted. The school often did not check. The teacher simply found a convenient tool for homework and suggested it to the class. A study conducted by the organisation Human Rights Watch in 2022 analysed 164 educational platforms from 49 countries. The result — 145 of the 164 platforms collected children’s data and transferred it to third parties. Advertising companies. Data brokers. In most cases — without the parents’ knowledge. What exactly is collected on educational platforms. Academic performance — grades, mistakes, time to complete tasks. This tells about the level of intelligence, strengths and weaknesses, learning style. Behavioural patterns — how long the child sits over a task, how many times they try before giving up, how persistent they are, how they react to failure. Social interactions — if the platform has communication features, all messages are recorded and analysed. Emotional reactions — some platforms use analysis of facial expression through the camera to assess the child’s engagement in the lesson. This is biometrics. This is a special category of data under GDPR. This requires explicit consent. No one asks for it. Do you think these are isolated cases? In 2021 an investigation in the Netherlands revealed that a platform used in thousands of schools collected data about children’s performance and transferred it to advertising partners. The Dutch Ministry of Education was forced to issue an official warning and demand that the practice stop.
The algorithm that shapes — does not describe
Here I want to dwell on something important. On what is talked about least. We are used to thinking that algorithms describe us. See who we are — and show us corresponding content. With children something different happens. The algorithm does not describe the child — it shapes them. A child aged between three and twelve is in a period of active formation of personality. Interests, values, worldview, behavioural patterns — all of this takes shape precisely now. And precisely now the algorithm gains maximum access. YouTube recommends the next video. The algorithm knows that this child watches videos about dinosaurs to the end — and shows more about dinosaurs. Then about space. Then about something else. The algorithm does not think about the child’s development. It thinks about time on the platform. It shows what holds — not what develops. Roblox knows that this child reacts to social pressure — and shows them items their friends have. Creates the feeling that without them they are not like everyone else. This is not chance — it is a documented mechanic of engagement. Facebook’s internal studies — made public in 2021 through whistleblower Frances Haugen — showed that the company knew about the special harm of Instagram for teenage girls. The algorithm showed content related to appearance and comparison of oneself with others — because it provoked strong emotions and held people on the platform. The company knew that this correlates with eating disorders and depression in teenagers. And continued. This is not a side effect. It is the result of optimising the algorithm for time on the platform — without regard for what happens to the living child on the other side of the screen.
The profile that waits ahead
Let us return to the child who had their first photo taken on the first day of life. They are now ten years old. Over these ten years the following has accumulated. Thousands of photographs on social networks — a biometric profile of the face from infancy. Years of activity on YouTube — a detailed map of interests, attention, behavioural patterns. History in educational apps — an academic profile, strengths and weaknesses, learning style. History in games — a psychographic profile, social patterns, attitude to risk and competition. Geolocation data — where they live, where they study, where they spend time. All of this exists. Is stored. Is sold. In eight years this child submits an application to university. The scoring algorithm looks at the digital profile. In ten years they get a job. The HR system analyses public data. In fifteen years they apply for a mortgage. The financial algorithm assesses the risks. The profile that began to form on the first day of life — meets them as an adult. At the most important moments of life. Without their knowledge. Without their consent. Without the possibility of changing anything. This is not the future. It is already happening to those children who were born in 2010–2015. They are already teenagers. Their profiles already exist. And the first consequences — are already visible.
One figure worth remembering
A study conducted in the US showed that by the age of 13 there are about 72 million data points on the average American child in various databases. 72 million. Not because someone specifically watched a particular child. Simply because they grew up in a digital world. Used apps. Watched videos. Played games. Studied on platforms. 72 million data points. On a thirteen-year-old person. They do not know about it. Their parents do not know about it. But someone knows. And this someone is already making decisions about their future — on the basis of data they never gave consciously. Next time — what specifically happens to this data. How a child’s profile is monetised. What algorithms do to a child’s personality. And what is already documented about the consequences.
Children in the digital world. Part two — what happens to the data. And what it does to children
Last time we talked about how data on children is collected. From birth. Through parents’ photos, games, educational platforms, YouTube Kids. What happens to this data next. And something that is talked about least. Not what corporations do with children’s data — but what algorithms do to the children themselves. Because these are two different stories. And the second — is more serious.
First — money. Because without this the logic is unclear
The children’s audience is one of the most valuable for the advertising market. Not because children themselves spend a lot. But because they form habits that remain for life. Studies show that brand loyalty formed in childhood is preserved for decades. A person who at seven fell in love with a certain brand — with high probability remains its customer at thirty-five. This is not an assumption — it is a documented marketing fact that the industry has long used. That is why access to a children’s audience costs a lot. Very much. The global market for advertising aimed at children is estimated at about 17 billion dollars a year. And is growing. Because children spend more and more time in the digital environment. Because there is more and more data about them. Because the algorithms become ever more precise. Data on children collected through games, platforms, apps — is used to build profiles. These profiles are sold. To advertisers who want to form brand loyalty from an early age. To educational companies that want to know which products to offer which families. To insurance companies that are already thinking now about future clients. This is not theory. In 2022 an investigation in the US showed that data brokers sold lists of children with labels — «overweight child», «child with learning difficulties», «child from a single-parent family». These lists were bought by companies selling diet products, tutoring services, psychological help. Children’s vulnerability — is monetised. Directly and openly.
The engagement algorithm. How the mechanism that keeps children on the platform works
Here begins a conversation that parents should know about — but which rarely sounds in an understandable form. Every large platform — YouTube, TikTok, Instagram, Roblox — optimises its algorithm for one metric. Time on the platform. Engagement. More time on the platform — more advertising — more money. The logic is simple and ironclad. To hold a user longer — you need to act on the mechanisms that govern behaviour. In adults these mechanisms are formed and partly protected by experience and self-control. In children — they are not. The dopamine loop. A like on a post causes a release of dopamine. The algorithm knows this. It shows the child content that provokes a reaction — and immediately offers the next. Without a pause. Without a break. Autoplay. An infinite feed. The mechanic is specially designed so as not to let the brain stop. Former Facebook president Sean Parker publicly admitted in 2017 — they consciously built the platform exploiting a vulnerability of human psychology. His words — «how do we consume as much of your time and attention as possible». And he added — «God only knows what it’s doing to our children’s brains». This was said by the man who built the system. From the inside. Social comparison. Instagram and TikTok show children and teenagers content related to appearance, popularity, success. The algorithm knows that such content provokes strong emotions — envy, admiration, the desire to conform. Strong emotions — more time on the platform. Facebook’s internal studies of 2021 — the very ones that leaked through Frances Haugen — showed that the company knew the following. 32% of teenage girls said that when they feel bad about their bodies — Instagram makes them feel worse. The company knew this. Concealed it from the public. Continued to work the same way. The fear of missing out — FOMO. Notifications are designed so as to create anxiety in their absence. You did not log in yesterday — look what you missed. Friends are online — you are not. This works especially strongly on children because social belonging is existentially important for them. Variable reward. This is the mechanic of slot machines transferred into the digital environment. Sometimes a like comes immediately. Sometimes not. Sometimes a post gets many reactions. Sometimes not. The unpredictability of the reward creates addiction stronger than the predictable. This is neurobiology. Algorithms use it deliberately.
What research says about the consequences
These are not opinions. These are data. A study published in the journal JAMA Pediatrics in 2023. More than 4,000 children were observed over three years starting from the age of nine. The result — children who spent more than three hours a day on social networks showed a significantly higher level of depression, anxiety and behavioural problems by the age of twelve. A study by the American Psychological Association of 2023. Teenagers who regularly use social networks sleep on average an hour less than needed. Chronic sleep deprivation in adolescence correlates with long-term problems of cognitive development. A study in the United Kingdom conducted among 10,000 teenagers. Girls who spent more than five hours a day on social networks reported symptoms of depression four times more often than those who spent less than an hour. Eating disorders among teenagers grew by 30% in the period from 2010 to 2020. 2010 — roughly the moment when smartphones and social networks became a mass phenomenon among teenagers. A direct causal link is not proven. The correlation — is documented. The number of teenagers seeking psychological help for anxiety disorders — has doubled over the last ten years in most developed countries. This is not a coincidence. It is the result of the environment we created.
TikTok. A separate matter
TikTok deserves separate attention — because its algorithm works differently from its competitors. And because its influence on children is documented especially well. TikTok’s algorithm is not based on social connections. It does not need you to subscribe to anyone. It looks only at behaviour — how long you watch a video, whether you watch it to the end, whether you rewatch it, what you do afterwards. And on this basis — after a very short time — it builds an extremely precise profile of what holds you in particular. An experiment conducted by Wall Street Journal journalists in 2021. They created accounts imitating teenagers with signs of depression — subscribed to sad content, watched videos about loneliness and hopelessness to the end. The algorithm reacted quickly. Within a few hours the feed filled with content about depression, suicidal thoughts, self-harm. The algorithm did not want to harm the teenager. It simply saw that such content held this user longer — and showed more. The logic of optimisation without ethics. In 2023 TikTok was fined in the United Kingdom 12.7 million pounds for the unlawful processing of the data of children under 13. It emerged that the platform knew about the presence of children below the permitted age — and took no real measures. It knew. And took none.
Education that surveils. The quietest scandal
We talked about this in the first post — but here it needs to be gone into more deeply. Platforms used in schools collect data that no other category of app collects. Because the educational context gives access to information a person reveals nowhere else. Academic difficulties. If a child makes mistakes time after time in tasks on a certain topic — the platform sees this. This is data about cognitive characteristics. About potential learning disorders — dyslexia, dyscalculia. This information should never leave the educational context. But it does. Emotional state. A number of platforms use analysis of text answers to assess the pupil’s emotional state. If a child writes short, angry answers — the system records this. If they sit over a task for a long time at night — this is also data. Social dynamics. Platforms with group-learning features see who interacts with whom, who is the leader, who is isolated. This is sociometry — the science of relationships within a group. Applied to children. Without their knowledge. A study conducted in the US in 2020 analysed 152 educational apps recommended by schools. 96% of them transferred data to third parties. A third transferred data to advertising companies. Half did not have a privacy policy meeting the requirements of the law. 96 percent. Of apps recommended by schools.
The profile that forms — and what it means for the future
Let us gather everything together and look at the whole picture. A child is born. Appears on social networks through the parents’ photos — a biometric profile. Begins to watch YouTube Kids — a behavioural and interest profile. Goes to school, uses educational platforms — an academic and cognitive profile. Plays Roblox and Fortnite — a psychographic and social profile. Sets up Instagram or TikTok — an emotional profile, self-esteem, social connections. By the age of thirteen — 72 million data points, as we said last time. What happens to this profile next. Insurance companies in a number of countries are already beginning to look at data about children when calculating future insurance products. Academic difficulties recorded on educational platforms — a potential risk factor. Behavioural patterns from games — an indicator of a propensity for risk. Employers in ten years will have access to data that exists already now. Hiring algorithms become ever more sophisticated. A person’s profile at twenty-five will include data about what they were like at ten. Financial organisations. The credit scoring of the future — not only financial history. A behavioural profile starting from childhood. Decision-making patterns. Impulsivity or caution recorded in game behaviour. This is not fiction. It is an extrapolation of existing trends five to ten years ahead. The technology for this already exists. The data is already being collected. The only question is when this will become standard practice.
The moment that changes everything
There is a thing I want to say directly. Not technically — humanly. We are talking about children. About people who cannot protect themselves. Who do not understand what is happening. Who simply play, study, watch videos — and do not know that each of their actions is recorded, analysed, sold. An adult who did not read the privacy policy — made a choice. A poorly informed one, but a choice. The child made no choice. None at all. GDPR understands this. Article 8 says that the processing of the data of children under 16 requires parental consent. Special protection for children is written out separately. Children’s data — a special category requiring particular caution. In practice this protection works poorly. Because platforms circumvent it through age restrictions that are not really checked. Because parental consent is obtained through a tick in a registration form that no one reads. Because educational platforms hide behind the «legitimate interest» of the school as an institution. The system of protecting children exists on paper. In practice — holes through which an industry worth billions passes.
Norway did something important
Not everything is hopeless. There are examples that show what works when a regulator really acts. In 2021 the Norwegian data-protection regulator Datatilsynet banned Facebook from targeting advertising at minors on the basis of behavioural data. Completely. Did not limit — banned. Facebook disputed the decision. Lost. The ban took effect. This is one regulator. One country. But a precedent has been set. And other regulators are watching. In 2022 the United Kingdom adopted the Age Appropriate Design Code — a design code for a children’s audience. It obliges platforms by default to apply maximum privacy settings for users who may be children. Not to ask — to apply by default. This is the right direction. Because a system that requires active actions from a child or their parents for protection — does not work. Protection must be by default.
The last thing to understand
The data collected on children today is not merely information about what they were like. It is data that will be used to make decisions about who they will be allowed to become. What education to receive. What job to find. What loan to take. What insurance to arrange. A profile formed without consent — will influence a life without consent. This is not the future we wanted to create for our children when we published their first photo. But it is the future we are creating — if we do not begin to think about it now. Next time — what specifically parents can do. Right now. Without panic. Without forbidding children everything digital. Practically and realistically.
Children in the digital world. Part three — what parents should do. Right now
Two posts ago we talked about how a child’s digital profile is formed. From the first photo on the first day of life. Last time — what happens to this profile and what consequences are already documented. But first — an important clarification that defines the whole conversation. The goal is not to isolate the child from the digital world. This is impossible and unnecessary. Digital skills are a part of life. A child who cannot navigate the digital environment will be just as helpless as one who cannot read. The goal — to raise a person who understands the environment they live in. Who knows what is happening. Who makes conscious choices — rather than automatic ones. This is called digital literacy. And it begins with the parents.
Let us start with the most uncomfortable
Before talking about what to do with the child — you need to talk about what to do with yourself. Because the biggest source of data about a small child is not games and not YouTube. It is the parents. Sharenting — the publication of children’s photographs on social networks — is the first thing to rethink. Not to forbid yourself completely. To rethink. A few questions worth asking yourself before each publication. Would my child, in ten years, want this photo to exist publicly? Does this photo contain information about location — school, playground, home? Does this photo show the child in a vulnerable situation — crying, ill, in an awkward moment? Who really sees this publication — only loved ones or in effect everyone? Practical steps. A private account instead of an open one. If you publish photos of children — the account must be private. Only confirmed followers. This is not paranoia — it is basic hygiene. Turn off geotags. In the smartphone camera settings — turn off saving geolocation in the photo metadata. Every photo taken with geolocation on contains the exact coordinates of the shooting location. This is visible in the file properties — and visible to the platforms that receive the photo. Do not publish a photo in a school uniform with the school logo. Do not publish a photo next to street signs or recognisable landmarks near your home. This is a combination that gives too much information about where the child lives and studies. Talk to other parents. Grandmothers, grandfathers, family friends — they also publish photos of your child. Sometimes more than you do. This is a conversation that needs to be had — calmly, without accusations, explaining why it matters.
Settings to check today
YouTube and YouTube Kids. Go into the child’s Google account if they have one. Settings — search and watch history. Turn off saving history. Turn on automatic deletion of data — every three months. Turn on restricted mode on YouTube. This is not a perfect filter — but it removes a significant part of unsuitable content. Use Family Link — Google’s tool for parental control. It lets you see which apps are installed, how much time the child spends on each, set limits. Free. Works on Android. On iPhone — Screen Time in settings. Similar functionality. Time limits, content restrictions, a ban on installing apps without a parent’s permission. Gaming platforms. Roblox. Go into the privacy settings of the child’s account. Limit who they can communicate with — friends only, not all users. Turn off the ability to receive private messages from strangers. Turn on a parental PIN — without it the child cannot change the privacy settings. An important detail about Roblox that few know. The platform allows you to submit a request to delete a child’s data. If the child is under 13 — a parent can request the deletion of the account and all associated data. This is a right. Use it if the account is no longer needed. Minecraft. Through a Microsoft account — family safety. Allows you to control who the child plays with and limit online interactions. Fortnite and Epic Games. In the parental-control settings — a PIN code the child does not know. A limit on game time. A limit on purchases — no spending without a parent’s confirmation. Educational platforms. This is the hardest — because the school recommends it and the parent feels they cannot refuse. You can. And you should — if the platform does not meet the data-protection requirements. A practical algorithm. When the school recommends a new app — find its privacy policy. Look for answers to three questions. Is the data transferred to third parties — and to which? Is the data used for advertising purposes? Where is the data physically stored — in the EU or outside it? If there are no answers or they are vague — write to the teacher or the school administration. Ask on what legal basis the school recommends a platform that does not comply with GDPR. This is not aggression — it is a lawful question. The school as an institution bears responsibility for the pupils’ data. In many cases the school simply did not think about it. The teacher found a convenient tool. Your question can change the practice for the whole class — not only for your child.
GDPR rights that parents have
Until the age of 16 — in most EU countries, in Estonia precisely so — the processing of a child’s data requires the parent’s consent. This means that the parent has the same rights regarding the child’s data as a person has regarding their own data. The right of access. You can request from any platform the child uses — what data they store. The template of the request we examined in detail in previous posts. The same text — you only add that you are acting as the legal representative of a minor. The right to erasure. The child has stopped using a platform — demand the deletion of all data. Not merely deactivation of the account. Full deletion. These are different things and you need to explicitly specify deletion. The right to object to profiling. If a platform builds a behavioural profile of the child — you can demand that this stop. Article 21 GDPR. Works even if consent was given earlier. The right to withdraw consent. If you once pressed «accept» in the privacy policy of an educational platform — this consent can be withdrawn. In writing. At any moment. The platform is obliged to stop processing data on the basis of this consent. A concrete example of how this works. The child used an educational app for two years. Now it is not needed. You write to the platform’s DPO address: «I am the legal representative of [child’s name], date of birth [date]. On the basis of Articles 17 and 21 of GDPR, I request the deletion of all my child’s personal data from your systems and the cessation of any processing of this data. I also withdraw any consent previously given to the processing of data. Please confirm the fulfilment of the request within one month.» That is all. The platform is obliged to comply. If it does not — AKI.
The conversation with the child. When and how
This is the most important part. Because settings can be changed. But the child will grow up — and one day find themselves one on one with the digital world without a parent nearby. Digital literacy is not prohibitions. It is understanding. At what age to begin. Earlier than it seems. Children at 5–6 are already capable of understanding simple concepts — «when you watch a video, the tablet remembers what you like». Not to frighten — to explain. In language that is understandable. At 8–10 — more concretely. «When you register in a game — they record your name and what you do. They can use this information to show you advertising». Children of this age understand perfectly when something is being sold to them — and react to this. At 12–14 — the full conversation. About data, about profiles, about how algorithms govern what they see. Teenagers of this age are capable of understanding the systemic picture — and often react to it with unexpected seriousness. Because they feel the manipulation — but did not know how to name it. What to talk about concretely. The algorithm is not a friend. It does not show you what is good for you. It shows what will hold you longer. These are different things. Sometimes they coincide. More often — no. Likes are not a measure of worth. This is the most important conversation for teenagers. The algorithm decides who sees your posts. Few likes does not mean you are uninteresting or unimportant. It means the algorithm decided to show your post to fewer people. For its own reasons. Which have nothing to do with you. What you publish — remains. Forever. A deleted photo is deleted from your page — but not from the servers. Not from the cache. Not from the screenshots others took. The internet does not forget. This is not a reason to publish nothing — it is a reason to think before publishing. The personal stays personal. Some things do not need to be published. Not because they are shameful — but because not everything should be publicly available. The border between the public and the personal — is your choice. No one should pressure you to share more than you want.
Three mistakes parents with the best intentions make
Mistake one — a total ban. «No phones until 16» — sounds decisive. In practice it means that the child gets access to the digital world later than everyone else — without preparation, without skills, without understanding. And at 16 finds themselves one on one with an environment they do not understand. Friends learned to navigate it long ago. They — did not. Restrictions are needed. A total ban — is counterproductive. Mistake two — control without explanation. To set up parental control and not explain to the child why — means to create a secret they will want to uncover. Teenagers circumvent technical restrictions. Always. If they do not understand why they are needed. Explanation works better than a ban. «I limit time on TikTok because I know how this algorithm works and I do not want it to govern your time and mood» — this is a conversation. A conversation creates understanding. Understanding — an internal choice. An internal choice is more stable than an external ban. Mistake three — doing everything for the child. Check the privacy settings — together with the child. Not instead of them. Submit a request to delete data — explaining what you are doing and why. Discuss the privacy policy of a new app — reading the key parts together. This takes more time. But it creates a skill — rather than dependence on a parent who controls everything.
School. A conversation worth starting
Parents rarely think of school as a place where a child’s data needs to be protected. And in vain. A school in Estonia is a government institution. It processes pupils’ personal data on the basis of the law. But when a school recommends or requires the use of commercial platforms — it in effect transfers children’s data to third parties. This requires a legal basis. What you can do. Write to the class teacher or the head with a question — which platforms are used for teaching, are there data-processing agreements with these platforms, where is the pupils’ data stored. This is not a complaint — it is a request for information. In Estonia a parent has the right to know how their child’s data is processed in the school context. The school is obliged to respond. If the school uses platforms that clearly violate GDPR — you can turn to AKI. This is a last resort. But knowing that it exists — changes the conversation.
What to do with data that already exists
The child is ten years old. Data has been collected since birth. What now. The honest answer — to delete it completely is impossible. Photographs that the parents published — exist in the platforms’ databases. Data from games over the years — exists. Academic profiles — exist. But you can do the following. An audit of accounts. Compile a list of all the platforms and apps the child has used — including those they stopped using. Delete unused accounts. For each — a request to delete data. The child’s Google account — go to myaccount.google.com. The data-and-privacy section. Delete search history, YouTube history, geolocation history. Set up automatic deletion every three months. Social networks. If the child is under 13 and has an account on Instagram or TikTok — this is a violation of the platforms’ own age rules. You have the right to demand deletion of the account and all data. The platforms are obliged to comply — and as a rule comply quickly precisely in cases with minors because this is their greatest legal risk. Old photos on social networks. This is harder — but you can go through the posts and delete those that contain too much information. Geolocation. School uniform. Recognisable places near home.
Tools right now
Google Family Link — free, Android and iPhone. App control, time limits, approval of downloads. Apple Screen Time — built into iPhone and iPad. Limits by app category, content restrictions by age, a request for permission for new apps. Common Sense Media — commonsensemedia.org. Independent reviews of apps, games, films from the standpoint of safety for children of different ages. In English — but a very useful resource before allowing a child a new app. Internet Matters — internetmatters.org. Step-by-step guides to privacy settings for each large platform. Updated regularly. Haveibeenpwned.com — if the child has an email, check whether it was in data leaks. If yes — change the password immediately.
Finally — and most importantly
There is a temptation to read all this — to be horrified — and either to forbid everything, or to give up because it is too difficult. Neither works. Something else works. One conscious decision today. Then one more. Then a conversation with the child. Then a check of the settings. Then a question to the school. Not a revolution. A habit. Because the digital environment in which our children grow up — will not disappear. It will become more complex. There will be more data. The algorithms will be more precise. The influence will be deeper. The only thing that changes this equation — is people who understand what is happening. And pass this understanding to their children. Not as a horror story. As knowledge. Knowledge that the algorithm is not a friend, but also not an enemy. It is a tool. Like a knife. You can prepare food. You can cut yourself. It depends on whether you hold it — or it holds you. Your child deserves to hold it themselves. Consciously. With an understanding of what it is. This is what digital literacy is. And it begins today. With this conversation.