The International Enforcement of Children’s Data Privacy Rights in a World Without a Shared Jurisdiction

Protecting the digital child requires a coordinated global response that mirrors the global reach of major technology companies. Only through such mechanisms can children’s data-privacy rights evolve from aspirational norms into enforceable guarantees.

11–16 minutes
2,540 words

Introduction

Children today grow up in an environment that is digitally connected, commercially exploited, and legally precarious. The modern child is simultaneously a consumer, a data subject, and a target of algorithmically engineered engagement, often before being old enough to read the terms of service that purport to bind them. Major technology companies—Meta, ByteDance, Google, Apple, Discord, and many others—operate across borders with unprecedented fluidity, collecting extensive data from minors in ways that no single legal system can comprehensively regulate. The result is a jurisdictional patchwork in which children’s data-privacy rights exist in principle but often cannot be meaningfully enforced in practice.

The gap between rights and remedies has become increasingly visible against the backdrop of rising concerns about mental health and digital dependency among young people. The U.S. Surgeon General and the American Psychological Association have both warned that social-media environments present measurable risks to adolescent well-being, particularly when used extensively during key developmental periods. Scholars such as Jonathan Haidt, in The Anxious Generation, argue that early and largely unregulated exposure to smartphone-mediated social platforms can contribute to developmental harms and exacerbate adolescent vulnerabilities, especially given design features crafted to maximize engagement and personal-data extraction. Haidt’s account underscores that the challenge is not merely one of privacy, but of neurological susceptibility, exploited at scale by global technology systems. This reality heightens the urgency of determining whether governments, courts, and corporate actors can meaningfully enforce children’s data-privacy rights across borders—even in the absence of shared jurisdictional authority.

Although international law increasingly acknowledges children’s privacy as a human right, its mechanisms remain structurally fragmented. Domestic regulators possess limited extraterritorial reach, while multinational technology companies benefit from complex corporate structures that obscure accountability. Nevertheless, through coordinated regulatory cooperation, legislative innovation, and strategic litigation, governments and private actors can take meaningful steps to improve children’s digital-privacy protections. A combination of treaty-based reforms, reciprocal enforcement mechanisms, and mandatory child-rights impact assessments can contribute to a more coherent global framework for protecting the “digital child”.

Foundational International Frameworks for Children’s Digital Privacy

The starting point for any discussion of children’s privacy rights is the United Nations Convention on the Rights of the Child (CRC), which was adopted in 1989 and ratified by every United Nations member state except the United States. Article 16 of the CRC guarantees children protection from “arbitrary or unlawful interference with his or her privacy, family, home or correspondence,” while Article 3 requires that the “best interests of the child” be a primary consideration in all actions concerning children by public authorities. Although drafted before the rise of social media and pervasive datafication, the CRC has become a central reference point for digital-era privacy analysis, with the Committee on the Rights of the Child treating these foundational principles as fully applicable in online contexts.

In 2021, the Committee issued General Comment No. 25, explicitly interpreting the CRC in relation to the digital environment. The Comment stresses that states must regulate digital services and business enterprises under their jurisdiction so that children’s rights are respected “in the digital environment,” including through legislation, child-rights impact assessments, and oversight of companies whose products are used by children worldwide. Many read this as supporting a form of cross-border responsibility when domestic companies design or operate digital services that affect children abroad, even though the General Comment remains a nonbinding interpretation of treaty obligations.

The CRC’s Optional Protocol on a Communications Procedure (OPIC) allows children or their representatives to bring complaints directly to the Committee when domestic remedies have been exhausted. However, the Committee’s views take the form of recommendations rather than binding judgments, and compliance depends on the political will of states. Ratification levels also remain modest compared to the CRC itself: only a minority of states are parties to OPIC. As a result, the U.N. framework provides strong normative guidance and a venue for individual complaints but does not, on its own, furnish a coercive enforcement system for children’s digital-privacy rights.

The Organization for Economic Co-operation and Development (OECD) Privacy Guidelines and the Council of Europe’s Convention 108+ represent some of the most developed international privacy regimes. The OECD Guidelines take the form of a nonbinding recommendation that has strongly influenced global privacy norms. Convention 108+, by contrast, is a binding data-protection treaty for its parties and is sometimes described as the only global binding instrument in its field, though its membership remains limited and largely regional.

Taken together, these instruments recognize privacy as a fundamental human right and help shape national and regional approaches to children’s digital privacy. Yet they still do not create a comprehensive framework for mutual recognition of privacy decisions or for automatic cross-border enforcement of regulatory penalties. This gap in reciprocal enforcement remains especially consequential when dealing with multinational platforms that process children’s personal data across numerous jurisdictions.

Regional Legal Systems and Their Enforcement Approaches

The European Union’s General Data Protection Regulation (GDPR) remains one of the most influential and comprehensive privacy frameworks in the world. Article 8 regulates children’s consent in relation to information-society services, while Articles 44–50 establish strict conditions for international data transfers. These provisions give the European Union authority to impose penalties on global firms whose processing activities fall within the GDPR’s territorial scope, including when data is transferred or processed across borders.

Recent enforcement actions reflect increasing regulatory assertiveness. In 2023, the Irish Data Protection Commission fined TikTok 345 million Euros for violations relating to minors’ data, including default public settings for accounts of child users and insufficient age verification. That same year, the Commission—following a binding decision by the EDPB—issued a 1.2 billion Euro penalty against Meta for unlawful transfers of personal data to the United States under standard contractual clauses after the invalidation of the EU–U.S. Privacy Shield.

The EU’s Digital Services Act (DSA) and Digital Markets Act (DMA) further impose obligations on “very large online platforms” and “gatekeepers,” including mandatory risk assessments, audits, algorithmic transparency, and protections for minors against harmful or manipulative design practices. Together, the GDPR, DSA, and DMA form the most advanced and integrated enforcement ecosystem for digital-privacy and platform governance currently in operation. Yet even the EU faces jurisdictional and procedural constraints. Because GDPR enforcement is tied to the “main establishment” of a company—often in Ireland—the one-stop-shop mechanism can produce delays, political sensitivity, and disagreements among national authorities.

In the United States, the primary federal law governing children’s data is the Children’s Online Privacy Protection Act (COPPA), enforced by the Federal Trade Commission (FTC). COPPA has produced significant settlements, including YouTube’s 170 million dollar penalty for unlawful data collection from children, and Epic Games’ record 275 million dollar civil penalty for violating children’s privacy, which was imposed alongside a separate 245 million dollar redress order for dark-pattern design practices. However, COPPA is limited in scope and applies only to children under thirteen, provides no private right of action, and imposes limited obligations on companies located outside the United States unless services are directed to U.S. children. The United States remains one of the few democracies without a federal data-protection authority with comprehensive jurisdiction.

Some U.S. state laws attempt to fill these gaps. For example, the California Age-Appropriate Design Code Act (AADC) imposes child-focused design obligations on online services, though it currently faces constitutional challenges, including on First Amendment grounds. Like most state-level privacy laws, the AADC has limited extraterritorial enforcement capacity and illustrates the tension between aggressive child-protection rules and speech concerns.

Despite these advancements, domestic frameworks often struggle to regulate multinational companies that lack local physical establishments, store data offshore, or rely on contractual jurisdiction clauses that complicate enforcement. As a result, even robust national laws may be difficult to enforce against global platforms operating through dispersed technical infrastructures and corporate networks.

The Core Challenge: Enforcing Rights Across Borders Without a Shared Tribunal

Data does not remain confined within national boundaries. Cloud-based processing, outsourced content moderation, and globally distributed ad-tech infrastructures mean that a child’s personal information may transit multiple jurisdictions before it is stored or associated with an identifiable corporate entity. Courts and regulators generally require some form of territorial nexus—such as conduct within the forum, harm suffered in the forum, or a defendant purposefully directing activities toward the forum—but digital conduct is diffuse, automated, and often mediated by algorithmic systems rather than discrete human actions. As a result, companies frequently argue that they lack sufficient contacts or purposeful direction toward a jurisdiction, even while processing the data of millions of children worldwide.

Efforts by regulators—particularly in the European Union—to extend privacy rules extraterritorially have at times provoked friction with other governments. The disputes between the United States and European Union over international data transfers, culminating in the Court of Justice of the European Union’s Schrems II decision invalidating the EU–U.S. Privacy Shield, illustrate the tension between stringent privacy protections and expansive national-security surveillance regimes. When enforcement of children’s data rights depends on cooperation between governments with incompatible regulatory philosophies or security priorities, progress often slows.

Unlike international arbitration awards, which can be enforced abroad under the New York Convention, regulatory fines and administrative privacy decisions have no equivalent multilateral mechanism for recognition or enforcement. This means that even very large penalties—such as the EU’s record fines against Meta—carry no direct legal effect in jurisdictions like the United States unless the company voluntarily complies or enforcement is pursued through separate domestic proceedings.

Multinational platforms routinely segment their operations into networks of subsidiaries, each responsible for distinct processing activities or regions. This corporate structuring can make it difficult for regulators to determine which legal entity controls or processes specific categories of personal data. Such structures also enable companies to strategically locate data-processing hubs in jurisdictions with favorable regulatory environments or lower compliance burdens.

Arbitration clauses are often embedded deep within terms of service. Courts differ on whether minors can be bound to arbitration agreements, particularly when assent is implicit or when a parent purportedly accepts on the child’s behalf. As a result, many claims involving children’s privacy never reach judicial resolution. The rights nominally granted to children in various legal systems thus often lack practical, cross-border mechanisms for vindication, leaving significant gaps between legal protections and real-world remedies.

Emerging Solutions: How Lawyers, Regulators, and Lawmakers Can Advance Enforcement

Emerging solutions for strengthening the enforcement of children’s data-privacy rights increasingly focus on coordinated action among regulators and lawmakers. One important avenue involves enhancing cross-border regulatory cooperation. Existing voluntary networks—such as the Global Privacy Enforcement Network (GPEN), the Global Privacy Assembly (GPA), and the Asia-Pacific Privacy Authorities (APPA)—facilitate communication among privacy regulators, support joint sweeps, information sharing, and capacity-building efforts. These networks provide important foundations for deeper forms of cooperation, despite being nonbinding authority. Governments can build on them by negotiating multilateral memoranda of understanding that enable coordinated enforcement, reciprocal evidence sharing, and parallel investigations. Comparable cooperation models already exist in competition law and anti-money-laundering regimes, templates that privacy regulators could adapt and refine.

Another promising approach involves developing mechanisms for mutual recognition of privacy-law decisions. A global treaty requiring signatory states to recognize and enforce each other’s privacy judgments could substantially narrow the current enforcement gap. Even a narrower instrument focused specifically on penalties concerning children’s data would represent meaningful progress. This concept parallels the structure of existing mutual-recognition systems in international arbitration under the New York Convention and resembles the cross-border cooperation provisions found in child-protection instruments such as the Hague Abduction Convention.

Litigation also serves as a catalyst for structural change. Organizations such as NOYB (None of Your Business), Fairplay, and Privacy International have demonstrated that targeted litigation strategies can accelerate regulatory action, reshape platform practices, and influence the interpretation of privacy norms. Litigators may challenge forced-arbitration clauses involving minors, bring representative or collective actions where permitted, and file simultaneous claims across multiple jurisdictions. Even when courts face jurisdictional constraints, judicial decisions can nonetheless shape global norms by recognizing extraterritorial duties or rejecting overly broad jurisdictional defenses.

Requiring Children’s Rights Impact Assessments (CRIAs) offers another method of strengthening protections. UNICEF has recommended that states require technology companies to conduct systematic assessments of the effects of their products and policies on children’s rights before releasing youth-facing features. Well-designed CRIAs can obligate platforms to evaluate potential mental-health impacts, data-profiling risks, addictive-design elements, and cross-border data flows. Regulators could further condition market access or licensing on the completion and public disclosure of these assessments, thereby increasing transparency.

Some jurisdictions may also enhance enforcement by requiring local representatives and establishing explicit data-stewardship duties. Countries can require major online platforms to appoint in-country representatives authorized to receive regulatory notices, accept service, and coordinate compliance—an approach already adopted under the GDPR and Brazil’s general data protection law. Legislatures may additionally impose fiduciary-like duties requiring technology companies to act in the best interests of children when processing minors’ personal data.

Finally, scholars increasingly advocate for a global treaty focused specifically on children’s digital rights. A Digital Children’s Rights Convention could standardize age-verification rules, data-minimization requirements, profiling restrictions, and enforcement-cooperation obligations across participating states. Even if initially adopted by a small coalition of countries, such an agreement could exert upward pressure on international standards and move toward harmonized protections for children’s personal data.

Why This Matters: The Child’s Mind as a Site of Global Commercial Exploitation

Jonathan Haidt’s The Anxious Generation underscores that the problem is not abstract. Haidt argues that early and extensive exposure to algorithmically curated digital environments may influence cognitive development, emotional regulation, sleep patterns, socialization, and mental health in adolescents–particularly when platforms are designed to maximize engagement rather than well-being. His account aligns with concerns raised by major health authorities, which report associations between certain patterns of social-media use and increased symptoms of anxiety, depression, and compulsive or problematic use among young people.

This combined harm—privacy intrusions alongside potential psychological and developmental risks—creates a compelling state interest in protecting children wherever digital processing occurs. Yet without coordinated cross-border enforcement mechanisms, companies can relocate data-processing operations, restructure their corporate presence, or contest jurisdictional authority, leaving children’s rights effectively unenforceable despite growing international recognition.

Children’s data-privacy rights are increasingly acknowledged in international law, but meaningful enforcement remains limited. The Convention on the Rights of the Child and subsequent U.N. interpretations provide strong normative guidance but no binding global enforcement mechanisms. Regional frameworks offer more powerful investigatory and sanctioning tools, yet they face jurisdictional, procedural, and sovereignty constraints when applied extraterritorially. Meanwhile, the United States and many other jurisdictions provide only fragmented or partial protections and lack coordinated structures for cross-border enforcement.

The challenge is not merely technical. It reflects a structural reality of the digital era: global technology companies operate with levels of mobility, decentralization, and corporate complexity that domestic legal systems were not designed to confront. Children—often the least empowered data subjects—experience the consequences most acutely, as their information flows far beyond the reach of any single legal system.

Nevertheless, meaningful progress is possible. Strengthened regulatory cooperation, mutual recognition of privacy decisions, mandatory child-rights impact assessments, strategic litigation, and the development of treaty-based harmonization can begin to close the enforcement gap. Protecting the digital child requires a coordinated global response that mirrors the global reach of major technology companies. Only through such mechanisms can children’s data-privacy rights evolve from aspirational norms into enforceable guarantees.


Scroll to Top