Social Media Platforms Called Out By ICO For Inadequate Children’s Privacy Practices
20th September 2024
The ICO has found that many social media platforms need to do more to protect children’s privacy. The ICO’s ongoing review of social media platforms (SMPs) and video-sharing platforms (VSPs) as part of their Children’s Code Strategy has led to questions being asked about the platforms relating to privacy settings, age assurance, and other issues.
What is the Children’s Code?
The ICO has collaborated with Ofcom, family services, schools and more to develop the Children’s Code. The Children’s Code gives guidance to digital services on how they can safeguard children’s personal information when using their platforms. The Children’s Code is not technically a law but provides standards for digital platforms to conform to, to display their commitment to acting in the best interests of the children who use their platforms.
Since the Children’s Code was introduced in 2021, it has led to significant changes to the treatment of minors’ data. Meta platforms Facebook and Instagram have limited targeted advertising to under-18s, disabling accounts where people can’t prove they are over 13, and launching parental supervision tools. YouTube turned off autoplay by default for Google accounts of under-18s and turned on ‘take a break’ and bedtime reminders. Google has enabled under-18s to request to remove their images from Google search results and has taken action to prohibit age-sensitive ads from being shown to minors.
This is a good start but according to recent information gathered by the ICO, some online platforms need to do more to protect the privacy of children.
The ICO Investigation’s Findings
Private Profiles by Default
Part of the ICO’s Children’s Code is that children’s profiles should be set to ‘private’ by default. During their investigation, they found that this was not the case for some platforms. In a few cases, it was discovered that users can only create a private profile by opting into a subscription service or paying a fee. Some platforms also enabled people to send ‘friend’ or ‘follow’ requests and even direct messages to children by default. These platforms have not been publicly revealed, but the ICO has contacted them to change their practices or face more investigation and potential enforcement measures.
This part of the Children’s Code aligns with Article 25(2) of the GDPR, which states that:
“The controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessible without the individual’s intervention to an indefinite number of natural persons.” Source – https://www.legislation.gov.uk/eur/2016/679/article/25
This also aligns with data minimisation, whereby organisations should not collect more data than required to accomplish a specific task. SMPs are advised to provide ‘high privacy’ default settings for children who use their platforms.
Default Geolocation Settings
Similar to the above, geolocation data should be turned off by default for children’s accounts on social media platforms. Geolocation data is taken from a user’s device which indicates the geographical location of that device. The risks of this type of data to children are immediately obvious – the ability to ascertain or track the location of a child can compromise their physical safety. The ICO’s research has also revealed that children have received unwanted and distressing communications after posting images with geolocation data tagged. While most SMPs and VSPs have geolocation data turned off by default for children, some do display a prompt to turn on geolocation data or encourage them to share their location when posting content. The platforms should also alert the user to the use of geolocation data in a way that is understandable by children, e.g. by using a clear symbol or notification whenever it is active.
Using Children’s Data for Targeted Advertising
Virtually every online platform including social media collects data about its users for targeted advertising, from cookies from websites they have visited to content they view on the platform. Children may not be fully aware of how much of their personal data is collected and used for this purpose. This can lead to unwanted intrusion from third parties in the form of push notifications and ‘nudge’ techniques, and financial harm where targeted ads encourage in-app purchases. Some targeted ads may even promote negative health behaviours or inappropriate lifestyle choices.
Some platforms have taken appropriate action by not displaying any ads to children or using limited data points like their age to ensure no inappropriate ads are shown to them. However, other platforms have not made it clear what data is being collected from children, how it is used, or have not provided a way for children to control their advertising preferences.
Using Children’s Data for Recommender Systems
Recommender systems are algorithms that take personal information from users and suggest more similar content to them. Some recommender systems recommend suitable content to minors based on their age, but could also be potentially harmful. Some platforms do not have built-in sufficient protections for children and could expose them to inappropriate content, and promote sustained viewing which leads to excessive screen time and disrupted sleep.
The ICO’s research has discovered that some platforms that use recommender systems may show inappropriate content to children. Platforms should take responsibility for content served to users by recommender systems, as it is the platforms’ processing of data that serves the content to the user without them having to actively search for it. Some platforms’ privacy notices also do not make it clear what data is used to make these recommendations, or what they are doing to protect children’s privacy.
Use of Data from Children Under 13
Most platforms the ICO have looked into require users of their platform to be 13 or older to access content or make a profile. The UK GDPR states that verified parental consent is needed for children under 13 to provide consent to personal data processing. This can be hard to enforce but it is the platform’s responsibility to ensure they dont process the data of children under 13, or face the consequences. The ICO has previously fined TikTok £12.7 million for processing children’s data without parental consent, although the platform is appealing the decision. Note also, that the GDPR only allows individuals aged 13 and over to give permission to sign up for information society services (ISS), in other words, social media platforms. In some EU countries, the age is 16, and countries like Australia are looking to ban access to social media by minors.
Age Appropriate Design Code
A significant element of the Children’s Code is the Age Appropriate Design Code of Practice. This must be followed by any organisation offering goods or services online, or even just monitoring or profiling young people. If your organisation targets younger people, or your site is such that it may attract younger people, you may need to obtain certification – see here.
The Children’s Code Strategy is ongoing and the ICO is inviting more stakeholders to participate in their current work to refine and develop the Children’s Code further to improve the online safety and privacy of children. They have not named any of the platforms that are not following the Children’s Code as yet, but have contacted them privately to give them the opportunity to improve before any enforcement action is taken.
If you have any questions on this topic or any other data protection matters, talk to one of our senior consultants at the Griffin House Consultancy.
Author: Mike Martin LLM
Mike is an information governance specialist and one of the founder Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.