This is the situation brands actually face now: a skincare or lifestyle brand can build a campaign with age-restricted targeting parameters that explicitly exclude minors, and still have the campaign reach users a platform’s own age signals suggest are under 16, because the ad system optimizes for engagement rather than for the demographic assumptions written into the brief. Nobody at the company targeted children. The targeting parameters excluded them. But the algorithm didn’t care what the targeting parameters said, and regulators — including the Irish Data Protection Commission, which has opened inquiries into exactly this gap between stated targeting and actual reach — increasingly treat that mismatch as the brand’s problem to solve, not the platform’s.
This is the situation brands actually face now. Not the one the compliance training described.
The regulatory architecture around children’s data has always been built on a paradox that the industry preferred not to look at directly. The GDPR sets the age of digital consent at 16, with member states permitted to lower it to 13, and requires verifiable parental consent for processing children’s data below that threshold. The Digital Services Act, in full application since 2024, requires online platforms accessible to minors to put in place proportionate measures protecting their privacy, safety, and security under Article 28, while separate provisions require the largest platforms to assess and mitigate systemic risks to minors under Articles 34 and 35. The problem, as The Next Web laid out in detail earlier this year, is that every one of these obligations requires knowing whether a given user is a child, and knowing whether a given user is a child requires collecting personal data about every user, including adults who have a right not to be age-checked.
Europe’s own solutions have not resolved this. The European Commission’s privacy-preserving age verification app, announced on April 15, was hacked by security researchers in under two minutes. On March 26, the European Parliament voted 311 to 228 against extending the ePrivacy derogation, letting the legal basis platforms had relied on to voluntarily scan private messages for child sexual abuse material expire on April 3. The CSA Regulation that was supposed to replace it remains stuck in trilogue negotiations that have now dragged on since 2022.
For brands, the practical consequence is that the ground beneath any children-adjacent marketing activity is moving continuously, and the regulators have signalled they are done being patient.
The fines make the point more clearly than any policy document. In February 2026, following a 2025 investigation, Reddit was fined by the UK’s Information Commissioner’s Office for children’s privacy failures, part of a broader enforcement pattern that has seen TikTok, Meta, and other platforms hit with penalties running into the hundreds of millions. According to Bitdefender’s coverage of the enforcement trend, regulators on both sides of the Atlantic have moved children’s data from a secondary concern to a first-order enforcement priority, with fines calibrated to hurt.
What this means for brands generally is that the risk calculation has inverted. It is no longer sufficient to demonstrate you didn’t intend to reach children. You have to demonstrate you took reasonable steps to prevent reaching them, that your data processing chain — including every ad tech vendor, every lookalike audience, every retargeting pixel — has been documented and controlled, and that you can produce that documentation on request.
Many retailers discover this the hard way when a routine audit asks a simple question: what actually happens to a customer’s data once it enters the marketing stack. A retailer running a dozen or more overlapping marketing technology platforms — each with its own data processing agreements, its own subprocessors, its own approach to age signals — often cannot trace that path cleanly. Internal counsel at several European retailers have described this exact problem: tracing what happens to a customer’s data through a stack of ad tech vendors is straightforward in theory and genuinely difficult in practice, and a data protection officer who cannot confidently answer a regulator’s basic questions has already failed the audit, whether or not enforcement follows.
This is closer to the actual state of the industry than the compliance decks suggest. The GDPR compliance requirements laid out by TechTarget — data tracking, encryption, and breach notification — all become materially harder when children’s data is potentially in the mix, because the standard of proof rises and the tolerance for ambiguity falls.
The complication brands often underestimate is that this is no longer a Europe-only conversation. India’s Digital Personal Data Protection Act, with Consent Manager provisions taking effect on November 14, 2026 and core obligations from May 14, 2027, treats anyone below 18 as a child and generally requires verifiable parental consent for processing their data. According to India Briefing’s comparison of the two frameworks, the DPDP Act also restricts tracking, behavioral monitoring, and targeted advertising directed at children, subject to notified exemptions. That is a materially higher threshold than the GDPR’s 16, and it applies to any company offering goods or services to individuals in India.
Brands that built their compliance programs around GDPR now discover that GDPR alignment is a floor, not a ceiling. A children’s marketing approach that satisfies Ireland may not satisfy India. A consent flow that satisfies Germany at 16 does not satisfy Spain at 14 or India at 18.
Marketing leads at edtech companies and other multinationals with significant European customers increasingly describe running three parallel compliance programs and hoping none of them contradicts the others. Separate consent flows for the EU, the UK, and India — each with different age thresholds, different parental consent mechanisms, and different retention rules — are becoming the norm rather than the exception. Legal counsel at several such companies have advised that the safest path is to design for the strictest jurisdiction and apply it globally, which is expensive but defensible.
The direction of travel in the United States adds another layer. As the R Street Institute has noted, Congress has repeatedly attempted and failed to pass comprehensive federal privacy legislation, leaving American brands to navigate a patchwork of state laws — California, Colorado, Connecticut, Virginia, Texas, and others — each with their own approach to children’s data. The Kids Online Safety Act and various state-level age-appropriate design codes continue to work their way through legislative processes with unclear outcomes. Brands operating internationally cannot wait for that clarity.
What is emerging, in practice, is a set of behaviors that competent marketers are now adopting whether the law formally requires them or not. Documented data flow mapping. Verified age gates on any content or product that could plausibly appeal to under-18s. Explicit exclusion of behavioral targeting for users flagged as potentially minors. Vendor contracts that specify children’s data handling in detail, including deletion obligations and audit rights. Retention schedules that default to shorter periods for younger users. Marketing calendars reviewed against school holiday periods for indirect targeting risk.
These practices have started to define what regulators consider reasonable in an area where the law provides little specific guidance until enforcement actions clarify the standard.
The temptation for brand leaders is to treat all of this as a legal team problem, something to be handled by the DPO and the outside counsel and reported to the board once a quarter. The problem with that approach is that children’s data compliance is not primarily a legal issue. It is a product design issue, a targeting infrastructure issue, a vendor management issue, and a creative brief issue. By the time it reaches the DPO, most of the decisions that create the risk have already been made.
The brands that will handle the next five years of this well are the ones that have accepted a difficult premise: the regulatory environment around children’s data will not stabilize. The EU will keep negotiating the CSA Regulation. Member states will keep passing their own age restrictions — France under 15, Spain under 16, Greece under 15 from 2027, Austria under 14. India will implement the DPDP Act. The United States will produce some combination of state and possibly federal rules. New frameworks will emerge in markets that don’t yet have them.
For brand teams, the practical implication is that any marketing infrastructure built on the assumption that children’s data rules will settle into a stable form is being built on sand. The competitive advantage, over the next five years, will go to the brands that treat data minimisation, age assurance, and consent granularity as design defaults rather than compliance retrofits. Not because the regulators demand it in every market — they don’t, yet — but because the cost of retrofitting a marketing stack that assumed permissive rules is now demonstrably higher than the cost of building for restrictive ones.
The brands still running the 2018 playbook — cookie banner, privacy policy, DPO on retainer, hope for the best — are the ones now discovering how expensive that playbook has become.