Skip to Content
OPINION

Back to school, into a new era of children's privacy

AI-enabled wearables and classroom technologies are creating a new children's privacy challenge by collecting data from children who never chose to use, or consent to, the technology requiring a need for updated protections to cover children as subjects, not just users, of technology.

Published
Subscribe to IAPP newsletters

Contributors:

Dona Fraser

Senior Vice President, Privacy Initiatives

BBB National Programs

Editor's note

The IAPP is policy neutral. We publish contributed opinion pieces to enable our members to hear a broad spectrum of views in our domains.

As students return to school this fall, artificial intelligence is coming with them. Yes, in the tools children choose to use, but also increasingly in the technology operating around them.

A student might wear AI-enabled glasses capable of seeing, hearing, recording and interpreting the people nearby. A teacher might use an AI tool to transform a kindergartner's photo into an image of what she could look like someday as a doctor. AI-powered cameras, learning tools or classroom applications may analyze children's images, voices, behaviors or work.

These uses raise a children's privacy question our existing legal framework wasn't built to answer: What happens when a child's data is collected without the child ever choosing to use the technology collecting the data?

For more than two decades, children's online privacy protections have largely centered on a familiar relationship: a child interacts with a website, app or digital service, and that service collects information from the child. But AI is rapidly complicating that model.

As lawmakers consider the next generation of children's privacy protections, they should account for children not only as users of technology, but also as subjects of it.

Consider AI-enabled glasses.

A ninth grader walks into biology class wearing AI-enabled glasses that look like ordinary prescription glasses. The glasses can see, hear, record and use AI to interpret what is happening around the wearer.

Twenty-five other students and their teacher are in the classroom. They did not purchase the glasses or activate the camera. They did not agree to be recorded, and they may not even know the glasses are capable of recording them.

Yet their faces, voices, conversations and surroundings could potentially be captured simply because they are nearby.

And the classroom is only the beginning. The same technology could follow students into the hallway, cafeteria, school bus, athletic field or after-school activity. A child could be captured by a device worn by someone else without ever interacting with the device, its manufacturer or the service processing the information.

That is a fundamentally different privacy problem.

Our privacy framework has traditionally been built around a direct relationship between a person and a technology service. The person visits the website, downloads the app or operates the device and the company collects information through that interaction.

AI-enabled wearables introduce a third party: the person who happens to be in range of the device.

That person may have no account, no relationship with the company and no opportunity to review its terms or privacy settings. They simply enter the device's field of view or microphone range.

For children, that creates an especially important policy question.

The Children's Online Privacy Protection Act was enacted in 1998, and the U.S. Federal Trade Commission's implementing rule took effect in 2000. The framework has evolved with technology, and the FTC's most recent amendments strengthened protections around children's data, including parental consent requirements for certain disclosures to third parties and the addition of biometric identifiers to the definition of personal information.

However, COPPA's jurisdiction is strictly tied to "online services." If a device operates completely offline, such as AI-enabled glasses, it may fall outside COPPA's scope. Determining whether a device is legally considered "connected" requires careful analysis of how modern hardware actually handles sensitive user data.

But AI wearables expose a scenario that is difficult to fit into a framework centered on a child's interaction with an online service.

What protections apply when the child has no relationship with the service at all?

That question will not be answered by schools alone. Districts will need to determine whether and how students can use AI glasses, earbuds and other wearables on campus. And though a school policy can regulate a device in a classroom, it cannot necessarily determine what happens to the information that device captures, where it goes or how it is subsequently used.

The technology and advertising industries face a similar challenge. Years of privacy debates have focused on cookies, device identifiers, first-party data, consent mechanisms and behavioral targeting. Those systems generally begin with an identifiable interaction between a person and a technology.

AI changes the equation. An AI system can observe, interpret and potentially retain information about people who never intended to provide it.

For children, that could mean being photographed, recorded or analyzed without ever opening an app, creating an account or making a conscious choice to participate.

This is why children's privacy policies need to expand beyond the concept of the child as a user.

We also need to consider the child as a subject of technology.

That distinction may become increasingly important as AI moves into objects children encounter every day. The technology may be worn by someone else, embedded in a classroom, or operating in the background. The child does not have to interact with it for its capabilities to affect them.

The question for policymakers, schools and the technology industry can no longer be limited to: Did the user agree? It must also be: What protections exist for the person who never had the opportunity to agree?

We have an opportunity to close this gap. As lawmakers consider the next generation of children's privacy protections, they have the opportunity to modernize COPPA for the AI age. That means broadening its reach beyond "online services" to cover passive exposure — including children's images, voices and biometric information — and ensuring meaningful protections apply even when there is no direct relationship between a child and the technology provider.

As technology continues to evolve, our definition of who deserves protection needs to evolve with it.

CPE credit badge

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.

Submit for CPEs

Contributors:

Dona Fraser

Senior Vice President, Privacy Initiatives

BBB National Programs

Tags:

AI and machine learningChildren’s privacy and safetyLaw and regulationAI governance

Related Stories