Direct Answer
Organizations that process children’s personal data in the Philippines must give children extra protection under NPC Advisory No. 2024-03. The Advisory applies to PICs and PIPs in digital or physical settings where a product or service is intended for, or likely to be accessed by, children. Before launch, the organization should conduct a child-oriented privacy assessment, use age-appropriate and just-in-time notices, adopt high-privacy settings by default, assess age assurance and parental/guardian involvement based on risk, and provide a practical way for children and parents to exercise data-subject rights.
September 2026 update for apps and games
On 23 September 2026, the National Privacy Commission reminded social media applications, online platforms, digital services and game developers accessible to minors in the Philippines that the Data Privacy Act, its implementing rules and related NPC issuances apply to them. The NPC specifically called for privacy-preserving age assurance to keep minors out of mature features and called on platforms to stop behavioral profiling that pushes violent, aggressive or unsafe content to child users.
This public advisory is a compliance reminder, not a finding that every named type of service has violated the law. It also does not impose one universal age-check method or require every service to collect a government ID. The control should be proportionate to the feature and risk, and the age-assurance process must itself follow the privacy principles.
Key Takeaways
- The Advisory covers products and services specifically intended for children and those likely to be accessed by them.
- A child is generally a person below 18, with the wider statutory definition referenced by the Advisory.
- Child Privacy Impact Assessments should be included in PIAs before launch and reviewed as the service or risks change.
- For children’s accounts, private profiles, disabled geolocation and minimized sharing are required as high-privacy defaults unless necessary for the specific purpose.
- Child-friendly notices must sit alongside the normal privacy notice; a dense adult-only policy is not enough.
Does the Child-Oriented Transparency Advisory Apply?
| Service or activity | General position | First compliance action |
|---|---|---|
| Learning app, game, school platform or youth community | Likely within the Advisory’s scope. | Conduct a Child Privacy Impact Assessment before launch. |
| General-audience platform likely used by children | Still covered where children are likely users. | Assess the actual audience, features and child-specific risks. |
| Store or event that collects child registrations or photos | Physical processing can also be covered. | Map collection, sharing, storage, notices and parent/guardian involvement. |
| High-risk profiling, location or behavioral features | Needs heightened analysis and controls. | Consider age assurance, data minimization, high-privacy defaults and whether the feature should be offered at all. |
What the Advisory Changes
NPC Advisory No. 2024-03 does not replace the DPA. It applies the DPA’s transparency, legitimate-purpose, proportionality, security and rights framework with special attention to a child’s best interests and evolving capacities. The practical shift is design: a business must consider whether a child can understand the information and controls at the moment the data is processed, not merely whether an adult can find a legal notice at the bottom of a website.
Run a Child Privacy Impact Assessment Before Launch
The Advisory requires PICs to incorporate a Child Privacy Impact Assessment as part of their PIA before launching products or services intended or likely to be accessed by children. It treats the PIA as a continuing requirement. The assessment should cover the purpose, types and sources of data, systems, storage/disposal, sharing, safeguards, impact on children, age range, responsible process owner, risks and parent/guardian involvement.
Questions the CPIA should answer
- Can the service achieve its goal with less data or without location, behavioral tracking or public profiles?
- What happens if a child shares too much, is contacted by another user, or loses account control?
- Does an AI feature profile, recommend, moderate, rank or infer information about children?
- Which features are on by default, and are those defaults safe for a child?
- When is parental or guardian involvement necessary, and how will the organization verify it proportionately?
Use High-Privacy Defaults
Children’s accounts must have privacy settings at the highest level by default. The Advisory identifies disabling geolocation, making profiles private and minimizing data sharing unless necessary for the specific purpose as examples. The user interface must also make the settings clear and easy to access, so a child can understand and control preferences while a minimum protection level remains in place.
Age Assurance and Parent/Guardian Involvement
Age assurance may be used to determine an age range and apply age-appropriate practices. The method itself processes data and therefore needs a lawful basis, data minimization and a clear explanation. The Advisory cautions that self-declaration alone may be inadequate for high-risk processing. Parent or guardian involvement may be necessary depending on the risk; the organization should decide and document a proportionate method rather than impose an unnecessary ID-collection process on every child.
Write a Notice a Child Can Actually Understand
A child-friendly privacy notice should tell the child what information is collected, why, the lawful basis, possible consequences or risks, privacy settings, rights, how to get help and when the notice changes. It should be accessible in the interface and delivered at the time a particular processing activity is about to occur. The NPC recognizes formats such as short text, video, infographics, animation and audio where appropriate. Provide the normal detailed notice as well, but do not treat it as a substitute.
Children, AI and Location Features
AI and emerging technology can amplify a child-data risk when a service profiles behavior, makes recommendations, produces inferences, processes voice or images, or tracks location. Review whether those features are necessary, whether the data is accurate, how a child or parent can question an outcome, and whether human oversight is available. For AI systems processing personal data, also apply the NPC AI Advisory.
Common Mistakes
- Designing for adults and adding a child privacy notice only after launch.
- Using “enter your birthday” as the sole safeguard for high-risk processing.
- Making a child profile, location sharing or behavioral tracking public by default.
- Using an adult-only legal policy with difficult vocabulary and no contextual explanation.
- Collecting extra parent or child identity documents without checking necessity and retention.
What apps and games should do now
| Risk area | Platform duty or control | What a parent or child can check |
|---|---|---|
| Account setup and data collection | Collect only what is necessary for a declared purpose, use an appropriate lawful basis, give a child-friendly notice and set high-privacy defaults. | Check whether the profile, contacts, photos, voice, school, location or device data are requested and why. |
| Age assurance and mature features | Use a risk-based, privacy-preserving method and restrict minors from adult features. Do not collect more age-verification data than necessary. | Record what proof is requested, which feature it unlocks, the stated purpose and the retention period. |
| Recommendations and behavioral profiling | Assess whether profiling is necessary and lawful. The NPC’s 23 September 2026 advisory calls on platforms to cease profiling that pushes violent, aggressive or unsafe content to child users. | Check the age setting, recommendation controls and whether “not interested,” reset or reporting tools change the feed. |
| Chat, location and sharing | Keep child accounts private by default, disable geolocation by default and minimize sharing unless needed for the specific purpose. | Review discoverability, direct messages, voice chat, friend requests, live location and who can view activity. |
| Rights and support | Provide an understandable route to exercise data-subject rights and to contact the responsible entity or data protection officer. | Ask for access, correction, objection, blocking or erasure where the Data Privacy Act requirements and limits apply. |
| Breach and vendors | Remain accountable for processors and safeguards. When mandatory breach notification rules apply, notify affected children and their parents or guardians in understandable language. | Save the notice, ask what data was involved and secure the account while the incident is assessed. |
Parent checklist for an app or game
- Check the child’s recorded age and privacy defaults. Review profile visibility, direct messages, friend requests, voice chat, location, advertising and recommendation controls.
- Reduce exposure first. Turn off unnecessary sharing or location, make the account private, remove unknown contacts and use the platform’s reporting tools.
- Preserve evidence before it disappears. Save screenshots or a screen recording showing the account age, settings, content, content ID or URL, timestamps and the steps taken.
- Send a specific privacy request. Use the platform’s privacy or data protection contact to ask what data is processed, why, who receives it, how long it is kept and which right you want to exercise.
- Escalate the right problem. Use the NPC route for a documented personal-data concern; use child-safety or law-enforcement channels for immediate threats, sexual exploitation, grooming or abuse.
Example: A 14-year-old joins a general-audience game. The profile and voice chat are public by default and the recommendation feed repeatedly surfaces violent content. A parent can record the age entered, the default settings and the recommendation sequence, then make the account private, report the content and send the platform a focused privacy request. The platform should assess its defaults, age assurance and profiling controls. The advisory does not guarantee a particular takedown, feed result or deletion request.
Evidence and action
| Situation | Evidence to preserve | Action | Limit |
|---|---|---|---|
| Child profile or location is public by default | Screenshots, account age, settings screen, date and app version. | Change the setting, report the default and ask the platform to explain the control. | A risky default is evidence to assess; it does not by itself prove every legal element of a violation. |
| Violent, aggressive or unsafe recommendations repeat | Screen recording, timestamps, content IDs or URLs, age setting and the sequence of interactions. | Report the content and recommendation, reset available controls and ask how profiling is used. | The NPC advisory does not promise a specific algorithmic result. |
| Age check demands identity data | The prompt, privacy notice, fields requested, purpose and stated retention period. | Ask why each item is necessary, the lawful basis, who receives it and when it will be deleted. | Age assurance can be lawful and necessary; the method must still be proportionate and privacy-preserving. |
| Access, correction or erasure request is ignored | The request, identity-verification steps, delivery proof, reply and dates. | Follow up with the platform or DPO, then assess a formal NPC complaint. | Erasure is not absolute and may be limited by lawful retention or other statutory grounds. |
| Possible data breach | Notices, emails, suspicious-login records, changed settings and exposed-data details. | Secure the account, ask what was exposed and use the breach or complaint route that fits the facts. | Not every security incident triggers mandatory notification. |
Where to complain about a child-privacy problem
Start with the platform’s privacy channel or data protection officer where it is safe and practical, state the child’s account, the processing or feature involved, the right or correction requested and the evidence attached. Keep delivery proof and the response. If the personal-data concern remains unresolved, the NPC’s current formal complaint instructions require the prescribed form, notarization and submission in person, by courier or by scanned email; check the linked fee schedule and form immediately before filing.
CyberCode’s NPC complaint guide and privacy complaint evidence guide explain the preparation steps. A privacy complaint does not replace emergency or criminal reporting where a child faces an immediate threat.
When the OSAEC and CSAEM law applies
A public profile, excessive collection, poor privacy notice or unwanted recommendation is not automatically an OSAEC case. Use the OSAEC and CSAEM guide when the facts involve online sexual abuse or exploitation of a child, grooming, sexual extortion or child sexual abuse or exploitation material. Preserve evidence without redistributing illegal material and use the appropriate child-protection or law-enforcement route as well as any privacy remedy.
Related Cybercode Guides
- Privacy Impact Assessment Philippines
- NPC AI Advisory Philippines
- Privacy Notice Requirements Philippines
- Data Privacy Act of 2012 Philippines
- Data Subject Rights Action Matrix
- How to File an NPC Data Privacy Complaint
- Evidence for a Data Privacy Complaint
- OSAEC and CSAEM Act Guide
FAQs
Does the Advisory apply only to children’s apps?
No. It also covers a product or service likely to be accessed by children, and it applies in physical as well as digital environments where children’s personal data is processed.
Must every website verify a child’s age using an ID?
No universal method is prescribed. The Advisory calls for a risk-based approach. A business should use an appropriate method for the processing and avoid collecting more information than is necessary.
Is parental consent always enough?
Parent or guardian involvement may be necessary in particular contexts, especially where risk is heightened. It does not remove the organization’s separate duties to be transparent, minimize data, secure the processing and consider a child’s best interests.
Official Sources
- NPC Public Advisory — Digital Platforms and Children’s Data, 23 September 2026
- NPC — Filing a Formal Complaint
- NPC Advisory No. 2024-03 — Guidelines on Child-Oriented Transparency
- Republic Act No. 10173 — Data Privacy Act of 2012
- NPC Circular No. 2023-04 — Guidelines on Consent
- NPC Advisory No. 2024-04 — AI Systems Processing Personal Data
Last materially reviewed: October 7, 2026. Cybercode.ph provides general educational information and is not a substitute for legal, cybersecurity or professional advice for a specific situation.

