Math Challenge
More

Children's Privacy and Data Protection Law for Math Challenge

mc-25 · Published: · by Math Challenge Research · 3,764 words · 20 cited sources

Executive summary

The pattern holds across all ten jurisdictions: a child's own consent is not enough, and below a threshold age it isn't solicited at all — an adult must consent, verifiably, not via checkbox. The US (COPPA) requires verifiable parental consent (VPC) under 13; the Rule was amended effective June 23, 2025, general compliance due April 22, 2026: it broadens "personal information" (adds biometrics), requires a written retention policy, and requires separate consent before third-party disclosure for advertising [7][8]. The EU sets digital consent at 16 by default (GDPR Art. 8), lowerable to a floor of 13 per member state — Spain 14, France 15 (reinforced since January 1, 2026), Germany/Ireland 16, Portugal 13 [1][12]. The UK keeps 13 and layers the ICO's Children's Code on top: 15 design standards, in force since 2020 [5]. Brazil's LGPD Art. 14 requires specific, highlighted parental consent, bars conditioning play on excess data, and requires verification "using available technologies" — full text obtained from the official translation [3]. Mexico dissolved INAI (reform published December 2024, implementing law March 2025); the Secretaría Anticorrupción y Buen Gobierno absorbed data-protection oversight, a transition too recent to have a tested posture on children's data [unverified]. Quebec sets 14; federal Canada has no numeric statutory age [unverified]. The Student Privacy Pledge was retired April 25, 2025 — no longer available [15]. A leaderboard alias remains personal data as long as Math Challenge keeps the alias→identity mapping (GDPR Recital 26).

240 words

This document was written in English. It is published here in full, unedited.

Verification status

Claims in this document that the author could not confirm against a primary source, flagged in the text and repeated here:

  1. This is research, not legal advice. A licensed lawyer in each target jurisdiction should confirm every claim below before launch, especially anything flagged [unverified].
  2. México disolvió el INAI (reforma de diciembre 2024, legislación de marzo 2025); la Secretaría Anticorrupción y Buen Gobierno absorbió la función de protección de datos, cambio tan reciente que su aplicación a menores sigue sin probarse [unverified].
  3. Quebec fija 14 años; Canadá federal no tiene umbral numérico en la ley [unverified].
  4. Mexico dissolved INAI (reform published December 2024, implementing law March 2025); the Secretaría Anticorrupción y Buen Gobierno absorbed data-protection oversight, a transition too recent to have a tested posture on children's data [unverified].
  5. Quebec sets 14; federal Canada has no numeric statutory age [unverified].
  6. Secondary reporting says 2025 adds knowledge-based-question and "text-plus" methods, but the exact CFR subsection was not independently confirmed [unverified].
  7. The UK kept 13 under DPA 2018 §9 post-Brexit (stable, widely reported, not re-fetched this session) [unverified].
  8. The LFPDPPP (2010) requires clear privacy notices and, per general civil-capacity doctrine, parental/legal-representative consent for a minor's data — it does not appear to contain a GDPR/LGPD-style dedicated children's-data article; this was not confirmed against the current consolidated text [unverified].
  9. Federal PIPEDA has no numeric consent age in the statute; OPC "meaningful consent" guidance is understood to treat a young child's own consent as generally not meaningful, evaluated contextually — not independently confirmed this session [unverified].
  10. For US transfers, the EU-US Data Privacy Framework adequacy decision (July 2023) is the relevant mechanism — stable, well-documented, but not re-verified live this session [unverified this session, high training-knowledge confidence].
  11. No explicit statutory age found [unverified]
  12. No numeric age [unverified]

[unverified] means the claim is stated in the research but was not confirmed against a primary source in the session that produced it. It is published rather than removed, because a research corpus that hides its gaps is not verifiable.

How this research was produced

The 47 documents were produced on 2026-07-31 by independent agents, each instructed not to invent citations and to flag as [unverified] anything it could not confirm against a primary source. The session's web-search quota ran out mid-way, and later agents worked by direct fetch against primary sources. Several sites (ftc.gov, ico.org.uk) block automated fetching, which is why certain legal claims are flagged on purpose.

Findings

United States — COPPA and the 2025 amended Rule

COPPA (15 U.S.C. §§6501–6506; 16 CFR Part 312) covers operators of services “directed to children” under 13, or with actual knowledge of collecting from a child under 13. The FTC’s amendments were announced January 2025, published in the Federal Register April 22, 2025 (Doc. 2025-05904), effective June 23, 2025, general compliance due April 22, 2026 (safe-harbor programs face shorter 90-day/6-month deadlines) [6][7][8]. Direct fetches of ftc.gov and federalregister.gov were blocked (403/bot-gate) this session; these dates are cross-confirmed across five independent law-firm summaries citing the same Federal Register document [8].

What changed: (1) “personal information” now explicitly includes biometric identifiers (fingerprints, retina, gait, facial/voice data) and government IDs; (2) a refined “mixed audience” category lets a general-audience service collect limited data pre-screening for specific purposes (parental consent, internal operations); (3) operators must name which third parties receive a child’s data and why, and get separate VPC before disclosing to third parties (e.g., targeted advertising) unless integral to the service; (4) a written data-retention policy is mandatory — no indefinite retention; (5) a written, size/sensitivity-scaled information-security program is mandatory [8]. Pre-existing accepted VPC methods (16 CFR §312.5(b)): signed form, card charge, staffed toll-free call, staffed video conference, government-ID-plus-live-photo match (approved Nov. 19, 2015). Secondary reporting says 2025 adds knowledge-based-question and “text-plus” methods, but the exact CFR subsection was not independently confirmed [unverified]. A 2025 report also noted the incoming FTC Chair had flagged parts of the rule for review — re-check the compliance calendar at implementation time.

European Union — GDPR Article 8 and member-state ages

Article 8 sets the default self-consent age at 16 for information-society services offered directly to a child; below that, consent must be “given or authorised by the holder of parental responsibility,” verified through “reasonable efforts… taking into consideration available technology.” States may lower this to a floor of 13 [1][2]. Commonly published national thresholds (cross-checked against multiple trackers, not individually re-verified per gazette — confirm before relying on any single figure): Austria 14, Belgium 13, Bulgaria 14, Croatia 16, Cyprus 14, Czech Republic 15, Denmark 13, Estonia 13, Finland 13, France 15, Germany 16, Greece 15, Hungary 16, Ireland 16, Italy 14, Latvia 13, Lithuania 14, Luxembourg 16, Malta 13, Netherlands 16, Poland 16, Portugal 13, Romania 16, Slovakia 16, Slovenia 15, Spain 14, Sweden 13. France was independently confirmed live: CNIL requires both child and parental consent under 15, reinforced by a “majorité numérique” law fully effective January 1, 2026 [12]. Since Math Challenge is parent-first — the child never independently consents — this split mainly affects future self-serve eligibility, not v1.

United Kingdom — Age Appropriate Design Code and UK GDPR

The UK kept 13 under DPA 2018 §9 post-Brexit (stable, widely reported, not re-fetched this session) [unverified]. The ICO’s Age Appropriate Design Code applies to any service “likely to be accessed by children” in the UK, in force since September 2, 2020 (12-month transition before enforcement). Its 15 standards (cross-confirmed via a secondary legal summary of the ICO’s own list; direct ico.org.uk fetch blocked, 403) [5]: (1) Best interests of the child; (2) Age-appropriate application; (3) Transparency; (4) Detrimental use of data; (5) Policies and community standards; (6) Default settings (max privacy); (7) Data minimisation; (8) Data sharing; (9) Geolocation (off by default); (10) Parental controls; (11) Profiling (off by default); (12) Nudge techniques (prohibited); (13) Connected toys and devices; (14) Online tools; (15) Data protection impact assessments. The UK Online Safety Act 2023 may separately impose age-assurance duties depending on how leaderboard/community surfaces are categorized — not verified this session, check Ofcom guidance before UK launch.

EU Digital Services Act — minors and profiling-based advertising

The DSA (Regulation 2022/2065) became generally applicable February 17, 2024 (VLOPs/VLOSEs earlier) [10]. Article 28 addresses “online protection of minors,” requiring appropriate privacy/safety measures; a widely reported provision (conceptually confirmed via the European Parliament’s January 20, 2022 amendments introducing “a ban on using a minor’s data for targeted ads” — EUR-Lex article-level text was not retrieved live, returning empty content on two attempts) prohibits profiling-based advertising to a user the platform reasonably knows is a minor [10][9]. Confirm the exact article/paragraph against EUR-Lex before citing it as law — the substance is high-confidence, the precise citation is not.

California — Age-Appropriate Design Code Act and its litigation

AB 2273 (2022) requires a DPIA before offering features likely accessed by children, high-privacy defaults, no dark patterns, and no data use “materially detrimental” to a minor. NetChoice v. Bonta (filed N.D. Cal., December 2022) produced a preliminary injunction on First Amendment grounds targeting the DPIA/reporting requirement; the Ninth Circuit’s August 2024 opinion affirmed that injunction specifically while vacating and remanding other provisions for severability analysis — some provisions enjoined, others arguably enforceable. Later secondary reports (a related NetChoice challenge to SB 976’s “addictive feeds” provisions, district court ruling December 2024, Ninth Circuit decided September 2025; and a further Ninth Circuit ruling around March 2026 “narrowing” a preliminary injunction) could not be reconciled into one consistent timeline this session [11]. This is genuinely unsettled, actively-litigated law — do not hard-code compliance against a specific CAADCA provision without counsel confirming current enforceability.

Mexico — LFPDPPP and the 2025 post-INAI reform

The LFPDPPP (2010) requires clear privacy notices and, per general civil-capacity doctrine, parental/legal-representative consent for a minor’s data — it does not appear to contain a GDPR/LGPD-style dedicated children’s-data article; this was not confirmed against the current consolidated text [unverified]. Better corroborated: a constitutional reform eliminating several autonomous bodies including INAI was published in the Diario Oficial de la Federación in December 2024, with implementing legislation in March 2025; the Secretaría Anticorrupción y Buen Gobierno absorbed INAI’s data-protection function, while a new body, “Transparencia para el Pueblo,” took access-to-information functions [13]. This transition is too recent to have a mature enforcement posture on children’s data specifically.

Brazil — LGPD Article 14

Full official-translation text was obtained directly [3]. Processing of children’s/adolescents’ data must serve their best interest (caput); requires specific, highlighted consent from at least one parent or legal representative (§1); controllers must publicly disclose data types, use, and rights procedures (§2); collection without that consent is allowed only to contact the parent, used once and not stored, or for the child’s protection, and may never reach third parties without §1 consent (§3); controllers must not condition participation in games/apps on data beyond what’s strictly necessary (§4); controllers must use all reasonable efforts, “considering available technologies,” to verify the consent-giver is really the representative (§5); information must be presented simply and accessibly, accounting for the child’s characteristics, with audiovisual aids where useful (§6). This is the most directly quotable, detailed children’s-data clause found, mapping closely onto COPPA’s “cannot condition participation” rule and both GDPR/LGPD’s verification-effort standard.

Canada — PIPEDA and Quebec’s Law 25

Federal PIPEDA has no numeric consent age in the statute; OPC “meaningful consent” guidance is understood to treat a young child’s own consent as generally not meaningful, evaluated contextually — not independently confirmed this session [unverified]. Quebec’s Law 25 is concrete and was confirmed live: personal information about a minor under 14 may not be collected from the minor without consent from the person with parental authority or the tutor, subject to a “clear benefit to the child” exception. It phased in September 2022 through a final September 2024 phase (including a data-portability right); penalties reach C$10 million or 2% of global revenue.

Classroom mode — FERPA and the (retired) Student Privacy Pledge

FERPA (20 U.S.C. §1232g; 34 CFR Part 99) gives parents rights to access, amend, and control disclosure of a child’s “education records,” transferring to the student at 18/postsecondary [16]. It binds federally-funded schools, not vendors directly — a vendor like Math Challenge typically becomes bound only through the “school official” exception (34 CFR §99.31(a)(1)(i)(B)), requiring direct school control over records use, ordinarily via a data-processing agreement with each school/district; a teacher’s in-app class code alone does not establish that (subsection not re-verified live, check before contract use). Importantly: the Student Privacy Pledge, the ed-tech FERPA-alignment self-certification, was retired by the Future of Privacy Forum on April 25, 2025 after ten years; FPF kept a public signatory list through July 31, 2025, but accepts no new signatories, and past signatories remain bound only for data collected during their signatory period [15]. Treat any “Student Privacy Pledge” claim as stale.

VPC mechanics, data minimization, aliases, international transfer

VPC cost: in-house baseline methods carry friction/per-transaction cost; specialized vendors (PRIVO, Yoti, k-ID) sell per-verification consent-as-a-service — pricing was not obtained this session, get direct quotes before budgeting. Data minimization appears near-identically everywhere: LGPD Art. 14 §4 and COPPA’s §312.7 both bar conditioning participation on excess data; GDPR Art. 5(1)(c) states the general principle. Leaderboard aliases are personal data as long as Math Challenge (the controller) keeps the alias→identity mapping — GDPR Recital 26 treats reversible pseudonymisation as information on an identifiable person, regardless of whether an outside viewer can re-identify anyone. International transfer / Cloudflare edge: R2 supports binding a bucket to an EU jurisdiction (or FedRAMP) at creation, fixed thereafter, via jurisdiction-specific S3 endpoints [17]. D1 gained an equivalent per-database jurisdiction setting (November 2025 release), alongside non-binding location hints since 2023 [19]. Cloudflare’s enterprise-only Data Localization Suite (Geo Key Manager, Customer Metadata Boundary, Regional Services) adds network/metadata-level residency but requires a paid enterprise sales relationship [17]. Workers KV’s residency story was not confirmed (its docs page 404’d) — verify directly with Cloudflare before storing EU/UK child PII there. For US transfers, the EU-US Data Privacy Framework adequacy decision (July 2023) is the relevant mechanism — stable, well-documented, but not re-verified live this session [unverified this session, high training-knowledge confidence].

Obligations matrix

JurisdictionConsent ageConsent method requiredRetention ruleMust NOT do
US — COPPA (eff. 2025-06-23)Under 13VPC (signed form, card charge, staffed phone/video, gov-ID+photo match, or FTC-approved novel method); separate consent before third-party disclosure for adsWritten retention schedule; no indefinite retentionCondition play on excess data; disclose to third parties without separate consent; skip written security program
EU — GDPR Art. 816 default, 13–16 per state (ES 14, FR 15, DE/IE 16, PT 13)Parental consent, “reasonable efforts” to verifyStorage limitation (Art. 5(1)(e))Rely on a child’s own consent below the applicable national age
UK — AADC + UK GDPR13 (DPA 2018 §9)Parental consent below 13; AADC’s 15 standards apply regardless once “likely accessed by children”Data minimisation (standard 7)Profiling, geolocation, or nudge techniques by default
California — CAADCANo single numeric age; DPIA covers under-18 broadlyDPIA + high default privacy (no new consent mechanic per se)N/A (privacy-by-design, not retention statute)Dark patterns; default profiling; data use “materially detrimental” to a minor — parts currently enjoined; confirm enforceability
Mexico — LFPDPPP (post-2025)No explicit statutory age found [unverified]General consent + civil-capacity doctrine implies parental consentGeneral “necessary for purpose”Not established with confidence — get Mexican counsel review
Brazil — LGPD Art. 14No numeric age statedSpecific, highlighted parental/guardian consent; reasonable verification effortDeletion once purpose fulfilled (Art. 15/16)Condition participation on excess data (§4); disclose to third parties without §1 consent
Canada federal — PIPEDANo numeric age [unverified]Contextual; parental consent expected for young childrenGeneral “as long as necessary”Rely on a young child’s own consent as meaningful
Quebec — Law 2514Parental/tutor consent under 14General “necessary,” data-portability right (Sept. 2024 phase)Collect from under-14 minor directly without consent, absent clear-benefit exception
Classroom / FERPAN/ASchool-official relationship needs a direct-control agreement, not just a class codeMirror school’s own retention policy contractuallyRely on the retired Student Privacy Pledge as a compliance signal

Design implications for Math Challenge

  1. Parent-first account creation only — no independent child sign-up flow anywhere, satisfying COPPA/GDPR Art. 8/LGPD Art. 14 simultaneously.
  2. Standardize on one VPC method. Start with an FTC-listed baseline (signed form or card charge); reconsider a safe-harbor vendor (PRIVO/Yoti/k-ID) once volume justifies the recurring per-verification fee. Do not build a custom age-estimation model — that needs the FTC’s §312.12 approval process.
  3. Minimum child-profile fields: nickname, birth year+month or age band, no photo, no school name unless classroom-linked, no phone number. Never ask the child for ID; only the parent, only via the chosen VPC method.
  4. Treat leaderboard aliases as personal data internally (GDPR Recital 26). Auto-generate from a word list, allow regeneration, never place a real name adjacent to an alias publicly.
  5. Default every leaderboard to classroom/family scope, not global-public; gate any global board behind a separate per-child parental opt-in.
  6. No profiling, no behavioral ad-tech, no third-party analytics against child profiles. Satisfies DSA Art. 28, matches CAADCA’s intent despite its unsettled litigation, and sidesteps COPPA-2025’s separate third-party-disclosure-consent requirement by never triggering it.
  7. Publish an internal written data-retention schedule now, ahead of COPPA-2025’s compliance date: deletion timeline after parent-initiated removal, inactive-account soft-delete with prior notice, immediate classroom-membership deletion on withdrawal.
  8. Maximum-privacy defaults: leaderboard participation off by default, no geolocation beyond country/locale, no profiling, no compulsion-framed engagement nudges.
  9. Separate the two classroom-mode consents: (a) parent consent for a specific classroom join, revocable anytime; (b) any data flow to the school itself needs its own FERPA school-official agreement — a class code alone doesn’t establish it.
  10. Do not use the Student Privacy Pledge as a trust signal — retired April 25, 2025. Use a currently-maintained certification or direct district contract language instead.
  11. Jurisdiction-pin EU/UK data at signup time via R2’s eu bucket jurisdiction and D1’s per-database jurisdiction setting — both fixed at creation, so the decision must happen at signup, not be backfilled. Verify KV’s residency story directly with Cloudflare first.
  12. Don’t rely on Cloudflare’s enterprise Data Localization Suite as the compliance boundary at current scale — it’s a paid add-on; R2/D1 jurisdiction pinning is the free-tier control that should carry the actual weight.
  13. Localize the digital-consent-age check by the parent’s declared country rather than one hardcoded number — relevant mainly for a future teen self-serve tier, since v1 never asks a child to consent themselves.
  14. Never condition basic play on data beyond what free play needs (LGPD Art. 14 §4, COPPA §312.7) — anything extra must be optional and tied to a specific parent-facing feature it unlocks.

Highest-risk decisions the owner must make

Open questions for the project owner

  1. Support a “teen self-serve” tier at the local digital-consent age before v1, or defer to v2?
  2. Is a global public leaderboard a hard product requirement, or is classroom/family scope sufficient for launch?
  3. What is the initial launch market order — it determines whether CAADCA litigation, Mexico’s transition, or Quebec’s Law 25 becomes the first hard deadline?
  4. Budget for a paid VPC vendor at launch, or DIY signed-form/card-charge flow with vendors revisited post-traction?
  5. Will classroom mode target schools/districts directly (needing a DPA template) or stay informal (teacher-generated class codes only) for now?
  6. Jurisdiction-pin EU/UK data for every family from day one, or only once a customer contractually requires it?

Sources

  1. GDPR Article 8 full text (mirror), gdpr-info.eu
  2. Regulation (EU) 2016/679 (GDPR), consolidated text, EUR-Lex
  3. LGPD, official English translation (Rennó Penteado Sampaio Advogados, as amended by Law 13,853/2019)
  4. Quebec Law 25, official text
  5. ICO Age Appropriate Design Code ("Children's Code")
  6. FTC press release, January 2025 COPPA Rule amendments
  7. Federal Register, "Children's Online Privacy Protection Rule," Doc. 2025-05904, April 22, 2025
  8. Skadden, "FTC Finalizes Long-Awaited Child Online Privacy [Rule Amendments]," January 2025
  9. Regulation (EU) 2022/2065 (Digital Services Act), EUR-Lex
  10. Wikipedia, "Digital Services Act"
  11. Synthesis of NetChoice v. Bonta litigation history
  12. CNIL guidance on minors' digital consent age (France)
  13. Reporting on Mexico's constitutional reform dissolving INAI (Diario Oficial de la Federación, December 2024) and the Secretaría's assumption of data-protection functions (March 2025) — [Secondary aggregation of a primary gazette event]; dof.gob.mx not independently fetched (TLS/certificate error)
  14. U.S. Department of Education, Student Privacy Policy Office, "What is FERPA?"
  15. Future of Privacy Forum, Student Privacy Pledge retirement notice
  16. FERPA statutory/regulatory citation: 20 U.S.C. §1232g; 34 CFR Part 99 (see #14) — not independently re-fetched in full text this session
  17. Cloudflare, "Data Localization Suite" documentation
  18. Cloudflare, R2 "Data location" reference
  19. Cloudflare, D1 platform release notes (jurisdiction feature, November 2025)
  20. Wikipedia, "Children's Online Privacy Protection Act"

Open questions this document leaves for the owner

These are unanswered on purpose. They are listed, not resolved — turning them into a FAQ would mean inventing answers the document does not contain.

One of 51 research documents, 168,346 words in total, counted at build time from the files themselves. Read this document in the repository