Cyberspace has become an integral part of children's lives. From online learning and social media entertainment, to gaming and accessing digital health services, children are generating and sharing vast amounts of personal data. However, children often lack awareness of the risks associated with collecting, using, and sharing this data, leading to problems such as misuse of information, targeted advertising, or even cybersecurity threats. Therefore, the protection of children's personal data in cyberspace has become a top priority in international legal frameworks.

In this article, we will focus on analyzing and comparing the regulations that protect children's personal data in four representative regions: Europe (with the General Data Protection Regulation - GDPR), Singapore (Personal Data Protection Law - PDPA and Personal Data Protection Commission - PDPC guidelines), China (Personal Information Protection Act - PIPL and related regulations), and the United States (specialized laws such as COPPA for the online environment, FERPA for education, and HIPAA for healthcare). The article will also focus on some specific areas such as online platforms, education, healthcare, social media, and online games.
1. Online platforms (Internet services, websites, applications)
Online platforms are the most common environment where children's personal data is collected, from registration information to behavioral data. Regulations in different regions emphasize the need for parental consent and special protection for children, but there are differences in age and strictness.
In Europe, the GDPR defines children as generally under the age of 16, but allows member states to lower the age of children to no less than 13[1]. If the online service processes data based on consent, consent is required from the person responsible for custody of the child under the prescribed age. The GDPR emphasizes that children need special protection because there is little awareness of risks, so data collection must be transparent, limited to the extent necessary, and prohibited from being used for targeted advertising or personal profile building. From 2024, the EU will also ban major platforms from running ads based on the personal data of[2] minors. Violations can result in administrative fines of up to €20 million or 4% of global revenue, with cases involving children being considered aggravating circumstances.
Singapore applies the PDPA, which considers children under the age of 18, but clearly distinguishes that children under 13 always need parental consent, while 13-17-year-olds can give their own consent if they understand the consequences. Children's data is considered sensitive, requires higher protection, with the principle of minimizing collection and prioritizing safety[3]. For example, the default account is private, disabling location, forcing organizations to set up "Privacy by Design" measures such as easy-to-understand language and parental monitoring features. In case of violation, organizations may be subject to a violation penalty of up to S$1 million or 10% of annual revenue, accompanied by a request to stop data collection or deletion.
China through the PIPL defines children under the age of 14 as needing special protection, considering their data to be highly sensitive. Parental consent is required prior to data processing, accompanied by specialized safeguards and parental identity verification. Data collection is strictly controlled, only for lawful purposes, and parents have the right to withdraw their consent or request deletion. Violations are subject to heavy fines of up to 50 million RMB or 5% of revenue, which can be suspended or criminally prosecuted[4].
In the United States, COPPA applies to children under the age of 13, requiring "verifiable consent" from a parent through a digital signature, phone, or form before collecting, using, or sharing data. The website/app must have a clear privacy policy, collect only the necessary information, and allow parents to check/delete the data. Do not condition participation by mandating the provision of irrelevant data. Fines of up to about $53,000 per violation per child, with serious violations such as the case of YouTube's violation of child data collection, the fine is up to $170 million in 2019[5].
There is a huge similarity between regions in the protection of children's data is the central and important role of parents and the principle of minimizing children's data when collecting and processing. However, COPPA fixes the age under 13 and focuses on verification, while the GDPR is more flexible in terms of age but prohibits ads specifically targeting children. The PIPL and PDPA consider children's data sensitive, resulting in tighter controls than the US.
2. Education (schools, student data)
In the education sector, student data protection focuses on academic records, achievements, and personal information. The regulations are intended to ensure that the data is only for educational purposes, with parental control.
Europe applies the GDPR to students under the age of 18, and parental consent is not required for educational activity necessary based on a public duty or legitimate interest, but consent is required if the data is disclosed. Student data must be handled transparently, for limited purposes, and not for commercial use. The fines are similar to the general GDPR penalties, but public schools are usually only required to remedy them.
Singapore considers students under the age of 18 to be children, recommending parental consent even for 13-year-olds in education. The school must comply with the PDPA such as limiting use, high security, and not disclosing to third parties unless authorized. Fines of up to S$1 million or 10% of revenue for data disclosure.
China defines adolescents under the age of 18, with data under 14 as sensitive under the PIPL. Schools must protect information in accordance with the Law on the Protection of Minors and not disclose sensitive achievements. Parents agree to share outside, with enhanced security measures. Penalties according to PIPL, accompanied by educational discipline.
The U.S. has FERPA that applies to students at schools that receive federal funds, the control of which passes from parents to students at age 18. Written consent is required to share educational records outside, except in the case of students transferring schools. "Contact information" may be published if there is no objection. If the school uses the online service for students under 13, it can represent consent under COPPA, but not use the data for commercial purposes.

3. Social media
Social networks such as Facebook, TikTok, Instagram contain high risks with children's data.
In Europe, the GDPR requires parental consent for children under 13-16. Social media platforms must design default safety such as high privacy requirements, disable location. Advertising based on data collected by children under 18 is prohibited under the DSA. Violations will result in fines of large amounts such as Instagram being fined €405 million by the European Commission in 2022 for violations in collecting children's data.
Singapore: PDPC recommends default protection for children under 18. Parental consent for under 13. Penalties under the PDPA.
China: "Teen" mode for under 18, identity authentication, feature limit for under 14. Agree to guardianship for posting content. Fines and revocation of licenses for violations.
United States: COPPA prohibits under 13 unless there is parental consent; most social media bans under 13. Some states prohibit the sale of data under 16. Fines like TikTok 5.7 million USD in 2019.
4. Online games
Online games not only collect children's behavioral data, but also require entering other personal information such as residential addresses, schools, and personal phone numbers/relatives. Therefore, personal data protection requirements are similar to other areas.
Europe requires parental consent for children under the age of 13, limiting advertising intended to target children. Meanwhile, Singapore applies the PDPA, which requires parental consent for young children to participate in online games, clearly informing the scope of collecting children's personal data. China requires real-name authentication, restricts playing time under 18 from 1-2 hours a day, and prohibits video games that require children to make a deposit if they are under 8 years old. In the United States, COPPA does not allow online games targeting children under 13, along with other strict requirements to ensure children's safety in cyberspace.
5. Experience for Vietnam
Regulations in Europe, Singapore, China and the United States all emphasize parental consent, the principle of minimizing data collection and storage for special protection for children, reflecting the common goal of reducing online risk for vulnerable groups. The requirements of these countries are quite similar, including a requirement to classify sensitive children's data as a parental center, and a ban on the use of children's information in unnecessary commercial activities. The difference lies in the approach if the EU is flexible and inclusive, the US with clear verification requirements within the scope of the collection and processing of children's data, then Singapore offers practical guidelines for enforcement.
For Vietnam, the first lesson is the need to develop an in-depth law on the protection of children's data online, similar to PIPL or COPPA, with a clear definition of age, such as under 14 like China, and the requirement for parental consent. Article 24 of Vietnam's Personal Data Protection Law 2025 also requires that the exploration and processing of children's data be limited to the consent of the child and the child's legal representative. However, regarding the determination of the age of children, this Law has not mentioned it. Second, Vietnam can learn from the EU and Singapore about "Privacy by Design" – which requires a default safe design platform for children, such as high privacy mode and disabled tracking. Third, apply strict sanctions in violations of children's data processing as a deterrent. Fourth, authorities need to empower parents to access their children's data in schools/health so that they can monitor and protect data and children from threats from the internet environment. Finally, Vietnam should cooperate internationally to handle cross-border platforms, avoiding non-compliant children accessing foreign services. The application of these lessons will help Vietnam create a safer online environment for the younger generation, promoting sustainable digital development in the coming time.
Protecting children's personal data in cyberspace is a global challenge that requires a balance between innovation and rights. The provisions of the Law on Personal Data Protection 2025 are not really complete for regulations on children's data protection. We hope that in the guiding Decree that will be issued in the near future, the contents related to the protection and handling of violations in the process of collecting and processing children's data will be clarified with detailed and effective regulations. Because only when children are well protected can the digital society be truly sustainable and fair.
[1] https://gdpr-info.eu/art-8-gdpr/ , accessed on 20/08/2025.
[2] https://commission.europa.eu/news-and-media/news/new-rules-protect-your-rights-and-activity-online-eu-2024-02-16_en, updated on 20/08/2025.
[3] https://www.pdpc.gov.sg/-/media/files/pdpc/pdf-files/advisory-guidelines/advisory-guidelines-on-the-pdpa-for-children's-personal-data-in-the-digital-environment_mar24.pdf, accessed 20/08/2025.
[4] https://www.twobirds.com/en/insights/2024/china/china-strengthens-the-protection-of-minors-in-cyberspace, accessed on 2025/08/20.
