As online safety debates intensify in Congress and across state legislatures, policymakers are increasingly grappling with how to balance privacy, personalization, and the protection of children online. Against this backdrop, the IAPP hosted its Global Privacy Summit 2026, an annual gathering of privacy and AI professionals focused on policy developments and the legal and regulatory implications of emerging technologies.
One panel, titled “Personal, Private, Protected: The Future of Youth Personalization,” brought together child development researchers, small business advocates, and privacy experts to explore how personalization and privacy can work together to support youth online. The discussion featured:
- Emily Kirstein, Child Safety Public Policy Lead, Google;
- Morgan Reed, President, Association for Competitive Technology (ACT);
- Holly Hawkins, Director of Youth Policy, Future of Privacy Forum;
- Yalda Uhls, Assistant Adjunct Professor, Founder, and Executive Director, Center for Scholars & Storytellers, University of California, Los Angeles.
Yalda Uhls opened by challenging policymakers’ tendency to treat young people as a single category. A 13-year-old and a 17-year-old have different developmental needs, just as a vulnerable child with limited family support may experience the online world differently from a well-resourced peer. Those differences matter because decisions about data and personalization ultimately shape the content, features, and experiences young people encounter. As Morgan Reed noted, privacy policy can no longer be separated from questions of content and developmental psychology. Effective policy and product design must reflect how young people’s needs and capacities change across ages and circumstances.
Designing for those differences also requires businesses to understand the broader environments in which their products appear. Holly Hawkins emphasized that personalization can rely on information users provide directly, such as during account set up, or on data inferred from their behavior, and each approach carries different risks. Morgan pointed to Nike’s storefront on Roblox as an example of how those risks can extend across platforms. Questions about data collected through Roblox raised the possibility that Nike could receive information used to personalize experiences for children under 13, potentially bringing the company within scope of the Children’s Online Privacy Protection Act (COPPA). He argued that businesses need visibility into how their products are distributed, advertised, and personalized through third parties. Without that visibility, they may struggle both to comply with privacy laws and to design experiences appropriate for the users they ultimately reach.
The discussion then shifted to how policymakers can address these risks without imposing overly broad obligations. Emily Kirstein stressed that any solution must preserve privacy and distribute responsibility appropriately across the digital ecosystem, instead of placing it on a single participant. Morgan agreed, warning against frameworks that require platforms to send age-related information to every developer. Receiving that information could give developers actual knowledge of a user’s age and trigger obligations under COPPA or state privacy laws, regardless of whether their apps are directed or marketed to children. As a result, developers could face significant compliance costs and liability without a commensurate online safety benefit.
Morgan argued that the Parents Over Platforms Act (POPA) offers a better approach. POPA would require app stores to ask users for their ages when they create an account and, with parental permission, provide age signals to developers whose products offer different experiences to minors and adults or are intended for adults only. In doing so, the framework would enable parents to protect their children from unsafe or inappropriate content without requiring excessive permission requests or imposing significant compliance costs and liability on developers whose apps pose little or no risk to online safety.
Morgan also reminded attendees that although the large majority of parents say they care about their children’s privacy, a significant percentage have circumvented parental controls. The implication for product design is significant: if a parental consent flow requires more than one or two interactions, parents may bypass it. Once that happens, the system can no longer personalize appropriately because it may begin treating a child’s account as an adult’s. Overloading parents with decisions, such as consent requests for every app download, can therefore undermine both privacy and the protective purpose of the controls.
Personalization can support online safety and children’s well-being, but only when policy reflects developmental differences, parental choices, and the risks particular products pose. Rather than imposing broad obligations on every developer, policymakers should pursue targeted approaches that empower parents, preserve privacy, and focus accountability where the risks are greatest.