Children's Online Privacy Code (Privacy Act 1988, section 26GC)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
Proposed: draft date not recorded.
An age-appropriate design code rule binding private bodies.
As of 15 July 2026.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Requires the Australian Information Commissioner to develop and register an Australian Privacy Principles code addressing the privacy of children, covering social media services, relevant electronic services and designated internet services likely to be accessed by children, within 24 months of the amending Act's Royal Assent on 10 December 2024, that is, by 10 December 2026.
An exposure draft, drawing partly on the UK Age Appropriate Design Code, was released for public consultation from 31 March to 5 June 2026 and includes proportionate age assurance and limits on retaining facial age estimation data, but the Code is not yet finalised or registered.
If you get it wrong
Penalties
A breach of the registered code will be treated as an interference with privacy under the Privacy Act 1988, subject to the Act's existing civil penalty framework.
Who enforces it
Enforcement body
Office of the Australian Information Commissioner (OAIC)
What it reaches
Covered services
Social media services, relevant electronic services and designated internet services that are likely to be accessed by children or primarily concern the activities of children, excluding health service providers.
Who checks it
Audit expectation
none
When LexLint raises it
serves_minors
Read the law
official statute text, Federal Register of Legislation
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.