57% of the 5,855 child-directed apps examined by researchers at the International Computer Science Institute (ICSI) were potentially violating the Children's Online Privacy Protection Act, according to the peer-reviewed 2018 study "Won't Somebody Think of the Children? Examining COPPA Compliance at Scale," published in Proceedings on Privacy Enhancing Technologies. Newer audits confirm the pattern has not gone away: Human Rights Watch found 89% of reviewed children's ed-tech products risked exposing student data to ad-tech networks in 2022, and Pixalate found 99% of reviewed child-directed apps still lacked verifiable parental consent in 2025.

How many apps illegally track children?

57% of the 5,855 popular, free children's apps ICSI researchers examined were potentially in violation of COPPA, mostly because of how they handled data through embedded third-party SDKs. The team did not read privacy policies; they ran each app on real devices and monitored its actual network traffic, catching violations that static analysis or policy review would miss.

57 percent of 5,855 child-directed apps studied potentially violate COPPA 57% of 5,855 child-directed apps studiedpotentially violate COPPA

The 5,855 apps came from Google Play's "Designed for Families" program, the same certification track Google uses to signal child-appropriate content to parents. Certification did not predict compliance: the paper found little difference in privacy behavior between apps certified as COPPA-compliant under industry "Safe Harbor" programs and apps with no certification at all. Two specific practices drove much of the noncompliance. First, 18.8% of apps shared persistent identifiers with third parties in ways that appeared to breach the SDK provider's own terms of service, since many ad and analytics SDKs explicitly prohibit their use in child-directed apps. Second, roughly 40% of apps shared personal information without applying reasonable security measures, meaning even data collected with some parental awareness could still leak insecurely in transit.

Share of studied apps or products flagged for risking children's data (by study) 0306090120%57ICSI 201889HRW 202299Pixalate 2025

Figure 1: Three independent studies, run seven years apart with different methods, all found a majority of the apps or products they reviewed risking children's data. Source: ICSI (2018), Human Rights Watch (2022), Pixalate (2025).

None of the three studies used identical criteria, and a single app is never guaranteed to appear in more than one sample, so these figures are not a single trend line. Taken together, though, they describe the same underlying problem from three different vantage points: automated network testing, a watchdog's manual product review, and a live compliance audit of the U.S. app stores.

How many children's apps risk exposing data to ad-tech trackers?

145 of the 163 government-endorsed educational technology products Human Rights Watch reviewed in 2022, or 89%, appeared to engage in data practices that put children's rights at risk. HRW's technical analysis, conducted between March and August 2021 and verified again that November, covered products used by children for remote schooling across 49 countries during the Covid-19 pandemic.

Government-endorsed ed-tech products reviewed by Human Rights Watch, 2022 8911Flagged as risking children's data89Not flagged11

Figure 2: Nearly nine in ten reviewed products showed data practices that risked or infringed children's rights. Source: Human Rights Watch, "How Dare They Peep into My Private Life?" (May 2022).

The report found that these products directly sent or granted access to children's personal data to 196 third-party companies, and the overwhelming majority of those recipients were ad-tech firms rather than the educational partners a parent or teacher might expect. Because the products HRW reviewed were endorsed by national governments for remote learning, a family had little practical choice about whether to use them once schools adopted them, which is part of why the report treated the finding as a rights violation rather than an ordinary commercial data-sharing dispute.

Do major social platforms protect children's data adequately?

The FTC's September 2024 report, "A Look Behind the Screens: Examining the Data Practices of Social Media and Video Streaming Services," examined 9 major social media and video-streaming companies under 6(b) study orders. The report found that most of the companies studied had no data protections specific to teenage users and, in several cases, could not reliably confirm which of their users were under 13 despite minimum-age policies that should have excluded them.

Figure 3: The core test regulators and researchers apply to decide whether an app's tracking is illegal under COPPA. Source: FTC COPPA guidance and ICSI's 2018 methodology.

The FTC's 6(b) orders compelling this review were originally issued in December 2020, so the September 2024 findings reflect several years of platform data practices rather than a single snapshot. Age verification came up as a recurring weak point: several companies relied on self-reported birthdates at signup with no further check, an approach the report found does little to keep users under 13 off services designed for teens and adults. A privacy policy generator with COPPA-specific disclosures is the fastest way for a smaller app or site to confirm its own age-gating and consent language matches what regulators are now scrutinizing at the largest platforms.

How much have regulators fined apps for illegal child tracking?

The FTC's $275 million civil penalty against Epic Games in December 2022 remains the largest COPPA-specific fine on record, issued after the agency found Fortnite collected data from players under 13 without parental notice or consent. That case sits inside a longer run of enforcement stretching back to 2019, detailed alongside device-ownership and teen social media data in our full children's online privacy breakdown.

Figure 4: Academic research, watchdog audits, and FTC enforcement have moved in the same direction for nearly a decade. Source: ICSI (2018), FTC press releases (2019-2024), Human Rights Watch (2022), Federal Register (2025).

Enforcement has broadened past the largest social platforms too, reaching anonymous messaging apps and ad-tech data sharing, which suggests regulators increasingly treat undisclosed tracking itself, not just headline data breaches, as the violation worth penalizing.

What is changing about illegal child-tracking enforcement in 2026?

The amended COPPA Rule, published in the Federal Register on April 22, 2025 and effective June 23, 2025, carries a full compliance deadline of April 22, 2026. The amendment adds a requirement for separate parental consent before a child's data is shared with a third party, directly targeting the SDK-sharing pattern ICSI's 2018 research first quantified at scale.

Figure 5: ICSI's 5,855-app sample is the largest of the three studies but reported the lowest share flagged; Pixalate's smaller, narrower 2025 audit found the highest. Source: ICSI (2018), Human Rights Watch (2022), Pixalate (2025).

Study or reportSample reviewedShare flaggedYear
ICSI, "Won't Somebody Think of the Children?"5,855 child-directed apps57% potentially violate COPPA2018
Human Rights Watch163 ed-tech products, 49 countries89% (145 products) risked children's rights2022
Pixalate1,149 child-directed apps99% lacked verifiable parental consent2025
FTC, "A Look Behind the Screens"9 major social/video platformsMost lacked teen-specific protections2024

The Bottom Line

Three independent research efforts, run seven years apart by an academic lab, a human rights watchdog, and a commercial ad-fraud auditor, all landed on the same conclusion: a majority of the apps and platforms children actually use collect or share data in ways that likely violate COPPA. The mechanism keeps repeating across every study, too: it is rarely the app's own code doing the tracking, but a bundled third-party SDK the developer may not have fully vetted. With the amended COPPA Rule's compliance deadline arriving April 22, 2026 and adding a separate consent requirement before any child's data reaches a third party, any site or app that might reach an under-13 audience should audit its embedded SDKs now rather than after a regulator or researcher finds the gap first. Building the underlying disclosures with a COPPA-aware privacy policy generator is the fastest way to close that gap before it becomes an enforcement action.

Frequently Asked Questions

What percentage of apps illegally track children? 57% of the 5,855 popular, free children's apps analyzed by researchers at UC Berkeley's International Computer Science Institute were potentially violating COPPA, primarily through third-party SDKs, according to the peer-reviewed 2018 study "Won't Somebody Think of the Children?"

How many ed-tech products did Human Rights Watch find risked children's privacy? 145 of 163 government-endorsed educational technology products (89%) reviewed by Human Rights Watch in 2022 appeared to engage in data practices that risked or infringed children's rights, and the products contacted 196 third-party companies, overwhelmingly ad-tech.

Has the FTC investigated major social media platforms over children's data? Yes. The FTC's September 2024 report "A Look Behind the Screens" examined data practices at 9 major social media and video-streaming companies under 6(b) orders and found most lacked protections specific to teens and could not reliably verify which users were under 13.

What is the compliance deadline for the updated COPPA Rule? April 22, 2026 is the compliance deadline for the amended COPPA Rule, which the FTC published in the Federal Register on April 22, 2025 with an effective date of June 23, 2025, adding a separate parental-consent requirement before sharing a child's data with third parties.

Where the Numbers Come From

  1. Reyes, Wijesekera, Reardon, Elazari Bar On, Razaghpanah, Vallina-Rodriguez, and Egelman. (2018). "'Won't Somebody Think of the Children?' Examining COPPA Compliance at Scale." Proceedings on Privacy Enhancing Technologies, 2018(3), pp. 63-83. Dynamic analysis of 5,855 popular free children's apps from Google Play's Designed for Families program; 57% found potentially violating COPPA.
  2. Human Rights Watch. (2022). "How Dare They Peep into My Private Life?: Children's Rights Violations by Governments That Endorsed Online Learning During the Covid-19 Pandemic." Reviewed 163 ed-tech products across 49 countries; technical analysis conducted March to August 2021, verified November 2021, published May 25, 2022.
  3. Federal Trade Commission. (2024). "FTC Staff Report Finds Large Social Media and Video Streaming Companies Engaged in Vast Surveillance of Users." Findings from 6(b) orders issued to 9 companies in December 2020, published September 19, 2024.
  4. Pixalate. (2025). "Verifiable Parental Consent (VPC) Failures in Mobile Apps Report, Q2 2025." 1,136 of 1,149 manually reviewed likely child-directed apps lacked VPC, published September 30, 2025.
  5. Federal Trade Commission. (2022). "Fortnite Video Game Maker Epic Games to Pay $520 Million to Resolve FTC Allegations It Violated Children's Privacy Law and Duped Users into Making Unwanted Charges." $275 million COPPA-specific civil penalty, announced December 19, 2022.
  6. Federal Register. (2025). "Children's Online Privacy Protection Rule." Final amendments published April 22, 2025, effective June 23, 2025, compliance deadline April 22, 2026.

Note: All figures verified as of August 2026. The ICSI and Human Rights Watch findings describe potential violations identified through independent research rather than adjudicated legal findings, and no single app or product is known to appear in more than one of the three studies compared here. Illegal child-tracking statistics are refreshed at least twice a year to track new Pixalate quarterly reports and FTC enforcement actions.