97% of the most popular kids' tech and edtech products disclosed collecting personal data from users in 2021, according to Common Sense Media's 2021 State of Kids' Privacy report, which evaluated 200 of the most widely used apps and services for children. That figure has climbed steadily since Common Sense first started tracking it in 2018, when 92% of evaluated products made the same disclosure. Below is what that 97% actually includes, how many apps cross the line into an outright COPPA violation, and which third parties end up with the data.

What percentage of kids' apps collect personal data?

97% of the 200 kids' tech and edtech products Common Sense Media evaluated in 2021 disclosed in their privacy policies that they collect personally identifiable information (PII) from users. Common Sense's evaluation framework treats not collecting PII as the "better" practice, so a 97% collection rate means only a small handful of the most popular children's products avoid gathering personal data at all.

Share of kids' tech and edtech products disclosing each data practice (Common Sense Media, 2021) Collect PII97%Usage data96%Behavioral data77%Third-party tracking55%Geolocation51%Sensitive data38%

Figure 1: Six data-collection practices disclosed across the 200 kids' tech and edtech products evaluated in 2021. Source: Common Sense Media, 2021 State of Kids' Privacy.

97 percent of kids tech and edtech products disclose collecting personal data 97% of kids' tech and edtech productsdisclose collecting personal data

Common Sense's evaluators, a team of trained privacy attorneys and privacy experts, reached this figure by reading and scoring the actual privacy policies and terms of use of 200 apps and services determined to be the most popular with parents, teachers, schools, and districts, based on interviews and App Store and Google Play download totals. If your app or site collects any personal information from users, a privacy policy generator built around COPPA and state child-privacy disclosures is the fastest way to confirm the required notices are actually in the document before a parent, teacher, or regulator goes looking for them.

How has kids' app data collection changed since 2018?

The share of kids' tech and edtech products disclosing that they collect PII has risen every year Common Sense Media has tracked it: 92% in 2018, 95% in 2019, 96% in 2020, and 97% in 2021. The trend has moved in one direction only, even as new privacy laws such as the CCPA and CPRA pushed companies to update their policies.

Share of kids' tech and edtech products disclosing PII collection, 2018 to 2021 0306090120%201820192020202197%

Figure 2: Four straight years of the same direction of travel. Source: Common Sense Media, 2021 State of Kids' Privacy.

That rise in collection has come alongside a rise in transparency about it, which is not quite the same thing as a rise in privacy protection. Common Sense's own rating system sorted products into a "Pass" or "Warning" tier based on whether they met a minimum set of privacy safeguards, and by 2021 only 26% of the 200 products earned a Pass, up from 10% in 2018. That still left 74% with a Warning rating, meaning three out of four of the most popular products used by children did not meet Common Sense's minimum privacy recommendation threshold that year.

How many kids' apps illegally collect or share data under COPPA?

57% of the 5,855 child-directed Android apps analyzed in "Won't Somebody Think of the Children? Examining COPPA Compliance at Scale," a 2018 study by researchers from UC Berkeley, the International Computer Science Institute, the University of Calgary, and Stony Brook University, were potentially violating the Children's Online Privacy Protection Act. The researchers used automated dynamic analysis, actually running each app and monitoring its network traffic, rather than just reading source code, on apps drawn from Google Play's Designed for Families program.

Figure 3: The compliance test behind the 57% figure. Source: Reyes et al., "Won't Somebody Think of the Children?" Proceedings on Privacy Enhancing Technologies, 2018.

The violations were not evenly spread across one type of misstep. The study found clear violations sharing a child's location or contact information without consent in 4.8% of apps, non-compliant transmission of personal information without reasonable security measures in 40.0% of apps, and potential violations from sharing persistent identifiers with third parties for prohibited purposes in 18.8% of apps. Google's own Safe Harbor certification program for COPPA compliance did not meaningfully change these odds: the researchers found potential violations were just as prevalent among apps built with certified, self-regulating SDKs as among the rest of the corpus.

Which third parties end up with data collected from kids' apps?

Of the 5,855 apps in the 2018 Berkeley and ICSI study, 235 actually accessed a device's precise GPS coordinates, and 184 of those went on to share that location data with an outside company. The most popular destinations for that data were a handful of advertising and location-analytics domains that received it from dozens of different apps each.

Domains most often receiving location data shared by children's apps (Reyes et al., 2018) mopub.com85aerserv.com84skydeo.com80youappi.com80inner-active.mobi76

Figure 4: Five ad-tech domains, hundreds of children's apps. Source: Reyes et al., PoPETs 2018, among the 184 apps that shared location data with a third party.

MoPub, the single most common destination, stated in its own terms of service at the time that its service should not be used by any app that collects data from anyone under 13, which the researchers flagged as a likely conflict given how many child-directed apps were using it anyway. A more recent and narrower audit points the same direction: Pixalate's Q2 2025 Verifiable Parental Consent Failures report found that 42% of the child-directed apps it reviewed shared a device's IP address in the real-time ad-bidding auction and 40% shared a device ID, numbers covered in more depth in our children's online privacy statistics roundup.

What does a "Pass" or "Warning" privacy rating actually measure?

Common Sense Media's rating is not a simple collect-or-don't-collect scorecard. A product earns "Pass" only by clearing a minimum bar across several privacy categories at once, including data collection, data sharing, and data security, so the 26% Pass rate reflects broad compliance rather than any single question.

2021 privacy rating outcomes across 200 kids tech and edtech products 7426Warning rating74Pass rating26

Figure 5: Three out of four of the most popular kids' apps and edtech products fell short of Common Sense Media's own minimum bar in 2021. Source: Common Sense Media, 2021 State of Kids' Privacy.

The gap between "collects data" and "collects data responsibly" is the whole story here. Nearly every popular kids' app collects something, but only about a quarter of them do it in a way that clears an independent privacy reviewer's minimum threshold.

How has research on kids' app data collection changed over time?

Large-scale, independently sourced audits of kids' app data collection are rarer than they should be, but the ones that exist tell a consistent story across nearly a decade.

Figure 6: Six years of measurement, one direction of travel. Sources: Reyes et al. (2018), Common Sense Media (2018, 2021), Pixalate (2025), Federal Register (2025).

Data collection practiceShare of apps/productsSource and year
Disclosed collecting personal data (PII)97% of 200 productsCommon Sense Media, 2021
Potentially violating COPPA57% of 5,855 appsReyes et al. (PoPETs), 2018
Collected usage data (IP, device ID)96% of 200 productsCommon Sense Media, 2021
Shared persistent identifiers with a prohibited third party18.8% of 5,855 appsReyes et al. (PoPETs), 2018

The Bottom Line

The headline number here, 97% of the most popular kids' tech and edtech products collecting personal data, is not really the surprising part. Nearly every app and service needs to collect some information to function. The more useful number is the 57% figure from the 2018 Berkeley and ICSI study: more than half of the child-directed apps examined crossed from ordinary data collection into a potential legal violation, usually because a bundled third-party SDK shared identifiers without the verifiable parental consent COPPA requires. Common Sense Media's own tracking shows the same pattern from a different angle: collection keeps climbing, transparency has improved, but only about a quarter of products actually meet a minimum privacy bar. For any site or app that might reach an audience under 13, the fix is not collecting less data than the industry average. It is making sure every category of data collected, and every third party that receives it, is actually disclosed and actually consented to.

Frequently Asked Questions

What percentage of kids' apps collect personal data? 97% of the 200 most popular kids' tech and edtech products evaluated in Common Sense Media's 2021 State of Kids' Privacy report disclosed in their privacy policies that they collect personally identifiable information from users, up from 92% in 2018.

How many children's apps illegally collect data under COPPA? 57% of 5,855 child-directed Android apps analyzed by researchers from UC Berkeley, ICSI, and other institutions were potentially violating COPPA, mainly through third-party SDKs that collected data without verifiable parental consent, according to the 2018 study "Won't Somebody Think of the Children?" published in Proceedings on Privacy Enhancing Technologies.

What types of data do kids' apps collect most often? Usage data such as IP addresses and device identifiers topped the list at 96% of products in 2021, followed by behavioral data at 77% and third-party tracking technology at 55%, per Common Sense Media's 2021 State of Kids' Privacy report.

Do kids' apps share collected data with third parties? Yes. 55% of the 200 products Common Sense Media evaluated in 2021 disclosed using third-party tracking technology, and the 2018 Berkeley and ICSI study found that 18.8% of 5,855 child-directed apps shared persistent identifiers with third parties whose own terms of service explicitly prohibit that use in children's apps.

Where the Numbers Come From

  1. Common Sense Media. Kelly, G., Graham, J., Bronfman, J., & Garton, S. (2021). "2021 State of Kids' Privacy." Evaluation of 200 kids' tech and edtech products' privacy policies across 155 questions by trained privacy attorneys and privacy experts.
  2. Reyes, I., Wijesekera, P., Reardon, J., Elazari Bar On, A., Razaghpanah, A., Vallina-Rodriguez, N., & Egelman, S. (2018). "Won't Somebody Think of the Children? Examining COPPA Compliance at Scale." Proceedings on Privacy Enhancing Technologies, 2018(3), 63-83. Dynamic analysis of 5,855 child-directed Android apps, tested November 2016 through March 2018.
  3. Pixalate. (2025). "Verifiable Parental Consent (VPC) Failures in Mobile Apps Report, Q2 2025." 1,136 of 1,149 manually reviewed likely child-directed apps lacked VPC, published September 2025.
  4. Federal Trade Commission. "Children's Online Privacy Protection Rule: Not Just for Kids' Sites." Guidance on which apps and sites COPPA covers, including the actual-knowledge standard.

Note: All figures verified as of July 2026. Common Sense Media's 2021 State of Kids' Privacy report remains the most recent full-scale evaluation of its kind at this sample size; figures are refreshed at least twice a year to track newer audits such as Pixalate's quarterly reports as they are published.