All articles
Image: The Innocent Souls Foundation
January 2026Adriana Jones · Founder, The Innocent Souls Foundation

Children's data is a breach multiplier, and we keep pretending it isn't

When breaches involve children's data, the damage is longer, deeper, and more difficult to unwind. Yet most impact models still treat it as a smaller version of adult data.

Share Share on LinkedIn

When a data breach happens, the first questions are almost always the same.

How many records were exposed. What type of data was involved. What is the likely financial impact.

What is rarely asked, at least not seriously enough, is who the data belonged to and how long the harm will last.

When breaches involve children''s data, the damage is not just greater. It is longer, deeper, and more difficult to unwind. Yet most breach impact models still treat children''s data as a smaller version of adult data, rather than something categorically different.

That is a dangerous blind spot.

Children''s data is a breach multiplier. It amplifies harm over time, across systems, and across stages of life. And the way we currently assess cyber incidents systematically undervalues that risk.

A child cannot meaningfully consent to how their data is collected, stored, reused, or combined. They also cannot anticipate how that data might be used against them years or decades later. When a breach exposes a child''s identity, behavioural data, location history, or family connections, the harm does not peak and fade the way adult breaches often do. It compounds.

Identity data belonging to a child is valid for far longer than adult data. Names do not change. Birth dates do not change. Family relationships remain linkable. This makes children''s data uniquely valuable to criminals and uniquely difficult to remediate once exposed. You cannot reset a childhood.

There is also a temporal asymmetry that rarely features in incident response planning. A breach involving adults tends to cause immediate harm. Fraud. Scams. Account takeover. With children, the harm is often delayed. The data sits quietly, waiting until the child grows older, enters financial systems, applies for education, employment, or services.

By the time the damage surfaces, the breach is long forgotten.

This is where our models fail us.

Most breach impact frameworks focus on short-term financial loss, regulatory exposure, or reputational damage. They do not account for long-tail harm, where consequences unfold over decades rather than quarters. They do not capture the psychological impact of knowing your data has been exposed since childhood. They do not capture the erosion of autonomy when identity and behavioural data has been circulating beyond your control for most of your life.

Children''s data also tends to be richer than we admit. It is rarely just a name and a date of birth. It often includes behavioural data, educational records, health information, usage patterns, and inferred attributes. When platforms designed for children or families are breached, the resulting dataset can be extraordinarily intimate. And because children''s platforms often integrate with parents'' systems, the blast radius expands. One breach becomes a family-level exposure. Social graphs, household patterns, and trust relationships are all pulled into scope.

From a security perspective, this should radically change how we prioritise controls. From a governance perspective, it should change how we assess materiality. From a moral perspective, it should change how we talk about responsibility. Yet too often, breaches involving children''s data are assessed using the same playbook as adult breaches. The same timelines. The same severity thresholds. The same remediation assumptions. This creates a false sense of proportionality.

In Australia, we are beginning to acknowledge this gap through privacy reform discussions and children-specific codes. That is important. But recognition alone is not enough if the underlying breach logic remains unchanged.

If we continue to treat children''s data breaches as lower-impact because children do not yet participate fully in economic systems, we are misreading the risk entirely. The harm is not lower. It is deferred.

Security teams feel this tension acutely. They are asked to protect systems that were never designed with long-term harm models in mind. They are asked to justify controls using risk frameworks that discount future impact. They are asked to respond to incidents where the true cost cannot be quantified in a reporting cycle.

Calling children''s data a breach multiplier is not about fear. It is about accuracy.

When data belongs to a child, the window of exposure is longer, the opportunity for misuse is broader, and the consequences are harder to contain. That should change how we design systems, how we classify incidents, and how seriously we treat ''minor'' breaches involving young users.

Protecting children''s data is not just a privacy issue. It is a security issue with a very long memory.

If we fail to recognise that now, we will keep rediscovering it later, when the people affected are old enough to finally understand what was taken from them.

Free CyberSafety training for every Australian family

Video lessons, downloadable guides and completion certificates — all free, forever.

Start free training